Privacy Policy

Your collection,
always safe.

How we process your data in Poesie

We do not collect or store the content of your poems on our servers: your collection stays on your device and in your personal Google Drive.

Last updated: September 2026

Introduction

Poesie is an Android mobile application that allows users to create, manage, and preserve their personal collection of poems, with synchronization via Google Drive. The app supports multiple independent collections, each with its own cover image and file on Drive.

The app offers a free version and a Premium version available through a one-time in-app purchase via Google Play. This policy describes what data is processed, for what purposes, and what rights you have as a user.

The developer does not collect or store the content of your poems on their own servers. Your collection remains on your device and in your Google Drive.

Data Controller

The data controller for personal data is:

For any privacy-related requests, you can contact the controller at the email address provided.

Processed Data

The app processes the following data exclusively for the functioning of the service:

  • Email address of the Google account (displayed in the settings screen after connecting to Drive)
  • .docx file of each collection, created/updated by the app in your personal Google Drive (drive.file scope)
  • OAuth 2.0 authentication token (saved locally using secure operating system mechanisms)
  • App preferences (e.g., selected language, visual theme, Premium activation status, collection list)
  • Custom cover image selected by the user via system picker (saved in the app's private directory)
  • Lock password: the app only saves a hash (not the plain text password) in a protected area of the device
  • Recovery code saved in a protected area of the device to allow password resets in case of loss
  • Premium purchase token (Google Play purchase token) — saved in a protected area of the device to verify purchase validity with Google Play Billing; it is never shared with the developer
  • Encrypted local backup file (password-protected ZIP archive) — generated upon user request and saved in local cache; not sent to third parties

No data is stored on servers owned by the developer.

Purposes and Legal Basis

Data is processed for:

  • Syncing and saving collections on Google Drive
  • Security functions (app lock via PIN or biometrics, recovery code, local file encryption, security overlay)
  • User-requested features (cover image, language preferences, visual theme, tags, favorites, streak widget, writing goals, local backup, anthology PDF generation, local processing of statistics and "Poetry Wrapped")
  • Local notifications (writing streak reminders, restored upon device reboot)
  • In-app purchase management (verification and restoration of the Premium purchase via Google Play Billing)

The main legal basis is Art. 6, par. 1, letter b) of the GDPR (performance of a service requested by the user). Local security features (app lock/recovery) are aimed at protecting access to user data on the device.

Google Drive

The app uses Google Drive APIs with the drive.file scope, which restricts access strictly to files created by the app itself.

  • The app cannot read other files present in your Google Drive
  • The app cannot modify or delete files not created by it
  • The Poesie.docx file remains your property and under your control
  • You can revoke access at any time from your Google settings

You can revoke the app's permissions by visiting myaccount.google.com/permissions.

Local Storage and Security

The following data is saved locally in the app's private folder, protected by the operating system and inaccessible to other applications:

  • OAuth 2.0 tokens (in secure operating system storage)
  • Files of each collection in local cache, encrypted with AES on the app side; the unencrypted copy is automatically deleted when the app goes to the background or is hidden by the security overlay
  • Preferences (e.g., language, visual theme, Premium status, list of collections, and related settings)
  • Custom cover images (only files chosen by the user via system picker)
  • Password hash + recovery code in a protected area (SecureStorage)
  • Premium purchase token in a protected area, used exclusively for local checks with Google Play
  • Local backup file (ZIP archive encrypted with a user-provided password), generated only upon explicit request and kept in temporary cache

This data is automatically deleted upon uninstalling the app. You can also remove the Drive session via "Disconnect" in the settings.

Network communications (app → Google) take place exclusively via HTTPS (TLS).

Permissions Required

To function properly, the app requests minimal permissions:

PermissionReason
InternetConnecting to Google APIs for authentication and synchronization on Google Drive; communicating with Google Play to verify Premium purchases
Network stateChecking connectivity (e.g., to display "offline/online" messages)
System file pickerCover image selection: access is limited to the file chosen by the user via system interface
android.permission.USE_BIOMETRIC / android.permission.USE_FINGERPRINTEnabling app lock via biometric authentication
android.permission.POST_NOTIFICATIONSSending local notifications to remind users to complete their writing streak
android.permission.WAKE_LOCKKeeping the processor active during daily notification scheduling
android.permission.RECEIVE_BOOT_COMPLETEDRestoring scheduled notifications when restarting the device
android.permission.VIBRATEProviding notification vibrations
android.permission.SCHEDULE_EXACT_ALARMScheduling exact notifications even when the device is in standby mode
android.permission.RECORD_AUDIOUsing the microphone for voice dictation (Speech-to-Text). Audio is not saved or transmitted by the developer, but processed via device speech services.
com.android.vending.BILLINGManaging in-app purchases via Google Play Billing for Premium version activation (permanent single purchase)

No permission is used for purposes other than those specified.

Premium Version and In-App Purchases

Poesie offers a single, permanent in-app purchase (one-time purchase) via Google Play Billing.

Activating the Premium version unlocks extra features (e.g., additional visual themes, advanced editor tools, advanced export features). These features are managed entirely locally on your device, without needing a separate account.

In relation to the Premium purchase, the app processes the following data:

  • Purchase token — an opaque identifier generated by Google Play, saved in a protected area of the device (SecureStorage). It is used strictly to verify purchase validity with Google Play Billing APIs and is never sent to the developer or third parties other than Google LLC.
  • Premium status — a boolean flag saved in app preferences to remember the activation state between sessions, with periodic reconciliation with Google Play on app launch.

The developer does not directly manage payments. All financial transactions occur strictly through the Google Play Store, under its policies. See the Google Privacy Policy for payment data details.

You can restore a previous purchase (e.g., after reinstalling or changing devices) using the "Restore purchase" feature in the app, which queries Google Play without requiring a new payment.

Third-Party Sharing

The developer does not share, sell, or transfer any user personal data to third parties.

Third-party services used for technical operations:

  • Google LLC — OAuth 2.0 and Google Drive storage. Google Privacy Policy
  • Google LLC / Google Play — In-app purchase processing via Google Play Billing and in-app review prompts. The purchase token is sent to Google solely to validate the Premium purchase; the developer has no access to payment details. Google Play Terms

Data Retention

  • Contents (Poesie.docx) remain in your Google Drive until you delete them
  • OAuth tokens remain on the device until you log out or uninstall the app
  • The recovery code remains on the device until you remove the password/lock or uninstall the app
  • The Premium purchase token remains on the device until you uninstall the app; it is automatically removed if the purchase is no longer active on Google Play

User Rights (GDPR)

As a data subject, under Articles 15-22 of the GDPR, you have the right to:

  • Access — Obtain confirmation of data processing and a copy of your data
  • Rectification — Request correction of inaccurate data
  • Erasure — Request deletion of your data
  • Restriction — Request restriction of processing under certain circumstances
  • Portability — Receive your data in a structured format
  • Objection — Object to processing where applicable
  • Complaint — File a complaint with the Data Protection Authority (www.garanteprivacy.it)

To exercise your rights, contact the controller at the email address provided in the "Data Controller" section.

Minors

Poesie is not intended for users under 14 years of age. The developer does not knowingly collect personal data from minors under 14. In accordance with the European General Data Protection Regulation (GDPR), processing minors' data requires consent from parents or legal guardians.

In-app purchases via Google Play require a valid Google account; parental consent management for purchases is subject to Google Play and Google Family Library policies.

Cookies and Similar Technologies

The Poesie mobile app does not use cookies or tracking technologies.

This web page may use essential technical cookies provided by the hosting service. No profiling cookies are used by Poesie.

Changes to this Privacy Policy

The developer reserves the right to update this policy. Changes will be published on this page with an updated date.

Have questions about privacy?

To exercise your rights or for any privacy-related questions, contact the data controller.

supporto.poesie.app@gmail.com