Privacy Policy

Dahlia · Effective date: July 17, 2026 · Last updated: September 30, 2026

This Privacy Policy explains how Dahlia: Date Night Ideas ("Dahlia", "the app", "we", "us", or "our") handles information in connection with your use of the Dahlia iOS application. Dahlia is developed and operated by an individual developer based in Israel (the "Developer"). The app's internal bundle identifier is xyz.bogtsi.ember — it reflects "Ember", a former working name for the app during development, and cannot be changed after publishing; it has no bearing on how the app functions or on this policy.

We built Dahlia to be private by design. Dahlia has no user accounts, no login, and no backend server operated by us. The data you create in the app stays on your device. The only information leaving your device is handled by the third-party services described below, each under their own privacy policy.

Short version: Your favorite date ideas, "we did this" history, saved date plans, Plan-it nights, Forget-me-nots entries and important dates (including an optional anniversary date), filter preferences, and streak are all stored on this phone unless you choose to back up or share them. You can save a complete backup — optionally protected with a passphrase only you know — to Files or email, and restore it later; we never see any of it. You can send a date-night invite as a calendar file, copy it as text, email it, or add it directly to your own calendar (write-only access — Dahlia never reads your calendar). We don't run a server and we can't see any of your data. There are no accounts, no ads, no advertising SDK, no analytics, and no tracking. Subscriptions are handled by Apple and RevenueCat. Optional local reminders — weekly, for a planned night, for an important date, or a monthly nudge to back up — are scheduled entirely on your device.

1. Who we are & how to contact us

Dahlia is operated by a solo developer based in Israel. For any privacy question or request, contact us at support@bogtsi.xyz.

2. Data stored locally on your device

The following information is created and stored on your device, using React Native's AsyncStorage inside the app's own sandbox — stored on this phone unless you choose to back up or share it (Section 4). It is never transmitted to us — we operate no server to receive it — and we cannot access it:

Because this data lives only on your device, it is removed when you delete the app — with one exception: a backup file you've exported to Files, Mail, or another app (Section 4) is a copy that has left the sandbox, and deleting Dahlia does not delete it; you manage those copies the same way you manage any other file on your device. We provide no cloud backup or sync of this information ourselves; if you use iCloud device backup, your device backup is governed by Apple's policies.

3. What we do NOT collect

Dahlia does not have user accounts or a login of any kind, so there is no name, email, or password for us to collect through the app itself. We do not operate a backend server, so there is no server-side database of your activity. We use no analytics or crash-reporting SDKs (no Firebase, Sentry, Amplitude, or similar). Dahlia contains no advertising and no advertising SDK, does not use the advertising identifier (IDFA), and does not present Apple's App Tracking Transparency prompt, because nothing in the app tracks you. We do not access Apple Health, your location, your camera, your microphone, your contacts, or your photo library — Dahlia requests none of these permissions. Dahlia can optionally request write-only access to your calendar (Section 4) to add a single event you choose; that permission never lets the app read, list, or alter anything already on your calendar, and nothing is requested until you tap "Add to my calendar" for the first time.

4. Backup, sharing, and calendar invites

Dahlia can open the standard iOS share sheet with a date idea or plan written out as text, so you can send it to your partner or anyone else. You choose the recipient and the app or method (Messages, Mail, etc.); that destination's handling of the content is governed by whatever app or service you pick. We receive nothing when you use any of the features below.

4a. Complete backup and restore

From Settings, you can export a complete copy of everything listed in Section 2 as a single file and save it to Files or send it by email, and later restore from that file on this or another device. You may optionally protect the export with a passphrase you choose; if you do, the file is encrypted on your device before it is written anywhere, using your device's own encryption library, and the passphrase is never stored or transmitted by Dahlia in any form. If you protect a backup and lose the passphrase, nobody — including us — can recover it. A plain (unprotected) export can be read by anyone who gets the file, including the destination app or provider you send it through, and by Apple/Google/your email provider while it's in transit through their systems — Dahlia shows this warning before you export one. Restoring a file always shows you what would change before anything is written, and a restore that replaces your record keeps one local, one-time "Undo" copy so you can put it back.

4b. Plan-it invites and calendar

You can turn a Plan-it night into a portable calendar file (.ics) and share it, email it, or copy its details as plain text — this works with any calendar app on any phone and needs no permission. You can also send a single Plan-it night as a small Dahlia-specific file to another Dahlia user; it carries only that one night's details, never your whole record. Separately, "Add to my calendar" creates one event directly on your own device's calendar using write-only access (Section 3) — Dahlia never reads, lists, or automatically edits anything already on your calendar, and never learns whether a recipient of a shared invite accepted, opened, or even received it.

5. Local notifications

If you turn on the weekly reminder, Dahlia asks for notification permission and then schedules a single repeating local notification on your device, on Friday evening, suggesting you open the app for a fresh idea. Separately, and only when you've put a night on the calendar or written down an important date with a reminder turned on, Dahlia schedules a single local, one-time or annual notification for that specific night or date — including, if you've marked one, your anniversary. If you turn on the optional monthly backup reminder, Dahlia schedules at most one local nudge after new, unsaved changes have gone a while without a backup. Every one of these is generated and delivered entirely on-device. We use no push tokens, run no push server, and no data about any reminder leaves your device.

6. Third-party services that process data

Dahlia relies on a small number of third-party services for subscriptions and distribution. When you use the app, these services may collect or process data directly, under their own privacy policies. We map each one below.

ServiceWhen it appliesWhat it processesPurpose
RevenueCat When you start, restore, or manage a Dahlia Premium subscription Purchase and subscription/receipt data, keyed to a pseudonymous app-user identifier (we never set a user ID, because there are no accounts). No favorites, history, plans, or preferences are ever sent to RevenueCat. To process purchases, validate receipts, and unlock Premium features
Apple / App Store Download, updates, and in-app purchases Purchase transactions and standard App Store data handled by Apple. Payment is made to Apple with your Apple ID — the Developer never receives or sees your payment card details. App distribution and payment processing

Their own privacy policies are here:

7. Apple's App Store data

Apple provides the Developer with aggregate sales and usage analytics about the App Store listing (for example, download counts and anonymized, aggregated engagement metrics), under Apple's own terms. This aggregate reporting is not linked to your identity and is not something Dahlia's own code collects or sends.

8. Data retention & deletion

Data stored locally on your device is retained until you delete the app — deleting Dahlia deletes all of it: your favorites, history, saved plans, Plan-it nights, Forget-me-nots entries, important dates, preferences, and streak. There is nothing stored on a server for us to delete on your behalf, because we don't have any. A backup file you've exported to Files, Mail, or elsewhere (Section 4) is a copy outside the app's sandbox and is not deleted when you delete Dahlia — you retain and delete those copies yourself, the same as any other file. The device-only calendar link described in Section 2 is deleted along with the app, like everything else in the sandbox. Data processed by RevenueCat and Apple is retained according to their own policies.

9. Children's privacy

Dahlia is not directed to children and is not intended for use by anyone under the age of 13 (or the minimum age of digital consent in your jurisdiction, such as 16 under the GDPR). Its content is general-audience relationship and date-planning content. We do not knowingly collect personal information from children — indeed, we do not collect personal information from anyone, since the app has no accounts and no server. If you believe a child has used the app in a way that concerns you, please contact us at support@bogtsi.xyz.

10. International users & your rights

The Developer is based in Israel. Dahlia is available through the Apple App Store internationally. Because we operate no server and hold no personal data about you outside of your own device, most data-subject rights recognized by laws such as the EU/UK GDPR or the California CCPA/CPRA (access, correction, deletion, portability) are already satisfied by the fact that your data exists only on your device, under your control — you can view, export a complete portable copy (Section 4), or delete it at any time by using the app or deleting it. The limited subscription information described in Section 6 is processed by RevenueCat and Apple, who may process data in the United States and other countries under their own policies and safeguards. If you have any question about your rights, contact us at support@bogtsi.xyz and we'll do our best to help, though as noted we hold no personal data to act on directly.

11. Security

Because your app data stays on your device, its security is tied to your device's own protections (passcode, encryption, biometric lock). If you protect a backup with a passphrase (Section 4), Dahlia encrypts it on-device using your platform's own authenticated encryption before writing the file anywhere, and never stores, logs, or transmits the passphrase itself — it exists only in your memory and, briefly, on your screen while you type it. There is no recovery mechanism for a lost passphrase; we cannot reset, retrieve, or bypass it. Data handled by RevenueCat and Apple is protected under their respective security practices. No method of storage or transmission is 100% secure.

12. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date above and post the new version at this URL. Material changes will be reflected here; your continued use of the app after an update constitutes acceptance of the revised policy.

13. Contact

Questions about this Privacy Policy or your data? Email support@bogtsi.xyz.