Moodroll — Privacy Policy
Last updated: 25 August 2026
Moodroll (com.ntb.moodroll.app) is a photo mood journal — a diary you keep one day at a time, with a film-style camera for the days worth a photograph. This page explains what it does with your data. The short version: it stays on your phone.
What we collect
Nothing from your diary. There is no account, no sign-in and no server that holds it. We cannot see your photos, your moods or your notes, because they are never sent anywhere.
Moodroll does send one kind of anonymous technical data, processed by Google Firebase: crash reports. There is no usage analytics in the app at all. Crash reports are listed in full in the next section, and one never contains a photo, a note, or which mood you tagged.
Crash reports
Moodroll is made by one person with no budget, and one thing has to leave your phone for it to work on phones we cannot hold: a report when something goes wrong.
Moodroll does not measure how you use it. There is no usage analytics in this app — not which screens you open, not how often, not which features you use, not whether you bought anything. That is switched off in the build itself rather than promised in a setting, so there is nothing to turn off and nothing to trust us about.
What is sent
- Crash reports — the error and where in the code it happened, your phone's model, its Android version, and a random identifier Google generates for this installation. It is never given a note, a mood, a date, a tag or a file name.
- Two facts about your phone's hardware, attached to a crash report — which performance class the app decided your phone is in, and how much of its camera processing the app was allowed to turn off. They are what make a report actionable: the failures this app cares most about are the ones that do not crash — a photo quietly saved without effects, a render that ran out of memory and retried smaller — and those are only fixable if the report says which pipeline the photo went through.
- A one-line description of something the app handled and worked around, sent the same way, for the same reason. It describes the machinery talking about itself, never anything you wrote or shot.
- Moodroll also downloads one number from Firebase, which decides when the Pro screen first appears. That is a download; it carries nothing about you.
What is never sent
- Your photos or their thumbnails, in any form.
- Your notes, the short one and the long one, and the tags you write on a day.
- Which mood you tagged, or that you tagged one at all. This is the line we care most about: "which mood, on which day" is the most sensitive thing Moodroll holds, and it does not leave your phone.
- The dates of your entries, your streak, or anything else that could reconstruct your diary.
- Anything about how you use the app — which screens, which cameras, how many photos, whether you opened the Pro screen, whether you bought it.
- Your advertising ID and your device's Android ID. Both are switched off, ad personalisation is switched off with them, and the advertising-ID permission is removed from the app entirely. Moodroll shows no ads and sells nothing to advertisers.
Google's handling of what is sent is covered by Google's Privacy Policy.
What the app stores on your device
All of it lives in Moodroll's private storage, which no other app can read:
- Photos you take with the app. Each one is kept as three files: the finished photograph, a small thumbnail of it, and the original frame exactly as your camera sensor delivered it, before any of Moodroll's colour work. That third file is what Darkroom develops from — it is how the same moment can be re-made through a different camera, any number of times, without ever copying a copy. It is kept for as long as the entry is, and deleting the entry deletes all three. It means a Moodroll photograph takes roughly twice the space of the picture you can see.
- Diary entries — the day, the mood you tagged and how strongly you felt it, any tags you wrote on that day, and your notes: the single line from the result screen and the longer one from the day screen. A day can be recorded with no photo at all, and many are.
- Cameras you build. Pro lets you assemble your own camera; if you do, the name you give it and the settings you chose are stored in Moodroll's private storage as a small text file, one per camera. The name is the only free text in it. Moodroll never sends a camera anywhere by itself — but you can, and only if you choose to: the shelf lets you hand one out as a short code or as a
.moodcamfile, through Android's own share sheet. Both carry the camera's name and its settings and nothing else — no days, no moods, no notes, no photographs. - Settings — your chosen camera, format, reminder time, whether the app lock is on, and technical details about your phone's camera and graphics performance that the app uses to process photos.
Uninstalling Moodroll deletes all of it. You can also delete any individual entry inside the app, and any camera you built.
Backups
Moodroll's diary and photos are excluded from Google Drive backup. If you back up your phone, your moods, notes and photos are not part of that backup.
On Android 12 and newer, the diary is included in direct device-to-device transfer — the copy your phone makes when you set up a new phone from your old one. That transfer goes straight between your two devices, not through a server. It exists so that a diary you have kept for years survives a phone upgrade, since Moodroll has no cloud sync to restore from.
Saving your own copy
Settings → Your diary → Save a copy writes your whole diary — every entry, note and photo — into a single .zip file, and Android asks you where to put it. You can restore it later on any phone with Restore from a file, which only adds days that are missing and never replaces or deletes anything.
The copy carries the original sensor frames described above as well as the finished photographs, which is why it is larger than the pictures alone. That is deliberate: a backup that could not re-develop a day would be a backup of the prints and not of the negatives.
Three things worth being plain about:
- The file holds your diary, and only your diary. Your settings are not in it — a restored phone starts with the daily reminder off, which the app says on screen after an import — and neither are any cameras you built. Those have their own copy: the shelf's Save my cameras writes a second
.zipholding the cameras alone, and Restore my cameras brings them back. Two separate files because they are two separate things, and the app says so under the import result when your shelf has none of your own cameras on it yet. - Moodroll does not send that file anywhere. It hands it to whichever place you chose and never looks at it again. If you pick a cloud folder, the file goes to that company under their terms, not ours.
- The file is not protected the way the app's own storage is. Inside Moodroll, your diary sits in private storage no other app can read. A
.zipyou have saved is an ordinary file — anything with access to that folder can open it. That is the trade for being able to keep your own backup, and it is why the app never makes one without you asking.
Permissions
| Permission | Why |
|---|---|
| Camera | To take photos. Only asked for when you open the camera — a diary of moods, tags and notes works without ever granting it. |
| Notifications | Only for the daily reminder, and only if you turn it on. |
| Run at startup | So the reminder you set still works after you restart your phone. |
| Biometrics | Only to unlock the app lock, if you turn it on. Moodroll never receives your fingerprint — Android only tells it yes or no. |
| Billing | To sell Moodroll Pro through Google Play. |
About the network permissions
If you look at Moodroll's permission list you will see INTERNET and a few related ones. Two things use them: the crash reports described above, and Google's Play Billing library, which the app includes in order to sell Moodroll Pro. Purchases themselves go through the Google Play Store app on your phone, not over a connection Moodroll opens.
We are telling you this because we would rather explain it than have you find it. No photo, mood or note is uploaded by Moodroll, with or without those permissions — that is the promise the app is built around, and it is the one thing here that will not change.
Purchases
Moodroll Pro is sold through Google Play. When you buy it, Google handles the payment and tells the app only whether you own it. We never see your card, your billing address, or your Google account. Google's own privacy policy covers that transaction.
Google's billing library also sends Google some diagnostic information about itself. That is Google's processing, described in Google's Privacy Policy, and it contains nothing from your diary.
Children
Moodroll is not directed at children under 13, and we do not knowingly collect anything from them — or, for that matter, from anyone.
This is not a medical app
Moodroll is a diary. It is not a medical device, not a diagnostic tool, and not a substitute for professional care. It describes what you recorded and nothing more: it will not tell you what your moods mean, will not warn you about them, and will not diagnose anything. If you are struggling, please talk to a qualified professional.
Changes
If this policy changes, the date at the top changes with it. Because Moodroll has no way to contact you, the current version always lives at this address.
Contact
Questions about privacy: thanhbinhntn2018@gmail.com
Camera controls
Moodroll stores guides, horizon, haptics, exposure defaults, shooting-mode preferences, zoom stops, selfie mirroring, the gallery pause and the printed-frame override in private preferences. Camera controls can be exported explicitly as a versioned JSON file through the Android document picker. The file includes date stamp and shutter sound, but excludes photos, journal entries, authored camera presets, purchases and app lock. Presets have a separate ZIP backup with merge-on-restore; journal ZIP transfer is separate. Each destination is selected explicitly through the document picker.
Location tagging is optional and asks for Android location permission. Location updates run only while the camera screen is started. Fresh available coordinates are written to JPEG metadata and the original image when enabled. PNG gallery exports do not include GPS metadata. Sharing a tagged JPEG can reveal its capture location. The app does not upload these coordinates.