Privacy Policy
For the Datey iOS app · Compliant with Apple App Store Review Guidelines §5.1.1
Last updated · 2026-07-07
1. The short version
Your dating life stays yours. Datey is built so that the entries, people, photos, notes, moods, and patterns you create stay on your device, in your private storage (Apple’s SwiftData and Keychain). We do not have an account system. We do not run our own servers that hold your data. We cannot read your journal — not even when you turn on iCloud sync.
What does leave your device is deliberately minimal: the data required to process your subscription purchase (handled by Apple and our subscription provider, RevenueCat), and anonymous usage statistics and crash reports (handled by TelemetryDeck and Sentry) that tell us which features are used and when the app breaks — never who you are, never anyone you’ve dated, never the contents of your journal. If you switch on iCloud sync (off by default), your journal travels only between your own Apple devices and your own private iCloud, end-to-end encrypted — it still never reaches us. §3 and §5 explain each of these precisely.
This policy explains exactly what is collected, by whom, and what your rights are.
2. Who we are
Tortuga Global Tech LLC (“we,” “us,” “Datey,” “the studio”) is the data controller for the limited data described in this policy.
- Registered address: 1021 E Lincolnway, Suite 10348, Cheyenne, WY 82001, United States
- Contact: support@tortugatech.co
For users in the European Economic Area, the United Kingdom, or California, we act as the “controller” of the limited data described in this policy within the meaning of the GDPR, UK GDPR, and CCPA respectively. The third parties in §4 do not all play the same role: RevenueCat and Sentry act as our processors under data processing agreements (§4.2, §4.4); Apple acts as an independent controller for your App Store purchases and your iCloud, under its own privacy policy (§4.1); and TelemetryDeck receives only anonymised signals and, on its own account, is neither a controller nor a processor of personal data (§4.3).
3. What we collect
We have grouped the data Datey touches into four categories. Read each carefully — the distinctions matter.
3.1 Data that stays on your device (not “collected” by us)
Everything you enter into Datey lives in the app’s own private storage on your iPhone or iPad:
- Information you record about each person — nickname, birth date or age, gender, height and other body measurements you enter, eye and hair colour, body modifications, education and occupation, where they live, how you met, free-text notes, and (if you choose to enter them) phone number, WhatsApp number, or Instagram handle.
- Information you record about each date — when, where (city, country, venue type), what you did, your mood and ratings (vibe, attractiveness scored across several dimensions), intimacy data, amount spent and currency, and the relationship status at the time.
- Photos you add to a person’s profile or to a date entry.
- Photos you place in PrivateVault (see §7 for the stronger protections that apply to vault photos).
- Calendar entries Datey writes when you add upcoming dates.
- Aggregated patterns and insights the app computes from the above.
We do not receive this data. It is not transmitted to our servers (we don’t have any for journal content). We cannot recover it for you if you lose your device or delete the app. If you uninstall Datey, this data is removed with the app — unless you turned on iCloud sync (§5.1), in which case a copy remains in your own private iCloud until you remove it, or it is included in an Apple-managed device backup you control through your iCloud settings (§5.2).
A note about other people. The journal records information about people who have not themselves installed Datey or agreed to this policy. We never see that information. You are responsible, under the laws that apply to you and to them, for whether and how you record it. We recommend treating Datey as a private diary, not as a shared database, and being thoughtful about recording intimate details of people who have not consented.
3.2 Data processed by Apple when you buy a subscription or one-time purchase
When you purchase a Datey subscription (monthly or yearly) or the lifetime purchase, the transaction is processed entirely by Apple under Apple’s own privacy terms. Apple does not share your Apple ID, name, email, or payment details with us. The only purchase-related data we receive flows through our subscription processor (see §4.2):
- A randomly generated anonymous identifier created by that processor the first time you open the app. It is not your Apple ID, name, email, or device identifier.
- The product identifier and purchase / renewal events Apple reports to the processor.
- Basic device metadata (iOS version, device model, app version, country).
We use this only to confirm that your subscription is active when you launch the app and to honour “Restore Purchases” if you reinstall.
3.3 Anonymous usage analytics and crash reports
Datey sends two kinds of anonymous, content-free signals so we can see which features matter and fix crashes:
- Usage signals, processed by TelemetryDeck (see §4.3): which feature was used (e.g. “a date entry was saved” — never what it said), app version, iOS version, device model, and coarse locale. TelemetryDeck is a German company; signals are salted-and-hashed on device so that neither we nor TelemetryDeck can identify you or link signals to a person, and the data is hosted in the EU.
- Crash and performance reports, processed by Sentry (see §4.4): a stack trace of where the app crashed, plus device model, OS and app version. We have configured Sentry to send no personal identifiers, and Datey strips user context and breadcrumb text from every report before it leaves your device.
What these signals can never contain: your journal. The analytics layer in Datey is a sealed, type-checked boundary — it has no code path to nicknames, notes, photos, ratings, locations, or any other journal field. A usage signal says “the insights screen was opened,” not what was on it.
These signals are not tied to your name, email, Apple ID, or any advertising identifier (Datey requests no advertising permissions and has no ATT prompt — see §6). We process them under our legitimate interest in keeping the app working and improving it (GDPR Art. 6(1)(f)). Because the signals are anonymous, we cannot single out and delete “your” signals — there is nothing that links any signal to you. If you object to this processing, contact us at support@tortugatech.co.
3.4 Data we deliberately do not collect
We want to be explicit:
- No accounts. Datey has no sign-up, login, email, or password.
- No behavioural or ad-tech analytics. We do not use Firebase, Mixpanel, Amplitude, Google Analytics, Segment, PostHog, or any equivalent. The only analytics is the anonymous, content-free kind described in §3.3.
- No crash reporting tied to your identity. Crash reports (§3.3) carry no account, name, email, or advertising identifier — we could not look up “your” crashes even if we wanted to. Apple’s separate, opt-in crash sharing remains under your control in iOS Settings → Privacy → Analytics & Improvements.
- No advertising. Datey contains no ads, no tracking pixels, no advertising identifiers.
- No social-media SDKs. No Facebook, no TikTok, no Snap, no Pinterest SDKs are embedded.
- Only one rendering library besides Apple’s. Datey bundles Lottie (an open-source animation library from Airbnb) to play decorative animations such as the launch screen. Lottie runs entirely inside the app from animation files we ship with the bundle. It does not make network requests and does not collect data.
4. Third parties who handle data
Datey relies on four third parties. Only the limited data described in §3.2 and §3.3 ever reaches them — never your journal:
4.1 Apple Inc.
Apple processes your App Store purchases, hosts the app, and provides the iOS frameworks (SwiftData, Keychain, EventKit, PhotoKit, MapKit) Datey uses. Apple’s handling of your data is governed by the Apple Privacy Policy.
4.2 RevenueCat, Inc.
We use RevenueCat (revenuecat.com) to track subscription entitlements across devices. When you first open the app, RevenueCat creates a randomly generated, anonymous identifier for your device (not your Apple ID, name, or email) and receives basic device metadata (iOS version, device model, app version, country) — this is what lets the app check whether you already have an active subscription. When you make a purchase or restore purchases, it additionally receives the product identifier and the purchase / renewal events Apple sends them.
RevenueCat acts as our processor under their Privacy Policy and Data Processing Addendum. They are SOC 2 Type II certified. They do not use this data for advertising or share it with third parties for marketing.
4.3 TelemetryDeck GmbH
We use TelemetryDeck (telemetrydeck.com) for the anonymous usage signals described in §3.3. TelemetryDeck is a German company and processes signals on EU-hosted infrastructure. Identifiers are irreversibly salted and hashed on your device before transmission, so the signals TelemetryDeck receives cannot be tied back to you. Because those signals identify no one, TelemetryDeck operates on the basis — set out in its Data Processing Agreement — that it is neither a controller nor a processor of personal data; it handles the signals under its Privacy Policy.
4.4 Functional Software, Inc. (Sentry)
We use Sentry (sentry.io) for the crash and performance reports described in §3.3. Sentry receives the stack trace and basic device metadata (device model, OS and app version) when the app crashes or stalls, and processes them on its infrastructure in the United States. We have disabled Sentry’s collection of personal identifiers, and Datey scrubs user context and breadcrumb text from every report before it is sent. Sentry acts as our processor under their Privacy Policy and Data Processing Addendum.
4.5 Our subprocessors
The four providers above — Apple, RevenueCat, TelemetryDeck, and Sentry — are the complete set of third parties that receive any data connected with Datey. We will update this section and the “Last updated” date before adding any new provider that would receive personal data, so you can always see who is involved.
4.6 How long data is kept
- Your journal stays on your device (and, if you enable sync, in your own iCloud) until you delete it or delete the app. We never receive it, so there is nothing for us to retain or delete.
- The anonymous subscription record (RevenueCat) is retained while your entitlement is active and for a limited period afterwards under RevenueCat’s own retention policy; we hold no separate copy.
- Usage signals (TelemetryDeck) are anonymous and retained per TelemetryDeck’s policy; because they identify no one, they cannot be tied to — or deleted for — a specific person.
- Crash reports (Sentry) are retained for Sentry’s configured event-retention period (90 days by default) and then deleted.
- Support emails you send us are kept only as long as needed to handle your request, and a reasonable period afterwards, then deleted.
5. iCloud sync and backup (sync is off by default — opt-in only)
Datey keeps your journal on your device. Two separate things can place a copy in your own private iCloud — Datey’s optional cross-device sync, and Apple’s standard device backup. In both cases the copy stays in your iCloud, which Tortuga Global Tech LLC has no key to and no way to access, and none of it ever transits our servers (we have none for journal content).
5.1 Cross-device sync
Datey can keep your journal in sync across the Apple devices signed into your Apple ID. Sync is off by default. You explicitly opt in from Datey’s Settings screen, and you can turn it off again at any time — from Datey’s Settings or from iOS Settings → [your name] → iCloud → Apps Using iCloud.
When sync is enabled:
- Your journal — the people, dates, your profile, and your achievement stamps — syncs through your own private iCloud database.
- The contents of every journal field are end-to-end encrypted: they are stored as CloudKit encrypted values whose key material lives in your iCloud Keychain. Neither we nor Apple can read them.
- Profile photos sync as iCloud file assets protected by Apple’s standard iCloud encryption (encrypted in transit and at rest, keys managed by Apple — end-to-end encrypted if you have enabled Advanced Data Protection).
- PrivateVault photos do not sync. They never enter iCloud’s sync database and stay only on the device where you added them.
- While sync is on, Apple delivers invisible, content-free “something changed” push notifications to your devices so they know to fetch changes from your private iCloud. These are Apple-internal signals, not notifications you see, and nothing about them reaches us.
5.2 Standard iOS device backup
Independent of sync, the iOS device backup managed by Apple (Settings → [your name] → iCloud → iCloud Backup) may include Datey’s data as part of your overall device backup. That is between you and Apple — it stays in your own iCloud. PrivateVault contents remain encrypted in any such backup because they are stored as AES-encrypted .enc files on disk.
6. Permissions Datey may ask for
iOS will prompt you the first time Datey needs each of the following. You can deny any of them and most of the app continues to work. None of these permissions is required to use Datey.
| Permission | What we use it for | What happens if denied |
|---|---|---|
| Photos (read) | Add a photo to a person’s profile, to a date entry, or to PrivateVault. Photos are read into Datey’s own on-device storage. | Profile, date, and vault photos cannot be set; everything else still works. |
| Photos (add) | When you choose to export a photo from PrivateVault back to your Photos library, iOS shows a separate “save to Photos” prompt (write-only). | The export back to Photos is cancelled; the photo remains in your vault. |
| Camera | Take a profile photo directly inside Datey, or capture a photo straight into PrivateVault. | You can still pick existing photos from your library if Photos permission is granted. |
| Contacts | When you tap “Pick from Contacts” while adding a date, iOS shows your contacts and hands Datey only the single contact you choose — never your wider address book. From that one contact we import their name and, to save you retyping, their phone number(s), photo, and birthday, into that person’s entry, where you can edit or clear any of it. | You can type the details in by hand instead. |
| Calendars (read & write) | When you tag a date with an upcoming time, Datey can write the event to your calendar so it appears with your other events. iOS 17 grants calendar permission in a single full-access prompt; we use it only to write new events when you ask us to, and to confirm an event was created. We do not read other calendar entries or share calendar data anywhere. | Nothing is written to your calendar; the in-app date entry still works. |
| Location (when in use) | Auto-fill the city and country for a date entry from your current location. We do not log your location anywhere; the resolved city name is what gets stored locally on your device. | You can type the location manually. |
| Notifications | Remind you about upcoming dates you planned and prompt you to log how a date went afterwards. Every notification is created and scheduled on your device from your own entries — no notification content comes from, or goes to, any server. | No reminders are shown; everything else still works. |
We do not request microphone, motion, Bluetooth, or HealthKit access, and we do not use App Tracking Transparency because we do no tracking. We do not use any other sensitive permission.
7. Sensitive data
Datey is a private dating journal. The data you put into it can be sensitive — relationships, intimacy, mental state, sexual orientation, locations. We have designed the app so that this data stays on your device precisely because of how sensitive it is. We never see it, and we have built no mechanism by which we could.
PrivateVault, an in-app feature for storing photos you want kept apart from your main camera roll, applies a stronger protection than the rest of Datey’s data:
- Photos imported into the vault are written to Datey’s sandboxed app container as AES-encrypted
.encblobs (using Apple’s CryptoKit). - The encryption key is held in iOS Keychain and gated by your device biometrics or passcode (Face ID / Touch ID). Even with the file off your device, the photos cannot be decrypted without unlocking the key on your hardware.
- Vault access inside the app is gated by a biometric prompt every time you open it.
- We have no copy of the key and no way to derive it. If you lose access to your device, the vault contents are recoverable only if they were captured in your standard iOS/computer device backup (§5.2); otherwise they are unrecoverable.
When you import a photo into the vault, the original remains in your iOS Photos library until you delete it. Datey shows a reminder; permanent removal from Photos → Recently Deleted is your responsibility. When you choose to export a vault photo back to Photos, iOS prompts for “add only” Photos permission and the decrypted image is written into your library at that moment.
Vault photos are excluded from cross-device sync (§5.1) — they stay on the device where you added them. The only way a vault photo reaches iCloud is inside your standard device backup (§5.2), where it remains an AES-encrypted .enc file; Apple’s iCloud never holds an unencrypted copy.
8. Children’s privacy
Datey is rated 18+ on the App Store, asks you to confirm your age during onboarding, and is intended for adults only. We do not knowingly collect any data from anyone under 18 — and because we never receive the journal (§3.1), we could not identify or retrieve a minor’s entries even if asked. We do not have them.
If you are a parent or guardian and discover that a minor has used Datey on their device, here is what actually removes the data:
- Deleting the app deletes the journal. Every entry lives in the app’s private on-device storage and is removed with the app. If iCloud sync was enabled, or the device’s iCloud backup included Datey, those copies live in that device’s own iCloud account and can be removed from iOS Settings → [your name] → iCloud (under “Apps Using iCloud”, or “Manage Account Storage → Backups”).
- Purchases are handled by Apple. Refunds for purchases made by a minor go through Apple’s Report a Problem, not through us.
- Screen Time (iOS Settings) can prevent 18+ apps from being installed on a child’s device in the first place.
The only trace we could hold ourselves is the anonymous subscription record described in §3.2 — if you send the Apple purchase receipt to support@tortugatech.co, we will delete it.
9. International users
9.1 European Economic Area and United Kingdom
If you are in the EEA or the UK, the General Data Protection Regulation (EU GDPR) or UK GDPR applies to the limited data described in §3.2, §3.3 and §4.
Lawful basis. We process subscription data under Article 6(1)(b) GDPR — processing is necessary for performance of the contract you enter into when you purchase a subscription or lifetime licence. We process the anonymous usage and crash signals described in §3.3 under Article 6(1)(f) GDPR — our legitimate interest in keeping the app reliable and improving it, using signals engineered so they cannot be linked to you.
Your rights under GDPR / UK GDPR include: access, rectification, erasure (“right to be forgotten”), restriction of processing, data portability, objection, the right to lodge a complaint with your national supervisory authority (e.g., the UK Information Commissioner’s Office at ico.org.uk; EU residents can find theirs via the European Data Protection Board at edpb.europa.eu), and the right to withdraw any consent you have given us (where we rely on consent — we currently do not). You also have the right not to be subject to a decision based solely on automated processing of your data — Datey does not make any such decisions about you.
Because we do not hold the contents of your journal — only an anonymous purchase identifier and anonymous, unlinkable usage signals — exercising these rights primarily involves deleting your anonymous subscription record. Email support@tortugatech.co and we will process the request within 30 days. Because that record is not linked to your name, we may — as GDPR Article 11 permits — ask you for the Apple purchase receipt, or the information needed to locate the specific record, so that we can identify it; if you cannot give us enough to identify it, we may be unable to action the request and will tell you so.
International transfers. RevenueCat and Sentry are US companies. Transfers of the limited subscription data to RevenueCat rely on the European Commission’s Standard Contractual Clauses, together with the UK International Data Transfer Addendum (IDTA) for transfers from the United Kingdom. Transfers of crash reports to Sentry rely on Standard Contractual Clauses and Sentry’s participation in the EU–US Data Privacy Framework. Usage signals go to TelemetryDeck in Germany and stay on EU-hosted infrastructure — no transfer outside the EEA occurs. Apple’s transfers are governed by Apple’s own arrangements.
EU representative. We have assessed our processing as falling within the Article 27(2)(a) GDPR exemption from the requirement to appoint an EU representative: the identifiable personal data we process (the anonymous subscription record) is occasional and minimal; the usage and crash signals of §3.3 are engineered to be anonymous and unlinkable to any person; no special categories of data reach us (the journal content, which could include special-category data, stays on your device — end-to-end encrypted even when you sync it); and the processing presents minimal risk to the rights and freedoms of data subjects. We keep this assessment under review as the app evolves. If you are an EU data subject and you would prefer a local point of contact, email support@tortugatech.co and we will accommodate.
9.2 California residents
If you are a California resident, the California Consumer Privacy Act (CCPA, as amended by CPRA) applies. You have the right to know what personal information we have, request its deletion, correct inaccuracies, opt out of any “sale” or “sharing” (we do neither), and to non-discrimination for exercising these rights.
Categories of personal information we hold about California residents:
- Identifiers — an anonymous device-bound subscription ID. Source: created by our subscription processor on first launch. Purpose: confirming subscription status and honouring “Restore Purchases.”
- Commercial information — which Datey product you purchased and your subscription status. Source: Apple, via our subscription processor. Purpose: confirming you have access to the features you paid for.
- Device metadata — iOS version, device model, app version, country. Source: your device. Purpose: subscription processing and basic troubleshooting.
- Anonymous usage and diagnostics data — feature-usage signals and crash reports as described in §3.3, not linked and not linkable to you. Source: your device. Purpose: improving the app and fixing crashes.
We do not sell or share personal information. We do not use it for cross-context behavioural advertising. We do not knowingly collect personal information from anyone under 16, and we do not have actual knowledge that we have done so. Because the journal content stays on your device and we do not receive it, we do not collect “sensitive personal information” within the meaning of CPRA §1798.140(ae).
Because we do not sell or share personal information and set no tracking cookies, there is no “Do Not Sell or Share My Personal Information” opt-out for us to offer, and there is no sale or share for a browser Global Privacy Control (GPC) signal to opt out of.
Exercising your rights. Email support@tortugatech.co. Because we do not have your real identity, we will ask you to provide enough information to identify the specific subscription record we hold about you — typically your Apple purchase receipt for Datey (the App Store emails one for every purchase, and Settings → Apple Account → Purchase History lists them). If you are using an authorized agent (such as a lawyer or family member) to make a request on your behalf, the agent must provide written, signed authorization from you and we may verify the request directly with you before acting. We will respond within 45 days as required by CCPA, with one 45-day extension if reasonably necessary.
10. Security
On-device data is protected by iOS — encrypted at rest when your device is locked, and gated by your device passcode, Face ID, or Touch ID. Photos in PrivateVault carry an additional AES layer inside Datey’s sandboxed container (§7). If you enable cross-device sync, journal field contents are end-to-end encrypted in your own private iCloud (§5.1).
The minimal subscription data held by RevenueCat is encrypted in transit and at rest, and accessed by Tortuga Global Tech LLC personnel only when investigating a billing issue you have raised with us. Usage signals and crash reports (§3.3) are encrypted in transit.
11. Changes to this policy
If we change this policy materially, we will update the “Last updated” date at the top, and — for a material change that affects your rights — we will display an in-app notice in Datey the next time you open it.
12. Contact us
For any privacy question or to exercise a right:
Tortuga Global Tech LLC 1021 E Lincolnway, Suite 10348, Cheyenne, WY 82001, USA support@tortugatech.co