Cookie & Tracking Policy (App & Website)

Date: 13/09/2025 · Version: 1.0
Scope: This policy applies to the Journory mobile app (iOS/Android) and our website www.journory.com.

1) What are cookies & similar technologies?

  • Cookies are small text files stored by a browser.
  • Similar technologies in apps include: Local/Async Storage, device identifiers (e.g. IDFA/AAID), SDK events, push tokens.

In this policy, we collectively refer to them as “cookies/tracking technologies”.

2) What purposes do we pursue?

We only use cookies/tracking technologies for the purposes listed below. The applicable legal basis is stated in brackets.

  1. Necessary – e.g. login/session, security, fraud prevention, language selection, consent storage.
    (Legal basis: Art. 6(1)(b) GDPR; § 25(2)(2) TTDSG – no opt-in required)
  2. Convenience/Functionality – e.g. settings, offline caches, user preferences.
    (Legal basis: Art. 6(1)(a) GDPR/§ 25 TTDSG – consent)
  3. Performance & Diagnostics (if enabled) – e.g. anonymous stability/performance metrics.
    (Legal basis: Art. 6(1)(a) GDPR/§ 25 TTDSG – consent)
  4. Marketing/Advertising (optional) – e.g. delivery of (non-)personalized ads, frequency capping, fraud prevention.
    (Legal basis: Art. 6(1)(a) GDPR/§ 25 TTDSG – consent; without consent only non-personalized ads)

Note: For EEA/UK/CH we use a Consent Management Platform (CMP) based on IAB TCF 2.2. You can manage purposes/partners granularly there.

3) Preference Center (CMP) – Manage consent

  • In the app: Settings → Legal/Privacy → Cookie Settings (Preference Center).
  • No preference centre is required on the website. journory.com loads no third-party content when opened and uses neither advertising nor analytics technologies: fonts and animation data are served from our own server, and no reach measurement takes place. Your browser's local storage holds only the appearance (light/dark) and language you selected yourself — used solely for the display you asked for, never evaluated or passed on. You can clear it at any time through your browser's site data.
  • Withdrawal: You can change or withdraw your consent at any time with effect for the future. The CMP stores your consent status (timestamp/version).

4) Which partners/technologies do we use?

The current, detailed list of providers (including purposes, storage durations, legal bases) is available in the Preference Center. Typical categories include:

  • Consent/banner (app only): Google UMP – stores the consent status.
  • Advertising (optional): Google AdMob (+ optionally “Limited Ads” without personalization).
  • Maps/Places: Google Maps/Places/Geocoding (functional; no ad personalization by us).
  • Push: APNs/FCM (via Expo) – delivery of technical notifications (necessary).
  • Weather: OpenWeather API – content delivery only (functional).

Some libraries (e.g. AsyncStorage, i18next) are purely functional and store settings/cache on your device.

5) Storage duration & device access

  • Necessary cookies/storage: until the end of the session or until you delete them; some settings may remain longer.
  • Convenience/Performance/Marketing: duration according to provider (see CMP list).
  • Device access: For non-essential purposes we obtain your prior consent (§ 25 TTDSG/PECR).

6) How can you disable tracking?

  • In the Preference Center: deactivate purposes/partners (App & Website).
  • Device advertising ID:
    o iOS: Settings → Privacy & Security → Tracking (allow/deny app tracking) and Ads → Reset/Limit Ad ID.
    o Android: Settings → Google → Ads or Privacy → Ads (reset/remove Ad ID).
  • Browser (Website): delete/block cookies (instructions depend on browser).
  • Do-Not-Track: Since there is no uniform DNT standard, we follow your CMP settings.

7) Regional notes

  • EU/EEA/UK/CH: CMP (IAB TCF 2.2) active; personalization only with opt-in.
  • Outside these regions: We adapt consent behavior to local requirements (at least opt-in for non-essential device access).

8) Legal bases (summary)

  • Art. 6(1)(b) GDPR (contract/necessary cookies)
  • Art. 6(1)(a) GDPR + § 25 TTDSG/PECR (convenience/performance/marketing)
  • Art. 6(1)(f) GDPR (security/fraud prevention within the strictly necessary scope)

9) Changes

We will update this policy whenever features or laws change. The current version is available in the app & on the website; material changes will be communicated in the banner or in-app.

10) Contact

Questions? privacy@journory.com
Legal/authority contacts (EU-DSA): legal@journory.com

Start free — 500 stops included.

Get it