Tessera

Privacy policy

Version of 16 September 2026

This notice is written to be read from beginning to end, and it describes what the app actually does. Where the General Data Protection Regulation applies to you, it also serves as the information we owe you under Article 13.

If you have no time for the rest, the important part is two lines: your diary is stored on your phone and never reaches us. There is no sign-up, no account, and nothing that tells us who you are.

1. Who is responsible for your data

The controller is Maksim Sergeyevich Kuznetsov, an individual entrepreneur registered in the Russian Federation (TIN 773391216156, state registration number 326508100402717).
Postal address: 142203, Moscow Region, Serpukhov, Sovetskaya St. 75, bld. 7, Russia.
Contact: support@tessera-app.ru.

Below, “the app” means the Tessera mobile app and “the site” means tessera-app.ru. There is no data protection officer: the processing described here does not require one, and the person who answers you is the person who wrote the app.

2. What stays on your device and goes nowhere

Everything the diary contains: how you rated your state, habit marks, time by category, sleep times, notes, photos of the day and voice notes. All of it is held in your device’s own storage.

We do not receive it and cannot read it. The app has no sign-up, no account and no link to a phone number or an email address — we do not know who you are.

This matters for a second reason. A diary of moods and sleep would count as data concerning health under Article 9 of the GDPR — a special category with stricter rules. We do not process it, because it never reaches us in a form anyone could read. The one thing that ever leaves the device is the cloud copy, and it is encrypted before it goes (section 6).

3. What the app sends to our server

The app does not request and does not transmit: your location, your contacts, the list of apps installed on your phone, advertising identifiers, or your phone number.

4. Why we process it, and on what legal basis

The law requires us to name, for every purpose, the legal basis, the data involved and how long it is kept. Here is all of it in one table — which also answers the plainer question of why we need any of this at all.

Do you have to give us any of this? There is no statutory or contractual obligation on you to provide any of it. The installation identifier and the build details are the minimum the app needs to work at all. Everything else is yours to choose: write to support if you want an answer, switch on the cloud copy if you want one.

No automated decisions, no profiling. We take no decisions about you by automated means, and we build no profile of you. The reports and insights you see are calculated on your own device, from your own entries, and never reach us.

5. Withdrawing your consent

Only one thing here runs on consent — the cloud copy — and you withdraw it by switching the copy off in the app. The file is erased from the server at that moment. No letter, no request, no waiting.

Withdrawing consent does not affect anything that was lawful before you withdrew it.

6. The cloud copy of the diary

An optional feature. Until you switch it on, nothing from the diary reaches the server at all.

When you do, the app packs the diary into a single archive and encrypts it on your phone before sending. What travels to the server is an encrypted file. The key is derived from a recovery code the app shows you once, and that code never leaves your device.

We store the encrypted file, its size and name, and a fingerprint of the recovery code — from which neither the code nor the identity of its owner can be recovered. We hold no link between a copy and an installation.

We cannot read your copy. That is a property of how it is built, not a promise we are asking you to trust: we do not have the key. For the same reason we cannot help if the recovery code is lost.

7. Device permissions

Each is asked for at the moment it is needed, and each can be refused: the app carries on working, and only the feature the permission was for becomes unavailable.

8. Who else sees the data

Nobody else. There are no advertising or analytics services in the app: no counters, no ad networks, no third-party statistics kits. We do not sell your data, do not share it for advertising, and pass it to no data broker.

The website sets no counters or tracking cookies and serves its fonts from our own server, without calling third-party services. If you choose the site language yourself, your browser remembers that choice so the site opens in that language next time; the choice never reaches us.

Data may be provided to state authorities where the law requires it and the request is properly made.

If the project passes to a new owner. We may transfer it in full to another person, who would then become the controller of your data instead of us. We will give at least 30 days’ notice in the app and on the site — before the transfer, not after. If you would rather not deal with the new owner, write to us within that period and we will erase your data.

9. Where the data is stored

We are based in Russia, and our server is in Russia. The data described in section 3 travels from your device straight to us: it passes through no one else and is handed to no one else.

We would rather say this plainly than bury it. Russia is not covered by a European Commission adequacy decision. In practice that means your data is protected by this notice, by our contract with the hosting provider and by the measures in section 12 — but not by the supervision of an EU authority over where it is held.

Knowing that, you can decide how much to entrust to the cloud copy — and the diary itself stays on your phone in any case.

10. How long the data is kept

11. Your rights

Where the GDPR applies to you, you have the right to ask us for access to your data, its rectification or erasure, restriction of processing, and portability — a copy in a machine-readable form. You may object at any time to processing we base on our legitimate interest, which here means the anonymous events. And you may withdraw consent to the cloud copy, as described in section 5.

Write to support@tessera-app.ru, or use the app: Settings → Support. We answer within one month. If a request turns out to be complicated we may take up to two months more, and we will tell you why within the first month. Exercising these rights costs nothing.

One honest limitation. If you have never written to support and never switched on the cloud copy, we hold nothing we can connect to you: the installation identifier is a random string with no name, no email and no phone number behind it. In that case we cannot identify you, and the law does not require us to collect more data just to be able to. So that we can find your data, tell us the recovery code fingerprint or write from inside the app — the message then arrives with the installation identifier attached.

You also have the right to lodge a complaint with a supervisory authority — in the EU, the authority of the country where you live, work, or where you believe the problem occurred.

The diary you delete yourself, without us: it is on your phone. Deleting the app erases it together with the photos and the voice notes. Switch the cloud copy off before deleting the app if you want that erased too. Step by step: deleting your data.

12. How we protect the data

The app talks to the server over an encrypted connection. The cloud copy is encrypted on the device before it is sent. Access to the server and to the admin panel is limited to a small number of people and protected by multi-factor authentication. The server keeps nightly backups of its own and holds each one for 14 days.

If a breach does happen, we must report it to the supervisory authority within 72 hours, and tell you as well where the breach is likely to put your rights at risk.

And here is what we do not promise. We do not guarantee that data on the server cannot be lost: there is one server, and nobody is insured against hardware failure. That is precisely why the diary lives on your phone rather than with us, and why the cloud copy is a copy and not the only original. Keep an export of your own: Settings → Export data.

13. Children

The app is not meant for children under 13 and is not designed for them, either in content or in appearance. We collect no information about age and do not knowingly process children’s data.

If you are a parent and believe your child has given us their data, write to support@tessera-app.ru and we will erase it. Note that the diary itself is stored on the child’s phone and never reaches us — it can only be erased on the device.

14. If the project closes

We owe you this too. If we shut the server down or close the project, we will give at least 90 days’ notice in the app and on the site, and when the period runs out we will erase everything we hold: installation records, anonymous events, support conversations and cloud copies.

The diary on your phone is untouched by any of this: it was there all along, never reached us, and keeps working. What happens to the app itself is set out in section 5 of the terms of use.

15. Changes

A new version is published on this page with the date at the top. If something substantial changes — a new recipient of data, a new purpose — we will say so in the app rather than quietly editing the text.

16. Contact

support@tessera-app.ru — for anything about this document and about your data. There is also a support page with answers to the questions that come up most.