Miuu Studio created the Miuu Note - Diary With Lock app as a free application with optional in-app purchases and ads. The base version of this Service is provided at no cost and is intended for use as-is. Users can opt to purchase a subscription or a one-time permanent upgrade for an ad-free experience and access to premium features.
This Privacy Policy informs users about how their Personal Information is collected, used, and disclosed when using this Service. By using the Service, you agree to the collection and use of information as described in this policy.
Information Collection and Use
The app may request personally identifiable information for a better user experience. When you sign in with Apple Login or Google Login, we collect your email address and display name for account identification and customer support purposes. This information is stored securely on our servers powered by Google Cloud. User-generated content (such as diary entries and images) is stored on your device by default. It leaves your device only when you use our backup service (see “Data Backup and Storage”) or when you choose to enable optional AI-powered features (see “AI Features and Third-Party AI Processing”). We do not otherwise collect your diary content. Limited anonymous or pseudonymous usage data may be collected through third-party analytics services for product improvement, as described below.
However, the app uses third-party services that may collect data to identify you. These include:
- Google Play Services / Apple App Store
- Google Firebase — sign-in, analytics, crash reporting, push notifications and feature configuration
- Sentry — error reporting
- Google AdMob — advertising in the free version
- RevenueCat — subscription and purchase status, and Apple Search Ads attribution on iOS
- Google Cloud — our servers, backup storage
- Anthropic — the optional AI features (see below)
Analytics & Product Usage Data
We use third-party analytics and error-reporting services (Google Firebase Analytics and Crashlytics, and Sentry) to understand how users interact with the app and to improve features, usability, and performance.
These services may collect anonymous or pseudonymous usage data, such as:
- App feature interactions (e.g., button taps, screen views)
- Device type, operating system, and app version
- Approximate location (derived from IP address, anonymized)
- Event timestamps and session duration
- Estimated age range, gender and interests, seen only as totals across many users (see Google signals below)
What we do NOT collect through analytics:
- Diary content or text entries
- Photos, images, or attachments
- User names, email addresses, or login credentials
- Any personally identifiable journal data
Google signals: we have turned on Google signals in Google Analytics. If you are signed in to a Google account and have allowed Google to personalise ads for you, Google may link the app's analytics data to that account so that it can give us estimates of our users' age ranges, genders and interests. We only ever see totals across many users. Google hides any group too small to stay anonymous, and we never receive your Google account details. We use these reports to understand who uses Miuu Note, not to target ads. In the European Economic Area and the UK this happens only if you agreed to personalised ads in the consent form described under Advertising. You can switch it off for your Google account at any time by turning off ad personalisation in My Ad Center.
Analytics data is used strictly for product improvement and is never sold. For more information, please review Firebase's Privacy and Security page and Sentry's Privacy Policy. The app also shows ads through Google AdMob; see Google's advertising policies.
Note: Email addresses and display names collected at sign-in are used solely for account management and customer support, not for analytics or advertising purposes.
Purchases and Subscriptions
Payment is handled entirely by the App Store or Google Play. We never see your card details. We use RevenueCat to tell the app whether a purchase or subscription is active; it receives an anonymous app user identifier and the purchase information the store provides. Cancelling or refunding a subscription is done through your store account.
On iOS, if you installed the app from an Apple Search Ads ad, RevenueCat also receives Apple's attribution token, which tells us which ad campaign led to the install. It contains no advertising identifier and does not require tracking permission.
Advertising
The free version shows ads through Google AdMob. Buying the ad-free upgrade or a subscription removes them.
- In the European Economic Area and the UK, the app shows Google's consent form before any personalised ads. You may choose non-personalised ads, and you can change your choice later.
- On iOS, the system “Allow app to track” prompt asks whether the app may use your device's advertising identifier. If you decline, ads still appear but are non-personalised. Apple Search Ads attribution (see Purchases and Subscriptions) does not use this permission.
- We never share your diary content, photos or voice notes with advertising partners. Ads are not targeted using anything you write.
Push Notifications
If you turn on reminders, the app registers a device notification token with Firebase Cloud Messaging so we can send the reminder you asked for. The token identifies a device installation, not you, and it is removed when the reminder is turned off, the app is uninstalled, or the token stops working. Notifications never contain your diary content. You can turn them off in the app or in your device settings.
Invite a Friend
When you invite a friend, or accept a friend's invite, the app uses our referral service so that both of you can receive in-app coins and rewards. This is what it stores and why:
- Invite codes: your personal code, when it was created, whether your phone is iOS or Android, and a one-way hash of the secret key that proves the code is yours. The key itself stays on your device.
- A device check: so that a phone cannot invite itself or be invited twice, the app sends a one-way, salted hash of your device's identifier (on Android, the Android ID; on iPhone, the identifier Apple gives each app developer). The identifier itself never leaves your device and cannot be recovered from the hash, and it is never linked to your advertising identifier. We use it only to prevent fraud.
- The link between friends: when a friend uses your code, we record that their (hashed) device used it, when, whether it came through a link or was typed, and when they wrote their first entry. We never record a friend's name, email or diary content, and the person who invited them sees only how many friends joined, not who they are.
- Install referrer: on Android, when you install Miuu from an invite link, the app reads the invite code that Google Play passes along with the install.
- Abuse limits: our server counts invite requests from each network address per hour. It stores only a one-way hash of the address and deletes it within about two days.
- Backups: your own code and any invite you accepted are included in your backup, so they come back when you restore.
Data Backup and Storage
Account Information: When you sign in, your email address and display name are stored on our secure servers (Google Cloud Firestore) for account identification, customer support, and data recovery purposes. This account metadata is stored separately from your diary content and is not used for marketing or advertising.
Your backups: Whether you sign in with Apple or Google, the backup service stores your user-input data (such as diary entries, images and voice notes) on our secure servers powered by Google Cloud Storage. This keeps your data recoverable if you switch devices or reinstall the app, on iOS or Android. Miuu Studio retains management control of the data stored on Google Cloud but does not directly access or read your personal content. For more information, please review Google Cloud's Privacy Policy.
Older Google Drive backups: Before February 2026, Android users who signed in with Google could choose to back up to their own Google Drive instead. Those backups were never sent to or stored by Miuu Studio. This option is no longer offered and is being retired: updated versions of the app move those devices to the backup service above, and no longer write to Google Drive. If you have an old Drive backup, it stays in your Drive, and the app reads it only when you ask it to import it. For this, when you sign in with Google the app asks for access to the files it created in your Drive (Google's “drive.file” permission), which does not let it see anything else in your Drive.
Please refer to Google's Privacy Policy and Google Cloud's Privacy Policy for details on their data handling practices.
AI Features and Third-Party AI Processing
The app offers optional, AI-powered features (for example, features that answer questions about your notes, or that automatically organize the people, places, and themes you write about). These features are turned off by default and only operate if you explicitly turn them on. They are intended for adult users (18 and older).
If you enable an AI feature, the text of the relevant notes is sent to a third-party AI provider, Anthropic (the maker of Claude), to process your request. Depending on the feature, this may happen only when you ask a question, or continuously in the background as you write. We never send your photos, images, or voice notes to the AI provider — only text.
For features that build a picture of the people, places and things you write about, you choose which past entries are included when you turn the feature on — for example your most recent entries, or entries you pick yourself — and each new entry is sent when you save it. You can change that choice at any time in the app.
Under our commercial agreement with Anthropic:
- Your content is not used to train AI models.
- Your content is processed to return a result and is not retained long-term. When past entries are processed together in the background, the provider holds them until the results have been delivered to your app, and we delete them as soon as they are; if they are never collected, the provider deletes them within 30 days.
- The results — such as the names of people, places and things you wrote about, together with short quotes from your own entries — are stored on your device, and, like your entries, in your backup if you use our backup service. You can remove them at any time from the app's settings.
- Miuu Studio does not keep the AI results on our servers beyond what is needed to operate the feature (such as counting usage against any free limit).
You can decline these features and continue using the rest of the app normally, and you can turn them off at any time. Because these features send the content of personal journal entries to a third party, we do not knowingly make them available to, or process the content of, children. For details on how the provider handles data, please review Anthropic's Privacy Policy.
Log Data
If the app encounters an error, it collects data such as your device's IP address, name, operating system, and usage statistics through third-party services. No user-input data is ever collected.
To protect the AI features from abuse, the app may also send our service a short-lived token from Apple App Attest or Google Play Integrity confirming that the request comes from a genuine copy of the app. These tokens contain no personal content and are not stored.
Our Website
Our website, miuunote.site, uses Google Analytics to count visits: which pages are viewed, which site or link a visit came from (for example our Instagram profile), how far a page is scrolled, and whether the App Store or Google Play button is tapped. Google Analytics also records the browser, device type and approximate location (country or city, from the IP address). It does not receive the invite code in an invite link. Google signals and advertising features are turned off for the website, and this data is kept separate from the app's analytics. In the European Economic Area, the UK and Switzerland, the website sets no analytics cookie and Google Analytics receives only cookieless signals. See how Google uses information from sites that use its services.
Cookies
The app itself does not use cookies but may include third-party code or libraries that do. You can choose to accept or refuse cookies in your settings, but some features may be affected. Our website uses Google Analytics cookies, outside the regions named above, to tell one visit from a returning visitor.
Third-Party Service Providers
- Facilitate the Service
- Perform Service-related functions
- Analyze Service usage
These providers may access your Personal Information but are obligated not to misuse it.
Security
We take reasonable measures to protect your Personal Information but cannot guarantee absolute security due to the nature of internet transmission and electronic storage.
Data Breach Response
In the event of a data breach that may affect your Personal Information, we will:
- Investigate the incident promptly and take immediate steps to contain the breach
- Notify affected users within 72 hours of discovering the breach, where technically feasible
- Provide details about what information was involved, steps we are taking to address the breach, and recommended actions for users
- Comply with applicable data protection laws and regulations regarding breach notification
- Implement additional security measures to prevent similar incidents
Limitation of Liability
While we implement industry-standard security measures and follow best practices to protect your data, we cannot be held liable for:
- Unauthorized access due to user negligence (sharing passwords, using insecure devices, etc.)
- Breaches caused by third-party services beyond our control (Apple iCloud, Google Drive, etc.)
- Acts of nature, cyber attacks, or other events beyond our reasonable control
- Data loss, corruption, or unavailability resulting from device failure, app deletion, user error, or failed backup/restore processes.
Our liability is limited to the maximum extent permitted by applicable law. We recommend users maintain their own backups and use strong, unique passwords.
Links to Other Sites
The app may contain links to external websites. Miuu Studio is not responsible for the privacy practices or content of these sites. Review their Privacy Policies for more information.
Children's Privacy
This app is intended for users aged 18 and older and is not directed to or designed for children. On the Google Play Store it is declared for a target audience of 18 and over.
Consistent with the Children's Online Privacy Protection Act (COPPA), we do not knowingly collect personal information from children under 13, and we do not knowingly send any child's content to third-party AI providers. The optional AI features described above are intended for adult users only. If we learn that we have collected personal information from a child under 13 without appropriate parental consent, we will delete it.
Parents or guardians who believe their child has provided personal information to us should contact us immediately at support@miuustudio.com for prompt deletion of such information.
How Long We Keep Data
- Invite records (codes, the hashed device check and the link between friends): kept while the invite program runs, so a phone cannot be invited twice. To have yours deleted, email us with your invite code (Settings → Invite friends).
- Backups: kept for as long as your account exists, so a backup is there when you need it. We keep the current backup and the previous one; older ones are replaced. Delete your account (below) and they go with it.
- Account record (email address, display name): kept while your account exists.
- Usage counters for free limits on the AI features: monthly counts, and a one-time count for the first build of your universe. They hold numbers, never your text.
- Reminder schedules: kept while the reminder is on, and removed shortly after it is turned off or stops working.
- Diagnostic logs (errors, request records): kept for a limited period, normally no more than 90 days.
- Diary content on your device: yours, for as long as you keep the app installed. Deleting the app deletes it, which is why we recommend keeping a backup.
Your Rights and Choices
The app is published by Miuu Studio, a sole proprietorship registered in Ontario, Canada, which is responsible for the personal information described here. Canadian federal privacy law (PIPEDA) applies to us.
Wherever you live, you can ask us to give you a copy of the personal information we hold, correct it, or delete it. If you are in the European Economic Area or the UK, you also have the right to object to or restrict certain processing, to receive your data in a portable form, and to complain to your local data protection authority.
Our legal bases for processing are: performing the service you asked for (your account and backups); your consent (the AI features, personalised ads and Google signals, notifications), which you can withdraw at any time without losing the rest of the app; and our legitimate interests in keeping the service working and safe from abuse.
You can act on most of this inside the app: turn the AI features off or choose “Forget my universe”, turn off reminders, change your ads choice, delete individual entries, or stop backing up. For anything else, write to us at support@miuustudio.com.
Deleting your account and backups: email support@miuustudio.com from the address you signed in with, and we will delete your account record and everything stored for it on our servers — your backups, their media, your reminder schedules and your usage counters — within 30 days. Diary entries on your own device are not affected; delete the app to remove those. If you have an older backup in your own Google Drive, that copy is yours to delete from Drive.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising. California residents may exercise the rights above without being treated differently for doing so. If you are in Canada and we have not resolved your concern, you may contact the Office of the Privacy Commissioner of Canada.
Where your data is processed: we are based in Canada, and the providers listed above — Google Cloud, Firebase, RevenueCat, Sentry and Anthropic — process data in the United States. Personal information handled by us in Canada is protected under Canadian federal privacy law; for transfers on to those providers we rely on the safeguards in our agreements with them, such as the standard contractual clauses, where the law requires them.
Changes to This Policy
This Privacy Policy may be updated occasionally. Users are encouraged to review this page regularly. Changes will be posted here and are effective immediately.
Effective Date: September 30, 2026
Contact Us
For questions or suggestions, contact us at: support@miuustudio.com