Legal
Privacy Policy — Laterpond
A Spanish translation of this policy is published alongside it. If the two versions differ, this English version governs.
1. Summary
Laterpond is a private diary. You write entries, you choose when each one comes back to you, and you decide what happens to it. Everything you write lives on your device.
- Laterpond has no accounts and no sign-in. There is no Laterpond server, so there is nowhere for your writing to be stored except your own device.
- Your entry text, photos, voice notes, transcripts, tags, groups and settings are kept in an encrypted database on your device and are never transmitted to the developer or to anyone else by the app.
- There is no advertising, no cross-app tracking, no behavioral profiling, and no crash reporter, and no AI or person reads what you write.
- Only three things ever reach a network, and each is listed in section 3: a purchase, opt-in dictation, and files you choose to back up or export.
2. What stays on your device
The following is created and stored only on your device and is never sent off it by Laterpond:
- the text and titles of your entries, and their state (returned, resting, or kept as a record);
- threads, notes, decisions, checklists, tags, collections and chapters;
- photos and voice notes you attach, and the text of any dictation you insert;
- your reviews, counts and local insights;
- your profile name and photo, and every app setting, including your app-lock PIN configuration.
How it is protected. The database is encrypted with SQLCipher using a key generated on your device and held in the iOS Keychain or Android Keystore-backed secure storage, restricted to this device and released only while the device is unlocked. The database directory is excluded from the operating system's device and iCloud backups, and photo and voice-note files are stored in an app-private directory that is likewise excluded. Laterpond never writes entry text to logs.
No interpretation. Laterpond counts and states facts about your own records. It performs no sentiment analysis, no topic detection, no profiling, and no diagnosis, on your device or anywhere else. There is no cloud model and no on-device model reading your entries.
Because the developer holds no copy, the developer cannot read, recover, reset or restore your writing. If you delete the app without having made a backup or export, that content is gone.
3. What leaves your device
This is the complete list. Nothing else in the app opens a network connection.
3.1 Purchases (Apple, Google Play, and RevenueCat)
Laterpond offers an optional Premium purchase. Payment is processed by the Apple App Store or Google Play under that store's terms; the developer never sees your card details, store account, name or billing address.
Subscription and purchase state is managed through RevenueCat, Inc., a subscription-management provider. When Premium is enabled in a build:
- RevenueCat is configured with an anonymous customer identifier generated on the device. Laterpond never sends your name, your email address, or any custom identifying attribute to RevenueCat.
- RevenueCat receives the App Store receipt or Google Play purchase token, purchase history and entitlement status tied to that anonymous identifier, and Laterpond asks RevenueCat whether Premium is active — when the app starts, when you buy, and when you restore a purchase.
- This information is used for App Functionality — unlocking and keeping Premium unlocked on your devices — and, in aggregate on RevenueCat's side, for purchase analytics (revenue and subscription totals the developer sees as numbers, never as people). It is not linked to your identity and is not used to track you across apps or websites. Laterpond contains no advertising identifier and no cross-app tracking of any kind.
- None of your entry content is involved. RevenueCat receives nothing you wrote.
- If a build ships without payment keys configured, no RevenueCat call is made at all and the app runs entirely offline.
Apple or Google also keeps its own transaction records under its policies, independently of the developer and RevenueCat.
3.2 Dictation (opt-in speech recognition)
Dictation is off until you turn it on in Settings. When it is on and you use it, your speech is handed to the speech-recognition provider selected by your operating system. Depending on your device, provider, settings and language, Apple, Google, or another installed provider may process that audio on the device or on its servers under its privacy policy — this is the one path where something you say can leave your device, and it happens only while a dictation session is open.
Laterpond receives only the resulting text, keeps it in the encrypted database with the rest of your entry, and never uploads it. Turning dictation off in Settings ends this entirely.
Voice notes are different: recording a voice note stores an audio file on your device and involves no network and no speech service.
3.3 Backups, exports and the optional iCloud Drive copy
Laterpond writes backup files so a lost app does not take your diary with it.
- On-device backups. An automatic backup is on by default and writes a file into the app's own Documents folder on your device, keeping the most recent files and deleting older ones. No network is involved. You can turn the automatic backup off, change how often it runs, or run one by hand.
- These backup files are readable files. Unlike the database, they can be included in operating-system or computer backups and may be visible through the platform's file tools. You can set an optional backup passphrase, which encrypts the file contents; when you do not set one, the app states plainly that the file is unencrypted. A lost passphrase cannot be recovered by anyone, including the developer.
- Optional iCloud Drive copy (iOS only). A separate toggle, off by default, also copies each backup into Laterpond's folder in your own iCloud Drive. That copy lives in your Apple account under Apple's terms; the developer has no access to it. Turning the toggle off stops further copies.
- Export. When you export, Laterpond writes a file and hands it to the operating-system share sheet at your request. Where that file goes is your choice, and once shared it is outside the app's control.
Exports and backups are transfers you control. The developer receives no copy of any of them.
3.4 Notifications
Reminders that an entry is returning, that a thread needs a follow-up, or that a review is ready are local notifications scheduled on your device by the operating system. There is no push server and no message from the developer. Settings let you choose how much a notification shows on the lock screen: the entry's own line, only its type and time, or a neutral text with no detail at all.
4. What Laterpond never does
- No accounts, no logins, no profiles held anywhere but your device.
- No server-side copy of your writing, and no cloud sync operated by Laterpond.
- No advertising, ad identifiers, ad SDKs, or third-party ad networks.
- No analytics about the content of your diary, and no crash reporter. RevenueCat may receive purchase history and entitlement information under an anonymous identifier for Premium, as described in section 3.1.
- No sale of personal information and no cross-app or cross-site tracking. RevenueCat's billing processing is limited to the anonymous purchase data described in section 3.1.
- No reading, scoring, or profiling of what you write, by software or by people.
5. Why each piece of information exists
| Information | Where it lives | Purpose |
|---|---|---|
| Entries, attachments, tags, threads, settings | Encrypted database on your device | Running the app for you |
| Anonymous customer identifier, receipt, purchase history, entitlement status | Apple, Google Play, and RevenueCat | App Functionality — unlocking and restoring Premium — plus aggregate purchase analytics |
| Speech audio, when dictation is on and in use | The device-selected speech provider | Turning your speech into text you can edit |
| Backup and export files | Your device, plus your iCloud Drive if you turn that on, plus wherever you share them | Letting you keep and restore your own copy |
There is no category beyond these. The developer holds no database of users, because there are no users to hold — only installations of an app.
6. Retention and deletion
Your writing is kept until you delete it. Laterpond does not expire your records on its own; entries you keep stay on the device until you remove them or remove the app.
- Delete everything inside the app. Settings has an erase action that wipes every record in one transaction, deletes attachment files and backup files the app created, cancels scheduled notifications, and destroys the database file together with its encryption key. The app then starts fresh, as on a new install. This action cannot be undone.
- Delete the app. Removing Laterpond from your device removes its container, including the encrypted database and attachments. Copies you exported or shared elsewhere, and backup files captured by your device's own iCloud backup, are outside the app and are removed where you put them.
- Delete the RevenueCat purchase record. To have the anonymous customer record deleted, write to support@laterpond.com and include the anonymous identifier the app displays on the subscription screen. That identifier contains nothing you wrote. The developer forwards the request to RevenueCat and confirms when it is done.
- Cancelling a subscription is a separate action. Deleting your data, or deleting the app, does not cancel a store subscription and does not produce a refund. Cancel it in your Apple App Store or Google Play subscription settings. The store, not the developer, controls billing, renewal and refunds.
Apple, Google Play, and RevenueCat retain transaction records under their policies, linked in section 9.
7. Children
Laterpond is a general-audience diary app. It is not directed at children under 13, no part of it is designed for or marketed to children, and the developer does not knowingly collect any information from a child — nothing is collected from anyone, at any age. Use of the app is also subject to the minimum age in the applicable distribution store's terms for your country. A parent or guardian who believes a child has used the app can delete it and erase its data using section 6; there is no server-side record to request removal of.
8. Security
Security here is architectural rather than promised after the fact: with no server and no account, there is no central store to breach.
- The local database is encrypted at rest with SQLCipher; its key is generated on the device and stored in the iOS Keychain or Android Keystore-backed secure storage, restricted to that device and available only while it is unlocked.
- The database and attachment directories are excluded from operating-system backups.
- An optional app lock (Face ID, Touch ID, Android device biometrics, or a PIN) gates the app on launch.
- Backup files can be encrypted with a passphrase you choose.
- Entry content is never logged, never sent to a diagnostic service, and never included in a support message unless you write it there yourself.
No method of electronic storage or transmission is perfectly secure, and no absolute guarantee is offered. Protecting the device itself — its passcode, its own backups, and who can unlock it — is your responsibility.
9. Third parties
Only the following organisations may be involved, and none receives your writing:
- Apple Inc. — app distribution, payment processing, local notifications, optional iCloud Drive storage of your backups, and the device speech service used by opt-in dictation. Apple's privacy policy: https://www.apple.com/legal/privacy/
- Google LLC — Android distribution and payment processing and, when it is the device-selected provider, optional speech recognition. Google's privacy policy: https://policies.google.com/privacy
- RevenueCat, Inc. — subscription and entitlement management, under an anonymous identifier. RevenueCat's privacy policy: https://www.revenuecat.com/privacy/
An installed speech provider chosen by the operating system may receive optional dictation audio as described in section 3.2. No other third party receives data from the app.
10. Not a medical or emergency service
Laterpond is a diary and productivity app. It is not a medical device, not professional advice, and not an emergency or crisis service; it does not diagnose, assess, or treat any condition, and it never contacts anyone on your behalf. In an emergency, contact your local emergency number.
11. Changes to this policy
If this policy changes, the updated version is published at the same address with a new effective date. Changes that affect what leaves your device will also be stated in the app's release notes. Continuing to use Laterpond after an update constitutes acceptance of the updated policy; if you disagree with it, you can export your data and delete the app.
12. Contact
Questions about this policy, or a request about the anonymous purchase record, go to support@laterpond.com. Because the app holds no account, please include the anonymous identifier shown on the subscription screen if your question concerns a purchase. Support replies are handled by the developer, who publishes Laterpond as an individual.