DeepJournal Privacy Policy
This Privacy Policy describes how DeepJournal (the "App", "we", "us", "our") collects, uses, shares, and protects information when you use our journal and self-reflection service. By installing or using the App, you agree to the terms of this Privacy Policy. If you do not agree, please discontinue use and follow the deletion process described below.
1. What DeepJournal Is and Is Not
DeepJournal is a private journaling and self-reflection tool. It stores your journal entries, identifies long-term themes, and produces AI-assisted summaries and suggestions. DeepJournal is not a medical device. It does not provide medical advice, diagnosis, treatment, therapy, counseling, or crisis intervention. The AI-generated content is informational and may be inaccurate. The App is not intended to replace professional care. If you are in crisis, contact 988 (US Suicide & Crisis Lifeline), text HOME to 741741 (Crisis Text Line), or dial 911 for emergencies.
2. Information We Collect
We collect only the information required to operate the service. Categories include:
- Account information: email address, display name, and authentication metadata provided by Supabase (including the authentication provider such as email/password, Google, or Apple).
- User content: journal session text, optional voice recordings, generated summaries, structured memories, weekly and monthly insights, and your action suggestions. You control this content.
- Device and push metadata: device tokens used to deliver optional reminder notifications through Apple Push Notification service.
- Subscription state: subscription tier, transaction identifiers, and entitlement information received from RevenueCat and Apple.
- Product analytics: aggregated, de-identified event counters covering onboarding completion, feature usage, and crashes. We do not collect journal text, memories, or other user content for analytics.
- Operational metadata: timestamps, request identifiers, trace identifiers, HTTP status codes, and error information required to operate the service securely.
We do not collect biometric identifiers, health measurements, contacts, advertising identifiers, precise location, or background-tracking information.
3. How We Use Information
We use the information we collect to:
- Authenticate you and maintain your account.
- Store your journal entries, generate AI-assisted summaries, structure memories, produce insights, and surface them back to you.
- Send optional notifications that you have explicitly enabled.
- Verify and process subscriptions and entitlements.
- Detect abuse, prevent fraud, and protect the integrity of the service.
- Diagnose crashes and improve stability, performance, and product decisions.
- Comply with applicable law and respond to lawful requests.
We do not use your journal entries, memories, or insights to train generative AI models, including Google Gemini. Where a third-party provider processes your content to generate a response, that processing is governed by the provider's terms and is not used to improve the provider's models.
4. Third Parties and Service Providers
We share the minimum information necessary with the following categories of providers. Each provider processes data according to its own terms.
- Authentication: Supabase. Provides authentication infrastructure; processes email, password hashes, OAuth tokens, and account identifiers.
- Cloud infrastructure: Cloudflare. Hosts our backend (Cloudflare Workers) and our database (Cloudflare D1) in secure, access-controlled regions.
- AI inference: Google Gemini. Receives your message text solely to generate a response in the current session. The data is sent over TLS, processed in a controlled environment, and is not used to train Gemini models. Sessions are not retained by us beyond the retention periods described below.
- Subscriptions: RevenueCat and Apple App Store. Receives transaction and entitlement information required to verify paid features.
- Push notifications: Apple Push Notification service. Receives device tokens to deliver reminders you enable.
- Email and support: We use a transactional email provider to deliver account-related messages and respond to support requests.
We do not sell your data, and we do not share it with advertising networks, data brokers, social networks, or third-party training pipelines.
5. Legal Bases for Processing (EEA / UK Users)
We process your data on the following legal bases under the GDPR:
- Performance of the contract when we provide the service you have signed up for.
- Our legitimate interests in operating a secure, reliable service, when those interests are not overridden by your rights.
- Your consent for non-essential processing, such as optional analytics or marketing communications.
- Compliance with legal obligations.
6. Data Retention and Deletion
We retain your data only for as long as necessary to provide the service and comply with legal obligations. Specifically:
- Journal content, memories, suggestions, and reports are retained while your account is active.
- Operational logs are retained for a maximum of 30 days, unless required for security investigation.
- Backups follow short retention windows and are overwritten in the ordinary course of operations.
You can delete your data at any time using one of the following methods:
- In-app: Settings → Privacy → Delete All Data removes journal content, memories, suggestions, and reports while keeping your account.
- In-app: Settings → Privacy → Delete Account permanently deletes your account and all associated data. The action is irreversible.
- Email: Send a deletion request to support@deepjournal.app. Include the email address on your account or your user identifier. We will process the request within 30 days.
After deletion, residual data may persist in encrypted backups for a short period until overwritten. We confirm completion by email.
7. Security
We design the service with privacy in mind. Measures include:
- TLS 1.3 for all data in transit.
- Industry-standard encryption at rest in Cloudflare D1 and related storage.
- Secure storage of credentials and tokens using iOS Keychain on device.
- JWT-based authentication with short access-token lifetimes.
- Strict row-level isolation in D1: every query is scoped to the authenticated user.
- Restricted access to production data; least-privilege roles for operators.
- Continuous dependency review, dependency vulnerability scanning, and static analysis.
No method of transmission or storage is perfectly secure. We cannot guarantee absolute security, but we work continuously to reduce risk.
8. Children and Age Requirements
The App is not directed to children under 13. We do not knowingly collect personal information from children under 13. Where local law sets a higher age of digital consent (for example, 16 in parts of the European Economic Area), we treat that higher age as the minimum. If you believe we have collected information from a child in violation of this policy, contact support@deepjournal.app so we can delete it.
The App is intended for self-reflection and is not designed to attract children as a primary audience.
9. International Transfers
We use providers in multiple regions, including the United States and the European Union. Where personal data is transferred across borders, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses or equivalent mechanisms. By using the App, you understand that your data may be transferred to and processed in jurisdictions other than your own.
10. Your Rights
You have the following rights, subject to applicable law:
- Access: Request a copy of the personal data we hold about you.
- Correction: Ask us to correct inaccurate or incomplete data.
- Deletion: Request that we delete your data, including via the in-app controls described above.
- Portability: Receive your journal data in a portable, machine-readable format.
- Restriction and objection: Ask us to restrict or stop certain processing.
- Withdrawal of consent: Withdraw consent at any time where processing is based on consent.
- Complaint: Lodge a complaint with a supervisory authority in your jurisdiction.
To exercise these rights, use the in-app controls or email support@deepjournal.app. We respond within the timeframes required by applicable law, including the GDPR and the California Consumer Privacy Act (CCPA/CPRA).
11. California Privacy Rights
If you are a California resident, you have the right to know what categories of personal information we collect, to access that information, to request deletion, to correct inaccuracies, and to limit the use of sensitive personal information. We do not sell or share personal information for cross-context behavioral advertising. You may exercise these rights through the in-app controls or by emailing support@deepjournal.app.
12. AI and Automated Processing
The App uses generative AI to produce summaries, reflections, suggestions, and insights. These outputs are generated and may be inaccurate, incomplete, or inappropriate. They are not professional advice. You can disable memory extraction and AI-assisted features in Settings; you can also delete any AI-generated content through the in-app delete tools.
13. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "last_updated" date at the top of this document. If the changes are material, we will notify you in-app or by email and, where required by law, request renewed consent.
14. Contact
For privacy questions, deletion requests, or to exercise your rights, contact:
- Email: support@deepjournal.app
For users in the European Economic Area, we will provide the name of our designated representative on request.
15. Governing Law
This Privacy Policy is governed by the laws of the State of Delaware, United States, without regard to conflict of laws principles.