Privacy Policy
Last Updated: October 30, 2024
At One Thought Journal, your privacy is our highest priority. This Privacy Policy explains how we handle your data when you use our iOS application.
Our Privacy Commitment
We do not collect, store, or have access to your journal entries. Your thoughts, voice recordings, and personal reflections remain entirely private and under your control.
Data Storage
Local Storage
All journal entries are stored locally on your iOS device using CoreData. This data never leaves your device unless you explicitly choose to:
- Enable optional iCloud sync
- Export your journal for backup or sharing
iCloud Sync (Optional)
If you enable iCloud sync, your journal entries are:
- Encrypted and stored in your personal iCloud account
- Only accessible by you through your Apple ID
- Subject to Apple's iCloud Terms and Conditions and Privacy Policy
- Never accessible by One Thought Journal or any third party
You can disable iCloud sync at any time in the app settings.
Voice Recording and Transcription
Audio Recordings
When you record a voice entry:
- Audio is temporarily stored on your device during transcription
- Audio files are automatically deleted after transcription completes
- We do not retain or have access to your audio recordings
AI Transcription (Google Gemini API)
Your voice recordings are processed through Google's Gemini API for high-quality transcription:
- Audio sent to Google - Your voice recording is sent to Google's Gemini API for transcription
- Immediately discarded - According to Google's API terms, audio is processed and immediately discarded
- Subject to Google's Privacy Policy - Review Google's Privacy Policy
Fallback Transcription
If AI transcription is unavailable, the app automatically uses Apple's on-device speech recognition:
- Processing happens entirely on your device
- No data is sent to external servers
- Subject to Apple's iOS Speech Recognition Privacy Policy
AI Insights Feature
When you use the AI Insights feature to ask questions about your journal:
- Your journal entries are sent to Google Gemini API for analysis
- Google processes your request and returns insights
- Data is processed according to Google's API terms and immediately discarded
- We do not store or retain these queries or responses
Biometric Authentication
If you enable Face ID or Touch ID:
- Biometric data is processed entirely by iOS
- We do not have access to your biometric information
- Authentication is handled by Apple's Secure Enclave
Information We Do NOT Collect
We want to be crystal clear about what we don't collect:
- No account creation or login credentials
- No email addresses or contact information
- No usage analytics or tracking
- No advertising identifiers
- No location data
- No device identifiers for tracking
- No crash reports (unless you opt in via iOS settings)
- No journal content or metadata
Third-Party Services
The app may interact with the following third-party services only when you explicitly choose to use them:
Google Gemini API
Apple iCloud (Optional)
Data Exports and Sharing
You have complete control over your data:
- Export anytime - Export your journal as text, markdown, or JSON
- Share as you choose - Use iOS share sheet to save, email, or print
- Permanent deletion - Delete individual entries or your entire journal
- No retention - We never see or store exported data
Data Retention
- Journal entries are retained on your device until you delete them
- If iCloud sync is enabled, entries are retained in iCloud until deleted
- Deleted entries are permanently removed and cannot be recovered
- We do not have backups of your data—you control retention entirely
Children's Privacy
Our app does not knowingly collect information from children under 13. Since we don't collect any personal information or require accounts, the app can be used by all ages under parental supervision.
Your Rights
You have the right to:
- Access your data - All your data is accessible within the app
- Export your data - Export at any time in multiple formats
- Delete your data - Delete entries or your entire journal
- Opt out of third-party services - Use on-device transcription and disable iCloud sync
Security
We take security seriously:
- All data stored using iOS secure storage (CoreData)
- Optional Face ID/Touch ID protection
- iCloud data encrypted in transit and at rest
- No central servers that could be breached
- All sensitive data encrypted at rest
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by:
- Updating the "Last Updated" date at the top of this policy
- Posting the new Privacy Policy on this page
- In-app notification for material changes (if applicable)
Open Source and Transparency
We believe in transparency. If you have technical questions about how we handle data, you can review our code or contact us for clarification.
Contact Us
If you have any questions about this Privacy Policy or how we handle your data, please contact us:
Summary
In simple terms: Your journal is yours. We can't read it, we don't store it, and we don't want it. Everything stays on your device (or your iCloud if you choose). The only time your data touches the internet is when AI transcription processes your voice recordings through Google's API—and even then, we never see it, and Google immediately discards it.
This privacy policy is designed to comply with Apple App Store requirements, GDPR, CCPA, and general privacy best practices.