JournL

Privacy Policy

Last updated: July 30, 2026

This Privacy Policy explains how JournL ("we," "us," or "our") handles information in connection with the JournL mobile app ("JournL," the "App," or the "Service"). It should be read together with our Terms of Service. JournL is built around a simple principle: your journal stays on your device and in your own private iCloud account — not on our servers.

1. Information We Collect

Sign in with Apple. JournL uses Sign in with Apple for authentication. We do not receive or store your Apple email address. When you first sign in, we store only a one-way SHA-256 hash of Apple's stable account identifier — never the raw identifier — plus your name if Apple shares it with us at that time.

Journal entries and chat content. Your journal entries, chat messages, moods, themes, and on-device search data (sentence embeddings used for semantic search) are created and stored locally on your device using Apple's on-device storage framework. If you have iCloud enabled on your device, this data syncs through your own private iCloud account so it's available across your devices — it does not pass through or get stored on JournL's servers.

On-device AI processing. Chat replies, personalized welcome messages, and journal summaries (including generated titles, moods, and themes) are produced entirely on-device using Apple's Foundation Models framework. Your prompts and journal content used for these features never leave your device and are not sent to us or to any third-party AI provider — JournL does not use OpenRouter or any other external AI/LLM service.

Minimal server-side authentication data. Our servers handle only the Sign in with Apple verification step (to issue and validate an authentication token stored securely in your device's Keychain). Standard technical logs (such as IP address and request timestamps) may be generated for this request for security and reliability purposes.

2. How We Use Information

  • To verify your identity via Sign in with Apple and issue an authentication token for your device;
  • To maintain the security and integrity of the Service and prevent abuse;
  • To comply with legal obligations.

Because your journal content and conversations are processed and stored entirely on-device and in your own iCloud account, we do not use them for advertising, analytics, or any other purpose — we don't have access to them at all.

3. How Information Is Shared

We do not sell your personal information. The only sharing that occurs is:

  • Apple. Sign in with Apple identity tokens are verified directly against Apple's servers. Your iCloud sync, if enabled, is handled entirely by Apple under Apple's own privacy policy — we have no access to your iCloud data.
  • Legal reasons. We may disclose the limited account information described above if required to do so by law, or in a good-faith belief that disclosure is necessary to comply with legal process, protect our rights, or protect the safety of any person.

4. Data Retention

We retain the hashed Apple identifier and associated authentication data for as long as your account remains active. Your journal content is retained on your device and in your private iCloud account for as long as you keep it there — deleting an entry, deleting the App, or managing your iCloud storage removes it, since we hold no separate copy. You may request deletion of your server-side account record at any time by contacting us.

5. Your Rights and Choices

You can view, edit, or delete your journal entries at any time directly within the App. Depending on where you live, you may also have rights to access, correct, or delete the limited account information we hold. If you are a California resident, the California Consumer Privacy Act (CCPA) may give you additional rights over your personal information, including the right to know what we collect and the right to request deletion. We do not sell personal information, so there is nothing to opt out of in that respect.

To request deletion of your server-side account record, contact us at info@journlapp.com.

6. Data Security

Your authentication token is stored securely in your device's Keychain. Your Apple sign-in identifier is stored on our servers only as a one-way cryptographic hash, and requests to our authentication endpoint are encrypted in transit. Your journal content's security in iCloud is governed by Apple's own security practices. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

7. Children's Privacy

The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us so we can delete it.

8. Apple's Role

JournL depends on Apple platform services — Sign in with Apple, the Foundation Models framework, and iCloud — that are governed by Apple's own privacy policy and terms in addition to this policy. We encourage you to review Apple's privacy policy to understand how Apple handles data related to your Apple ID and iCloud account.

9. International Users

Our authentication service is operated from the United States. If you access the Service from outside the United States, the limited account information described above will be transferred to and processed in the United States, which may have different data protection laws than your country of residence. Your journal content itself follows Apple's iCloud data residency practices, not ours.

10. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will update the "Last updated" date above. Your continued use of the Service after changes take effect constitutes acceptance of the revised policy.

11. Contact Us

If you have questions about this Privacy Policy or how we handle your information, please contact us at info@journlapp.com.

© 2026 JournL. All rights reserved. FAQ Terms of Service Privacy Policy