Privacy Policy
Effective 23 August 2026
PDiary is operated by Panagiotis Vasiliou (“PDiary”, “we”, “us”), Ydras 17, Lemesos 3052, Cyprus. Privacy contact: vasiliou.panos@yahoo.com.
1. Local-first workspace data
PDiary is designed as a local-first practice workspace. Appointment, client, service, reminder, finance, planning, record, and Secretary content is stored on the user's device unless the user deliberately enables cloud sync, starts a purchase, or opens another external service.
PDiary does not send names, phone numbers, email addresses, diagnoses, ICD codes, appointment text, notes, record content, or Secretary message content to product analytics.
2. Optional product analytics
Product analytics is disabled by default. PDiary uses Google Analytics for Firebase only after the user explicitly selects Allow analytics. When enabled, analytics helps us understand installation and app-lifecycle activity, acquisition source or campaign, app version, country or region, feature adoption, free-allowance progress, paywall activity, and purchase-funnel outcomes.
Firebase may process an app-instance or installation identifier, device and app metadata, approximate location derived from network information, and privacy-safe interaction events. PDiary custom events use a restricted vocabulary and categorical or count parameters. They record that an action occurred, not the user's clinical or free-text content. Free-allowance measurements use counts or buckets from the app's real entitlement logic.
PDiary does not assign a Firebase user ID containing a person's name, email, phone number, or clinical identifier. Advertising storage, advertising user data, and advertising personalisation consent remain denied.
3. Optional performance diagnostics
When the user allows analytics, Firebase Performance Monitoring may process app start time, screen rendering, network-request latency and payload size, CPU or memory usage, app and device metadata, and IP address for country-level reporting. PDiary custom performance traces use fixed technical labels and do not include client, appointment, record, note, or Secretary content.
4. Subscriptions and purchases
Google Play Billing processes payment details directly. PDiary does not receive or store full card or bank details. RevenueCat helps PDiary retrieve subscription products and determine whether the pro entitlement is active.
RevenueCat and Google Play may process an opaque app user ID, product and entitlement identifiers, purchase, renewal, cancellation and expiration timestamps, price and currency, store environment, purchase history, and technical identifiers needed to validate and attribute subscriptions. While analytics is enabled, PDiary may provide RevenueCat with the opaque Firebase app-instance ID so subscription lifecycle events can be attributed to the same analytics installation.
The internal business analytics store keeps daily subscription aggregates and salted one-way hashes rather than raw RevenueCat customer identifiers. Sandbox licence-test purchases are kept separate from production revenue.
5. Advertising attribution
PDiary links its app Google Analytics property to Google Ads to measure campaign, source, medium and downstream conversion performance. Personalised advertising is disabled for this link. Google Ads, Google Play, Firebase/GA4, and RevenueCat totals may differ because they use different identities, processing times, consent states, and attribution windows.
6. Optional cloud and external services
Cloud sync is optional. When enabled, workspace data is sent to the configured PDiary cloud endpoint so the user's own devices can sync; a private sync key protects access.
When the user deliberately opens SMS, WhatsApp, Viber, payment links, booking links, or external AI, the relevant provider processes the information needed for that action under its own terms. PDiary does not place workspace text into analytics events.
7. Purposes and legal bases
Optional Firebase Analytics and Firebase Performance processing is based on the user's consent. Consent can be withheld or withdrawn without losing access to PDiary. Processing needed to complete a purchase and provide the PDiary Pro entitlement is necessary to perform the subscription contract. Limited records may also be processed or retained where necessary for security, dispute resolution, or a legal and accounting obligation.
8. Retention
- Local workspace data remains on the user's device until the user deletes or replaces it.
- The current GA4 app property retains event-level data for 2 months and user-level data for 14 months. These controls do not remove most standard aggregated reporting.
- Firebase Performance applies its own service retention periods to performance and installation-associated data.
- RevenueCat and Google Play subscription records are kept for as long as needed to provide the subscription and meet applicable legal, accounting, fraud-prevention, and dispute-resolution obligations, then deleted or de-identified where applicable.
- Internal privacy-safe analytics snapshots, daily aggregates, webhook deduplication records, and inactive customer hashes are retained for 24 months, then deleted automatically. Active-subscription hashes remain while needed for current subscription reporting and enter the same 24-month period after becoming inactive.
9. User choices and privacy requests
On first use, users can select Allow analytics or Not now. Analytics and Performance remain off unless permission is given. Users can later turn privacy-safe product analytics off or on in PDiary settings. Turning it off stops future PDiary product analytics and performance collection on that installation. Records already processed by providers remain subject to their retention and deletion rules. Subscription validation and transaction records needed to provide PDiary Pro may still be processed.
Users can export backups, import their own data, disable cloud sync, and delete local workspace data from app settings. For step-by-step deletion instructions and details about what is deleted or retained, see the PDiary data-deletion page. To request access, correction, objection, restriction, or deletion relating to provider-held or internal data, contact vasiliou.panos@yahoo.com. Because PDiary does not use an analytics user ID tied to an email or account, some anonymous installation data may not be technically identifiable as belonging to a particular requester.
Users in the European Economic Area may also contact their local data-protection authority. In Cyprus this is the Office of the Commissioner for Personal Data Protection.
10. Service providers and international processing
PDiary uses service providers including Google Firebase and Google Analytics, Google Play and Google Ads, RevenueCat, and Netlify. These providers process data on PDiary's behalf under their applicable service, privacy, and data-processing terms. They may process data outside the user's country using the safeguards described in those terms, including applicable contractual transfer safeguards.
11. Security
Provider traffic uses encrypted HTTPS transport. The internal analytics dashboard is invite-only and role-restricted. Secrets are stored server-side and are not included in browser code. No method of storage or transmission is completely risk-free.
12. Adults only
PDiary is intended only for users aged 18 and older and is not designed for children. We do not knowingly offer the service to children. If you believe that a child's data has been processed contrary to this policy, contact vasiliou.panos@yahoo.com.
13. Changes and contact
We may update this policy when PDiary features, providers, or legal requirements change. The effective date above will be updated. Questions and privacy requests: vasiliou.panos@yahoo.com.