Privacy policy
annary is a personal diary. Your entries belong to you. This page explains what data is involved, where it is kept and what happens to it. This service is operated from Germany; the German version is the legally binding one.
1. Controller
Martin Dellert Online Services, Martin Dellert
Stadthausbrücke 8a, 20355 Hamburg, Germany
Email: martin@annary.com
2. What data is processed
Account
Your email address is stored so you can sign in. There is no password: you receive a one-time sign-in link by email, valid for 30 minutes and used up afterwards.
Diary entries
Your entries and mood entries are stored encrypted (AES-256-GCM, the same standard banks use). The key is not held in the database: a stolen database dump on its own contains no readable sentence.
Your data is not analysed, not sold and not shared with third parties. No ad networks, no profiling, no mining of your content.
Photos
Images you upload to a day are stored encrypted on the server and can only be retrieved through your account. They live outside the web directory and cannot be reached through any address directly.
Technical data
When you open the site, the hosting provider processes ordinary server logs (IP address, time, page requested, browser). This is necessary for operation and security.
One thing should be said plainly: the addresses of the list pages contain the
short name you chose — for example /people?p=anna. That short
name therefore appears in the server logs, even though it is encrypted in the
database. The entries themselves cannot be reached this way, and the provider
deletes its logs according to its own retention periods.
3. Cookies
One single cookie is set (annary_sess).
It keeps you signed in and is strictly necessary. You choose how long it
lasts in the settings. No tracking, no analytics cookies, no advertising.
4. Third-party services
Hosting
The application runs at ALL-INKL.COM – Neue Medien Münnich, Hauptstraße 68, 02742 Friedersdorf, Germany. A data processing agreement under Art. 28 GDPR is in place. The servers are located in Germany.
Place search (Photon / OpenStreetMap)
When you search for a place while writing, your search term is sent to komoot's Photon API (based on OpenStreetMap), along with an IP address. If you share your location, coordinates are sent as well so that nearby results appear first. This only happens when you actively search for a place.
Analytics with Matomo
To understand which features are used, the open-source software
Matomo is used. It runs on our own server
(statistik.martindellert.de) — no data is passed to analytics
corporations.
- No cookies. Nothing is stored on your device.
- “Do Not Track” is respected. If your browser sends this signal, no measurement takes place at all.
- IP addresses are truncated and not stored in full.
- No cross-device recognition, no profiles, no advertising.
What is recorded: pages viewed and which controls are used — for example that an entry was written, a photo uploaded or a setting changed. No diary content is transmitted: neither entries nor names of people, places or topics, nor search terms or mood values.
So that this holds technically and not merely as an intention: the address is
transmitted without its query string, and the page title is
replaced by a technical name. Otherwise ?p=anna and the display
name in the title bar would end up there.
The legal basis is our legitimate interest in privacy-friendly analytics (Art. 6 (1) (f) GDPR). As nothing is stored on or read from your device, no consent is required under § 25 (1) TDDDG. You may object at any time by enabling “Do Not Track” or by contacting us.
Strava (only if you connect it)
If you connect your Strava account, your activities there are fetched and shown in your diary. Access tokens are stored encrypted. You can disconnect at any time in the settings; the stored Strava data is deleted with it.
Email delivery
The sign-in link is sent through the hosting provider's mail server. The only recipient is your own address.
5. Legal bases
Entries and account: performance of the user relationship (Art. 6 (1) (b) GDPR). Server logs and technical security: legitimate interest (f). Optional connections such as Strava: your consent (a), revocable at any time.
6. Retention
Your data is kept as long as your account exists. On deletion, entries, photos and account data are removed. Server logs are deleted by the hosting provider according to its own retention periods.
7. Your rights
You have the right of access (Art. 15), rectification (16), erasure (17), restriction (18), data portability (20) and objection (21 GDPR). For portability there is an export function in the settings: it downloads all entries, decrypted, as a Markdown or JSON file. You may also lodge a complaint with a data protection supervisory authority; the competent one here is the Hamburg Commissioner for Data Protection and Freedom of Information.
8. Changes
If the application gains features that process new data, this policy will be updated accordingly.
Last updated: 2026-09-21