Privacy policy
Last updated: 15 September 2026
This policy explains what data DiariApp processes, why, and what rights you have. It applies to the web app (diariapp.com) and to the Android app.
1. Data controller
- Owner: [PENDIENTE: nombre o razón social]
- Tax ID: [PENDIENTE: NIF]
- Address: [PENDIENTE: domicilio]
- Contact email: impuweb@gmail.com
More information in the legal notice.
2. Demo mode (no account)
You can use DiariApp without creating an account. In that case, the areas, tasks and hours you log are stored only in your device's browser storage and are not sent to our servers.
- They are not synced with other devices or browsers.
- They may be lost if you clear your browser data, use a private window or change devices.
- If you later create an account or log in on that device, that data is copied to your account and removed from the browser.
3. Data we process if you have an account
- Registration data: email, name and password, managed by our authentication system (Keycloak). Your password is stored encrypted and we cannot access it.
- Service data: the areas, tasks, hours, dates and catalogs you record.
- Technical data: IP address, browser and device in server logs, for security and troubleshooting.
4. Cookieless usage analytics
We measure how the app is used (sections viewed, features used and approximate session length) with our own system and without cookies. To count unique visitors we use an identifier derived from a hash that rotates every day, from which your IP address cannot be recovered and you cannot be identified. This analytics does not require consent.
If you arrive from a campaign link (with utm parameters, for example from a Facebook post), we record that campaign together with the events of that visit to learn which posts work. This information travels in the page address and is not stored on your device.
5. Purposes and legal basis
- Providing the service and managing your account: performance of a contract (Art. 6(1)(b) GDPR).
- Necessary service communications (email verification, password recovery, relevant changes): performance of a contract.
- Security, abuse prevention and service improvement through anonymous analytics: legitimate interest (Art. 6(1)(f) GDPR).
6. Providers and data location
We do not sell your data. The following providers process it on our behalf:
- Railway: database, application server and authentication system.
- Vercel: web app hosting.
These providers may process data outside the European Economic Area. In that case, transfers are covered by the safeguards provided for in the GDPR, such as the European Commission's standard contractual clauses. We may also disclose data where required by law.
7. Retention
We keep your account data while your account is active. If you request its deletion, we delete your personal data within 30 days, unless we are legally required to keep it. How to request it: account deletion.
8. Your rights
You can exercise your rights of access, rectification, erasure, objection, restriction of processing and portability by writing to impuweb@gmail.com. You can also download your hours as CSV from the reports at any time.
If you believe we have not handled your request properly, you can file a complaint with the Spanish Data Protection Agency (www.aepd.es).
9. Cookies and on-device storage
- Technical session cookies: keep you logged in. They are necessary and do not require consent.
- Browser storage: stores demo mode data and preferences such as light or dark theme.
- Android app: stores your session in the device storage.
We do not use advertising cookies or third-party analytics cookies.
10. Minors
DiariApp is not intended for children under 16. If we find that we have collected data from a minor, we will delete it.
11. Changes to this policy
If we change this policy, we will publish the new version on this page with its update date and, if the change is significant, we will announce it in the app.