Privacy Policy
هذه الصفحة بالإنجليزية. إذا اختلفت عن النص الإسباني فالنسخة الإسبانية هي المعتمدة.
Fecha de entrada en vigor / Effective date: 8 October 2026
Operator: Matej Mozola · Spanish NIE/NIF: Z2770421F · Address: Calle Felix Rodriguez de la Fuente 11, 4I, 03182 Torrevieja, Alicante, Spain · Contact: hello@diarioautonomo.es · Website: https://diarioautonomo.es
1. Controller and scope
Matej Mozola controls personal data used to operate Diario Autónomo, accounts, support and online services. The basic diary works without an account. This policy describes the intended production implementation and must match the services actually deployed.
2. Data categories
Accounts: verified email, internal user ID, securely hashed password, sessions and support requests. Subscriptions: store transaction identifiers, product, entitlement status and verification records; no full payment-card details. Security: minimal IP addresses, timestamps and technical logs. Diagnostics: crash and performance data if Firebase Crashlytics/Performance are enabled. On device: diary entries, amounts, categories, tax hints, professions, time records, invoices, receipts, images/PDFs, settings and local access controls. Receipts may include third-party personal data.
3. Local-first processing
Diary entries and attachments are primarily stored on your device and are not routinely synchronized to our servers. The free diary does not require registration. You control local exports and recipients. Removing the app, clearing its storage or losing the device may cause data loss.
4. Purposes and legal bases
Accounts, purchase verification, requested support and contracted features: GDPR Article 6(1)(b). Proportionate security and fraud prevention: legitimate interests, Article 6(1)(f), subject to balancing. Legal obligations: Article 6(1)(c). Optional analytics and tracking requiring consent: Article 6(1)(a) and applicable cookie rules. User-initiated scans and backups are processed to provide the requested feature, with transparency about external providers. Not all optional processing necessarily has the same legal basis.
5. AI document scanning
When you request a scan, the image/PDF and necessary processing data travel over encrypted connections through our Hetzner backend in Germany to OpenAI. Our backend processes document content transiently in memory without persisting or logging it. OpenAI has separate retention practices: abuse monitoring logs may contain content and be retained up to 30 days by default; some endpoints may store application state. We cannot promise immediate deletion across provider systems. Check amounts, dates, currencies and categories; no automatic foreign-exchange conversion is guaranteed. Documents may include third-party data.
6. Cloud backups
Premium supports manual and automatic ZIP backups to your own Google Drive or Apple iCloud. Diario Autónomo does not apply additional ZIP encryption before upload. Anyone obtaining access to the archive may read financial information and documents. Provider security and terms also apply. Deleting a Diario Autónomo account does not delete your Drive/iCloud archives; you manage them yourself.
7. Recipients and transfers
Services include Hetzner (German backend hosting), OpenAI (AI), Google (Play, Drive, Firebase and website Analytics), and Apple (App Store and iCloud). Contracting entities, controller/processor roles, sub-processors and agreements must be confirmed in internal records. Transfers outside the EEA may occur and require valid adequacy decisions, standard contractual clauses or other lawful safeguards. We do not claim all processing stays in the EU.
8. Diagnostics and website analytics
The mobile app plans Firebase Crashlytics for troubleshooting, subject to lawful configuration and data minimization. Optional Firebase Analytics will not run without an appropriate consent mechanism where required. Website Google Analytics 4 will not set non-exempt analytics cookies or identifiers before consent; visitors can reject and withdraw consent.
9. Retention
On-device data stays until you delete it. Account data remains while active. Intended policy: review and possible deletion after three years of inactivity, with advance notice and no automatic deletion of active subscribers. Ordinary security logs: 30 days, except justified incident/legal holds. Records subject to legal obligations or claims may be retained with restricted access. Providers have their own contractual/configured retention periods.
10. Your rights
Subject to applicable conditions, you may request access, correction, erasure, restriction, objection, portability, withdraw consent and exercise rights concerning automated decisions. Contact hello@diarioautonomo.es or the contact form. We may reasonably verify identity and respond within statutory deadlines. You may complain to the Spanish Data Protection Agency: https://www.aepd.es.
11. Account deletion
The primary deletion flow is in-app: after backend deletion succeeds, the app erases local diary data and attachments, with safeguards for partial failures. If you cannot access the app, use https://diarioautonomo.es/delete-account or email us. A website request can delete server records but cannot remotely wipe an offline device. Drive/iCloud backups remain yours. Deleting an account DOES NOT cancel an Apple/Google subscription.
12. Security, children and changes
Security includes email verification, hashed passwords, access controls and encrypted transport. Biometric templates are handled by the operating system, not collected by us. No system is perfectly secure. The app primarily targets adults/self-employed professionals, though individuals may use it; it is not designed for children. Material changes will be notified when required. Current version: https://diarioautonomo.es/en/privacy-policy.
Diario Autónomo