This policy explains what information Journalify collects, why we collect it, and the control you have over it. It covers the Journalify iOS app and this website (journalifyapp.com). Journalify is operated by Thomas Bowen, a sole proprietor ("we", "us"). If you have any question about this policy, email support@journalifyapp.com.

The short version

  • Your journal is private. We don't show ads, we don't sell your data, and we don't send marketing email.
  • Your journal text is sent to an AI service in exactly one case: when you tap Compile, the notes you jotted that day are sent to our AI providers to be written into a finished entry. Text you write or edit by hand is never sent to the AI.
  • Our analytics never receive your journal content — only metadata such as "an entry was created" and its word count.
  • You can export all your entries and permanently delete your account and its data from inside the app.

1. Information we collect

Account information

When you sign up with email, we collect your email address and password. The password is stored in hashed form by our authentication provider (Supabase); we cannot read it. If you use Sign in with Apple or Google Sign-In instead, we receive a sign-in token from that provider along with your first name and the email address associated with it. With Apple you can choose to hide your real email, in which case we receive Apple's private relay address.

Onboarding answers

During onboarding we ask a short set of questions and store your answers with your profile: your first name, age band, how often your thoughts get lost, your emotional baseline, your journaling history and what has gotten in the way of it, how much time you want to spend journaling each day, your commitment level, and your reminder preference.

Journal content

We store the journal entries you save, the raw notes ("jots") that each compiled entry was created from, and the date each entry is about. Before you compile them, the notes you jot are kept only on your device so you don't lose them if you close the app. When you tap Compile, those notes are saved to our database as part of the entry record and the on-device copy is cleared. You can remove this data at any time by deleting the entry or your account.

Subscription status

Our subscription partner RevenueCat and Apple tell us whether your account has an active subscription or trial, which plan it is, and when it expires. Payment itself is handled entirely by Apple — we never receive your card or bank details.

Feedback and support

If you use the in-app feedback form, we store your message together with your email address, app version, and device platform (for example "ios 17"). "Contact Support" simply opens your own email app.

Usage analytics

See section 3 below.

Service and security data

Our backend keeps small operational records: how many AI compiles your account has used (to enforce fair-use limits) and standard timestamps. Our backend provider processes IP addresses to operate the service and to rate-limit sign-in attempts.

What we don't collect

The app does not access your location, contacts, photos, camera, or microphone. It contains no advertising or cross-app tracking SDKs. Reminders are scheduled on your device, so we don't collect push notification tokens.

2. The AI compile feature

Compile is the heart of Journalify, so here is exactly how it works. When you tap Compile, the notes you jotted for that day and the entry's date are sent over an encrypted connection to our server, which forwards them to OpenRouter (an AI routing service), which passes them to an Anthropic "Claude" language model. The model writes a journal entry from your notes, and the result is returned to the app for you to review and edit before saving.

  • Only the note text and the entry date are sent. Your name, email address, and account ID are not included in the request, and because the request is made by our server, the AI providers do not receive your device's IP address.
  • Entries you write by hand, and edits you make by hand, are never sent to the AI. Compile is the only feature that shares journal text with an AI service.
  • OpenRouter and Anthropic process this text as our service providers under their own privacy policies (linked in section 6). Our AI routing provider (OpenRouter) is configured not to retain the content of compile requests.

3. Usage analytics

We use PostHog to understand how the app is used. PostHog receives events such as "signed up" (and how — email, Apple, or Google), "onboarding completed", "entry created" (with the entry's word count and whether it was compiled — never the text), "streak earned", "paywall viewed", "trial started", "subscription started", and "notifications enabled", plus which screens you visit. These events are linked to your account ID together with your email, first name, and sign-up date, and include standard device information attached by the analytics SDK (app version, device model, OS version). PostHog receives your IP address as part of each request. Your journal text, notes, and AI output are never sent to analytics.

4. How we use your information

  • To run Journalify — storing and syncing your entries, compiling entries when you ask, and managing your account and subscription.
  • To send transactional email only — a password-reset code when you request one, and a confirmation when you change your email address. We do not send marketing email.
  • To remind you to journal — reminders are computed and scheduled on your device. The app checks locally whether you've journaled today to decide whether a reminder is needed; the notification text is generic and never includes journal content.
  • To improve the app — via the analytics described in section 3.
  • To keep the service safe — fair-use limits on AI compiles and rate limits on sign-in attempts.
  • To respond to you — when you contact support or send feedback.

5. Where your data is stored

Your account data and journal entries are stored with Supabase in the US East (Northern Virginia) region of the United States. If you use Journalify from outside the US, your information is transferred to and stored in the US. For users in the EU, EEA, and UK, we rely on the Standard Contractual Clauses (SCCs) provided in our processors' data processing addenda as the legal mechanism for these transfers.

6. Third-party services

We use a small number of service providers to run Journalify. Each receives only what's needed for its job:

  • Supabase — hosts our database, authentication, and server functions, and sends the transactional auth emails described above. Stores the account, profile, and journal data in section 1. (privacy policy)
  • OpenRouter and Anthropic — receive your jotted notes and the entry date when you use Compile, to generate the entry. (OpenRouter privacy policy, Anthropic privacy policy)
  • PostHog — analytics, as described in section 3. (privacy policy)
  • RevenueCat — manages subscriptions; receives your account ID and purchase/renewal events from Apple. (privacy policy)
  • Apple — Sign in with Apple, App Store billing, and the on-device rating prompt. (privacy policy)
  • Google — Google Sign-In. (privacy policy)
  • Vercel — hosts this website. The site is static: our site code sets no cookies and runs no analytics. (privacy policy)

7. Security

  • All traffic between the app, our servers, and our AI providers is encrypted in transit (HTTPS/TLS).
  • Database access rules (row-level security) ensure that only your signed-in account can read or change your rows — one user's queries can never return another user's entries.
  • On your device, your session token is stored in the iOS Keychain (encrypted storage), not in plain files.
  • The keys for our AI providers live only on our servers, never inside the app.

To be transparent: your journal entries are not end-to-end encrypted. They are stored in our database, and like any service built this way, the operator is technically able to access that database. We do not read your journal entries except where strictly needed to operate the service — for example, investigating a fault in your account at your request. Our database provider encrypts all stored data at rest using AES-256 encryption.

8. Data retention

  • Journal entries and profile data — kept until you delete the entry or your account.
  • Account deletion — deleting your account in the app immediately removes your profile, all journal entries (including the raw notes behind them), your usage counters, and your subscription-entitlement record from our database, and wipes any uncompiled notes and scheduled reminders from your device. This cannot be undone.
  • Feedback — feedback messages you sent are kept after account deletion for our product records. They are detached from the deleted account, but still include the email address you had when you sent them.
  • Backups — Deleted data may persist in encrypted database backups for a limited period before those backups are automatically cycled out. All backups are encrypted at rest.
  • Analytics — Analytics data is retained for as long as needed to understand product usage, subject to our analytics provider's retention settings.
  • Subscriptions — Apple and RevenueCat keep their own transaction records under their own policies. Deleting your Journalify account does not cancel a subscription — manage that in your Apple ID settings.

9. Your rights and choices

  • Export — Settings → Export Entries emails you a CSV of every entry.
  • Correction — edit your name and email in Settings; edit or delete any individual entry in the app.
  • Deletion — Settings → Delete Account removes your account and data as described in section 8. You can also email us to request deletion.
  • Reminders — controlled entirely by the iOS notification permission: iOS Settings → Journalify → Notifications.
  • Analytics — the app does not currently offer an in-app analytics opt-out. Email us and we will delete the analytics data associated with your account.

To exercise any right, use the in-app controls above or email support@journalifyapp.com.

10. For users in the EU, EEA, and UK (GDPR)

The data controller is Thomas Bowen, who can be reached at support@journalifyapp.com. We process your data on these legal bases: performance of our contract with you (providing the app, including the compile feature and your subscription); our legitimate interests in keeping the service secure and preventing abuse; and our legitimate interests in understanding product usage through the analytics in section 3.

You have the right to access, correct, delete, and receive a copy of your personal data, to restrict or object to certain processing, and to withdraw consent where processing is based on consent. The in-app export and deletion tools in section 9 cover the most common requests; for anything else, email us. You also have the right to lodge a complaint with your local data protection supervisory authority.

11. For California residents (CCPA/CPRA)

In the last 12 months we have collected these categories of personal information: identifiers (name, email, account ID, IP address); content you create (journal entries and notes); commercial information (subscription status); and internet activity (app usage events and screens viewed). We collect them from you directly, from your device, and from the providers in section 6, for the purposes in section 4, and we disclose them only to the service providers listed in section 6.

We do not sell your personal information, and we do not share it for cross-context behavioral advertising. You have the right to know what personal information we hold about you, to delete it, to correct it, and to not be discriminated against for exercising these rights. Use the in-app tools in section 9 or email support@journalifyapp.com.

12. Children

Journalify is not directed to children and requires users to be at least 16 years old. We do not knowingly collect personal information from anyone under 16. If you believe a child under 16 has created an account, email us and we will delete it.

13. Changes to this policy

When we change this policy we will post the new version here and update the date at the top. If a change meaningfully reduces your privacy, we will take reasonable steps to notify you in the app before it takes effect.

14. Contact us

Email support@journalifyapp.com.