Back to about

Privacy Policy

We take your privacy seriously. This policy explains what data we collect, how we use it, and how we keep it safe.

What we collect

When you create a free account, we ask for:

  • • Your first name
  • • Your email address
  • • Your journal entries (which we store securely but never access or read)

We don't collect: your surname, phone number, location, organisation name unless you choose to add it, job title, or any other personal information.

Why we collect it

  • Email address — so you can sign in, and so we can contact you if there's a security issue with your account
  • First name — so your journal feels personal to you (you'll see your name at the top of the page)
  • Journal content — to store and protect your private reflections. You own your writing. We never read it, analyse it, or use it for any purpose except to give it back to you when you ask.

Where we store it and how long

Your account and journal are stored on Supabase, a database service that keeps data secure. Your data is encrypted in transit (HTTPS) and backed up automatically.

How long? We keep your account and journal as long as your account exists. If you delete your account, all your data is permanently deleted within 7 days.

Your journal is genuinely private

Your journal entries are protected by row-level security (RLS) on our database. This means:

  • ✓ Only you can read, write, or delete your entries — even if someone had direct database access, they couldn't see them
  • ✓ Admins cannot read your journal
  • ✓ Your journal is never analysed for performance, learning, or any other purpose
  • ✓ Your journal is never shared with your employer, team, or anyone else unless you choose to share it yourself

What we don't do with your data

  • ✗ We don't sell your data
  • ✗ We don't use your data to advertise to you or anyone else
  • ✗ We don't use your data to train AI or machine learning models
  • ✗ We don't use your data for performance monitoring or metrics of your work
  • ✗ We don't share your data with third parties (except Supabase, which stores it safely)
  • ✗ We don't use your data for any purpose other than keeping your account and journal safe

How we keep it safe

  • • All data in transit is encrypted (HTTPS)
  • • Passwords are hashed and never stored in plain text
  • • Supabase uses industry-standard encryption and security practices
  • • Row-level security means your data is isolated from other users' data at the database level

Your rights

You have the right to:

  • • Access all your data (export your journal) — coming soon
  • • Delete your account and all your data at any time
  • • Ask us what data we hold about you

To exercise these rights, email becky.ledwith72@gmail.com.

Changes to this policy

If we change this policy, we'll update this page and notify you by email. The last update was June 2026.

Questions about how we use your data? Get in touch: becky.ledwith72@gmail.com