This Policy explains how Jinventra ("we," "us," or "our") handles data in Worry Fossil (the "App") and on its official privacy-policy website. This Policy takes effect when it is first published on worryfossil.com.

1. Scope and nature of the service

This Policy applies to:

  • the Android and iOS versions of the App; and
  • the privacy-policy pages we provide on worryfossil.com.

The App is an offline-first tool for personal writing, sealing, and reflection. It is not a medical, diagnostic, treatment, counseling, or crisis-intervention service. If you face immediate danger or need medical assistance, contact local emergency services or a qualified professional.

2. Privacy at a glance

  • The App does not require an account and has no Jinventra-operated user backend.
  • Drafts, worry text, stars, fossils, names, inscriptions, and related records are processed and stored by the App on your device. Jinventra does not receive this content through the App.
  • The App does not use advertising, analytics, or tracking tools, and it does not submit your content for AI analysis. It currently provides no cloud sync or automatic cloud backup.
  • The App does not transmit private writing, search terms, manual-backup contents, or diagnostic data to Jinventra or third parties.
  • A manual backup that you choose to export leaves the App's private storage and is managed by you and your chosen file service. The file has no separate password protection.
  • Visiting this Policy website or voluntarily emailing support involves limited website or email processing that is separate from the App's on-device data, as explained in Section 8.

3. Data processed by the App on your device

3.1 Data categories

Depending on the features you use, the App may process the following on your device:

  • unsealed drafts and worry text;
  • sealing duration, creation and update times, status, input method, and necessary identifiers;
  • appraised stars, intensity, astronomical identifiers, and visual-display data;
  • fossils, names or inscriptions, image bindings, styles, and visual-display data;
  • relationships between records and data needed for search and filtering;
  • general App settings such as language, sound, and haptic feedback; and
  • local keys and security metadata needed to protect content.

Your writing may contain health, emotional, relationship, or other sensitive information that you choose to include. The App does not determine, classify, or transmit that content.

3.2 Purposes and methods of processing

This data is used only on your device to provide features you choose to use, such as saving drafts, sealing and unsealing entries, displaying stars and fossils, searching or filtering, editing or deleting records, preserving settings, and maintaining data security. Search terms are processed only on your device and are not transmitted to us.

If you choose not to enter private content, you can still open the App and adjust some settings, but you cannot create or save the corresponding writing, stars, or fossils.

4. Data we do not collect or share through the App

The App's everyday features operate on your device. They do not send your private writing, search terms, manual-backup contents, or usage behavior to Jinventra. We do not collect, sell, rent, or share this data through the App.

When you select Privacy Policy in Settings, the App asks your system browser to open the fixed URL https://worryfossil.com/privacy. The App does not add journal, backup, or other App content to the URL or send that content to the Policy website. Information provided by the browser to load the page is described in Section 8.2.

An export or import to a file location you choose is a device or file-provider operation that you direct; it is not an upload to Jinventra.

5. On-device security and system backups

The App protects sensitive content with authenticated encryption (currently AES-256-GCM). The raw content key is kept separate from the database and stored using Android or iOS platform-secure storage. Jinventra has no universal decryption key, remote account copy, or support backdoor.

Private App data on Android and iOS is not designed to be restored through system automatic backups. Cross-device transfer is available only through a manual backup that you explicitly initiate. A compromised platform or device and circumstances outside the App's control can still create risk; no security measure can guarantee absolute security.

If your device, content key, and every usable manual backup are lost, we may be unable to help recover your content.

6. Manual backups and replacement imports

6.1 Exporting a backup

You may choose to export a snapshot of your formal journal for transfer between Android and iOS. The backup is a directly readable UTF-8 JSON file with no separate password protection. Anyone who obtains the file may be able to read and import its contents.

The backup includes formally sealed worry content, stars, fossils, inscriptions, required dates and statuses, relationships, and stable image identities. It excludes unsealed drafts, general settings, the content key and other security material, and the image, font, or audio files themselves.

The App does not create backups automatically in the background and does not retain a copy of your most recent export. A device location, cloud drive, or other file provider you choose may handle the file under its own terms. Store it only in a location you trust and use any access controls offered by that service.

6.2 Importing and replacing

An import is a full snapshot replacement, not synchronization, merging, or partial restoration. The App validates the entire file first. Only after a successful replacement does it replace the target device's existing formal journal with the backup and clear the target device's old draft and temporary cooldown data. General App settings are preserved.

An old backup may still contain content you later deleted from the App. Importing that backup can cause the content to reappear. The App cannot track or delete external copies that you moved outside it.

Choosing not to export a backup does not affect the App's other features, but you will not have an external copy for manual transfer or restoration.

7. Retention, deletion, and uninstalling

7.1 Data in the App

On-device data is generally retained until you edit or delete it, perform a replacement import, run the full journal-data clearing flow, or the operating system removes the App data.

  • Individual deletion: Depending on the feature, this removes the selected fossil, inscription, original worry content, and necessary related data.
  • Clear all data: After the Settings flow requires the exact uppercase word DELETE, it removes drafts, all sealed or pending-appraisal content, stars, fossils, inscriptions, image bindings, temporary cooldown data, derived content data, and the content-security material that must be destroyed. This cannot be undone.
  • Data that remains: General App settings, including language, sound, and haptic feedback, and bundled assets that can be obtained again are outside the scope of this full journal-data clearing operation.
  • Uninstalling the App: The operating system normally removes private App data, although the lifecycle of platform-secure storage can vary by platform and device. Uninstalling does not remove backups you exported elsewhere.

The App has no user account or Jinventra backend, so there is no remote App account or journal copy for us to delete on your behalf.

7.2 External backups

You and your chosen file provider control the retention and deletion of external backups. Deleting records in the App, clearing all data, or uninstalling the App does not remove these external copies. You must delete them at each storage location yourself.

8. Policy website and support email

8.1 Voluntarily emailing support

Only when you voluntarily email support@worryfossil.com will we and the providers used to route and receive mail receive the sender address, name (if included), message, and attachments you provide. This data is used only to reply, handle privacy or security requests, and complete necessary follow-up.

We retain support mail only for as long as reasonably necessary and delete or de-identify it after the issue and necessary follow-up are complete, unless applicable law requires longer retention. Do not email full private writings, content keys, passwords, complete manual backups, or other unnecessary sensitive data.

Not sending an email does not affect the App's on-device features, but we cannot respond to you by email.

8.2 Visiting the Policy website

This Policy website uses Cloudflare for website hosting, delivery, and security. When your browser loads the website, Cloudflare receives information contained in an ordinary web request, such as the IP address, request time and path, browser language preferences, and browser, device, or system information. This information is used to deliver, maintain, and protect the website.

The /privacy route uses the language preference provided by your browser only to redirect immediately to the Traditional Chinese or English page; we do not separately retain that language preference. This website may use traffic, security, and performance analytics provided by Cloudflare to understand website usage, maintain website security, and improve the service. This website data does not include private writing, search terms, or manual backups from the App. Cloudflare handles related data under its Privacy Policy.

If your browser or network blocks the requests necessary to load the website, the Policy page may be unavailable. This does not affect the App's on-device writing features.

9. Processing parties, locations, and international transfers

Depending on the context, data may be processed by:

  • You and the App: Private content is processed on your device.
  • A file provider you choose: A file is processed only when you initiate a manual-backup export, storage, or import operation.
  • Cloudflare: It provides hosting, delivery, security, traffic and performance analytics, and support-email forwarding for the Policy website. A related web request or email passes through its service when you visit the website or contact support.
  • Email service providers: Mail is transmitted and stored when you voluntarily contact support.
  • Google Play or the Apple App Store: App download and update data is processed by the stores under their own policies. The App does not thereby receive your private writing.

Cloudflare, an email provider, or a file provider you choose may process data in countries or regions outside your location, subject to its own policy and local law. Jinventra does not sell or rent personal data obtained in these contexts. If a valid legal demand requires disclosure of limited data we actually hold, we will handle only what is necessary as required by law.

10. Your choices and rights

Subject to applicable law, you may have rights regarding personal data Jinventra actually holds, including rights to inquire about or access it, request a copy, supplement or correct it, request cessation of collection, processing, or use, and request deletion. Contact support@worryfossil.com to make a request. To protect data, we may reasonably verify your identity and the scope of the request.

Because Jinventra cannot access App data that exists only on your device, we cannot remotely view, export, correct, or delete it. You can control it directly through the App's editing, individual-deletion, manual-backup, and DELETE clearing features. You must address external backups with their storage locations or file providers. Data held by another service may also need to be handled through that service's privacy tools or procedures.

11. Changes to this Policy

If our data-handling practices change materially, we will update this Policy and provide appropriate notice as required by applicable law and platform rules.

12. Contact us

Operator/developer: Jinventra

Privacy and support email: support@worryfossil.com