Welcome to Grateful Daily (also operating under the visual theme name "Morning Sanctuary"). We are deeply committed to respecting and protecting your personal privacy. This Privacy Policy outlines our strict data handling practices and explains how your information is kept entirely safe and secure while using our mobile application.
Our Core Philosophy (Zero-Knowledge & Full Privacy): We believe your personal reflections, blessings, and daily thoughts belong strictly to you. Our app is architected so that we (the developers) have absolutely zero access, visibility, or control over your personal journal entries.
1. Information Collection and Use
Unlike traditional apps that harvest data on remote clouds, Grateful Daily prioritizes absolute device localization:
- Personal Journal Data: Any gratitude notes, blessings, mental reflections, or mood symbols you record in the app are saved exclusively in your device's private local storage. This data is never transmitted to our servers because we do not operate any external storage servers for your content.
- Biometric Data: When you enable Fingerprint or Face Login to lock your sanctuary, the authentication process is entirely managed by your device's native secure operating system framework. The app never intercepts, tracks, views, or stores your biometric fingerprints or facial vectors.
2. Advanced Cryptography & Client-Side Encryption
To ensure that even your backups are completely safe from prying eyes, the app implements a robust security model:
- Client-Side Encryption: Before any backup file leaves your device, it is heavily encrypted client-side using military-grade AES-GCM (Advanced Encryption Standard - Galois/Counter Mode).
- Secret Passphrase: The encryption is driven entirely by your custom Secret E2EE Passphrase. This phrase is strictly stored on your own device. If you lose this passphrase, your backups cannot be unlocked by anyone—including us.
3. Cloud Integration & Permissions
Grateful Daily offers an optional feature allowing you to sync and restore your journal using your personal Google account. To achieve this safely, the app requests minimal scoped access:
- Google Drive Scopes: The app utilizes the restricted
drive.file and drive.appdata API scopes. This grants the app permission *only* to create its own hidden configuration folder and manage the encrypted backup files created by the app itself.
- No General Access: The app cannot read, modify, or delete any other files, photos, or documents residing in your personal Google Drive account.
4. Third-Party Services
The app leverages stable core industry infrastructure provided by Google to run reliably:
- Google Play Services: Utilized for background reliability, licensing, and security infrastructure.
- Google Drive API: Utilized exclusively to stream your user-triggered encrypted backup blobs safely to your personal cloud.
5. Data Retention and Deletion
Because your data lives locally, you have total autonomy over its deletion:
- Uninstalling the app from your mobile device immediately purges all local databases, settings, and mood tracking history.
- You can delete your cloud-synchronized backups at any time directly through your Google Drive app management dashboard or by wiping the backup within the application.
6. Changes to This Privacy Policy
We may update our Privacy Policy periodically to reflect app updates or regulatory adjustments. Any modifications become effective immediately upon being updated within the app configuration or published online. We encourage you to review this document occasionally to stay informed.
7. Contact Us
If you have questions, feedback, or need clarification regarding our zero-knowledge security infrastructure, please contact us: