journAI — Privacy Policy
Effective 2026-06-09 · Last updated 2026-06-09
journAI ("journAI", "we", "us") is a personal journaling app operated by Tushar, based in India. This policy explains what we collect, why, who processes it, and the choices you have.
If you do not agree with this policy, please do not use journAI.
1. A quick summary
- Your journal is private to you. We do not sell your data, and we do not use it for cross-app advertising or tracking.
- To give you AI reflections, the text of your entries is sent to Google (Gemini) for processing. See §4.
- We use a few standard services to run the app: Supabase (accounts + storage), Google Gemini (AI), PostHog (analytics), Sentry (crash reports), and RevenueCat (subscriptions). See §5.
- Conversations in "Chat with your journal" are not stored after you leave the screen.
- You can delete your account and all associated data at any time. See §9.
2. Information you provide
- Account information — your email address, and (if you use Apple or Google Sign-In) the account identifier and email those providers share with us.
- Journal content — the entries you write, including their text, word counts, and entry dates.
- Preferences — your journaling style (gratitude / freewrite / reflection), notification settings, and appearance (light / dark / system) settings.
3. Information created or collected automatically
- AI-generated analysis — derived from your entries: a mood label and mood score, a short insight, and (for Pro) summaries, themes, and suggested action items. Weekly digests are generated from your past 7 days of entries.
- Streaks and mood history — counts and timestamps used to show your progress and mood chart.
- Usage analytics — via PostHog: a pseudonymous identifier plus product events such as creating an entry, completing an AI analysis, sending a chat message, viewing the paywall, subscribing, and reaching a streak milestone. We record event metadata (e.g. word count, message length, duration), not the text of your entries.
- Diagnostics — via Sentry: crash and error reports, which may include device and app state needed to fix bugs.
- Subscription data — via RevenueCat and the app stores: your purchase and subscription status. Payment card details are handled by Apple/Google and are never seen by us.
- Local device storage — drafts and your session are cached on your device (via secure storage / MMKV) so the app works offline and keeps you signed in.
We do not collect your advertising identifier (IDFA) and do not perform cross-app tracking.
4. How your journal content is processed by AI
To produce reflections, weekly digests, and chat answers, the relevant text of your entries is transmitted — over an encrypted connection, from our secure backend (Supabase Edge Functions), never directly from your device — to Google's Gemini API (gemini-2.5-flash).
- Google processes this text to generate the response and returns it to us.
- Based on Google's API terms as of the date of this policy, content submitted through Google's paid API tier is not used to train Google's models. Google controls its own processing, and its terms may change; we operate on the paid API tier and will update this policy to stay aligned with Google's current terms.
- "Chat with your journal" builds its context for a single session only and is not saved once you leave the chat screen.
If you are not comfortable with AI processing of your entries, note that AI analysis is a core part of journAI's functionality and cannot currently be disabled per-entry.
5. Service providers (sub-processors)
| Provider | Purpose | Data involved | Region / notes |
|---|---|---|---|
| Supabase | Auth, database, storage, backend functions | Account info, journal entries, derived analysis | Hosted in the US (East) |
| Google (Gemini API) | AI analysis, digests, chat | Entry text sent for processing (§4) | Per Google API terms |
| PostHog | Product analytics | Pseudonymous ID + usage events (no entry text) | US (us.i.posthog.com) |
| Sentry | Crash & error reporting | Diagnostic/device data | US (configurable region) |
| RevenueCat | Subscription management | Purchase/subscription status | US |
| Expo (EAS) | App delivery & over-the-air updates, build/crash infrastructure | Device/app diagnostic data, update delivery | Per Expo's terms |
| Apple / Google | Sign-in and payments | Auth identifiers, payment processing | Per their policies |
Each provider processes data under its own privacy policy and our agreements with them. We share only what is needed for these functions.
6. Why we process your data (legal bases)
We process your data to provide and maintain the app and its features; generate the AI reflections you ask for; keep the app secure and stable; process subscriptions; and improve the product.
Your journal content, and the mood readings derived from it, may reveal information about your health or wellbeing. Laws in the places we serve treat this as sensitive or health information — including India's Digital Personal Data Protection Act, Australia's Privacy Act (sensitive information), and U.S. state health-data laws such as Washington's My Health My Data Act. We collect and process this information only with your explicit consent, which you give when you start using the app's AI features and which you can withdraw at any time by deleting your account (see §9). We never sell it or use it for advertising.
For other data, where required by law our legal bases are performance of our contract with you (running your account and the features you request), your consent (where separately asked), and our legitimate interests in operating, securing, and improving journAI.
Automated processing. AI outputs are for personal reflection. We do not use them to make automated decisions that produce legal or similarly significant effects about you.
7. International data transfers
journAI is available in India, the United States, Canada, and Australia, is operated from India, and uses service providers located in the United States and other countries. Regardless of where you live, your data is transferred to and processed in these countries, and may be subject to access by courts, law-enforcement, or government authorities there under their laws. We use providers that offer recognised security and contractual protections, and we take reasonable steps to protect your data in line with this policy and applicable law (including Canada's PIPEDA and the Australian Privacy Principles). By using journAI, you understand that your data is processed outside your country of residence as described here.
8. Data retention
- Journal entries and derived analysis are kept until you delete them or delete your account.
- Chat sessions are not retained after you leave the chat screen.
- Analytics and diagnostic data are retained according to each provider's defaults and our configuration.
- Backups may persist for a limited period after deletion before being overwritten.
9. Your rights and choices
- Access / export / correct — contact us (§12) to request a copy or correction of your data.
- Delete your account — in the app, go to Profile → Delete account. This permanently deletes your entries, analyses, digests, streaks, and account data. The action requires a two-step confirmation and cannot be undone.
- Withdraw consent — because AI processing of your journal content relies on your consent, you can withdraw it at any time by deleting your account (Profile → Delete account), which stops all further AI processing and removes your data as described above.
- Notifications — daily reminders are optional and can be turned on/off and rescheduled in Profile → Settings.
- Region-specific rights — depending on where you live you may have additional rights and protections: India (Digital Personal Data Protection Act); the United States (e.g. California's CCPA/CPRA and other state privacy laws, and health-data laws such as Washington's My Health My Data Act); Canada (PIPEDA and Quebec's Law 25); and Australia (the Privacy Act and Australian Privacy Principles). These may include the right to access, correct, delete, or port your data, to withdraw consent, and to complain to the relevant data-protection authority. We do not sell personal information.
To exercise any right, email us at tushardahiya84@gmail.com.
10. Security
Data is encrypted in transit. Accounts are protected by your chosen sign-in method. Our database enforces row-level security so that each user can only access their own data, and privileged keys are held only on our backend, never in the app. No system is perfectly secure, but we take reasonable measures to protect your information.
11. Children
journAI is not directed to children. You must be at least 18 years old (or the minimum age of digital consent in your country, if higher) to use it. We do not knowingly collect data from children below that age; if you believe a child has provided us data, contact us and we will delete it.
12. Contact
Questions or requests about this policy or your data:
- Email: tushardahiya84@gmail.com
- Operator: Tushar, India
- Grievance / data protection contact: Tushar — tushardahiya84@gmail.com. We aim to respond to data requests and complaints within the timeframes required by applicable law.
13. Changes to this policy
We may update this policy as the app evolves. We will revise the "Last updated" date above and, for material changes, provide notice in the app. For changes that materially affect how we process your journal content, we will seek fresh consent where the law requires it. Continued use after non-material changes means you accept the updated policy.
14. Governing law
This policy is governed by the laws of India, without regard to conflict-of-law principles.
See also our Terms of Use.