Violune

VIOLUNE / PRIVACY

Privacy Policy

Violune is designed so that you can use your intimate calendar without an account or an internet connection.

Last updated: September 3, 2026 · version 2026-09-03

1. Operator and scope

The personal-data operator is ООО «Джоурлой», INN 2373027111, OGRN 1252300023359, at 353217, Краснодарский край, Динской м.р-н, п. Южный, ул. Лунная, д. 14. Contact for data-subject requests: hello@violune.com.

This Policy applies to the Violune website, iOS app, API, account, backup, and synchronization features. It describes processing by the operator and does not replace Apple's privacy settings.

2. Using Violune without an account

Without an account, calendar entries, selected activities, time, place, and protection details remain only on your device in Violune's local database. This information is not sent to the operator. You can erase local data in the app settings. An account is not required for everyday calendar use or offline operation.

3. Data used with an account

When you create an account, the operator may process:

  • your email address;
  • an Argon2 password hash; the plain-text password is not stored;
  • one-time email-verification and password-reset codes;
  • session tokens;
  • calendar entries you choose to synchronize;
  • a registration consent record containing the date and time, document and Policy versions, source, IP address, User-Agent, and a subject key — an irreversible SHA-256 hash of the email address.

An account uses only an email address and password; Apple and Google sign-in are not used. Codes verify the address or restore access and expire after a limited period. An account is needed only for server-backed features: backup and synchronization between the account owner's devices.

The app and API provide no functions for the operator's staff to view entry contents. Database access is limited to the operator's authorised technical staff and is used only to maintain and protect the service.

4. Special categories of personal data

Calendar entries may characterize intimate life and therefore fall within the special categories of personal data under Article 10 of Federal Law No. 152-FZ. They are processed only with separate explicit consent, collected separately from acceptance of the Terms of Use. The consent terms are in the standalone Special Category Data Consent document.

5. Processing purposes

  • operating the calendar, account, backup, and synchronization;
  • verifying your email address and restoring account access;
  • securing the service, preventing abuse, and troubleshooting;
  • maintaining technical statistics without an account link, described in section 9.

6. Legal bases

Ordinary personal data is processed on the basis of the agreement with the user — clause 5, part 1, Article 6 of Federal Law No. 152-FZ. The agreement is formed when the user accepts the Terms of Use at registration; no separate general personal-data consent is requested.

Calendar entries that may characterize intimate life are processed only with separate explicit consent under Article 10 of Federal Law No. 152-FZ. It is collected through its own checkbox, separately from accepting the Terms and acknowledging this Policy.

7. Processors and third parties

To operate the service, the operator may entrust processing to processors and involve third parties only to the necessary extent and under confidentiality and data-protection obligations:

  • the hosting and infrastructure provider running the API, database, and backup storage;
  • a transactional-email delivery provider, only for emails containing verification and password-reset codes;
  • security and technical-maintenance providers where their involvement is needed to operate and protect the service.

Data is not sold, used for advertising, or sent for marketing messages. The operator does not send advertising messages.

8. Database localization

Recording, systematisation, accumulation, storage, updating, and extraction of personal data of citizens of the Russian Federation are performed using databases located in the Russian Federation, in accordance with part 5 of Article 18 of Federal Law No. 152-FZ.

9. Technical telemetry

The app creates a random installation identifier. It is not linked to an account or email address. Telemetry contains technical fields: app version, platform, language, region, and settings, plus one presence record for each UTC day. Reinstalling the app generates a new identifier.

Activity counters leave the device only as global daily aggregates without any identifier. They cannot be attributed to a user. A deletion request sent by email may include the installation identifier if it is known.

10. Retention and deletion

Local entries remain on the device until you delete them or remove the app's data. Account data and synchronized entries remain until account deletion or while needed to operate the service and meet mandatory legal requirements. One-time codes expire after a limited time; session tokens remain until logout, expiry, or revocation.

The installation identifier, technical telemetry fields, and daily presence records are retained for 12 months from the last snapshot and then deleted automatically. Global daily activity aggregates are retained only as long as needed for technical statistics and then deleted or used in impersonal form.

The record of consent is retained while the consent is effective; after account deletion or consent withdrawal, evidence of the consent is retained for 3 years and then deleted automatically. On account deletion, the IP address and User-Agent in that record are erased. The email address is not kept in the record; it is represented by a subject key, an irreversible SHA-256 hash of the email address.

Deleting an individual calendar entry also erases its content on the server. Deleting the account in the app — Settings → Account → Delete Account — immediately erases all synchronized entries. You may also send a deletion request to hello@violune.com.

11. Data-subject rights and contact

A data subject may request information about processing, correction, blocking, or deletion of inaccurate data; request termination of processing where the law allows; withdraw consent where processing is based on consent; change cookie settings; and complain to the competent authority or a court.

To exercise data-subject rights or withdraw consent, send a request to hello@violune.com or to 353217, Краснодарский край, Динской м.р-н, п. Южный, ул. Лунная, д. 14. For a telemetry-deletion request, include the installation identifier if you know it and a contact method. Usage and deletion instructions are also available on the support page.

12. Security and policy updates

Data sent between the app and API is protected with TLS. Passwords are stored as Argon2 hashes, and on-device tokens are stored in the Keychain. Face ID, Touch ID, or a device passcode can further hide app content and its snapshot in the app switcher.

The operator may update this Policy as the service or legal requirements change. The current revision, date, and version are published on this page; material changes may also be announced in the app. Current revision: September 3, 2026, version 2026-09-03.

The Russian-language version of this Policy prevails in the event of a difference in legal interpretation.