VideoDiary

Privacy policy

Pre-launch draft, 19 July 2026. VideoDiary is in development and not yet released; this policy is published early so the bar is public before the app is. It describes what the app actually does — features that are designed but not yet built are listed separately under "Planned features". An effective date will be added before launch. Questions: support@videodiary.app.

The short version

VideoDiary is a video diary. What you record is about as personal as data gets, so the app is built local-first:

  • Your videos never leave your iPhone. No feature sends your video or audio to us or to any AI service, and no feature ever will.
  • By default, nothing leaves your iPhone. Out of the box, transcription and titles run entirely on-device using Apple's on-device speech and language models.
  • Connectors send data only when you tap Send. You can optionally send individual entries — as text, never video or audio — to services you connect yourself: Google Sheets, GitHub, Notion, a folder you choose (including iCloud Drive), or a webhook you control. Nothing is ever sent automatically — not new entries, not edits. Every send is a tap you make. Connectors are part of Premium, an optional subscription; the diary itself never needs it.
  • We run no servers that store or read your content. We can't read your diary. We don't want to.
  • No accounts, no ads, no analytics, no tracking, no selling data. None of it.
  • Delete means delete. Deleting an entry removes everything derived from it. Deleting the app removes everything.

The rest of this policy is detail on the above. There are no surprises hidden further down.

What the app stores on your device

Everything the app knows lives on your iPhone, protected by iOS's built-in file encryption and an app-level Face ID/passcode lock that turns on automatically once your diary has content (you can turn the lock off in Settings — the choice is yours):

  • your video recordings and their audio;
  • transcripts, including your corrections;
  • entry titles, dates, and durations;
  • if you use connectors: a local record of what was delivered where (which itself never contains diary content).

We — the developer — have no access to any of this. There is no account and no server-side copy.

Backups: by default your entries are excluded from iCloud and computer backups, so your diary can't leak through a backup you forgot about. You can include them in Settings if you'd rather protect against losing your phone — we explain the trade-off right where the switch is.

In the background: two things can keep running when you leave the app, both entirely on your phone:

  • Playback. If an entry is playing when you switch apps, its audio keeps playing and the standard media controls appear on your lock screen and in Control Center. While the app's Face ID/passcode lock is on, those controls deliberately say only "Diary entry" — never an entry's real title — so your lock screen gives nothing away.
  • Recording. If you switch apps mid-recording, the recording no longer stops. iPhones don't let apps use the camera in the background, so camera capture pauses and the saved recording shows a blurred still of the last captured frame while the app keeps recording audio only underneath until you come back (video resumes automatically) or until a 30-minute limit ends the entry safely. iOS shows its standard microphone indicator the entire time.

What leaves your device, and when

Default mode: nothing. Transcription and titles run entirely on-device using Apple's frameworks; Apple states its on-device models do not send your content to Apple. Zero diary content crosses the network — and because nothing is ever sent without a tap from you, there is no background activity to audit. (Anyone can verify this from outside the app with standard network-inspection tools; we welcome that.)

If you connect your own services (optional): the app offers connectors — destinations you already use: Google Sheets, GitHub, Notion, a folder you pick (including iCloud Drive folders), or a webhook URL you control — that you can send an entry to as text. You can set up several, including two of the same service (say, a work and a personal GitHub repository), and you name each one so it's always clear where a tap will send.

Connecting a destination sends nothing by itself. Nothing is ever sent automatically: an entry's transcript, title, date, and duration go to a destination only when you tap Send on that entry for that destination (there's a moment to undo before anything actually leaves), or when you press one of the counted catch-up buttons in Settings that say exactly what they will send ("12 entries have never been sent here" → Send all). Everything travels directly from your iPhone, under your own account or token.

  • Never the video. Never the audio. Connectors physically cannot send them.
  • Entries marked "Local only" are never sent, full stop.
  • If you edit an entry after sending it, the edit is not sent automatically. The entry simply shows "edited since last send" for that destination until you choose to send the update — so what each service holds is always something you explicitly pushed.
  • Removing a connector stops nothing mid-flight because nothing is ever in flight on its own; it simply removes the destination from your list. Sign-ins you've granted stay on your iPhone so re-adding is easy, and each can be removed individually in Settings (deleting the app removes them all). Notion is the exception: its sign-in belongs to one connector and is deleted with it.
  • Your entries travel straight from your phone to the service you chose — no server of ours ever sees your content. One narrow exception on the sign-in side: connecting GitHub or Notion exchanges a sign-in code through a small relay we run, because those services require an app secret for that step that can't live in the app itself. The relay sees only the sign-in handshake — never an entry, never a transcript — and stores nothing.
  • Once delivered, that copy lives in your account under your agreement with that service (your Google or GitHub terms, your webhook). We are not a party to it — choosing the destination is the point. One honest specific: GitHub keeps history, so a file you later delete there still exists in the repository's older versions.
  • For Google Sheets, the app's access is limited to spreadsheets it created itself — it cannot see or touch the rest of your Google Drive.
  • For Notion, access is limited to the pages you explicitly share with VideoDiary during sign-in — Notion's own screen does the choosing. Entries become pages in a database the app creates under a page you pick, and sending an edited entry updates its page in place.
  • The Folder connector is the quiet one: it writes each sent entry as a markdown file into a folder you picked, and makes no network requests at all. If that folder syncs somewhere — an iCloud Drive folder, an Obsidian vault — that's your folder doing what it already does, under your own Apple account. Filenames are content-free (date and an ID, never the title).
  • When you do send an update, destinations handle it sensibly: webhooks get an update event, GitHub's file is updated in place (its history keeps prior versions), and Sheets gets a corrected row marked with the same entry ID (the built-in "Latest" sheet shows only the newest version of each entry).
  • The app remembers, on your phone only, what it has already sent to each destination — so each entry can show you exactly where it was delivered (for example, which row of your spreadsheet), removing and re-adding a destination never creates duplicates, and the app can tell you when a destination holds an older version. This record contains no diary text and is deleted with the entry.

If we ever add features that send your content to an AI provider, they will be separately opt-in, disclosed in-context before the first byte moves, and this policy will be updated before the change takes effect — with the provider held to a strict bar (no training on your data, bounded retention, independent security audits, a signed data-processing agreement).

What we never do

  • No advertising, and no advertising SDKs.
  • No analytics or tracking SDKs; no fingerprinting; no App Tracking Transparency prompt because there is nothing to consent to.
  • No selling, renting, or sharing your data with anyone. The only parties that ever receive diary content are the services you connect.
  • No human on our side can read your entries — architecturally, not just by policy.
  • No use of your diary content to train any model, ours or anyone else's.

Your rights and controls

Because your data lives on your device, you exercise most rights directly:

  • Access / portability: export any entry (video and/or transcript) via the iOS share sheet at any time.
  • Rectification: edit any transcript or title in place.
  • Erasure: delete any entry — this removes the video, audio, transcript, thumbnail, and everything derived from it, including the app's local record of where it was sent. Deleting the app removes everything. There is no server-side copy for us to erase. Copies you routed to connected services live in your own accounts there and are deleted there — we have no reach into your Google Drive or GitHub, which is rather the point.
  • Withdraw consent: remove any connector at any time (Settings) — or exclude individual entries with "Local only". And because no connector ever sends on its own, simply not tapping Send is itself complete control.

If you are in the UK/EEA: the app processes your diary on your device to provide the features you invoke. Where a feature moves data off your device — a connector you configured — the legal basis is consent (Art. 6(1)(a) GDPR), given when you enable that feature and withdrawable at any time as above; diary content may include special-category data you choose to record about yourself, processed under explicit consent (Art. 9(2)(a)). Connector transfers go to services you chose under your own agreements with those providers; we operate no server-side processing of your content. You may lodge a complaint with your supervisory authority (the ICO in the UK). Complaints or questions to us: support@videodiary.app.

If you are in California: we do not sell or share personal information as defined by the CCPA/CPRA, and we collect none ourselves.

Payments

Premium is an optional subscription (monthly or yearly) that unlocks connectors. The diary itself — recording, transcription, titles, lock, backups — is complete without it, and paying changes nothing about where your diary lives.

The subscription is a standard in-app purchase through Apple's App Store, and may start with a free trial — Apple shows the exact terms before you confirm, and cancelling during the trial costs nothing. Apple processes the payment: we never see your card details, billing address, or Apple ID. The app checks whether your subscription is active on-device using Apple's StoreKit; that check involves no VideoDiary server (we don't run one) and carries nothing about your diary. If the subscription lapses, sending stops until you resubscribe — your entries, your configured connectors, and the record of what was already sent all stay on your iPhone, untouched.

(The app is not yet released, so there is nothing to buy today; this section describes the subscription as built.)

Planned features

Designed but not yet in the app. Each will ship together with its update to this policy, built to the bar stated here:

  • iCloud Archive — an optional, off-by-default way to move older videos into your own iCloud to save phone storage. Each video will be encrypted on your iPhone before upload, with a key that lives only in your iCloud Keychain — so what sits in iCloud is unreadable to us and to Apple. Transcripts, titles, and thumbnails stay on your phone.
  • Insights — generated on-device by Apple's models. No diary content will leave the phone for this.
  • Correction learning — a personal vocabulary learned from your transcript corrections (e.g., names the transcriber mishears), stored on-device only and used only to improve your own transcriptions.

Children

VideoDiary is not directed at children under 13 (or the applicable age of digital consent in your region) and we do not knowingly process their data.

Security

In brief: all content is encrypted at rest with iOS Data Protection; a Face ID/passcode app lock is on by default once your diary has content (you can turn it off in Settings), and while the lock is on, the app switcher shows only an opaque cover — no diary content; all network traffic uses TLS; we operate no server that touches your content; connector credentials live in the iOS Keychain on your device. No system is perfectly secure, but our architecture is designed so that the most valuable data — your recordings — never exists in readable form anywhere but your device.

Changes to this policy

We will not weaken the commitments above without your explicit, informed consent in the app — a policy update alone is not consent. Material changes are announced in-app before they take effect, with the option to keep using local-only mode.