Journal Thing — Privacy Policy
Journal Thing keeps your journal on your device unless you turn on sync. We never sell your data, show ads, or track you across other companies' apps or websites. We use limited app-usage analytics and crash reports, such as session duration, feature use, and error details, to improve the app. Those reports exclude what you write in your journal. You can turn both off any time with one switch in Settings → Privacy.
This policy applies to the Journal Thing apps for iOS, watchOS, Android, and Wear OS and to the Journal Thing web journal at journalthing.com/app, published by Things Things Things LLC ("we", "us", "our"). Sections below say which platform they describe when the two differ. It is specific to the apps — the Things Things Things website privacy policy covers thingsthingsthings.studio separately.
What we collect
Your journal content is local by default. Sync and dictation send data only when you use them. We also collect limited app-usage analytics:
- Sync. Two kinds, both optional. iCloud sync keeps an iPhone and iPad in step through your own private iCloud, where Apple stores the copy. Journal Thing Sync, part of Premium, keeps iPhone, iPad, Android, and the web journal in step through a Journal Thing account, where we store a protected copy. The details are below.
- Purchase management. We and our purchase providers use purchase status and identifiers to confirm Premium. On Android, this processing starts when you open the app, before a purchase or sync sign-in. See "Purchases" below.
- Feedback you send. The in-app feedback form sends us your message, an optional email address, and an optional screenshot. See "Feedback and support" below.
- Voice dictation. Audio is processed to return a transcript, with app-integrity and rate-limit data used to protect the service. See "Voice dictation" below.
- App-usage analytics. We collect a small allowlisted set of product-usage events to understand how the app is used and improve it. Journal content is expressly excluded.
- Crash reports. If the app crashes or hits an internal error, a diagnostic report (stack trace, app version, OS version, device model) is sent so we can fix it. Journal content is expressly excluded, and the same Settings switch that controls analytics turns crash reporting off too.
What stays on your device
Everything you create in the app is written to local storage on your iPhone, iPad, or Android device, and stays there:
- journal entries, titles, and timestamps;
- moods, tags, todos, and daily intentions;
- your name, if you choose to enter one during setup;
- app settings such as theme, font, text size, and reminder times;
- backup files you create, until you delete or share them.
Deleting the app removes its local storage; exported backups can remain wherever you saved them. The Apple Watch app and home-screen widgets use journal data from your devices. Wear OS keeps a phone-provided snapshot, unsent entries waiting for the phone, and recoverable dictation drafts. Its local data is excluded from Android cloud backup and device transfer. Watch dictation uses the optional cloud service described below; Wear OS asks for cloud-dictation consent separately. Journal content is never included in analytics. We receive content through optional hosted sync, dictation processing, or feedback you choose to send, as described below.
iCloud sync — iPhone and iPad (optional, off by default)
You can turn on iCloud sync to keep your journal up to date across your iPhone and iPad. When you do, your entries sync through your own private iCloud database (Apple CloudKit), tied to your Apple Account. That data is:
- stored and protected by Apple, not by us — no server of ours is involved, and Apple encrypts iCloud data in transit and at rest;
- scoped to the private CloudKit database associated with your Apple Account, rather than a Journal Thing account or database we operate;
- under your control — you can turn sync off at any time, and Settings includes a "Delete iCloud Data" action that removes the journal copy stored in your iCloud.
Apple's handling of iCloud data is governed by Apple's Privacy Policy.
Journal Thing Sync — iPhone, iPad, Android, and web (optional, off by default)
Journal Thing Sync keeps one journal current across iPhone, iPad, Android, and the web journal at journalthing.com/app. It works differently from iCloud sync, and we would rather state it plainly than let the sentence above be read too generously. When you sign in:
- you sign in with Google or Apple, which creates a Journal Thing account. We receive and store the email address of that account (or Apple's private relay address, if you hide your email) and an account identifier. Our authentication provider, Supabase, can also retain the display or full name in your Google or Apple profile to manage the account. This is separate from the name you type during local app setup. We never receive your Google or Apple password.
- your entries, titles, moods, tags, daily focus, five-minute exercises, custom mood packs, and their timestamps are copied to a database that we operate (hosted for us by Supabase, in the United States). The copy is encrypted in transit and protected with the hosting provider's encryption at rest.
- dated mood ratings are personal wellbeing information. We use them only to show and sync your mood history, not for medical assessment or advertising. Sync records also carry a random installation identifier to keep changes from your devices in order.
- photos you attach to entries are uploaded, as the compressed image the app stores, to private storage in your account (also hosted for us by Supabase) so they appear on your other devices. Only your own signed-in devices can read them.
- if an entry carries optional place details — a place name, address, or coordinates, for example on an entry imported from another journaling app — those details sync with the entry. Journal Thing never asks for your device's location and has no location permission; the only coordinates it can hold are ones already attached to an entry.
- hosted sync is part of Journal Thing Premium. When you sign in, the app checks whether your account has an active Premium purchase (see "Purchases" below); if it does not, syncing pauses and your journal stays on the device and in your account.
- that copy is not end-to-end encrypted. Access is restricted to your own account, but the content is not scrambled in a way that would make it unreadable to us as the operator. We do not read it, and we do not use it for anything but syncing your devices — but we are not in a position to claim we cannot, and on iCloud we are.
- sync stays off until you choose it, and your journal always remains on the device as well, so it keeps working offline.
Turning sync off does not delete the copy on our server. Disconnecting signs this device out and stops syncing; the journal already in your account stays there. To erase it, use Settings → Journal Thing Sync → "Delete sync account" on iPhone or iPad, Settings → Sync & Backup → "Delete sync account" on Android, or Settings → Delete Account in the web journal. Either permanently deletes your account and the journal and photos stored in it, and signs this device out. The journal on your device is not touched. You can also email hello@journalthing.com from the address you signed in with, or follow the steps at journalthing.com/delete-account.
The web journal
journalthing.com/app is the same journal in a browser, available once you sign in to Journal Thing Sync. It keeps your display preferences, recent searches, and the reply address you type into its feedback form in your browser's local storage. It uses the same limited analytics and crash reporting as the apps, with the same opt-out switch in its Settings, and its feedback form works like the in-app one. Older journalthing.com email-and-password accounts can be deleted from the web journal's Settings or by emailing us.
Voice dictation (optional)
Journal Thing includes voice dictation you can use instead of typing. While you dictate, your audio is sent over an encrypted connection to our transcription relay, hosted by Cloudflare, and forwarded to OpenAI's speech-to-text service, which returns the text in real time. About that audio:
- we do not store the audio or the resulting text — our relay holds neither once your transcription request completes;
- native-app requests include an app-integrity proof and are subject to rate limits. On Apple devices, the service retains a hashed App Attest installation key and its public verification material so it can recognize valid app installations and prevent replay or abuse. This is not an advertising identifier and is not used for analytics;
- on Android, Google Play Integrity verifies the app and installation. Our relay keeps hashed rate-limit identifiers derived from a service label and the request's network address, plus an attempt count and time window, to prevent abuse of dictation and feedback. We do not use those identifiers for analytics or infer your location from them;
- OpenAI processes these requests as a service provider. Its standard API policy excludes customer data from model training unless optional data sharing is enabled. We use its audio-transcriptions endpoint; OpenAI's published default retention table lists no abuse-monitoring or application-state retention for that endpoint. These defaults do not override an account's optional sharing choices. See OpenAI's endpoint data controls and optional data-sharing settings;
- the microphone is used only while you are actively dictating — the app never listens otherwise, and typing never touches the dictation service.
Cloudflare also processes network metadata, such as IP addresses, request times, and URLs, to deliver and secure our service. We have not enabled stored Worker request logs or log exports. Cloudflare's operational metadata is separate from dictation content and follows its own privacy and retention practices; we do not promise that all network metadata disappears when a transcription request ends.
Limited app-usage analytics
Journal Thing sends PostHog a small, allowlisted set of product-usage events to help us understand whether features are useful and where the app needs work. These may include app launches, coarse session duration, feature interactions, app version, platform, OS version, and broad device type. We attach an app-scoped random installation ID so we can count sessions without using your name, email, account ID, or an advertising identifier, and we ask our analytics provider not to derive a location from your network address.
Android events include app opening, onboarding completion, entry creation or deletion, setting or clearing a mood, adding, removing or tapping a tag, completed dictation, attaching a photo, performing a search, and opening Rewind. A journal summary sends only entry, tag and mood-day counts. Other properties can say whether a prompt was used, which built-in mood pack was used (all custom packs share one generic category), and the feature where an interaction happened. These events record occurrences, not the content involved.
These app-usage events never include journal entries, titles, prompt text, names, mood ratings, tag names, todos, daily intentions, search text, typed text, dates from your journal, locations, photos, audio, transcripts, or other content you create. We do not use autocapture, session replay, advertising profiles, or tracking across other companies' apps or websites.
We use analytics only to improve and operate Journal Thing. The events are processed for us by PostHog, Inc. (United States) under contractual limits that prohibit selling the data or using it for its own advertising. PostHog stores these event records. Our current plan lists a 12-month query window. That window limits access to older events when enforced; it is not a promise that stored events are deleted after 12 months. We have not confirmed a fixed deadline for deletion of all stored copies. Turning analytics off stops future collection from that device; it does not delete events already sent.
You can turn this off. Settings → Privacy → "Share anonymous analytics" stops PostHog usage events and Sentry crash reports on that device. This reporting is on by default. The switch does not stop RevenueCat purchase management or its purchase and subscription reporting, described below.
Crash reports
If Journal Thing crashes or hits an internal error, a diagnostic report is sent to Sentry (Functional Software, Inc., United States), which processes it for us as a service provider. A report contains technical details such as stack symbols, app version, OS version, device model, the affected feature and operation, a fixed error category, HTTP status family, bounded retry count, and approved app-operation breadcrumbs — never journal entries, titles, tag names, search text, or other content you create, and never an advertising identifier. Crash reports received during our current Sentry trial have a 90-day retention period in its live service. If the account moves to the free Developer plan, newly received reports have a 30-day period; earlier reports keep the period assigned when received. Sentry deletes individual events after their retention period. Backup copies follow a separate schedule: Sentry deletes them 90 days after each backup is created, so copies may remain after an event leaves the live service. See Sentry's plan retention periods and backup deletion practices. The Settings → Privacy analytics switch turns crash reporting off along with analytics; it does not erase reports already sent.
No sale of data, ads, or cross-app tracking
We do not sell or rent personal data. We do not show ads, use IDFA, or combine Journal Thing data with data from other companies' apps, websites, or offline properties for advertising or ad measurement. We share data only with service providers—Apple for iCloud, Supabase for Journal Thing Sync, Cloudflare for our web service and relay, OpenAI for transcription, RevenueCat for purchase management, PostHog for limited app-usage analytics, Sentry for crash reports, Resend for feedback delivery, and Hostinger for our support mailbox—or when law requires it. Those providers must protect the data and may use it only to provide their service to us.
Device permissions
- Microphone — only if you use voice dictation, and only while you dictate (see "Voice dictation" above).
- Face ID / Touch ID — only if you turn on biometric unlock. Authentication is handled entirely by iOS; the app is told only whether it succeeded. We never see your biometric data, and iOS never shares it with any app.
- Camera and photos — only when you attach a photo to an entry. The camera is used only while you take a picture. To show your recent photos inside the app, iOS and Android ask for photo-library access when you open the photo sheet; you can allow selected photos only, and if you decline, the camera and the system photo picker still work. Photos are stored with your journal on the device. With iCloud sync on, they travel in your private iCloud; with Journal Thing Sync on, they are uploaded to your account's private storage as described above.
- Notifications — only if you enable reminders. All reminders are scheduled locally on your device. There is no push server of ours, and no notification content ever leaves your device. (If you enable iCloud sync, Apple delivers silent push notifications between your own devices so changes arrive promptly; these contain no journal content readable by us.)
Backups you create
Journal Thing can export a backup file of your journal, which you can optionally protect with a passphrase. Backup files are created on your device and go wherever you save or share them using the system's file picker or share sheet. If you choose a passphrase, only you have it — we cannot recover a backup whose passphrase has been lost.
Android's automatic journal snapshots are device-only. Android cloud backup and device transfer exclude the journal databases, their SQLite sidecars, recovery copies and local snapshots. To keep a copy outside the device, export a backup to a location you control or enable hosted sync. Uninstalling, clearing app storage or losing the device can remove local copies. If a newer journal database must be preserved for recovery, the app explains how to export it; that recovery ZIP is unencrypted and is intended for support-assisted recovery, not normal backup import.
Purchases
- iPhone and iPad. Journal Thing Premium is sold through Apple's In-App Purchase system. Apple processes the payment and tells the app only whether a purchase is active. We never receive your name, email, or payment details. If you sign in to Journal Thing Sync, the app sends Apple's signed record of your purchase to our server so we can confirm Premium for your account; we keep a hashed transaction reference, the product, its status, and its expiry with the account. We also keep an encrypted copy of the original transaction identifier and product ID so we can check current purchase status with Apple when the app is closed. This does not include your payment details. Apple's handling of that transaction is governed by Apple's Privacy Policy.
- Android. Journal Thing Premium is sold through Google Play Billing. Google processes the payment; we never receive your card, bank, or other payment details, and Google's handling of the transaction is governed by Google's Privacy Policy. Premium features work on the device without an account. If you sign in to Journal Thing Sync, the app associates its purchase identity with your sync account so our server can confirm Premium through RevenueCat. We also support direct verification: the app sends the Play purchase token and product ID to our server to check with Google. We keep a hashed transaction reference, the product, its status, and its expiry with your account. For direct checks with Google, separate encrypted storage holds the purchase token and product ID so we can check status when the app is closed. Deleting your account removes those stored proofs and account links; the retention section below explains the unlinked purchase references we may retain. Google can also notify our server of purchase changes so we can check renewals, refunds and replacement subscriptions even when the app is closed or you have not signed in to sync. We keep hashed purchase-family references to maintain account ownership, and hashed notification receipts to avoid processing the same message twice. Google Cloud Pub/Sub delivers those notifications for us. Its delivery queue temporarily holds the original message, including the purchase token, until our server acknowledges it or the seven-day retention window ends. We do not enable retention of acknowledged messages.
- Purchase management (RevenueCat). We use RevenueCat, Inc. (United States) as a service provider to validate purchases with Apple and Google and to keep Premium status current across your devices. RevenueCat also provides purchase and subscription reports that help us understand how Premium is used. On Android, RevenueCat initializes when you open the app, before a purchase or sync sign-in. It uses a generated installation identifier or the purchase identity already stored on that device to maintain Premium status. The app supplies store purchase records and product identifiers when available. Optional Journal Thing Sync sign-in also gives RevenueCat your sync account identifier so a purchase made before signing in follows the account. Signing out of Journal Thing Sync does not clear RevenueCat's purchase identity on that device, so Premium can remain available after sign-out. RevenueCat never receives your name, email, card, or other payment details. Apple and Google send RevenueCat notifications about renewals, refunds, and billing problems, and RevenueCat tells our server the resulting Premium status; our server keeps the same hashed transaction reference, product, status, and expiry described above and records that RevenueCat holds data for your account. When you delete your sync account we instruct RevenueCat to delete its records for that account, and the deletion does not complete until that instruction succeeds. Purchase records that were never linked to a sync account stay with RevenueCat under the installation identifier and are governed by RevenueCat's Privacy Policy.
Feedback and support
The in-app feedback form sends us the message you type, the email address you choose to enter (optional, so we can reply), and — only if you turn on the per-message toggle, which is off by default — a screenshot of the app as it looked when you opened the form. Because that screenshot can show your journal, please check it before sending. Each message also carries the app version, OS version, device model, and language so we can reproduce problems. Feedback reaches our support inbox through our email delivery provider (Resend, United States). On our current plan, Resend retains email and delivery logs for 30 days; its backups persist for seven days. See Resend's retention practices. Our support mailbox is hosted by Hostinger. We keep the inbox copy only as long as needed to respond and fix the issue; the Resend delivery window does not automatically delete that copy. Messages deleted into Hostinger's Trash may remain there for up to 30 days before permanent deletion, as described in Hostinger's deleted-email guidance. Email to hello@journalthing.com is handled with the same support-retention criteria.
Apple's role
- Device backups. If you have iCloud Backup or encrypted local backups turned on in iOS, your device backup may include Journal Thing's data — as it does for other apps. That backup is controlled by Apple and your iOS settings, not by us, and we have no access to it.
Children's privacy
Journal Thing is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided personal information through Journal Thing Sync, analytics, or support, contact us and we will investigate and delete it where required.
Your rights
Rights such as access, correction, deletion, and portability normally apply to data a company holds about you. Unless you sign in to Journal Thing Sync, we do not hold a copy of your journal: entries live on your device, and in your private iCloud if you enable iCloud sync. You can export them, delete the iCloud copy from Settings, and delete the on-device copy by deleting the app.
If you signed in to Journal Thing Sync on any platform, we do hold a copy, and those rights apply to it. You can delete your sync account and its server-held journal from Settings → Sync & Backup → "Delete sync account". This action removes the account; it does not keep the account while permanently erasing selected journal records. For a copy of your data or another privacy request, email hello@journalthing.com from the address you signed in with. Contact us about requests that the app does not support directly.
PostHog app-usage analytics is associated with a random installation ID rather than your name or account. Because we deliberately do not keep a lookup from your identity to that random ID, an email address alone may not let us locate event-level analytics for an individual installation.
Retention and deletion
- on-device journal data is stored in the app. Removing an entry on Android hides it from your journal. Its content and related tag data remain in local storage and, if synced, in server deletion records. Removing an entry does not permanently erase these copies. Deleting your sync account removes its server copy but leaves your local journal. Uninstalling the app removes its local storage; exported backups remain wherever you saved them;
- iCloud journal data remains until you delete it using Journal Thing or your Apple Account controls;
- Journal Thing Sync data, including uploaded photos, and account details remain until you use "Delete sync account" or ask us to delete the account;
- our relay does not retain dictation audio or transcripts after the request; the audio-transcriptions endpoint's published retention rules are described above;
- PostHog usage events and Sentry crash reports follow the provider retention and deletion practices described above. Turning reporting off stops future collection by those services; it does not erase reports already sent or stop RevenueCat purchase processing;
- app-integrity public keys and hashed installation credentials may be retained for as long as we operate the transcription service because they let us reject replayed or invalid requests. They are not used to analyze app usage or advertising.
- abuse-rate records become eligible for deletion after 24 hours and are pruned on authentication requests and daily scheduled maintenance. Purchase-notification receipts become eligible after 31 days and are pruned daily, including receipts for purchases without a sync account; account-linked receipts and purchase-ownership links are also removed when the account is deleted. To prevent old purchase proofs from restoring deleted ownership, we may retain hashed purchase-family references without the deleted account identifier. These references remain for as long as needed to prevent reuse of those proofs. These scheduled processes are not promises of deletion at an exact hour. Encrypted Apple and Google purchase proofs remain while needed to check the purchase selected for your account, including when a store service is temporarily unavailable. Our scheduled checks remove obsolete proofs once they confirm that a different purchase is selected. Deleting your account removes its stored proofs before the account deletion finishes. These records are separate from the notification queue and hashed receipts. Undelivered Google purchase notifications have the separate seven-day queue limit described above; deleting a sync account does not cancel a Play subscription or erase Google's own transaction records.
Changes to this policy
If this policy changes, we will revise the "Last updated" date above and describe any new data practice clearly before it ships.
Contact
Questions about this policy or about Journal Thing? Email hello@journalthing.com.