Privacy policy for the Dear Semester app
1. Scope
This privacy policy applies to the Dear Semester mobile app for iOS and Android. It does not apply to the dear-semester.eu website. The website requires a separate privacy policy because visiting a website may involve the processing of server log data by its hosting provider.
Dear Semester is a local journal and reflection app. The app has no user account, backend, or cloud database. Journal entries are not transmitted to the provider.
2. Controller
Erik Engler
trading as Leviora Studio
Gartenstraße 29C
06406 Bernburg
Germany
- Phone: +49 151 10481071
- Email: erik@leviora.studio
- Website: dear-semester.eu
Leviora Studio is a business name used by Erik Engler and is not a separate legal entity. No data protection officer has been appointed.
3. Local processing principle
All content you enter in Dear Semester is processed exclusively on your device. Erik Engler does not have access to this content and cannot read or restore it.
In particular, the app contains no advertising, tracking, analytics, remote crash reporting, or external or AI-based analysis. It does not create or read unique advertising or tracking identifiers.
4. Data processed locally
Journal data
The app processes the following data on your device:
- the date of an entry;
- your selected mood and perceived university workload;
- optionally selected modules, energy, and procrastination;
- optional free text;
- local creation and modification timestamps.
Mood information and free text may contain particularly personal or sensitive information. This data is not collected by the provider and is not transmitted to the provider or to any processor engaged by the provider. Please do not enter another person’s personal data unless doing so is necessary and lawful.
Settings and technical data
The app also stores settings locally, such as language, appearance, reminder time, app lock, and the time of a successful manual backup. It queries the current device time zone and notification permission state from the operating system so that a local reminder can be scheduled at the selected local time.
Local insights
Distributions, timelines, and recaps are calculated directly on your device from your existing entries. They are not sent to a server and are not stored as a separate user profile. The analysis is rule-based, does not use AI, and does not make automated decisions that have legal or similarly significant effects.
5. Purposes and legal bases
To the extent that purely technical processing on your device is attributable to the provider under data protection law, it is performed to provide the app features you request under Article 6(1)(b) GDPR. Optional local notifications are used only after you activate them and grant the operating-system permission. Where consent is required, the processing is based on Article 6(1)(a) GDPR. You can disable the reminder in the app or withdraw the permission in the operating system at any time.
The journal data you enter remains under your control. The provider does not process it for the provider’s own purposes, and it never enters the provider’s possession.
6. Encryption and device protection
The local SQLite database is encrypted with SQLCipher. Its randomly generated database key is stored separately in the iOS Keychain or in secure storage protected by the Android Keystore.
If you enable the optional app lock, iOS or Android performs authentication using the device protection you have configured. Dear Semester neither receives nor stores biometric characteristics, your device PIN, or your device password.
The app obscures content in the app switcher. While the app is active, the operating system may still allow screenshots. You decide whether to create or share such screenshots.
7. Local notifications
After you enable the feature, Dear Semester can display a neutral daily reminder. The notification contains no mood, journal text, or module data. It is scheduled locally. The provider does not use a push service or its own server for this purpose.
8. Exports and restoration
Encrypted portable backup
You can export your data to an encrypted .sjb file. The file is protected by a password you choose and is written only to the location you select. The password is not transmitted to the provider and cannot be recovered by the provider.
CSV export
The CSV export is unencrypted and may contain journal data and free text. The app warns you before exporting it. Keep the file protected and delete it when you no longer need it.
Storage locations selected by you
When saving or opening a file, Dear Semester uses the operating system’s file picker. If you select cloud storage or another app as the destination, that provider processes the file under its own privacy terms. Erik Engler does not gain access to the file.
9. Device backups
iOS
Depending on your iOS, iCloud, or Finder settings, Dear Semester app data may be included in an Apple device backup or device transfer. The database remains encrypted with SQLCipher. For a usable restoration, iOS must also restore the associated migratable Keychain item. Apple and your settings determine how the device backup is performed and retained and whether it succeeds; Dear Semester cannot guarantee a successful restoration.
For information about Apple’s processing, see the Apple Privacy Policy.
Android
Dear Semester does not participate in Android cloud backup or automatic Android device-to-device transfer for its app data. The reason is that the database key protected by the Android Keystore cannot be transferred securely to another device. For a device change on Android, use the encrypted portable .sjb backup.
Files you export manually may independently be stored at a location you select and may be backed up by that storage provider.
10. App stores and standard reports
Dear Semester is distributed through the Apple App Store and Google Play. Apple and Google process data under their own responsibility when you access the store, download the app, and manage it. Depending on your platform and sharing settings, they may provide the provider with standard, predominantly aggregated or pseudonymised information about installations, app versions, device types, operating-system versions, stability, and crashes. These reports do not contain journal entries and are not linked to your local content.
To the extent such reports contain personal data, they are processed under Article 6(1)(f) GDPR. The legitimate interest is the secure operation, troubleshooting, and improvement of the app. Dear Semester does not integrate analytics or crash-reporting SDKs provided by the stores.
Any processing in third countries by Apple or Google is governed by their privacy policies and the transfer mechanisms described there. The provider does not transmit journal data to Apple or Google.
11. Contacting us
If you contact us by email or phone, Erik Engler processes the contact details and content you provide in order to respond to your request. The legal basis is Article 6(1)(b) GDPR where the communication relates to your use of the app or a pre-contractual request, and otherwise Article 6(1)(f) GDPR. The legitimate interest is responding to and documenting legitimate enquiries.
Enquiries are deleted when they are no longer required for handling the matter. Statutory retention obligations and retention required to establish, exercise, or defend legal claims remain unaffected.
12. Retention and deletion
Local journal data remains stored until you delete individual entries, all app data, or the app itself. The “Delete all app data” function removes journal entries, modules, and settings from the app. A random technical database key that does not itself contain journal content may remain in the operating system’s secure storage until the app is uninstalled.
Files you exported outside the app and existing device backups are not automatically removed when you delete data within the app. Delete those files using the relevant file storage or operating-system backup management.
The provider has no server-side copy of your journal data and therefore cannot view, delete, or restore it for you.
13. Your rights
Where Erik Engler processes your personal data, and subject to the applicable legal requirements, you have rights including access, rectification, erasure, restriction of processing, data portability, and objection. You may withdraw consent at any time with effect for the future.
You can view, correct, and delete your exclusively local journal data in the app and export it as CSV or an encrypted backup. Because the provider has no access to this data, the provider cannot retrieve or alter it in response to a request.
To exercise your rights, contact erik@leviora.studio.
You also have the right to lodge a complaint with a data protection supervisory authority. The authority with particular jurisdiction at the controller’s place of residence is:
Landesbeauftragte für den Datenschutz Sachsen-Anhalt
Otto-von-Guericke-Straße 34a
39104 Magdeburg
Germany
datenschutz.sachsen-anhalt.de
14. Requirement to provide data
There is no legal requirement to use Dear Semester or enter data in the app. To save a daily entry, the date, mood, and perceived university workload are technically required. All other daily information is optional.
15. Changes to this privacy policy
This privacy policy will be updated if features, data flows, or legal requirements change. The current version will be provided in the app and at dear-semester.eu.
Last updated: 30 August 2026