This Policy explains how Jinventra ("we," "us," or "our") handles data in Worry Fossil (the "App") and on its official website. This Policy takes effect when it is first published on worryfossil.com.

1. Scope and nature of the service

This Policy applies to:

  • the Android and iOS versions of the App; and
  • the Privacy Policy and Terms of Use pages we provide on worryfossil.com.

The App is an offline-first tool for personal writing, sealing, and reflection. It is not a medical, diagnostic, treatment, counseling, or crisis-intervention service. If you face immediate danger or need medical assistance, contact local emergency services or a qualified professional.

2. Privacy at a glance

  • The App does not require an account and has no Jinventra-operated user backend.
  • Drafts, worry text, stars, fossils, names, inscriptions, and related records are processed and stored by the App on your device. Jinventra does not receive this content through the App.
  • The App does not use advertising, analytics, or tracking tools, and it does not submit your content for AI analysis. It currently provides no cloud sync or automatic cloud backup.
  • The App does not transmit private writing, search terms, manual-backup contents, or diagnostic data to Jinventra or third parties.
  • In-app payments are handled by the Apple App Store or Google Play. The App checks purchase status with the store to provide purchased features. Private writing is not sent to the store with a transaction; see Section 3.3.
  • A manual backup that you choose to export leaves the App's private storage and is managed by you and your chosen file service. The file has no separate password protection.
  • Visiting this official website or voluntarily emailing support involves limited website or email processing that is separate from the App's on-device data, as explained in Section 8.

3. Data processed by the App

3.1 Data categories

Depending on the features you use, the App may process the following on your device:

  • unsealed drafts and worry text;
  • sealing duration, creation and update times, status, input method, and necessary identifiers;
  • appraised stars, intensity, astronomical identifiers, and visual-display data;
  • fossils, names or inscriptions, images, styles, and other necessary display data;
  • relationships between records and data needed for search and filtering;
  • general App settings such as language, sound, and haptic feedback, and custom font files you select;
  • reminder settings, system notification permission status, and times and counts needed to schedule reminders;
  • purchased-feature status, the last successful check time, and records needed to avoid processing a support-the-creator purchase more than once;
  • App Lock mode, initialization state, and verification information for a dedicated PIN (the PIN is not stored in plaintext); and
  • local keys and related security information needed to protect content.

Your writing may contain health, emotional, relationship, or other sensitive information that you choose to include. The App does not determine, classify, or transmit that content.

3.2 Purposes and methods of processing

Private content and general settings are used on your device for writing, sealing and unsealing entries, displaying stars and fossils, searching or filtering, editing or deleting records, and security. Search terms are processed only on your device and are not transmitted to us. Purchase-data processing is described separately in Section 3.3.

When you use a custom font, the App copies the font file you select into its storage on your device to display text. It does not upload the file to us.

Local reminders are scheduled by your device according to your settings and system permissions; they do not use remote push notifications. Notifications show a general reminder and the number of entries ready to revisit, without private writing. Whether they appear on your lock screen depends on your system notification settings. You can turn reminders off in the App or system settings.

If you choose not to enter private content, you can still open the App and adjust some settings, but you cannot create or save the corresponding writing, stars, or fossils.

3.3 In-app purchases and restoring purchases

Versions that offer in-app purchases use the Apple App Store or Google Play to obtain product information, process purchases, restore purchases, and check purchase status. The App may also check with the store when it starts or returns to the foreground, not only when you select a purchase.

The App receives information needed to provide purchased features, such as the item purchased, transaction identifiers, and purchase or refund status. Your device stores purchased-feature status and the last successful check time. For support-the-creator purchases, it also stores records needed to avoid processing a transaction or showing its thank-you message more than once. These activities do not send private writing, search terms, or backup contents to the store or Jinventra.

Apple or Google handles and stores payment information; the App does not directly collect or store your full credit card details. The stores may provide us with transaction information or sales reports related to the App under their policies. We do not operate a user backend to receive App transaction data. See Section 9 for the stores' data-processing policies.

4. Data we do not collect or share through the App

The App's writing and reflection features operate on your device. They do not send your private writing, search terms, manual-backup contents, or usage behavior to Jinventra. We do not collect, sell, rent, or share this data through the App.

When you select Privacy Policy in Settings, the App asks your system browser to open the fixed URL https://worryfossil.com/privacy. The App does not add journal, backup, or other App content to the URL or send that content to the official website. Information provided by the browser to load the page is described in Section 8.2.

An export or import to a file location you choose is a device or file-provider operation that you direct; it is not an upload to Jinventra.

5. On-device security and system backups

The App encrypts sensitive content and keeps the key needed to decrypt it separate from the content, using Android or iOS secure storage. Jinventra has no universal decryption key, remote account copy, or support backdoor.

You can lock the App using your device's system authentication or a dedicated six-digit PIN. System authentication is handled by the operating system; the App receives the authentication result, not fingerprint or facial-recognition data or your device unlock code. The dedicated PIN is processed on your device, and its verification material is kept in platform-secure storage and is not sent to Jinventra. App Lock controls authentication to enter the App; it does not replace content encryption or guarantee that saved previews in the system app switcher are hidden. Support cannot recover a forgotten dedicated PIN, so please remember it carefully.

Private App data on Android and iOS is not designed to be restored through system automatic backups. Cross-device transfer of journal content is available only through a manual backup that you explicitly initiate. A compromised platform or device and circumstances outside the App's control can still create risk; no security measure can guarantee absolute security.

If your device, content key, and every usable manual backup are lost, we may be unable to help recover your content.

6. Manual backups and replacement imports

6.1 Exporting a backup

You may choose to export a snapshot of your formal journal for transfer between Android and iOS. The backup is a directly readable file with no password protection. Anyone who obtains the file may be able to read and import its contents.

The backup includes formally sealed worry content, stars, fossils, inscriptions, required dates and statuses, relationships, and information needed to display the images. It excludes unsealed drafts, general settings, the content key and other security material, and the image, font, or audio files themselves.

Backups do not include App Lock mode, PIN verification information, purchase status, or support-the-creator transaction-processing records. They cannot transfer purchase entitlements.

The App does not create backups automatically in the background and does not retain a copy of your most recent export. A device location, cloud drive, or other file provider you choose may handle the file under its own terms. Store it only in a location you trust and use any access controls offered by that service.

6.2 Importing and replacing

An import is a full snapshot replacement, not synchronization, merging, or partial restoration. The App validates the entire file first. Only after a successful replacement does it replace the target device's existing formal journal with the backup and clear the target device's old drafts and temporary reroll waiting-period records. General App settings, purchase status, and support-the-creator transaction-processing records on that device are preserved. Purchase entitlements must be checked with the relevant store and cannot be obtained by importing a backup. An import preserves the target device's existing App Lock mode; if a lock is enabled, authentication is required again after import.

An old backup may still contain content you later deleted from the App. Importing that backup can cause the content to reappear. The App cannot track or delete external copies that you moved outside it.

Choosing not to export a backup does not affect the App's other features, but you will not have an external copy for manual transfer or restoration.

7. Retention, deletion, and uninstalling

7.1 Data in the App

On-device data is generally retained until you edit or delete it, perform a replacement import, run the full journal-data clearing flow, or the operating system removes the App data.

  • Individual deletion: Depending on the feature, this removes the selected fossil, inscription, original worry content, and necessary related data.
  • Clear all data: After the Settings flow requires the exact uppercase word DELETE, it removes drafts, all sealed or pending-appraisal content, stars, fossils, inscriptions, image associations, temporary reroll waiting-period records, derived content data, and the content-security material that must be destroyed. This cannot be undone.
  • Data that remains: General App settings, including language, sound, and haptic feedback, custom fonts you selected, and bundled assets that can be obtained again are outside the scope of this full journal-data clearing operation. Purchased-feature status and the last successful check time are also retained.
  • Uninstalling the App: The operating system normally removes private App data, although the lifecycle of platform-secure storage can vary by platform and device. Uninstalling does not remove backups you exported elsewhere.

Clearing journal data deletes the local records used to avoid processing support-the-creator transactions more than once, but does not delete transaction records held by Apple or Google. Clearing data or uninstalling the App is not a refund; purchase and refund status remain subject to checks with the store.

Choosing Clear all data also turns App Lock off and removes PIN verification material. After a full uninstall and reinstall, when the App confirms that no existing content is present, it handles any remaining App Lock data so an old lock does not block a new, empty App. This does not recover old content or a forgotten PIN.

The App has no user account or Jinventra backend, so there is no remote App account or journal copy for us to delete on your behalf.

7.2 External backups

You and your chosen file provider control the retention and deletion of external backups. Deleting records in the App, clearing all data, or uninstalling the App does not remove these external copies. You must delete them at each storage location yourself.

8. Official website and support email

8.1 Voluntarily emailing support

Only when you voluntarily email support@worryfossil.com will we and the providers used to route and receive mail receive the sender address, name (if included), message, and attachments you provide. This data is used only to reply, handle privacy or security requests, and complete necessary follow-up.

We retain support mail only for as long as reasonably necessary and delete or de-identify it after the issue and necessary follow-up are complete, unless applicable law requires longer retention. Do not email full private writings, content keys, passwords, complete manual backups, or other unnecessary sensitive data.

Not sending an email does not affect the App's on-device features, but we cannot respond to you by email.

8.2 Visiting the official website

The official website uses Cloudflare for website hosting, delivery, and security. When your browser loads the website, Cloudflare receives information contained in an ordinary web request, such as the IP address, request time and path, browser language preferences, and browser, device, or system information. This information is used to deliver, maintain, and protect the website.

The /privacy and /terms routes use the language preference provided by your browser only to redirect immediately to the corresponding Traditional Chinese or English page; we do not separately retain that language preference. This website may use traffic, security, and performance analytics provided by Cloudflare to understand website usage, maintain website security, and improve the service. This website data does not include private writing, search terms, or manual backups from the App. Cloudflare handles related data under its Privacy Policy.

If your browser or network blocks the requests necessary to load the website, the website pages may be unavailable. This does not affect the App's on-device writing features.

9. Processing parties, locations, and international transfers

Depending on the context, data may be processed by:

  • You and the App: Private content is processed on your device.
  • A file provider you choose: Relevant files are processed when you initiate a manual-backup export, storage, or import operation, or select a custom font.
  • Cloudflare: It provides hosting, delivery, security, traffic and performance analytics, and support-email forwarding for the official website. A related web request or email passes through its service when you visit the website or contact support.
  • Email service providers: Mail is transmitted and stored when you voluntarily contact support.
  • Google Play or the Apple App Store: The stores process data related to App downloads, updates, in-app payments, restoring purchases, purchase-status checks, and refunds, including account, payment, and transaction information needed for their services. See Apple App Store & Privacy and the Google Privacy Policy. The App does not send private writing to the stores.

Apple, Google, Cloudflare, an email provider, or a file provider you choose may process data in countries or regions outside your location, subject to its own policy and local law. Jinventra does not sell or rent personal data obtained in these contexts. If a valid legal demand requires disclosure of limited data we actually hold, we will handle only what is necessary as required by law.

10. Your choices and rights

Subject to applicable law, you may have rights regarding personal data Jinventra actually holds, including rights to inquire about or access it, request a copy, supplement or correct it, request cessation of collection, processing, or use, and request deletion. Contact support@worryfossil.com to make a request. To protect data, we may reasonably verify your identity and the scope of the request.

Because Jinventra cannot access App data that exists only on your device, we cannot remotely view, export, correct, or delete it. You can control it directly through the App's editing, individual-deletion, manual-backup, and DELETE clearing features. You must address external backups with their storage locations or file providers. Data held by another service may also need to be handled through that service's privacy tools or procedures.

11. Changes to this Policy

If our data-handling practices change materially, we will update this Policy and provide appropriate notice as required by applicable law and platform rules.

12. Contact us

Operator/developer: Jinventra

Privacy and support email: support@worryfossil.com