com.anonymous.jornaAI)This Privacy Policy describes how JournaI (“the App,” “we,” “us,” or “our”) accesses, collects, uses, stores, and shares information when you use the App on Android (and iOS if offered).
JournaI is local-first. Journal entries and on-device companion chats stay on your phone unless you enable a feature that sends data elsewhere. We do not sell personal information. We do not operate servers that store your journal text, and the App does not create a JournaI cloud account.
Data retention policy (summary): We do not store or retain your journal entries or companion chat text on our servers. On-device data remains until you delete it, reset the App, or uninstall. Optional analytics and purchases follow the retention periods in section 12.
The App is for users aged 13 and older. We do not knowingly provide the App to children under 13. See section 11.
The following stays in the App sandbox on your device unless you export, back up, share, or paste it into cloud chat:
| Data | Purpose |
|---|---|
| Journal entries (text, tags, mood, dates, times) | Core journaling |
| Companion conversations and reflections | Chat and timeline replies |
| Settings (persona, theme, trial/subscription state, language) | Personalization and unlock state |
| Optional personality summary from your entries | “You” graph / companion context |
| Optional profile name and photo you choose | Identity in the App |
| Date of birth you enter at the age gate | Age check and lifeline start |
| Downloaded on-device AI model files | Local companion replies |
| Optional local diagnostics log | Troubleshooting if you enable it |
| API keys you paste for cloud AI | Calling the provider you chose |
Storage: SQLite and files in the App sandbox. A key is kept in the Android Keystore / iOS Keychain. The database file is not SQLCipher-encrypted at rest in the current release.
Biometric lock: If you enable lock, the operating system authenticates you. We do not receive fingerprint, face, or passcode data.
Permissions: microphone (optional dictation), photos (optional profile picture), internet (model download, optional analytics, optional cloud AI, billing, optional Drive backup).
We do not run a JournaI backend that stores journal entries or chat text. There is no JournaI login that uploads your writing to us.
We share data only as described here, when you use the related feature, or as required by law. We do not sell personal information.
| Party | When | What |
|---|---|---|
| Google Firebase Analytics / Google Analytics 4 | If Share usage analytics is on | Usage events (screens, taps, errors). Not journal or chat text. Google Privacy Policy |
| Google Play / Google Payments / RevenueCat | Trial or purchase | Purchase identifiers and subscription status. Not journal text. RevenueCat Privacy Policy |
| OpenRouter, OpenAI, Anthropic, or another AI provider you choose | If you enable cloud companion | Chat messages and the context you send from the device. Journal is not uploaded as a backup. |
| Google Drive / Google APIs | If you enable Drive backup | Encrypted backup file to your Drive |
| Apple or Google speech services | If you allow OS speech when on-device dictation is unavailable | Audio to produce text; JournaI does not store recordings |
| Model-file hosts / CDNs | If you download an on-device model | Download request metadata, not journal text |
For OpenRouter, JournaI requests zero data retention (ZDR) and denies providers that may train on prompts. The provider’s own policy still applies to data they process.
Native builds may send usage events to Firebase Analytics if Settings → More settings → Share usage analytics is enabled. Disable it anytime. Analytics does not include journal bodies, chat text, or API keys.
If you connect your own key, chat in cloud mode is sent from your device to that provider to generate replies. Keys stay in the device keystore. Journal entries remain on device unless you paste them into chat.
On-device recognition is preferred. If it is unavailable, JournaI asks before using the OS speech service, which may send audio over the network. Only the resulting text is saved in your journal.
Purchases use Google Play Billing (via RevenueCat). We do not receive your card number. We store trial/subscription state on device to unlock companion features. Google’s and RevenueCat’s policies apply to payment records.
Not directed to children under 13. We do not knowingly collect personal information from children under 13. Contact 12097darshan@gmail.com if you believe a child has used the App.
We do not store or retain your journal entries, companion chat text, photos, or profile content on our servers. JournaI has no cloud database for your writing. The table below states how long each type of information is kept:
| Data type | Where it is stored | Retention period |
|---|---|---|
| Journal entries, companion chats, settings, profile photo, personality summary | On your device only (App sandbox) | Until you delete entries, reset the App in Settings, or uninstall. We do not keep server-side copies. |
| Journal or chat text on our servers | Not stored by aifor.codes | We do not retain this data. |
| Optional usage analytics (Firebase / Google Analytics 4) | Google, if Share usage analytics is on | Typically up to 14 months per Google Analytics for Firebase default settings, or until you disable analytics. See Google’s data retention documentation. |
| Subscription / trial status | On your device; purchase records at Google Play and RevenueCat | On-device state until reset or uninstall. Google Play and RevenueCat retain billing records per their policies. |
| Cloud AI messages you send | The AI provider you choose (e.g. OpenRouter) | Not retained by us. OpenRouter zero-retention (ZDR) routes request no provider retention; other providers follow their own policies. |
| Google Drive backup you enable | Your Google Drive account | Until you delete the backup file or revoke access. We do not host the file. |
| Voice dictation via OS speech | Apple or Google speech service, if you allow it | Not stored by JournaI. The OS provider’s retention policy applies. |
| On-device AI model files | Your device | Until you delete the model in Settings or uninstall the App. |
To remove on-device data, see section 13. To stop analytics collection, turn off Share usage analytics in Settings. For billing or analytics records held by Google or RevenueCat, email 12097darshan@gmail.com and we will help with requests to those providers where we can.
JournaI does not create a cloud account. To delete App data:
We use HTTPS for network calls, OS keystore for keys, and the App sandbox for journal files. No method is 100% secure. You can add biometric lock in Settings.
If you use Google, Apple, or a cloud AI provider, they may process data in other countries under their terms.
| Goal | How |
|---|---|
| Stop analytics | Settings → More settings → Share usage analytics off |
| Stay fully local | Use on-device companion; do not connect cloud AI |
| Refuse network speech | Decline the prompt; type instead; revoke mic in system Settings |
| Delete App data | Settings reset, or uninstall |
| Revoke Drive | Turn off Drive backup; revoke access in your Google Account |
Companions are not therapists or emergency services. If you are in crisis, contact local emergency services.
We may update this policy. The new version will be posted at https://journai-analytics.web.app/privacy with a new “Last updated” date.
aifor.codes
Email: 12097darshan@gmail.com
This policy is also linked in the App under Settings → Data & privacy → Privacy policy.