Privacy Policy
Plimm is operated by Dias Jakupov ("we", "us"). This policy explains what Plimm stores, what leaves your device, and what never does.
The short version
Your journal stays on your phone. Plimm has no accounts and no server that stores your writing. We cannot read your entries.
What stays on your device
- Your journal entries and your conversations with the AI
- Voice recordings and the transcripts made from them
- The analysis the AI produces — detected emotions, topics, patterns, and insights
- Bookmarks and app settings
On Android, this data is stored in a database encrypted with SQLCipher (AES-256). On iOS, it is encrypted at rest by iOS Data Protection. The AI models run entirely on your device. Your writing is never sent anywhere to be processed.
Voice journaling
When you record a voice entry, Plimm asks for microphone access and captures audio only while you are recording. The recording is transcribed on your device by a speech model that Plimm downloads during setup. Neither the audio nor the transcript is uploaded — there is no server involved in turning your voice into text.
Recordings are kept by default so you can play back what you said, and you can turn that off or delete every recording in Settings → Recordings. Deleting an entry deletes its recordings with it, and Delete All Data removes all of them.
One honest distinction is worth making: your entries live in the encrypted database described above, while recordings are audio files in Plimm's private storage, protected by your device rather than by the app. On Android that is file-based encryption, on iOS it is Data Protection. Both keep the files unreadable to other apps and to anyone without your device passcode — but the protection comes from the operating system, not from Plimm's own encryption. If you would rather no audio existed at all, turn recordings off and only the transcript is kept.
What leaves your device
Five things, and only these:
- Usage events. We use PostHog to learn which features are used — for example, that an entry was saved, that the settings screen was opened, or that crisis support resources were shown (see Crisis detection below). Each event carries the event name, coarse details such as a subscription plan name or a message count, your device model, operating system version, app version, and a random identifier — never your writing, your name, or your email. We do not collect your name or email at all. PostHog's servers, like any web service, receive your IP address when events are delivered. You can turn usage analytics off at any time in Settings. See the PostHog Privacy Policy.
- Basic app-lifecycle events. The Google Firebase SDK automatically reports coarse app-lifecycle events such as first open and session starts, along with device model and operating system version. See the Google Privacy Policy.
- Crash reports. If the app crashes, Google Firebase Crashlytics sends a technical report: device model, operating system version, and what the code was doing when it failed. Crash reports never include journal content.
- Purchase information. Subscriptions are processed by Apple or Google and verified by RevenueCat. RevenueCat receives your purchase receipt and a random identifier — not your name, and nothing from your journal. See the RevenueCat Privacy Policy.
- The AI model download. During setup, Plimm downloads its AI models (about 437 MB in total — one for reflection, one for turning speech into text) one time from Hugging Face's servers. As with any download, their servers see your device's IP address. Nothing about you or your journal is sent with the request. See the Hugging Face Privacy Policy.
What we never collect
- Your journal text, or anything you write in the app
- Your voice recordings, or the transcripts made from them
- Your name, email address, or contacts
- Your precise location — Plimm never asks for GPS access; analytics services may infer an approximate region from your IP address
- Advertising identifiers — Plimm shows no ads and does not sell data, to anyone, for any reason
Crisis detection
Plimm looks for signs of crisis in what you write so it can show support resources. The detection itself happens entirely on your device, and what you write never leaves it. If support resources are shown, Plimm sends a usage event to PostHog recording that they appeared and the severity level that triggered them — never your words, and never why. This event carries the same random identifier as other usage events and is not sent if you turn usage analytics off in Settings.
Deleting your data
In the app, Settings → Delete All Data erases everything Plimm has stored. This is immediate and permanent. Uninstalling the app also removes all of its data. There is no server copy of your journal to delete, because your journal never leaves your device. Usage events already sent to PostHog are tied only to a random identifier, not to your name or email. For questions about those events, or about purchase records held by Apple, Google, or RevenueCat, contact us at diasjakupov04@gmail.com.
Children
Plimm is intended for adults. You must be 18 or older to use it, and we do not knowingly collect any information from children.
Where Plimm is offered
Plimm is currently offered in the United States. The practices in this policy apply wherever you use the app.
Changes to this policy
If this policy changes, we will post the new version here and update the effective date. For material changes, we will also say so in the app.