Privacy Policy
Last updated: July 6, 2026
journalbot is a personal journaling app built to keep your journal on your device. This policy explains the limited data that leaves your device when you choose to use optional server features or anonymous beta usage analytics, and how we handle it.
The short version
- Your journal entries — text, audio recordings, photos, and videos — are stored on your iPhone by default. If you turn on iCloud sync or iCloud Backup, Apple may store that data in your private iCloud account. We never receive it, except the one case described in “Server transcription” below.
- You can use the entire app without an account. An account (Sign in with Apple) is only needed for optional server features.
- Sharing an entry with friends is optional and moves through Apple's iCloud sharing between you and the people you invite — we never receive shared content either.
- Anonymous beta usage analytics are off unless you choose to share them.
- Your journal is yours: export it, or delete it — and any account — entirely, at any time.
Data that stays on your device (we never receive it)
- Journal entries: transcripts, summaries, audio recordings, photos, and videos.
- If you choose Link to Photos library for media attachments, journalbot stores a reference to the item in your Photos library instead of making its own copy. The original remains in Photos/iCloud Photos, and journalbot does not delete it when you remove the attachment from an entry.
- Tags, people and places, moods, reminders, and your comments on entries (including comment photos).
- Your optional profile name and photo. They leave your device only as part of comments on entries shared with friends, so participants can see who wrote a comment.
- Content you import from Apple's Journaling Suggestions picker — photos, workouts (including their GPS route when you pick one), places, and songs. Only items you explicitly pick in Apple's picker are imported; we never query your health data, location, or listening history ourselves. Imported content becomes part of your on-device journal like anything else.
- The interest profile used to suggest relevant offers — it is generated and stored only on your iPhone.
If you turn on Sync to my iCloud, the app stores your journal data in your private CloudKit database so it can sync across your devices. Apple hosts that private iCloud data; journalbot does not receive it. Your normal iCloud device backup may also include the app's local journal files; you can manage device backups in iOS Settings.
When you import a song suggestion and allow Apple Music access, the song's title and artist are sent to Apple Music's catalog — an Apple service — to build a tappable song card. That lookup is governed by Apple's privacy policy and never touches our server. If you decline, songs import as plain text.
Manual backup files can include media files, or export only your journal data plus Photos-library link metadata. Link metadata records which Photos items were attached to your entries — it is not a copy of your photos or videos and not a public link. Linked attachments work through the Photos library on the iPhone where they were attached; they are not available on other devices and stop working if the original item is deleted from Photos.
Sharing entries with friends (optional)
You can share individual entries with people you invite, using Apple's iCloud sharing (CloudKit). What is shared is exactly what you choose in the share screen: the entry text (minus any sentences you hold back), and optionally the summary, mood, tags, media, original recording, your comments, and a workout route. Shared content moves through Apple's iCloud between you and your invitees — our server never receives it.
Invited participants can read the shared entry, comment (comments are visible to everyone in the share and carry the commenter's profile name and photo), and keep a copy in their own journal. A copy someone keeps belongs to them: it survives you stopping the share, and their edits stay on their device. A shared entry cannot be edited after sharing — to change what's shared, stop sharing and share again. You can stop sharing at any time, and Delete all data also deletes every share you created.
Data we receive only when you use optional server features or analytics
1. Account (Sign in with Apple)
When you choose to connect an account, Apple provides us with:
- A stable, anonymous identifier for your Apple ID (Apple's “user identifier”).
- Your email address — only if you choose to share it. You may use Apple's “Hide My Email” to share a private relay address instead.
We also receive your device model, OS version, and app version. We use this to create and recognize your account so server features work. We do not receive your name or your Apple ID password.
2. Server transcription (optional)
On-device transcription is the default, and nothing leaves your phone. If you turn on Server transcription, your audio recording is sent over an encrypted connection to our server, transcribed, and then the audio is deleted immediately. We do not keep your recording. The transcript is returned to your phone and held only briefly (about an hour) to deliver it, then removed. For each transcription we keep non-identifying metadata — recording length, transcript length, time taken, your account identifier, and your device/app version — to operate and improve the service.
3. Feedback (optional)
Feedback requires Sign in with Apple. If you send feedback, we receive the message you write, along with your device model, OS version, app version, and account identifier, so we can read it and follow up. If you choose to include diagnostic logs with a bug report, we also receive recent sanitized technical/app-action events. These logs do not include journal text, transcripts, summaries, audio, photos, videos, tag names, theme prompts, search text, entry IDs, account IDs, or media IDs.
4. Telegram migration (optional)
If you migrate from the journalbot Telegram bot, we send a one-time code to retrieve your previous entries from our server back to your phone.
5. Anonymous beta usage analytics (optional)
If you choose to share beta usage data, we receive aggregate feature-use counts, app version, OS major version, and device family, together with one random, anonymous install identifier so we can tell how many people use a feature rather than only how often. We also receive a snapshot of your non-content settings — your theme and which optional features are on (for example whether iCloud sync or biometric lock is enabled, and whether you have set a profile name or photo, but never the name itself) — so we can see how the app is actually configured. That identifier is generated on your device, is never tied to your account or Apple ID, is deleted when you turn analytics off (re-enabling creates a new one), and disappears if you delete the app. We do not receive journal text, audio, photos, videos, tag names, theme prompts, entry IDs, or account IDs. This is used only to understand which app features are used and where the beta needs improvement. You can turn it off any time in Settings.
How your data is protected
All data sent to our server travels over an encrypted (HTTPS/TLS) connection. Your account token is stored in the iOS Keychain. We do not share your data with third parties for their own purposes.
Retention and deletion
- Audio sent for server transcription is deleted immediately after transcription.
- Your account and the limited server-side data tied to it (transcription metadata, feedback) are kept until you delete your account.
- You can delete your account and its server-side data at any time in Settings → Delete account & data. Deleting the app removes the on-device journal but does not delete your server account — use Delete account for that.
- Signing in again with the same Apple ID reconnects you to the same account.
Children
journalbot is not directed to children under 13.
Changes
We may update this policy. The “Last updated” date above reflects the latest version.
Contact
Questions or requests: support@journalbot.app