PathMemos PathMemos
· Proton · 13 min read

Privacy Policy

General

Your privacy is critically important to us. At PathMemo, we have a few fundamental principles:

  • We only store personal information when we have a legitimate reason to do so.
  • We aim to make it as simple as possible for you to control what information is shared publicly, encrypted, or permanently deleted.
  • We strive for full transparency in how we collect, use, and share your personal information.

This Privacy Policy incorporates and explains these principles.

Information We Collect

We only collect information when we have a reason to do so — for example, to provide better services or to communicate with you.

We collect information from three sources: information you provide to us directly, information automatically collected by the app, and information collected from external sources.

Information You Provide to Us

We collect information you provide directly to us. Examples include:

  • Diary Entries: The most important information we collect is your diary entries. Your diary entries are private. When you create a diary using PathMemo, none of its entries are published on the internet. Other PathMemo users cannot access your diary entries. We also provide end-to-end encryption for diaries, which means our employees cannot access your diary data.
  • Account Information: If you register for an account to use services such as sync and backup, you need to provide basic account information including your phone number, email address, and password.
  • Transaction Information: When you purchase our premium services, we may collect information to complete and record the transaction. For example, if you purchase a membership, we collect your name and payment account information to process payment. We also retain your purchase history.
  • Communications with Us: You may also provide information when giving feedback or communicating with our support team. When you contact us via forms, email, phone, or other means, we keep a copy of the communication (including call recordings where permitted by applicable law). You may choose not to provide certain information, but this may limit the features you can use.

Information Collected Automatically

We also automatically collect certain information:

  • System Log Information: Like most online service providers, we collect information that web browsers, mobile devices, and servers typically make available, including browser type, IP address, unique device identifiers, language preference, referring site, date and time of access, operating system, and mobile network information. We collect log information when you use our services, such as when you log into your account or create a diary entry.
  • Device and Usage Information: We collect your device type, wireless carrier, device ID, and how you use our services. Additionally, if our app crashes on your device, we receive information about your device model, software version, and carrier, which helps us identify and fix bugs and improve app performance.
  • Location Information: We may determine your device’s approximate location from your IP address. We use this information to understand user geography and tailor features accordingly.
  • Information from Cookies and Other Technologies: Like many online services, we use cookies to collect information. Cookies are strings of information that a website stores on a visitor’s computer, and the visitor’s browser provides to the website on each return visit. PathMemo uses cookies and similar technologies to identify and track visitors, usage patterns, and preferences, as well as to measure the effectiveness of email marketing campaigns. For example, we use Google Analytics to help analyze how users interact with our website. We do not merge information generated by Google Analytics with your personal information. Google’s ability to use and share information collected by Google Analytics is governed by the Google Analytics Terms of Use and Google’s Privacy Policy.

Information from Other Sources

We may also obtain information about you from other sources, such as:

  • Third-Party Account Information: When you connect an account from another service, we typically receive basic account information from that service. For example, when you connect PathMemo with your Apple or Google account for login, we may receive certain user data such as your name, user ID, and email to provide our services.
  • Motion, Activity, and Fitness Data: Motion and fitness information is used to enhance metadata in personal diary entries and summaries. For example, we use your device’s motion processing capabilities to allow you to add step counts to diary entries. If you connect Apple HealthKit, time spent in the PathMemo app is recorded as “Mindful Minutes” in HealthKit. We never use your motion, activity, or fitness data for advertising or usage-based data mining. We do not share this information with third parties for their own use, nor do we sell it to advertising platforms, data brokers, or information resellers.

How We Use Collected Information

We use your personal information to:

  • Respond to your requests, resolve disputes, and/or troubleshoot issues;
  • Communicate with you about our services;
  • Detect, investigate, and help prevent security incidents and other malicious, deceptive, fraudulent, or illegal activities, and protect the rights and property of ourselves and others;
  • Fulfill our legal and financial obligations. We will primarily communicate with you via SMS and phone to address issues.

How We Share Information

We share your information in limited circumstances and with appropriate safeguards to protect your privacy:

  • Third-Party Vendors: We may share your information with third-party vendors, consultants, and advisors who help us provide services or operate our business. This includes payment processors (such as WeChat Pay and Alipay), cloud storage providers, SMS services, customer support platforms, LLM providers (such as Tongyi Qianwen and ChatGLM for intelligent diary analysis), data analytics services, and other tools that help us operate. We require these vendors to agree to privacy commitments before sharing information with them.
  • Subsidiaries: We may disclose your information to current or future parent companies, subsidiaries, joint ventures, or other entities under common control (collectively, “Affiliates”). In such cases, we will require Affiliates to comply with this Privacy Policy.
  • Business Transfers: In the event of a merger, sale of company assets, or other corporate acquisition of all or part of our business, or in the event of insolvency or bankruptcy, user information may be among the assets transferred or acquired by a third party. If this occurs, this Privacy Policy will continue to apply to your information, and the receiving party may continue to use your information only in accordance with this Privacy Policy.
  • Legal, Regulatory, and Other Obligations: We may disclose your information if we believe in good faith that it is necessary to: (a) resolve disputes, investigate issues, or enforce our Terms of Service; (b) comply with applicable laws, warrants, subpoenas, court orders, or other enforceable legal processes; or (c) protect the property or rights of PathMemo, you, third parties, or the public. For example, if we have a good faith belief there is an imminent risk of death or serious physical injury, we may disclose the minimum information necessary to address the emergency.
  • With Your Consent: We may share and disclose information with your consent or at your direction.

Anonymous Information

We reserve the right to publicly disclose anonymous information or other information that cannot reasonably identify you, without restriction.

Data Retention

For example, we retain web server logs for several months. We keep logs for this period to analyze traffic and investigate issues, after which server logs are automatically discarded.

As another example, when you delete your account, we permanently delete all of your diary entries, attachments, and account data.

Security

While no online service is 100% secure, we do our utmost to protect your information from unauthorized access, use, alteration, or destruction, and take reasonable measures to this effect. We monitor our services for potential vulnerabilities and attacks.

To enhance the security of your account, all new diary entries are end-to-end encrypted. Diary entries encrypted in this way cannot be accessed by anyone other than the logged-in author — including us.

Your Choices

You have several choices regarding your information:

  • Delete/Update Information You Provide: You can log into our website or app and access your account to view, change, and/or delete certain personal information.
  • Delete the App: You can stop all information collection by uninstalling the app.
  • Opt Out of Marketing Communications: You may choose not to receive promotional communications from us. Simply follow the instructions in the communication or let us know.
  • Set Your Browser to Reject Cookies: Before using our website, you can typically set your browser to remove or reject browser cookies. However, certain features may not function properly without cookies.

Deleting Your Account

To delete your account, go to “Settings” → “About Us” → “Delete Account” and follow the instructions.

To ensure data security, we will verify your identity before account deletion. After 24 hours, we will stop providing services and delete your personal information upon request, unless otherwise required by law.

App Permissions

We need to request certain system permissions that involve personal privacy to ensure specific features function properly. We will request authorization when you use these features, and will only access your personal information after obtaining your explicit consent. If you do not need to use these features, you may decline authorization. We will not request permissions or access your personal information if you have never used these features.

The permissions we may request and their corresponding features include:

Android Permissions

  • Write External Storage: Requested when you save generated images to your phone. After authorization, you can download images to local storage. Also used during phone number verification for SD card information writing.
  • Read External Storage: Requested when you upload images while creating or editing content.
  • Camera/Photo Library Access: Requested when you take photos or add images while creating or editing content.
  • Microphone Recording: Requested when you add videos while creating or editing content.
  • Read Phone ID: Used for product functionality analysis and improvement, without association with your identity.
  • Location Access: Requested when you record a diary and add a location.
  • Device Sensors: Allows use of gyroscope and accelerometer sensors for location and navigation features.
  • Read Installed Apps: If you need to share diary entries to other apps, we need to check your installed app list to determine whether the target app is installed.

iOS Permissions

  • Camera Access: Requested when you need to take photos to upload as attachments while creating or editing content.
  • Photo Library Access: Requested when you need to upload images from your photo library as attachments while creating or editing content.
  • Write to Photo Library: Requested when you save shared images to local storage.
  • Location Access: Requested when you record a diary and add a location.
  • Read Phone ID: Used for product functionality analysis and improvement, without association with your identity.

Your Rights

If you are located in certain regions, including some US states or countries subject to the General Data Protection Regulation (GDPR), you may have certain rights regarding your personal information, such as the right to access or delete your data.

Contacting Us About These Rights

You can typically access, correct, or delete your personal data using your account settings and the tools we provide. If you are unable to do so or wish to contact us regarding other rights, please refer to the “How to Contact Us” section below.

When you contact us regarding one of these rights, we need to verify your identity before disclosing or deleting any content. For example, if you are a user, we will need you to contact us from the email address associated with your account. You may also provide written authorization designating an authorized agent to make a request on your behalf. We may still require you to verify your identity.

Appeal Process for Denied Rights Requests

In some cases, we may deny your request to exercise one of these rights. For example, if we cannot verify you as the account owner, we may deny access to personal information associated with your account. If the law requires us to retain a copy of your personal information, we may deny a deletion request.

If we deny your request, we will inform you in writing. You may appeal our decision by responding in writing to our denial email and stating that you wish to appeal. All appeals will be reviewed by an internal expert who was not involved in your original request. If your appeal is also denied, that decision will be communicated to you in writing.

If your appeal is denied, in certain US states (Colorado, Connecticut, and Virginia), you may submit the denied appeal to the state attorney general if you believe the denial conflicts with your legal rights. We will provide you with written instructions on how to do this at the same time as we communicate our appeal decision.

Other Information You Should Know

Third-Party Software and Services

This Privacy Policy only addresses the use and disclosure of information we collect from you and/or about you through our services. Any information you disclose to third-party software or services is not covered by this Privacy Policy.

Our website may contain content or links to other websites not owned or controlled by us. We cannot control the privacy policies or content displayed on third-party operated websites.

Children’s Use

Our services are not directed at children, and children are not permitted to use our services. Protecting children’s privacy is very important to us. We do not knowingly collect or maintain personal information from persons under 13, and no part of our services is designed to attract persons under 13. If we later learn that a user is under 13, we will take steps to remove that user’s personal information from our databases and prevent the user from using the services.

Data Transfers

Because our services are provided globally, information we process about you when you use our services within the EU may be used, stored, and/or accessed by individuals working for us outside the European Economic Area (EEA), other members of our group companies, or third-party data processors. This is necessary for the purposes listed in the “How We Use Collected Information” section above.

When providing information about you to entities outside the EEA, we will take appropriate measures to ensure the recipient adequately protects your personal information in accordance with this Privacy Policy and applicable law. These measures include entering into Standard Contractual Clauses approved by the European Commission with entities in countries outside the EEA.

You may request more information about the safeguards we have in place regarding transfers of your personal information from the EU.

Changes to This Privacy Policy

Although most changes are likely to be minor, we may change this Privacy Policy from time to time. We encourage visitors to check this page frequently for any changes. We will post the latest revised version of the Privacy Policy on this page, and in some cases, we may provide additional notice (such as a statement on our homepage or a notification via email or app). Your continued use of the services after changes to this Privacy Policy will be subject to the updated policy.

How to Contact Us

If you have any questions, concerns, or complaints regarding our Privacy Policy or our information collection or processing practices, or if you wish to report a security breach, please contact us at help@papafeiji.cn.

This Privacy Policy was last revised on March 25, 2025.