Legal
Privacy Policy
This Privacy Policy explains how Ruvia Pte. Ltd. (“Ruvia,” “we,” “us,” or “our”) collects, uses, discloses, stores, and protects personal data when you use Floria, including our mobile application, websites, features, content, and related services (collectively, the “Service”).
On this page
- About the Service
- Personal Data We Collect
- How We Use Personal Data
- AI-Assisted Journal Processing
- Legal Bases for Processing
- How We Disclose Personal Data
- International Data Transfers
- Data Retention
- Account Deletion
- Data Security
- Data Safety Disclosure (Google Play)
- Your Choices and Rights
- Notifications
- Children
- Region-Specific Information
- Third-Party Links and Services
- Third-Party SDKs and Permissions
- Changes to This Privacy Policy
- Contact Us
Please read this Privacy Policy carefully. By using the Service, you acknowledge that your personal data will be handled as described in this Privacy Policy.
Ruvia Pte. Ltd. is located at 28 EMERALD HILL ROAD, SINGAPORE 229308, SINGAPORE. You may contact us at support@ruviagroup.com.
1. About the Service
Floria is a personal journaling application. The Service currently allows users to create journal entries, add text and images, use AI-assisted journal organization, view general emotional labels, and display journal records through flower, garden, calendar, or timeline-style views.
The Service is designed for personal journaling, self-reflection, and emotional recordkeeping. It is not a medical, psychological, therapeutic, crisis intervention, or professional counseling service.
2. Personal Data We Collect
The personal data we collect depends on how you use the Service.
2.1 Account Data
When you create, sign in to, or manage an account, we may collect:
- account ID, user ID, or guest ID;
- nickname, profile image, language, region, and time zone;
- email address or other login identifier;
- information provided by supported third-party login services, such as Apple or Google, if you choose to use them;
- account creation time, login status, and authentication records.
2.2 Journal and User Content
When you create or manage journal entries, we may collect:
- journal text, titles, notes, tags, and related text input;
- images you upload and image descriptions you provide;
- AI-organized or AI-generated journal text, titles, summaries, or related outputs;
- general emotional labels or categories associated with journal entries;
- flower, garden, calendar, timeline, or other visual record data generated from your journal entries;
- edits, deletions, and other actions you take within the Service.
Your journal entries and images may contain sensitive or highly personal information. Please avoid submitting information that you do not want processed by the Service.
2.3 Device, Usage, and Log Data
To operate, secure, and improve the Service, we may collect:
- device model, operating system, app version, language, region, and time zone;
- IP address, network status, device identifiers, and push notification identifiers;
- pages viewed, buttons clicked, features used, and in-app events;
- crash logs, performance data, error messages, and diagnostic data;
- AI request status, generation success or failure, latency, and error codes;
- security logs, abuse prevention records, and fraud prevention signals.
We do not use your private journal text as ordinary analytics event properties. Product analytics should use aggregated, anonymized, or de-identified information where reasonably possible.
2.4 Customer Support and Communications
If you contact us, submit feedback, or report a problem, we may collect:
- your contact information;
- the content of your request;
- screenshots, logs, or other information you choose to provide;
- records of our communications with you.
3. How We Use Personal Data
We use personal data to:
- provide, operate, maintain, and secure the Service;
- create, authenticate, and manage accounts;
- save, display, edit, delete, and organize journal entries and images;
- provide AI-assisted journal organization, title generation, summary generation, and related features;
- generate and display general emotional labels, flowers, garden views, calendar views, and timeline views;
- sync data across devices if account sync is supported;
- provide customer support and respond to your requests;
- detect, prevent, and investigate abuse, fraud, security incidents, and violations of our Terms;
- debug errors, monitor performance, and improve reliability;
- analyze aggregated or de-identified usage patterns to improve the Service;
- comply with legal obligations and respond to lawful requests;
- protect the rights, safety, and property of Ruvia, users, and others.
4. AI-Assisted Journal Processing
The Service uses artificial intelligence technologies to help organize, refine, summarize, or structure journal entries based on your input. It may also generate titles or general emotional labels for journal entries.
To provide these features, we may process your journal text, images, image descriptions, previous edits, and related context. We may send necessary data to third-party AI technology providers or cloud service providers that process data on our behalf.
We require service providers to process personal data only as necessary to provide services to us and to apply reasonable security protections. Where available and appropriate, we seek to use settings or contractual terms that restrict providers from using your private journal content to train their general-purpose models.
AI outputs may be inaccurate, incomplete, or inappropriate. Emotional labels and AI-organized journal content are for personal reflection only and do not constitute medical, psychological, therapeutic, or professional advice.
5. Legal Bases for Processing
Depending on your location, we may rely on one or more legal bases to process your personal data, including:
- performance of a contract, where processing is necessary to provide the Service you request;
- your consent, where required by law, such as for certain optional features or permissions;
- legitimate interests, such as securing, maintaining, and improving the Service, provided those interests are not overridden by your rights;
- compliance with legal obligations;
- protection of vital interests, such as responding to urgent safety risks.
6. How We Disclose Personal Data
We do not sell your private journal entries. We may disclose personal data in the following circumstances.
6.1 Service Providers
We may share necessary personal data with service providers that help us operate the Service, such as:
- cloud hosting and storage providers;
- AI technology providers;
- analytics and product performance providers;
- crash reporting and diagnostics providers;
- push notification providers;
- customer support tools;
- security, fraud prevention, and abuse prevention providers.
These providers are authorized to process personal data only as necessary to provide services to us, subject to appropriate contractual and security obligations.
6.2 Legal, Safety, and Compliance Reasons
We may disclose personal data if we believe it is reasonably necessary to:
- comply with applicable law, legal process, or government requests;
- enforce our Terms or other policies;
- detect, prevent, or address fraud, security, or technical issues;
- protect the rights, safety, or property of Ruvia, users, or others;
- respond to urgent risks, including potential self-harm, harm to others, or other emergencies.
6.3 Business Transfers
If Ruvia is involved in a merger, acquisition, financing, reorganization, sale of assets, bankruptcy, or similar transaction, personal data may be transferred as part of that transaction. We will require the recipient to protect personal data in a manner consistent with this Privacy Policy or as required by law.
7. International Data Transfers
Ruvia is based in Singapore. Your personal data may be stored and processed in Singapore and other countries where we or our service providers operate.
These countries may have data protection laws that differ from those in your country or region. We take reasonable steps to protect personal data when it is transferred internationally, such as using contractual protections, access controls, data minimization, security measures, and vendor assessments.
Where required by applicable law, we will use appropriate transfer mechanisms for international transfers.
8. Data Retention
We retain personal data for as long as reasonably necessary to provide the Service, fulfill the purposes described in this Privacy Policy, comply with legal obligations, resolve disputes, enforce agreements, maintain security, and operate backup systems.
In general:
- account data is retained while your account remains active;
- journal entries, images, AI-organized content, flowers, and garden records are retained while you keep them in the Service or while your account remains active;
- deleted journal entries and images are removed from active user-facing views, but may remain in backups or technical systems for a limited period;
- diagnostic, security, support, and legal records may be retained for longer where necessary for legitimate business, safety, or legal reasons;
- aggregated, anonymized, or de-identified data may be retained for analytics and product improvement.
You may request account deletion by using available in-app settings or by contacting us at support@ruviagroup.com.
9. Account Deletion
You have the right to delete your account and the personal data associated with it at any time. We provide TWO methods for account and data deletion:
9.1 Option 1 — Delete through the App (Recommended)
You can delete your account directly inside Floria without contacting support:
- Open Floria and sign in with your account (Google or Apple).
- Go to Settings → Account → Delete Account.
- Read the on-screen information about what data will be deleted.
- Confirm your choice by tapping Delete on the confirmation dialog.
- Once confirmed, your account and all associated data will be permanently deleted from our active production systems immediately or within a short processing window.
- You will be signed out automatically after deletion completes.
9.2 Option 2 — Request Deletion by Email
If you cannot access the app or prefer to request deletion remotely, send an email to:
📧 support@ruviagroup.com
Email subject format (for faster processing):
Request to delete my Floria account
Please include the following information in your email so we can verify your identity and locate your account:
- Your registered email address (the Google or Apple email you used to sign in).
- (Optional) Your approximate sign-up date or last active date.
We will respond to confirm receipt within 5 business days and complete verified deletion requests within 30 calendar days from the date of verification. If additional identity verification is needed, we will contact you by reply email.
9.3 What Will Be Deleted
Upon account deletion, the following data will be permanently deleted from our active systems:
- Your account information: account ID, login credentials, nickname, profile image, language and time-zone settings.
- All journal entries: titles, text, tags, AI-generated summaries, and mood labels.
- All uploaded images stored in association with your journal entries.
- Flower path, garden view, calendar view, timeline view and any visual records generated from your journal entries.
- Device associations linked to your account.
- Customer support tickets tied to your account (after resolution, if any).
9.4 What May Be Retained (and Why)
A small amount of data may be retained after account deletion when required or permitted by applicable law:
- Anonymised / de-identified crash logs and performance diagnostics — data is no longer linked to an identifiable user and is kept only for app stability, security and product improvement.
- Legal / compliance records — if required by tax, accounting, regulatory or legal obligations, records may be kept for the applicable statutory retention period (typically 1–7 years depending on jurisdiction).
- Backup systems — recently deleted data may remain in encrypted, offline backup snapshots for up to 30 days before being purged automatically. These backups are not used for ordinary day-to-day operations.
9.5 Effect of Deletion
Deleting your account is permanent and cannot be undone. After deletion:
- You will no longer be able to sign in with the same account.
- All journal entries and uploaded images stored on our servers will no longer be recoverable.
- If you sign up again later using the same third-party login, a new account will be created — your previous content will not be restored.
10. Data Security
We use reasonable technical, organizational, and administrative measures to protect personal data, including encryption in transit, access controls, security monitoring, data minimization, and vendor management.
However, no method of transmission or storage is completely secure. You are responsible for keeping your device, account credentials, and third-party login accounts secure.
11. Data Safety Disclosure (Google Play)
This section summarises the data-handling information that Google Play displays under the Data safety section on the Floria store listing page. The information below complements (and does not replace) the full details in the rest of this Privacy Policy.
11.1 Is data collected or shared?
Yes. Floria collects certain user data as described in this Privacy Policy. Floria does not sell user data, and does not share private journal content with third parties for their own advertising or marketing purposes.
11.2 Data Collected
| Data category | Data types | Purpose | Encrypted in transit |
|---|---|---|---|
| Personal info | Email address (from Google / Apple sign-in), display name, user ID | Account creation, authentication, customer support | Yes (HTTPS) |
| User-generated content | Journal text, titles, notes, tags, uploaded photos, AI-organized journal output | Core service — saving, displaying, editing, deleting and organising your journal entries | Yes (HTTPS) |
| Device or other IDs | Device model, OS version, app version, unique device identifier (Android ID / IDFV), IP address | App functionality, security, fraud / abuse prevention, crash diagnostics | Yes (HTTPS) |
| App activity | Features used, buttons tapped, pages viewed, crash logs, performance data | Debugging, performance monitoring, product improvement | Yes (HTTPS) |
| Photos / media | Images chosen by the user via the in-app photo picker | Attached to user-created journal entries | Yes (HTTPS) |
11.3 Data Sharing
We do not sell user data. We may share data with the following categories of recipients only as necessary to provide and operate the Service:
- Service providers — cloud hosting and storage providers, AI technology providers, analytics and crash-reporting providers, customer-support tools, security / fraud-prevention providers.
- Legal, safety and compliance recipients — government authorities, courts or other parties, when we believe disclosure is reasonably necessary to comply with law, protect rights, safety or property, or respond to an emergency.
- Business transfer recipients — in connection with a merger, acquisition, financing or similar transaction, subject to appropriate confidentiality and data-protection obligations.
11.4 Security Practices
- All data transmitted between the app and our servers is encrypted in transit using TLS / HTTPS.
- Access to personal data is restricted through role-based access controls and authentication mechanisms.
- We apply data minimisation, security monitoring, vendor assessments and reasonable organisational and administrative safeguards.
- Account credentials (for third-party logins) are handled directly by the identity providers (Google / Apple) and are never stored in plain text on our systems.
11.5 Account and Data Deletion
Users can delete their account and all associated data at any time. See Section 9. Account Deletion above for step-by-step instructions (in-app deletion and email-based deletion request). Deletion requests are processed within 30 calendar days of verification.
12. Your Choices and Rights
Depending on your location and applicable law, you may have rights to:
- access the personal data we hold about you;
- correct inaccurate or incomplete personal data;
- delete your account or certain personal data;
- withdraw consent where processing is based on consent;
- object to or restrict certain processing;
- request a copy of your personal data in a portable format;
- lodge a complaint with a data protection authority.
You may also control certain permissions through your device settings, such as photo access and notifications.
To exercise your rights, contact us at support@ruviagroup.com. We may need to verify your identity before responding. Some requests may be limited by applicable law, security requirements, technical limitations, or the rights of others.
13. Notifications
We may send you service-related notices, such as account, security, system, or important product notices. These notices are part of the Service and may not be fully optional.
If we offer optional reminders or push notifications, you can manage them in the Service or through your device settings.
We aim not to include private journal text or sensitive emotional content in lock-screen notifications unless you choose settings that allow such display.
14. Children
The Service is not intended for children under the age of 13. If the laws of your country or region require a higher minimum age, that higher age applies.
If you are under the age of majority in your country or region, you should use the Service only with the consent and supervision of a parent or legal guardian.
If we learn that we have collected personal data from a child who does not meet the applicable age requirement without appropriate consent, we will take reasonable steps to delete the data or restrict the account.
If you believe a child has provided us with personal data without appropriate consent, please contact us at support@ruviagroup.com.
15. Region-Specific Information
15.1 Singapore
Subject to applicable law, users in Singapore may request access to or correction of their personal data, and may withdraw consent for certain processing. We will handle such requests in accordance with applicable data protection laws.
15.2 European Economic Area, United Kingdom, and Similar Regions
If you are located in the European Economic Area, the United Kingdom, Switzerland, or a region with similar data protection laws, you may have additional rights, including rights of access, rectification, erasure, restriction, objection, portability, and withdrawal of consent.
You may also have the right to lodge a complaint with your local data protection authority.
15.3 United States
Depending on your state of residence, you may have privacy rights such as access, deletion, correction, and the right to opt out of certain regulated data disclosures. We do not sell your private journal entries.
If we introduce features that require additional disclosures or opt-out rights, we will update this Privacy Policy accordingly.
16. Third-Party Links and Services
The Service may contain links to or integrations with third-party services. Third-party services are governed by their own privacy policies and terms. We are not responsible for the privacy practices of third parties that we do not control.
17. Third-Party SDKs and Permissions
Floria ("the App") uses the following third-party SDKs to provide its features. Each third-party SDK processes user information in accordance with its own privacy policy. Please review this notice before using the App.
17.1 Authentication SDKs
1. Firebase Authentication Authentication
Purpose: User authentication and account management
Data Collected:
- Email address (obtained via Google / Apple sign-in)
- User ID (Firebase UID)
- IP address
- App version
Data Transmission: Encrypted (HTTPS)
Provider: Google LLC
Privacy Policy: https://firebase.google.com/support/privacy
2. Google Sign-In Authentication
Purpose: Google account sign-in
Data Collected:
- Email address
- User's full name
- Google account ID
- ID Token (for authentication)
Data Transmission: Encrypted (HTTPS)
Provider: Google LLC
Privacy Policy: https://policies.google.com/privacy
3. Sign in with Apple Authentication
Purpose: Apple account sign-in (iOS only)
Data Collected:
- Email address (user may choose to hide real email)
- User's full name (user may choose to hide)
- Apple ID Token
Data Transmission: Encrypted (HTTPS)
Provider: Apple Inc.
Privacy Policy: https://www.apple.com/legal/privacy/
17.2 Device Information SDKs
4. Device Info Plus Device Info
Purpose: Obtain device identifiers for device recognition and security
Data Collected:
- Device model
- Operating system version
- Unique device identifier (Android ID / IDFV)
Data Transmission: Encrypted (HTTPS)
Open Source: https://pub.dev/packages/device_info_plus
5. Package Info Plus App Info
Purpose: Obtain app version information for version management and logging
Data Collected:
- App version number
- App package name
- Build number
Data Transmission: Local read only, not uploaded
Open Source: https://pub.dev/packages/package_info_plus
17.3 Local Storage SDKs
6. Shared Preferences Local Storage
Purpose: Store user preferences and login state locally
Data Collected: User preferences, login state
Storage Location: Stored on device only, not uploaded to servers
Open Source: https://pub.dev/packages/shared_preferences
7. SQFLite Local Database
Purpose: Local database storage for caching diary data
Data Collected: Locally cached diary content
Storage Location: Stored on device only, not uploaded to servers
Open Source: https://pub.dev/packages/sqflite
17.4 Network and Media SDKs
8. Dio Network
Purpose: HTTP networking library for server communication
Data Collected:
- IP address (inherent to network communication)
- Request logs (QA builds only; disabled in production builds)
Data Transmission: Encrypted (HTTPS)
Open Source: https://pub.dev/packages/dio
9. Cached Network Image Image Cache
Purpose: Load and cache network images
Data Collected: Image cache stored locally
Storage Location: Cache data stored on device only
Open Source: https://pub.dev/packages/cached_network_image
10. image_picker Photo Picker
Purpose: Select photos from the device gallery for diary content
Data Collected: None (uses system photo picker, no gallery permission required)
Note: On Android 13+ / iOS, the system photo picker is used without requiring storage permissions. On older Android, the file picker is used. No photos are accessed or uploaded without explicit user action.
Open Source: https://pub.dev/packages/image_picker
11. Flutter Image Compress Local Processing
Purpose: Compress images selected by the user
Data Collected: None (local image processing only, no user privacy data involved)
Open Source: https://pub.dev/packages/flutter_image_compress
12. WebView Flutter Web View
Purpose: Display web pages such as privacy policy and terms of service
Data Collected:
- Browsed URL addresses
- Cookies (if set by the web page)
Open Source: https://pub.dev/packages/webview_flutter
17.5 Analytics SDKs
13. SolarEngine SDK (US) Analytics
Purpose: Mobile analytics, attribution tracking, and user behavior analysis
Data Collected:
- Device identifiers (Android ID / IDFV)
- Device model and OS version
- App version and package name
- IP address
- App events (feature usage, button clicks, page views)
- Install and attribution data (channel source, campaign info)
- Session duration and frequency
Data Transmission: Encrypted (HTTPS)
Provider: SolarEngine
Privacy Policy: https://www.solar-engine.com/privacyPolicyEN.html
Note: SolarEngine is used for analytics, attribution tracking, and performance monitoring. It does NOT display advertisements to users.
14. Sensors Analytics Analytics
Purpose: User behavior analytics and event tracking
Data Collected:
- Device identifiers (Android ID / IDFV)
- Device model and OS version
- App version
- User events (feature interactions, page views)
- Session data
Data Transmission: Encrypted (HTTPS)
Provider: Sensors Data
Privacy Policy: https://docs.sensorsdata.com/sa/docs/tech_sdk_client_privacy_policy
17.6 Permissions Used
| Permission | Purpose | Required |
|---|---|---|
| Internet (INTERNET) | Communicate with servers and load data | Required |
17.7 SDK Security Measures
The App implements the following security measures for data transmission and processing:
- All network communications use HTTPS encrypted transmission
- User sensitive data, such as login credentials, is stored on device only
- Production builds do not output debug logs
- Code is obfuscated to prevent decompilation
18. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will provide notice through the Service, by email, or by other reasonable means.
The updated Privacy Policy will be effective as of the date stated in the updated version. Your continued use of the Service after the updated Privacy Policy becomes effective means that you acknowledge the updated Privacy Policy.
19. Contact Us
If you have questions about this Privacy Policy or our handling of personal data, please contact us:
Website: https://www.floriaapp.com
Email: support@ruviagroup.com