Duskeep is a voice journal. You record a short spoken note about your day, and Duskeep turns it into a written summary. This policy explains what we collect, how it's used, who processes it, and the choices you have.
What we collect
- Voice recordings you make in the app.
- Transcripts and AI-generated summaries derived from those recordings.
- Mood and topic tags the AI extracts from an entry.
- Photo selections (optional): if you enable photo context, you choose which of a day's photos to attach. Only the photos you explicitly select are used; we never scan or upload your whole library.
- Account information: if you sign in, your email and display name from Apple or Google. If you don't sign in, an anonymous identifier is used so the service can process your recordings.
- Subscription status (whether you have Duskeep+), via our payments provider.
How your data is used
Your recording is encrypted on your device, uploaded, decrypted briefly on our server so it can be transcribed and summarized, and the finished page is encrypted back to your device before being stored. See How your recordings are protected below. It is the most important section of this policy.
Third-party processors
To provide the core feature, your content is processed by:
- Deepgram: speech-to-text transcription of your recording.
- Google (Gemini API): generates the written summary, mood, and topics from your transcript.
- Google Firebase: authentication, encrypted cloud storage of recordings, and the database for your entries.
- RevenueCat: manages Duskeep+ subscription status.
Your audio and text are transmitted securely (HTTPS/TLS), encrypted in transit and at rest, decrypted only transiently during processing, and are not used to train AI models. (This reflects the paid API terms of our providers.) Deepgram and Google are the only third parties that ever see your content in a readable form, and only during the few seconds a page is being written.
How your recordings are protected
Your recording is encrypted on your device before it is uploaded, with a key that is itself encrypted to a public key built into the app. The matching private key is held inside a hardware security module (Google Cloud KMS) and cannot be exported by us or by anyone else.
To turn your voice into a written page, that recording has to be readable for a short time. Here is exactly what happens in that window, and what happens after:
- The Cloud Function asks the hardware module to unwrap the key for this one recording. Every such request is recorded in an audit log we cannot alter.
- The recording is transcribed and written up. Deepgram and Google (Gemini) receive the audio and the transcript in the clear during this step. This is unavoidable if a machine is to write your day for you. Both are paid services, contractually barred from retaining your content or training on it.
- The finished page is encrypted to your device's public key, signed, and stored. The audio is deleted according to the retention schedule below.
- The key that let us read the recording is deleted from the entry. From that moment we cannot open that entry again: not from the database, not from a backup, not with any credential we hold.
Your device holds the only key that can open your stored pages. It is generated on your phone, kept in the iOS Keychain or Android Keystore, and never transmitted. We do not have a copy.
Consequences you should know about
- We cannot recover your journal for you. If you lose your phone without your recovery code (Settings → Account → Your recovery code), the pages stored in your account cannot be decrypted by anyone, including us.
- Anyone with your recovery code can read your journal. Keep it as you would keep a spare key to your home.
- Names, moods, topics, past entries and the transcript needed for a rewrite are sent by your device with each request and are not retained afterwards. We do not keep a list of the people you talk about.
- Dates, entry timestamps, recording lengths and processing status are stored unencrypted so your calendar, streaks and audio-retention timers work. These reveal when you journalled, never what you said.
On-device encryption
Separately from the above, everything stored on your phone (transcripts, summaries, moods, topics and chapters) is encrypted with AES-256-GCM before it is written to the journal database, under a second key held in the iOS Keychain or Android Keystore. If the database file were extracted from your phone or from a device backup, its content columns would be unreadable.
Erasing your journal also destroys that key, so any residue left in freed database pages becomes permanently unreadable.
Data retention
- Transcripts and summaries are kept as long as your account exists (or locally on your device), encrypted throughout to a key only your device holds.
- Raw audio: on the free plan, audio is automatically deleted after one year (your written entry remains). On Duskeep+, audio is kept until you delete it.
Your choices
- Record without an account (anonymous), or sign in to sync.
- Delete a single entry at any time.
- Erase your whole journal from Settings → Account → Erase my journal.
- Delete your account and all cloud data from Settings → Account → Delete account. This permanently removes your cloud data.
- Turn off photo context in Settings.
Children
Duskeep is not directed to children under 13 (or the minimum age in your region) and we do not knowingly collect their data.
Contact
Questions or requests: chandankadarla2722002@gmail.com