1. Operator and scope The personal-data operator is ООО «Джоурлой» , INN 2373027111 , at 353217, Краснодарский край, Динской м.р-н, п. Южный, ул. Лунная, д. 14 . Contact for data-subject requests: hello@violune.com . This Policy applies to the Violune website, iOS app, API, account, backup, and synchronization features. It describes processing by the operator and does not replace Apple's privacy settings or Apple Health rules. 2. Using Violune without an account Without an account, calendar entries, selected activities, time, place, and protection details remain only on your device in Violune's local database. This information is not sent to the operator. You can erase local data in the app settings. An account is not required for everyday calendar use or offline operation. 3. Data used with an account When you create an account, the operator may process: your email address; an Argon2 password hash; the plain-text password is not stored; email-verification and password-reset codes; session tokens; calendar entries you choose to synchronize. a registration consent record containing the IP address, User-Agent, acceptance date and time, purpose, and document and Policy versions. Codes are used to verify or recover access and expire after a limited period. An account is needed only for server-backed features: backup and synchronization between the account owner's devices. 4. Special categories of personal data Calendar entries may characterize intimate life and therefore fall within the special categories of personal data under Article 10 of Federal Law No. 152-FZ. They are processed only with separate explicit consent, collected separately from acceptance of the Terms of Use. The consent terms are in the standalone Special Category Data Consent document. 5. Apple Health With your separate permission, Violune may write selected partner activity to Apple Health. This integration is write-only: Violune does not read Health data or use it for its own purposes. You can manage permission and written records in Apple Health settings. 6. Processing purposes operating the calendar, account, backup, and synchronization; verifying your email address and restoring account access; securing the service, preventing abuse, and troubleshooting; maintaining anonymous technical statistics described in section 9. 7. Legal bases Ordinary personal data is processed on the basis of the agreement with the user — clause 5, part 1, Article 6 of Federal Law No. 152-FZ. The agreement is formed when the user accepts the Terms of Use at registration; no separate general personal-data consent is requested. Calendar entries that may characterize intimate life are processed only with separate explicit consent under Article 10 of Federal Law No. 152-FZ. It is collected through its own checkbox, separately from accepting the Terms and acknowledging this Policy. 8. Contractors and transfers To operate the service, the operator may entrust processing to contractors only to the necessary extent and under confidentiality and data-protection obligations: hosting and other infrastructure running the API, database, and backup storage; Mailgun, only for transactional email containing verification and password-reset codes; security and technical-maintenance providers where their involvement is needed to operate and protect the service. Data is not sold, used for advertising, or sent for marketing messages. Apple Health receives data only with your separate permission through iOS mechanisms. 9. Anonymous telemetry Telemetry associated with a particular device contains technical data: app version, platform, language, settings, and other app-operation parameters, as well as a persistent randomly generated installation identifier (UUID; TelemetryReporter.installID ). The operator retains this identifier indefinitely in telemetry_devices.device_id and keeps one presence row for each UTC calendar day in telemetry_daily . It contains no information about calendar entries. Counters of activity records leave the device exclusively as impersonal global daily sums, without a device or account identifier, so they cannot be attributed to any user. 10. Retention and deletion Local entries remain on the device until you delete them or remove the app's data. Account data and synchronized entries remain until account deletion or while needed to operate the service and meet mandatory legal requirements. Verification and reset codes expire after a limited time; session tokens remain until logout, expiry, or revocation. The installation identifier, the latest technical device telemetry, and the related daily presence records in telemetry_devices and telemetry_daily are retained indefinitely. Delete the account and synchronized calendar in the app: Settings → Account → Delete Account. Deletion cascades to related entries. Data is then deleted or anonymized unless further retention is required by law. You can also send a deletion request to hello@violune.com . 11. Data-subject rights and contact A data subject may request information about processing, correction, blocking, or deletion of inaccurate data; request termination of processing where the law allows; withdraw consent where processing is based on consent; and complain to the competent authority or a court. To request deletion of installation telemetry, including the telemetry_devices record and related telemetry_daily rows, email hello@violune.com . If you know the installation identifier, include it and a contact method; otherwise, include any available details that can help locate the relevant installation. Usage and deletion instructions are also available on the support page . 12. Security and policy updates Data sent between the app and API is protected with TLS. Passwords are stored as Argon2 hashes, and on-device tokens are stored in the Keychain. Face ID, Touch ID, or a device passcode can further hide app content and its snapshot in the app switcher. The operator may update this Policy as the service or legal requirements change. The current revision, date, and version are published on this page; material changes may also be announced in the app. Current revision: August 27, 2026, version 2026-08-27 . The Russian-language version of this Policy prevails in the event of a difference in legal interpretation.