Quillver Privacy Policy
Effective September 23, 2026
What the app stores
Quillver stores the following on your device, in storage private to the app:
- Your entries: titles, text, dates, and optional details such as mood and mood color.
- Photos you attach to entries. Photo files are kept exactly as you added them, including any information embedded in the file such as the capture time or location.
- Your settings.
- A small diagnostic log (see below).
How your data is protected
- Your entries, photos and settings are kept in Quillver’s private app storage, which Android does not let other apps read.
- Quillver cannot use the internet, so there is no server to break into and nothing to intercept on its way anywhere.
- On most Android devices, storage is encrypted and unlocked with your screen lock. Setting a screen lock protects your journal along with the rest of your phone.
- App lock, described below, adds a check before the app opens. It does not encrypt anything.
- Backup and export files are not encrypted. Keep them somewhere you trust.
App lock
Quillver has an optional “App lock” setting that asks for your device’s own screen lock (fingerprint, face, PIN, pattern or password) before the app opens. This is a privacy screen, not encryption: your entries are stored on disk exactly the same way whether App lock is on or off, so it protects against someone picking up your unlocked phone, not against someone with direct access to the device’s storage.
Permissions and network access
Quillver requests no Android permissions. In particular it does not have the internet permission, and it does not access your location, contacts, microphone, or photo library. Photos reach the app only when you pick or capture one yourself, through the system file picker or your camera app.
When data leaves the app
Data leaves Quillver only when you choose to send it somewhere:
- Backups and exports. “Back up to file” and the Markdown export write a file to a location you choose. That file is not encrypted; anyone who can read it can read your journal, so keep it somewhere you trust.
- Sharing. Sharing an entry hands its text to the app you pick in the Android share sheet. What happens next is governed by that app.
- Links. Tapping a link in an entry opens it in your browser.
- Debug log. “Save debug log” writes the diagnostic log to a file you choose, for example to attach to a bug report. Nothing is sent automatically.
Android backup
If you have turned on backup in your device’s Android settings, Android may include Quillver’s entry database in your device backup, which is stored in your own Google account, and may copy it when you transfer to a new device. Attached photos are not included. This backup is operated by Google under Google’s privacy policy, is controlled from your device settings, and is not accessible to the developer.
Diagnostic log
To help diagnose problems, Quillver keeps a short rotating log on your device (at most about 512 KB). It records technical events such as screen changes, entry ids, counts, text lengths, and crash details. It never records what you write: no titles, entry text, prompts, or search terms. The log stays on your device unless you save and share it yourself.
Google Play
If you install Quillver from Google Play, Google may collect installation, usage, and crash statistics according to your device settings and provide them to the developer in aggregate. This happens outside the app, under Google’s privacy policy, and never includes your journal content.
Deleting your data
Deleted entries go to the trash inside the app, where you can remove them permanently; entries left there are deleted for good after 30 days. Uninstalling Quillver, or clearing its storage in Android settings, deletes everything the app has stored. Backup and export files you created are yours to delete, and an Android backup can be removed from your Google account’s backup settings.
Children
Quillver is not directed at children, and it collects no personal information from anyone.
Changes
If this policy changes, the updated version will be posted on this page with a new effective date. If the app ever gains a feature that sends data off your device, this policy will be updated before that version is released.
Contact
Questions about this policy: derek@stobbe.dev.