Witch Diary Privacy Policy

Last updated: 28 July 2026

Witch Diary ("the app", "we", "us") is an iOS app for tracking cosmetics and skincare product research, formulation, ingredient inventory, and production, developed and provided by Matic Oblak, an individual developer (no company or other legal entity). This policy explains what data the app handles, where it lives, and what we — the developer — can and cannot see.

The short version: Witch Diary has no server. Everything you enter stays on your device and, if you choose to sync it, in your own private iCloud account. We do not operate a backend, we do not collect analytics, and we cannot see your content.

What data the app handles

Everything Witch Diary stores is content you create by using the app:

We do not ask you to create a Witch Diary account, and we do not collect your name, email address, or any other registration information. The app identifies you only through your existing Apple ID when syncing via iCloud — Witch Diary itself never sees that Apple ID or any credentials.

Where your data lives

What we don't collect

Push notifications

The app is configured to support Apple's silent remote-notification background mode, which is standard plumbing for NSPersistentCloudKitContainer to detect when your iCloud data has changed on another device — it is not used to send you visible notifications, marketing messages, or alerts of any kind today. If that ever changes, this policy will be updated first.

In-app purchases

Witch Diary offers an optional auto-renewable subscription, handled entirely through Apple's App Store and StoreKit. We never see or store your payment details — Apple processes the transaction, and the app only checks your purchase entitlement locally on-device. See Apple's own privacy practices for how App Store purchases are handled.

Children's privacy

Witch Diary is not directed at children and is not designed to collect data from anyone, of any age. Since we do not operate a server or collect personal data, no age-specific data-collection concerns apply.

Your data, your control

Because there is no server-side copy of your data, most of the rights you'd typically ask a company to honor (access, export, deletion) are already in your hands:

The flip side of this is also worth being direct about: if your data is lost, corrupted, or missing, we have no way to help recover it. We don't have a copy, we can't see into your iCloud account, and there's no backend for us to check. Apple's iCloud/Account support is the only place equipped to help with that — not us.

If you're in a jurisdiction with statutory data-subject rights (e.g. New Zealand's Privacy Act 2020, GDPR in the EU/UK, or CCPA/CPRA in California), the same practical answer applies: we don't hold a copy of your personal data to access, correct, or delete on your behalf, because it never reaches us. If you have questions about this, contact us using the details below.

Security

Data stored locally is protected by your device's own security (passcode, encryption at rest). Data synced via iCloud is encrypted in transit and at rest by Apple; if you've enabled Apple's Advanced Data Protection, iCloud data is end-to-end encrypted such that even Apple cannot read it.

Changes to this policy

We may update this policy as the app changes — for example, if we ever add a feature that changes what data is collected. We'll update the "last updated" date above when we do. Material changes will be reflected in the app's release notes.

Contact

Questions about this policy: witch.diary.admin@gmail.com.