Privacy Policy
Effective 21 September 2026 · Applies to the Dolia app (iOS and Android) and mydolia.com
Dolia is a mood journal. What you write in it is personal, so this policy is written to be read. If anything is unclear, write to support@mydolia.com.
1. What we collect
- Account: your email address and a salted hash of your password. We never store the password itself.
- Journal data (encrypted): mood check-ins, journal entries, tags, photos and practice history are stored on your device. When sync is on, they are encrypted on your device with a key derived from your password and sent to our server as opaque records. The server sees only a record type, an ID, a timestamp and a deleted flag — never the content. We cannot decrypt your entries.
- AI requests (only with your permission): when you ask for an AI reflection, the text you select or a summary of your moods and tags is sent through our server to the AI provider Anthropic (Claude). Excerpts of notes are included only if you choose them. The result may be kept on our server for up to 24 hours to recover a failed request, then deleted. You can turn this off at any time in Privacy settings, or use Local-only mode, which stops all network requests.
- Technical data: standard server logs (IP address, request time, status) kept for a short period for security and reliability. We do not log request bodies.
Dolia does not sell data, does not show ads, and does not use advertising trackers.
2. What we use it for
- To sign you in and keep your journal in sync across your devices.
- To produce the AI reflections you request.
- To keep the service secure and working.
3. Who else sees data
- Anthropic (AI provider) — receives only the text of an AI request you initiate, under its usage policies for API customers, which do not permit training on that data.
- Hosting — our server runs in the European Union (Helsinki, Finland).
- App stores — Apple and Google process purchases and crash reports under their own policies; we do not receive your payment details.
We share data with authorities only when required by law.
4. Retention and deletion
- Account and encrypted sync records are kept while your account exists.
- Delete account in Settings removes your account, all sync records and AI history from our server, and all data from the device. This is immediate and cannot be undone.
- Signing out keeps local data on the device; deleting the app removes it.
- You can export your entries as CSV at any time from Privacy settings.
5. Your rights
Depending on where you live (including under the GDPR and the UK GDPR), you can ask to access, correct, export or delete your data, or object to processing. Most of this is available directly in the app; for anything else, email support@mydolia.com. We answer within 30 days.
6. Children
Dolia is not directed at children under 16, and we do not knowingly collect their data. If you believe a child has created an account, contact us and we will delete it.
7. Not a medical service
Dolia offers reflection and self-care tools. It is not therapy, diagnosis or emergency help. If you are in danger, contact your local emergency services.
8. Changes
If this policy changes materially, we will show a notice in the app before the change applies. The current version is always at mydolia.com/privacy.
9. Contact
Dolia · support@mydolia.com