Privacy policy
Diarama is a personal weekly planner. This policy covers the website and application living under diarama.cc, and describes what the service collects, why it needs it, and how's it used.
About us
Diarama is an independent project rather than a company. Privacy questions and requests should be sent to privacy at diarama.cc.
What is collected
- Basic account information. When you sign in with Google or Microsoft, Diarama receives your name, your email address, and a profile picture where the provider supplies one. It never receives or stores your password.
- What you put in. The tasks, notes, dates, categories, and settings you create while planning.
- Services you connect. Data from a calendar or other account only once you connect it yourself, limited to what the feature you turned on needs.
- Operational records. Ordinary server request records — an IP address, a timestamp, the page requested — kept briefly to keep the service running and secure. There are no advertising or analytics trackers, on the website or in the app.
What it is used for
- Running the planner: storing your plan and showing it back to you.
- Delivering the features you switch on, such as reminders, a calendar feed, or backups. Each of those is off until you turn it on.
- Keeping accounts secure and preventing abuse of the service.
- Replying when you get in touch.
Your content is not profiled, not used to build advertising audiences, and not used to train machine learning models. If you connect an AI assistant yourself, see feeds, tokens and assistants below: what you hand it is then covered by that assistant’s policy as well as this one.
Optional services you connect
Every integration below is optional, connected at your discretion, and can be disconnected at any time. Each asks for the narrowest access the provider offers for the job, which is not always as narrow as the job itself — where that is the case, it says so.
- Google or Microsoft sign-in
- Your name, email address, and profile picture, to identify your account and provide you the means to identify who's logged in.
- Google Calendar · read only
- Reads the calendars you choose so their events can appear alongside your days. Diarama never creates, edits, or deletes anything in your calendar. It also receives your name and picture, to label the connected account.
- Microsoft Calendar · read only
- Reads the calendars you choose so their events can appear alongside your days. It also receives your name and picture, to label the connected account.
- Google Drive · only its own files
- Writes a periodic backup of your own Diarama data to your Drive. The access is per file and covers only the files Diarama itself creates: it cannot see, open, or list anything else in your Drive. It also receives your email address, name and picture, to label the connected account.
- GitHub · repository access
- Diarama reads issues from the repositories you link, and does nothing else with the connection. GitHub does not offer a read-only repository scope for apps like this one, so the grant you approve covers full access to your repositories. Disconnecting revokes it.
Feeds, tokens and assistants
Some features work by handing something else access to your plan. They are all off until you switch them on, each has its own secret, and each can be revoked on its own.
- Calendar feed. A private URL containing a secret, which any calendar app can subscribe to. Anyone who has that URL can read the tasks in it without signing in, so treat it as a password: share it carefully, and regenerate it if it gets out.
- Automation token. A token you create for shortcuts and scripts, which can read and change your tasks. Anyone holding it can do the same as you.
- AI assistants. A separate token lets an assistant you choose read and change your tasks on your behalf. Diarama sends nothing to any assistant by itself; the assistant asks, and only while you have given it a valid token. What that assistant then does with what it reads — including whether it retains or trains on it — is governed by its own provider’s policy, not this one.
Google user data
Diarama’s use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Data obtained through Google APIs is used only to provide or improve the features you connected it for. It is not sold, not transferred to others except as needed for those features or where the law requires it, not used for advertising, and not read by a person except with your explicit permission, for security reasons, or to comply with the law.
Who else sees your data
Your data is solely yours, and used exclusively for the purposes of the service. It is not for sale, and it is not shared for advertising. The only third parties involved are the providers needed to run the service, such as hosting and email delivery, which process data on Diarama’s behalf and are not free to use it for their own purposes. Data may also be disclosed where the law genuinely requires it.
How it is protected, and what is yours to protect
Traffic is encrypted in transit. Sensitive fields — including the content of your tasks and the credentials for the services you connect — are encrypted at rest and scoped to the account that owns them.
Despite our best efforts, no online service can promise perfect security. Diarama is a planner, not a vault: please keep genuinely sensitive material out of it — passwords, financial or medical records, government identifiers, or anything else you would rather not entrust to a third party. What you choose to put in remains your responsibility.
Keeping and deleting
- Your content is kept for as long as your account exists.
- Disconnecting an integration deletes the stored credentials for it and, where the provider supports it, revokes Diarama’s access at the same time. Backup files already written to your Drive stay in your Drive; they are yours to keep or delete.
- Revoking a feed or token stops it working immediately. You can also revoke access independently at any time from your Google, Microsoft, or GitHub account settings.
- You may request deletion of your account and all its contents at any time by emailing
privacy at diarama.cc; your account and its contents will be deleted within 30 days. Operational records are kept only briefly by the hosting provider and are not linked back to a deleted account.
Children
Diarama is not intended for children under 18 and is not knowingly offered to them.
Changes
If this policy changes, the date at the top changes with it, and anything material is described here rather than quietly folded in.