App privacy
Your people stay yours.
Arju does not maintain an account server or hosted database containing your relationships, notes, diary, tasks or contact records. Core app data is stored locally on your device, and Dhivinora Ltd cannot view or retrieve it.
LAST UPDATED · 11 AUGUST 2026
At a glance
Local first means local
Arju is designed to work without an Arju account. People, relationships, interactions, important dates, notes, tasks, places, diary entries, attachments and unconfirmed Capture drafts are written to the app’s local database inside the operating system’s app container.
Dhivinora Ltd does not receive a copy of that database in normal use. There is no Arju relationship-data server, no advertising SDK and no general-purpose tracking SDK in the app. Some optional actions can make a network request, and every one is explained below.
Local storage is different from anonymous storage. Your records can identify you and other people, but they remain under your device and operating-system controls unless you choose an action that sends specific information elsewhere.
Data map
What the app handles
| Data | Where it is stored | Does Dhivinora receive it? |
|---|---|---|
| People, names, contact methods, photos, tags, relationships and imported-contact links | Local Arju database and app files | No, not in normal app use |
| Important dates, reminders, interactions, facts, notes, tasks, places and saved addresses | Local Arju database | No, not in normal app use |
| Diary text, mood, linked people or places and attachments | Local Arju database and app files | No, not in normal app use |
| Capture text and generated draft | Processed locally by default; saved locally only after confirmation | No when Local only is used |
| OpenAI or Google Gemini API key | Operating-system secure storage, configured as device-bound | No |
| Cloud AI request | Sent directly to the provider you select only after cloud AI is enabled | No Arju server receives the request |
| Help-improve event | Not sent by default. Requires both your opt-in and a release configured with a collection endpoint | Only if both conditions are met |
| Support email | Your email service and ours | Yes, when you choose to contact us |
Contacts
Import starts with permission
Arju asks for the operating system’s Contacts permission only after explaining the import. If you allow access and choose to import, the app can read selected contact fields such as names, phone numbers, email addresses, birthdays and photos. It creates local Arju records and does not modify the source contacts on your device.
Potential duplicates are shown for review rather than silently merged. Revoking Contacts permission in system settings stops future reads. It does not automatically erase people you already imported, because those are separate local Arju records. You can delete those records in Arju.
Other permissions
Access follows the feature
You can change permissions in iOS or Android settings. A revoked permission can limit the related feature but does not delete existing local records.
| Permission | When Arju asks | Use |
|---|---|---|
| Location while using the app | When you choose to save or position an address | Read the device location for the requested place action. Arju does not continuously track location in the background |
| Photos or media | When you choose an image for a person, important date or supported attachment | Let you select the file you asked to add to the local record |
| Notifications | When you enable reminders | Schedule local notifications for dates, tasks and follow-ups |
| Internet | When the app checks a chosen network service, such as optional cloud AI | Complete only the network action described in this notice |
Smart Capture
Local parsing is the default
Smart Capture first uses a deterministic parser on your device. Local-only Capture makes no network call. It produces a reviewable draft, and Arju does not save the proposed records until you confirm them.
The parser can identify proposed people, dates, reminders, tasks, interactions and related items from the text you enter. Suggestions are assistance, not decisions. You can edit or reject them before anything is written to your local records.
Cloud AI
You choose if text leaves
Cloud AI fallback is optional. Before the first transfer, Arju identifies that capture information will be sent to a third-party AI provider and asks for permission. If you enable it, the app sends the current Capture text, capped by the app at 2,000 characters, the item types the parser may return and a limited set of relevant candidate references using opaque identifiers. It does not send your full address book, full database or internal database identifiers.
You select OpenAI or Google Gemini and provide your own API key. The request travels directly from your device to that provider. It does not pass through an Arju server. The provider receives the prompt content, your API credential and ordinary connection information such as your IP address. Its own terms, retention settings and privacy policy apply to that processing.
Arju asks the provider for a constrained structured response. Oversized, malformed or unsupported output is discarded, and the local draft remains available. Cloud output is never saved without your review and confirmation.
- Cloud AI is off until you enable it and grant the in-app permission.
- Return to Local only at any time to stop future cloud requests.
- Delete one provider key or reset all AI data from the app settings.
- Deleting a key stops Arju from making future requests with it but cannot recall information already processed by the provider.
Provider standard
Third parties must protect it
Dhivinora Ltd only enables a third-party service where its published terms, technical controls and available contractual protections are suitable for the limited transfer described here. We require service providers acting for us to protect personal information to a standard no less protective than this notice and applicable law.
For bring-your-own-key AI, you also form a direct service relationship with the provider you select. Review that provider’s account settings and data controls before enabling cloud AI. If those terms do not fit your needs, keep Smart Capture on Local only.
API keys
Secrets stay device bound
Provider API keys are stored in the operating system’s secure credential storage, not in the Arju database, ordinary preferences, logs or sync metadata. On Apple platforms they are configured not to synchronise and to remain available only after the device is unlocked. Android backup rules exclude the secure-storage material used for these keys.
The key is sent only to the selected provider as the credential for a request. Dhivinora Ltd cannot read or recover it. If a key may be compromised, delete it in Arju and revoke or rotate it in the provider account.
Help improve
Improvement sharing is off
The Help improve setting is off by default. The standard app configuration contains no collection endpoint, so no improvement event is transmitted. Sending can occur only if you opt in and a distributed release is deliberately configured with an endpoint.
If both conditions apply, the app attempts to scrub Capture text before transmission by replacing known names, @mentions, email addresses, phone numbers, web addresses and long numbers. It can also include parser features and whether suggested item types were kept. Scrubbing reduces identification risk but cannot guarantee that every free-text detail is anonymous.
Dhivinora Ltd will update this notice and identify the recipient, purpose and retention before enabling an operational collection endpoint in a public release. You can switch Help improve off to stop future events.
No production upload
Debug tools are not app collection
The source repository contains a developer-only database snapshot utility for controlled testing. It is guarded by debug-build checks and a separate build flag, encrypts a snapshot before upload, and is not active in production releases. It is not used to collect public App Store or Play Store user databases.
Backups and sync
No Arju cloud copy
The current app does not implement an Arju account or cross-device cloud sync service. Design documents discuss a possible future encrypted, user-owned drive sync, but that is not an active feature and is not described as current processing.
Your operating system may include app files in a device backup or device-to-device transfer according to your Apple or Google account settings. That backup is provided by the operating-system provider, not an Arju server, and Dhivinora Ltd cannot access it. Device-bound API keys are configured separately and are not designed to travel with those backups.
We will update this notice and the in-app explanation before any public sync feature begins processing personal information.
Retention
You control local retention
Local records remain until you delete them in Arju, use an available reset control, or remove the app and its local container. Deleting an imported person in Arju does not delete the source entry from your device contacts. Removing the app may not remove copies already held in an operating-system backup, which are controlled through your Apple or Google backup settings.
Dhivinora Ltd has no server copy of local records to delete for you. Support correspondence is normally retained for up to 24 months after the last substantive contact, unless a longer period is needed for a legal duty, unresolved complaint, security investigation or legal claim. Optional AI providers apply their own retention rules to requests already sent to them.
Security
Protection starts on the device
Arju relies on the operating system’s app sandbox, permission model and secure credential storage. Sensitive actions are designed to minimise data movement, cloud responses are validated before use, and app logs must not contain relationship content or API keys.
Protect the device with a strong passcode, keep the operating system updated and secure any Apple, Google, OpenAI or Gemini account connected to your use. No storage system can promise absolute security.
People in your records
Use relationship data thoughtfully
Arju lets you store information about other people. Keep only details you have a legitimate reason to remember, respect confidential information and delete material that is no longer appropriate. Do not use Arju to record information unlawfully or to make decisions that unfairly affect another person.
Your choices
Revoke, delete or ask
There is no Arju server account to close and no remote relationship database for us to export. If you make a request about support information, we may ask for the minimum details needed to verify that the request belongs to you.
- Revoke Contacts, Location, Photos or Notifications access in the device settings.
- Keep Smart Capture on Local only or revoke the cloud AI permission in Arju.
- Delete provider keys and reset local AI settings from Arju.
- Delete local people, notes, dates, tasks, diary entries and other records in the app.
- Manage operating-system backups through your Apple or Google account settings.
- Email support@arju.app about information Dhivinora Ltd actually holds, such as a support message.
Legal position
Rights and lawful bases
For local content that never reaches Dhivinora Ltd, we do not possess the information and cannot fulfil access or deletion from a server. Your controls are the app and device controls described above.
Where Dhivinora Ltd receives personal information, such as support correspondence, we generally rely on legitimate interests in supporting and securing Arju, steps at your request before a contract, legal obligations, or consent where a feature specifically asks for it. Depending on the circumstances, you may have rights to access, correction, erasure, restriction, portability and objection, and the right to withdraw consent.
Children
Not directed to under 13s
Arju is not directed to children under 13. We do not knowingly collect a child’s information through an Arju server because there is no app account or relationship-data server. If a parent or guardian believes a child sent personal information to support, contact us so we can review it.
Complaints
Contact us or the ICO
Email support@arju.app with an app privacy question or complaint. You may also complain to the Information Commissioner’s Office in the UK, or to your local data protection authority where applicable.
Changes
New data paths need a new notice
We review this notice before introducing an account, live sync, an operational improvement endpoint, analytics or another service that changes where information goes. Material new processing will be explained before it starts and, where required, will ask for a new choice. The date at the top identifies the current version.
