LogHero

Privacy policy

Last updated 7 September 2026

LogHero is a private journal. It only works if you can be honest in it, so the app is built to hold as little of you as it can, and to hand it all back the moment you want out. This policy explains exactly what is stored, where, and for how long.

LogHero is made by CreativeApps, Karim Mortabit, France (“we”). For anything in this policy, write to karim@creativeapps.studio.

What we store

What we don’t

There is no analytics SDK, no advertising SDK and no third-party tracker in the app. We do not build a profile of you, we do not sell or share your data, and nothing you write is used to train any model. We do not ask for your contacts, location or health data.

Reminders are scheduled by your own phone. The app has no push notification server, so a reminder never involves us knowing it fired.

Where it lives

Your account and content are stored with Supabase, which hosts our database, authentication and file storage. Access rules are enforced by the database itself: a row can only be read or written by the account that owns it.

Other companies involved, and the only thing each one gets:

How long we keep it

For as long as your account exists. Delete an entry and it is removed from the database. Delete your account — Settings, then Delete account — and your account, everything you logged and every photo you uploaded are deleted with it. That action cannot be undone, and there is no recovery window.

Your rights

Under the GDPR you can ask for a copy of your data, ask us to correct it, ask us to delete it, or object to how we handle it. Deleting your account in the app does the third one immediately; for anything else, email karim@creativeapps.studio and we will answer within 30 days. You also have the right to complain to your national data protection authority.

We handle your data because you asked us to run this app for you — the legal basis is performance of our agreement with you, set out in the terms.

Children

LogHero is not built for children under 13, and we do not knowingly hold data from them. If you believe a child has an account, email us and we will remove it.

Security

Traffic between the app and our servers is encrypted in transit, data is encrypted at rest, and per-account access rules run inside the database rather than only in the app. No system is perfect; if we ever discover a breach affecting your data we will tell you and the relevant authority without undue delay.

Changes

If this policy changes we will update the date at the top, and for anything material we will say so in the app before it takes effect.