Privacy Policy
We take your privacy seriously. This policy explains what data we collect, how we use it, and how we keep it safe.
What we collect
When you create a free account, we ask for:
- • Your first name
- • Your email address
- • Your journal entries (which we store securely but never access or read)
We don't collect: your surname, phone number, location, organisation name unless you choose to add it, job title, or any other personal information.
Why we collect it
- Email address — so you can sign in, and so we can contact you if there's a security issue with your account
- First name — so your journal feels personal to you (you'll see your name at the top of the page)
- Journal content — to store and protect your private reflections. You own your writing. We never read it, analyse it, or use it for any purpose except to give it back to you when you ask.
Where we store it and how long
Your account and journal are stored on Supabase, a database service that keeps data secure. Your data is encrypted in transit (HTTPS) and backed up automatically.
How long? We keep your account and journal as long as your account exists. If you delete your account, all your data is permanently deleted within 7 days.
Your journal is genuinely private
Your journal entries are protected by row-level security (RLS) on our database. This means:
- ✓ Only you can read, write, or delete your entries — even if someone had direct database access, they couldn't see them
- ✓ Admins cannot read your journal
- ✓ Your journal is never analysed for performance, learning, or any other purpose
- ✓ Your journal is never shared with your employer, team, or anyone else unless you choose to share it yourself
What we don't do with your data
- ✗ We don't sell your data
- ✗ We don't use your data to advertise to you or anyone else
- ✗ We don't use your data to train AI or machine learning models
- ✗ We don't use your data for performance monitoring or metrics of your work
- ✗ We don't share your data with third parties (except Supabase, which stores it safely)
- ✗ We don't use your data for any purpose other than keeping your account and journal safe
How we keep it safe
- • All data in transit is encrypted (HTTPS)
- • Passwords are hashed and never stored in plain text
- • Supabase uses industry-standard encryption and security practices
- • Row-level security means your data is isolated from other users' data at the database level
Your rights
You have the right to:
- • Access all your data (export your journal) — coming soon
- • Delete your account and all your data at any time
- • Ask us what data we hold about you
To exercise these rights, email becky.ledwith72@gmail.com.
Changes to this policy
If we change this policy, we'll update this page and notify you by email. The last update was June 2026.
Questions about how we use your data? Get in touch: becky.ledwith72@gmail.com