Privacy Policy

Strong Feminine Aura

Effective date: 2026-09-24

This policy explains how this application handles information and how to contact us about privacy.

Information we process

Strong Feminine Aura stores journal entries, mood tags, categories, dates, goals, steps, a chosen display name, profile photo, language choice, saved articles, reminder preferences, cached editorial content and pending changes on the device. The installation secret is generated on the device and stored in Keychain. When the app connects, it sends the secret in an HTTPS request header and sends journal and goal data to the service. The service stores a SHA-256 digest of the secret, journal entries, goals, steps and their update timestamps in PostgreSQL. Public article, glossary and affirmation requests do not require the secret. Railway, our hosting provider, receives requests and may process IP addresses, request metadata and infrastructure logs. We do not ask for an account, password or email address in the app. The email below is a privacy contact, not an in-app data collection feature.

How we use information

Device data makes the journal, goals, profile, reminders, favorites and offline reading work. The backend stores installation-scoped entries and goals so the app can synchronize changes and restore them on the same installation while its secret remains available. Update timestamps resolve conflicting changes by last write. Public editorial routes provide daily affirmations, articles and glossary terms in German or English. Request metadata is processed by hosting infrastructure to operate and protect the service.

Service providers and sharing

We use Railway to host the application service and PostgreSQL database; Railway may handle network requests, database storage and infrastructure logs as a service provider. We do not add analytics, advertising SDKs, email delivery, social sign-in or third-party content APIs. The app does not upload the chosen profile photo or display name. We do not publish private journal or goal records.

Data retention

Journal and goal records remain on the server until they are deleted, the installation is erased, or the service is discontinued. Individual deletions erase the entry or goal content and leave only an identifier and deletion timestamps in a server-side tombstone so offline clients can learn of the deletion. Deleting all data removes the installation's entries and goals and retains only a revoked digest of the old installation secret to prevent an old client from restoring deleted data. Local data remains until the user deletes it or removes the app. We do not set a fixed retention period for Railway infrastructure logs or provider backups because those periods are controlled by the provider and are not established in this product. Data in any provider backup may persist until that backup expires under the provider's practices.

Deleting your information

In Me, choose Delete all data and confirm while connected to the service. The app first requests deletion of this installation's server records, then removes its local records, profile photo and Keychain secret. If the request fails, the app keeps local data and reports the failure so the user can retry. Individual journal entries and goals can also be deleted; offline changes are queued for later synchronization. Removing the app deletes its ordinary local files, but Keychain behavior after uninstall is controlled by iOS and an uninstall cannot instruct the server to delete its copy. Without the original installation secret, the app cannot recover or identify that server copy. For privacy requests, contact illyaromanov565@gmail.com.

Permissions and your choices

Photo library access is used only when the user chooses a profile image; the selected image stays on the device. Notification permission is requested only if the user enables daily local reminders. Reminders are scheduled by iOS on the device and can be disabled in the app or iPhone Settings. The app does not request location, camera, microphone or contacts access. Permission choices can be changed in iPhone Settings.

Your privacy rights

You can view, edit and delete your journal and goals in the app and delete all data for the current installation in Me. You may contact illyaromanov565@gmail.com for questions or privacy requests. The service has no account identity; please do not send your installation secret by email. If the secret is lost, we may be unable to associate a server record with you. Applicable privacy rights depend on your location.

Security

The app uses HTTPS for service requests, stores the installation secret in iOS Keychain, and requires that secret for private API routes. The server stores its SHA-256 digest rather than the raw secret and restricts database queries to the installation identified by that digest. Local records are stored in the app's container. No security method eliminates all risk; protect access to your device and its backups.

Children’s privacy

Strong Feminine Aura is intended for adults interested in self-reflection and feminist learning, not for children. We do not design it to solicit children's personal information. If you believe a child has entered information, contact illyaromanov565@gmail.com.

Changes to this policy

We may update this policy when app features or processing change. The updated policy will be posted at this page with a new effective date. Material changes will be reflected in the app or this page before the changed processing is used. Contact illyaromanov565@gmail.com with questions.