← thingsthingsthings.studio

Journal Thing — Privacy Policy

This policy applies to the Journal Thing apps for iOS, watchOS, Android, and Wear OS and to the Journal Thing web journal at journalthing.com/app, published by Things Things Things LLC ("we", "us", "our"). Sections below say which platform they describe when the two differ. It is specific to the apps — the Things Things Things website privacy policy covers thingsthingsthings.studio separately.

What we collect

Your journal content is local by default. Sync and dictation send data only when you use them. We also collect limited app-usage analytics:

What stays on your device

Everything you create in the app is written to local storage on your iPhone, iPad, or Android device, and stays there:

Deleting the app removes its local storage; exported backups can remain wherever you saved them. The Apple Watch app and home-screen widgets use journal data from your devices. Wear OS keeps a phone-provided snapshot, unsent entries waiting for the phone, and recoverable dictation drafts. Its local data is excluded from Android cloud backup and device transfer. Watch dictation uses the optional cloud service described below; Wear OS asks for cloud-dictation consent separately. Journal content is never included in analytics. We receive content through optional hosted sync, dictation processing, or feedback you choose to send, as described below.

iCloud sync — iPhone and iPad (optional, off by default)

You can turn on iCloud sync to keep your journal up to date across your iPhone and iPad. When you do, your entries sync through your own private iCloud database (Apple CloudKit), tied to your Apple Account. That data is:

Apple's handling of iCloud data is governed by Apple's Privacy Policy.

Journal Thing Sync — iPhone, iPad, Android, and web (optional, off by default)

Journal Thing Sync keeps one journal current across iPhone, iPad, Android, and the web journal at journalthing.com/app. It works differently from iCloud sync, and we would rather state it plainly than let the sentence above be read too generously. When you sign in:

Turning sync off does not delete the copy on our server. Disconnecting signs this device out and stops syncing; the journal already in your account stays there. To erase it, use Settings → Journal Thing Sync → "Delete sync account" on iPhone or iPad, Settings → Sync & Backup → "Delete sync account" on Android, or Settings → Delete Account in the web journal. Either permanently deletes your account and the journal and photos stored in it, and signs this device out. The journal on your device is not touched. You can also email hello@journalthing.com from the address you signed in with, or follow the steps at journalthing.com/delete-account.

The web journal

journalthing.com/app is the same journal in a browser, available once you sign in to Journal Thing Sync. It keeps your display preferences, recent searches, and the reply address you type into its feedback form in your browser's local storage. It uses the same limited analytics and crash reporting as the apps, with the same opt-out switch in its Settings, and its feedback form works like the in-app one. Older journalthing.com email-and-password accounts can be deleted from the web journal's Settings or by emailing us.

Voice dictation (optional)

Journal Thing includes voice dictation you can use instead of typing. While you dictate, your audio is sent over an encrypted connection to our transcription relay, hosted by Cloudflare, and forwarded to OpenAI's speech-to-text service, which returns the text in real time. About that audio:

Cloudflare also processes network metadata, such as IP addresses, request times, and URLs, to deliver and secure our service. We have not enabled stored Worker request logs or log exports. Cloudflare's operational metadata is separate from dictation content and follows its own privacy and retention practices; we do not promise that all network metadata disappears when a transcription request ends.

Limited app-usage analytics

Journal Thing sends PostHog a small, allowlisted set of product-usage events to help us understand whether features are useful and where the app needs work. These may include app launches, coarse session duration, feature interactions, app version, platform, OS version, and broad device type. We attach an app-scoped random installation ID so we can count sessions without using your name, email, account ID, or an advertising identifier, and we ask our analytics provider not to derive a location from your network address.

Android events include app opening, onboarding completion, entry creation or deletion, setting or clearing a mood, adding, removing or tapping a tag, completed dictation, attaching a photo, performing a search, and opening Rewind. A journal summary sends only entry, tag and mood-day counts. Other properties can say whether a prompt was used, which built-in mood pack was used (all custom packs share one generic category), and the feature where an interaction happened. These events record occurrences, not the content involved.

These app-usage events never include journal entries, titles, prompt text, names, mood ratings, tag names, todos, daily intentions, search text, typed text, dates from your journal, locations, photos, audio, transcripts, or other content you create. We do not use autocapture, session replay, advertising profiles, or tracking across other companies' apps or websites.

We use analytics only to improve and operate Journal Thing. The events are processed for us by PostHog, Inc. (United States) under contractual limits that prohibit selling the data or using it for its own advertising. PostHog stores these event records. Our current plan lists a 12-month query window. That window limits access to older events when enforced; it is not a promise that stored events are deleted after 12 months. We have not confirmed a fixed deadline for deletion of all stored copies. Turning analytics off stops future collection from that device; it does not delete events already sent.

You can turn this off. Settings → Privacy → "Share anonymous analytics" stops PostHog usage events and Sentry crash reports on that device. This reporting is on by default. The switch does not stop RevenueCat purchase management or its purchase and subscription reporting, described below.

Crash reports

If Journal Thing crashes or hits an internal error, a diagnostic report is sent to Sentry (Functional Software, Inc., United States), which processes it for us as a service provider. A report contains technical details such as stack symbols, app version, OS version, device model, the affected feature and operation, a fixed error category, HTTP status family, bounded retry count, and approved app-operation breadcrumbs — never journal entries, titles, tag names, search text, or other content you create, and never an advertising identifier. Crash reports received during our current Sentry trial have a 90-day retention period in its live service. If the account moves to the free Developer plan, newly received reports have a 30-day period; earlier reports keep the period assigned when received. Sentry deletes individual events after their retention period. Backup copies follow a separate schedule: Sentry deletes them 90 days after each backup is created, so copies may remain after an event leaves the live service. See Sentry's plan retention periods and backup deletion practices. The Settings → Privacy analytics switch turns crash reporting off along with analytics; it does not erase reports already sent.

No sale of data, ads, or cross-app tracking

We do not sell or rent personal data. We do not show ads, use IDFA, or combine Journal Thing data with data from other companies' apps, websites, or offline properties for advertising or ad measurement. We share data only with service providers—Apple for iCloud, Supabase for Journal Thing Sync, Cloudflare for our web service and relay, OpenAI for transcription, RevenueCat for purchase management, PostHog for limited app-usage analytics, Sentry for crash reports, Resend for feedback delivery, and Hostinger for our support mailbox—or when law requires it. Those providers must protect the data and may use it only to provide their service to us.

Device permissions

Backups you create

Journal Thing can export a backup file of your journal, which you can optionally protect with a passphrase. Backup files are created on your device and go wherever you save or share them using the system's file picker or share sheet. If you choose a passphrase, only you have it — we cannot recover a backup whose passphrase has been lost.

Android's automatic journal snapshots are device-only. Android cloud backup and device transfer exclude the journal databases, their SQLite sidecars, recovery copies and local snapshots. To keep a copy outside the device, export a backup to a location you control or enable hosted sync. Uninstalling, clearing app storage or losing the device can remove local copies. If a newer journal database must be preserved for recovery, the app explains how to export it; that recovery ZIP is unencrypted and is intended for support-assisted recovery, not normal backup import.

Purchases

Feedback and support

The in-app feedback form sends us the message you type, the email address you choose to enter (optional, so we can reply), and — only if you turn on the per-message toggle, which is off by default — a screenshot of the app as it looked when you opened the form. Because that screenshot can show your journal, please check it before sending. Each message also carries the app version, OS version, device model, and language so we can reproduce problems. Feedback reaches our support inbox through our email delivery provider (Resend, United States). On our current plan, Resend retains email and delivery logs for 30 days; its backups persist for seven days. See Resend's retention practices. Our support mailbox is hosted by Hostinger. We keep the inbox copy only as long as needed to respond and fix the issue; the Resend delivery window does not automatically delete that copy. Messages deleted into Hostinger's Trash may remain there for up to 30 days before permanent deletion, as described in Hostinger's deleted-email guidance. Email to hello@journalthing.com is handled with the same support-retention criteria.

Apple's role

Children's privacy

Journal Thing is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided personal information through Journal Thing Sync, analytics, or support, contact us and we will investigate and delete it where required.

Your rights

Rights such as access, correction, deletion, and portability normally apply to data a company holds about you. Unless you sign in to Journal Thing Sync, we do not hold a copy of your journal: entries live on your device, and in your private iCloud if you enable iCloud sync. You can export them, delete the iCloud copy from Settings, and delete the on-device copy by deleting the app.

If you signed in to Journal Thing Sync on any platform, we do hold a copy, and those rights apply to it. You can delete your sync account and its server-held journal from Settings → Sync & Backup → "Delete sync account". This action removes the account; it does not keep the account while permanently erasing selected journal records. For a copy of your data or another privacy request, email hello@journalthing.com from the address you signed in with. Contact us about requests that the app does not support directly.

PostHog app-usage analytics is associated with a random installation ID rather than your name or account. Because we deliberately do not keep a lookup from your identity to that random ID, an email address alone may not let us locate event-level analytics for an individual installation.

Retention and deletion

Changes to this policy

If this policy changes, we will revise the "Last updated" date above and describe any new data practice clearly before it ships.

Contact

Questions about this policy or about Journal Thing? Email hello@journalthing.com.