Privacy Policy
Effective August 18, 2026
Smart Journaling is a private voice journaling app. This policy explains what the app stores, what it sends, and what your choices are — and, in its own clearly marked sections near the end, what this website collects when you visit it. It is written in plain language. If something is unclear, email support@smart-journaling.com.
Who we are
Smart Journaling is built and operated by an independent developer, who is the data controller for the purposes of UK and EU data protection law. There is no company behind it and no team — one person, reachable at support@smart-journaling.com. We do not currently have an EU or UK representative; if you are in the EEA or UK and that matters to your request, say so and we will tell you plainly how we’re handling it.
What lives on your iPhone
Everything you journal is stored on your device, inside the app’s protected container using iOS file protection:
- Your voice recordings (audio files)
- Journal transcripts
- Mood and emotion logs
- Tags, echoes, lens reflections, threads, and letters
- Your Personal Wiki — the private map of people, places, and projects you mention
- Personal info you provide during onboarding (name, gender, age range)
Your audio recordings never leave your device. When cloud features are on, some of the items above are sent as text — the next two sections list exactly what and when. With cloud features off, nothing you write leaves this iPhone.
Cloud features (on by default)
Settings → Privacy → Cloud features is the master switch. When it is on, the following are sent over HTTPS to our backend, which forwards them to third-party AI and voice-synthesis providers:
During a reflection
- The transcribed text of what you said in the current session
- A stand-in name in place of your first name (see “Your name” below)
- Mood and emotion labels you select during that session
- Your age range and gender, if you provided them
- Up to three short excerpts from your earlier reflections (“echoes”), for continuity
- Basic session context, such as the time of day and your recent mood
- A pruned excerpt of your Personal Wiki, if that feature is on
At other times
- The full text of an entry, when you tap a Lens on it
- Recent entries, to detect themes you keep returning to
- Candidate sentences from an older entry, to choose your weekly letter
- Your saved echoes and theme summaries, to generate affirmations and session questions
- A pruned excerpt of your Personal Wiki, to keep it tidy and current
- The text your companion speaks, so it can be read aloud
Your audio is never sent. The transcription happens on your iPhone.
Your name. Before anything is sent to the AI provider, your first name is replaced with a randomly chosen stand-in. The mapping back to your real name stays on your device, and replies are shown on your iPhone with your real name restored. Two caveats, in the interest of full honesty: the reply text sent to the voice-synthesis provider does include your first name (or the phonetic respelling you set), so your companion can speak your name naturally; and if you say your name aloud during a reflection, it may appear in the transcribed text that is sent.
We do not store your reflection content on our server beyond the moments needed to generate a reply. The content is not used to train any model, is not sold, and is not shared for advertising.
Turning cloud features off switches the app to on-device mode: reflection runs entirely on your iPhone using Apple’s on-device models (iOS 26+) or a rules-based fallback, and every item listed above stops being sent. One call still happens with the switch off — the app asks our server whether your version is too old to be safe. It carries no journal content, and it is the only way we can tell you to update.
Automated decision-making
Your journal text is read and processed by automated AI systems. They generate replies, titles, tags, mood estimates, affirmations, themes, and the Personal Wiki. Everything they produce may be wrong, and is offered for your reflection rather than as fact or advice. None of it produces legal effects or decisions about you — there is no scoring, profiling for third parties, or automated judgement that affects your rights.
Who processes your data
- Anthropic (United States) — generates AI replies and the text-based features above. Receives what the section above lists; does not receive your real name, email, or any account identifier.
- ElevenLabs (United States) — turns your companion’s replies into speech. Receives the reply text, which includes your first name so it can be spoken.
- Cloudflare (United States) — hosts our backend and stores the technical request records described below. Also hosts this website, stores the waitlist described later in this policy, and runs the bot check on its form.
- Google (United States) — the waitlist emails are sent through our own Google Workspace mailbox, so Google handles those messages in transit. Nothing else on this list touches it.
- TelemetryDeck (Germany) — receives anonymous crash signatures, only if Crash Reports is on.
- Apple — App Attest verifies that requests come from a genuine copy of the app.
Processing takes place in the United States, and in Germany for crash reports. Where personal data is transferred out of the UK or EEA, we rely on the providers’ Standard Contractual Clauses.
Legal bases (UK/EU)
- Performance of a contract — running the app you installed.
- Consent — cloud features, usage analytics, and crash reports. Each has its own switch in Settings, and you can withdraw at any time. Joining the waitlist is also consent: you asked us to email you, and every one of those emails can unsubscribe you in one click.
- Legitimate interests — keeping usage limits fair, preventing abuse (including the bot check and signup throttle on this website), and verifying requests come from a real copy of the app.
Service protection and how long we keep things
To keep usage limits fair and the service healthy, our server keeps anonymous technical records of cloud requests — which feature was used, when, how large the request was, and a random per-install identifier that is not tied to your name or any account. These records never contain journal content.
- Technical request records and anonymous usage events: 30 days, then deleted automatically.
- Daily usage counters: 7 days.
- App Attest device key: kept until you ask us to delete it, or until the app is reinstalled.
- Journal content on our server: none, at any point.
- Website signup-throttle counters (keyed by IP address): 1 hour, then they expire on their own.
- Waitlist entries and
/beta/ invite-link visit records: kept until you ask us to remove them, or until the waitlist is retired after launch.
Anonymous usage analytics (your choice)
When Usage Analytics is on in Settings, the app sends anonymous metadata to help us understand how features are used:
- Entry counts and duration buckets
- Which transcription source was used
- App version and iOS version
- Feature usage (no journal content)
No transcripts, no audio, no personal identifiers. In App Store builds this starts off; in TestFlight builds it starts on, to help us find problems during testing. Either way, you can change it anytime in Settings → Privacy.
Crash reports. When Crash Reports is on (it starts on, and contains no journal content), the app sends an anonymous crash signature — which part of the app crashed and the type of failure, never your words or recordings — to a third-party crash-reporting provider. Turn it off anytime in Settings → Privacy.
Backups
The encrypted backup feature (Settings → Your Data) creates a .sjbackup file on your device, encrypted with a password you choose. We never see the password and we never receive the backup. iCloud Backup (an OS-level feature) may also include the app’s data unless you opt out in iOS Settings.
This website
Everything above describes the app. This section and the four that follow describe smart-journaling.com itself, which collects different things — and, unlike the app, collects nothing at all unless you use the waitlist form, the /beta link, or a personal invite link. Reading the site sets no cookies, loads no analytics, and runs no third-party script.
The waitlist
If you enter your email address in a signup form on this site, we store, in a Cloudflare D1 database:
- The email address itself
- Which form you used, and whether you asked about launch or about a beta slot
- The two-letter country your request came from, as reported by our hosting provider
- The first 300 characters of your browser’s user-agent string (browser and OS, roughly)
- The date and time
- If you arrived through the
/betalink, the identifier of that visit — see below
We do not store your IP address with your signup. It is used twice and then gone: as the key of a signup counter that expires within the hour, and as one input to the bot check below.
We use this to send you one email — the day the app launches, or the moment a beta slot opens — and to understand roughly where interest is coming from. It is never sold, never shared with an advertiser, and never used to build a profile of you. There is no account here and no login; the database has no public read path.
Unsubscribing
Every email we send carries an unsubscribe link that works in one click, with no sign-in and no reply needed. Using it records that your address has opted out, and we keep the address for exactly that reason — so that a later export or signup can see it and skip you. It is a suppression mark, not an accident.
Because a form submission can’t tell us who typed an address, unsubscribing sticks: signing up again won’t undo it. Email support@smart-journaling.com if you’d like to rejoin, or if you’d rather we deleted the row entirely instead of keeping it suppressed.
Bot protection on the form
The signup forms are protected by Cloudflare Turnstile, which tells us whether a submission came from a person rather than a script. Two things worth knowing:
- Its script loads only when you interact with a form — not when you simply read a page.
- When you submit, your IP address is sent to Cloudflare as part of that check. Cloudflare’s own privacy terms govern what it does with that.
It is the one third-party script on this site. If you never touch a form, it never loads.
The /beta link
smart-journaling.com/beta is the door to our TestFlight beta. Visiting it writes one row on our side, before you are forwarded to Apple:
- What happened — forwarded, shown the “beta is full” page, or told it’s iPhone-only
- Any
?src=or UTM tags in the link you followed - The address of the page that linked you, if your browser sent one
- The two-letter country of the request
- A coarse device and major OS version (for example “iphone”, “iOS 18”)
It holds no IP address and no raw user-agent string — the user-agent is reduced to those two coarse fields and the original is discarded. On its own the row identifies nobody.
The one case where it stops being anonymous, stated plainly: if the beta is full and you then join the beta list from that page, we store the visit’s identifier alongside your email address. From that point the visit record — including the link that brought you and the country it came from — is linked to an address that identifies you. It is how we can tell which post found the people who actually signed up. Ask us and we’ll unlink or delete it.
Personal invite links
Someone using the app can share it with a link of the form smart-journaling.com/i/<code>, where the code identifies the person who shared — not you. Following one behaves exactly like /beta: the same destinations, and the same visit record as above, additionally marked as having come through an invite link.
Because the point of these links is to tell the sharer that their invitation worked, we also pass a small, fixed set of details about the visit to our own server: the visit’s identifier, the invite code, the two-letter country, your browser’s preferred language, the iOS version if you’re on an iPhone or iPad, and whether the device runs iOS. Nothing more — no IP address, no full user-agent, and no record of where you found the link. If the app is then installed on a device that plausibly matches those coarse details, the sharer is told that someone joined through their link: a count, never a name, and never anything about you. You are not asked to sign in, confirm, or hand anything over to be counted.
Link previews and crawlers that fetch an invite link are redirected but never recorded, and a link whose code doesn’t validate records nothing at all.
Cookies
This website sets no cookies of its own, and there is no analytics of any kind — no beacon, no pixel, no session tracking. Fonts are served from this site rather than a font CDN. The only third-party code that can run here at all is the bot check described above, and only once you interact with a form; what it stores is governed by Cloudflare’s terms, not ours.
Children
Smart Journaling is for people aged 13 and over. Onboarding asks your age range and will not set up the app for anyone who tells us they are under 13. If you believe a child under 13 has used the app, email us and we will delete anything associated with their device.
Not medical advice
Smart Journaling is a journaling tool. It is not therapy, counseling, or medical care. If you are in crisis, call or text 988 (Suicide & Crisis Lifeline) in the US, or your local emergency number. Settings → About → Get support now lists crisis lines for your region.
Your rights
In the app, at any time:
- Delete any single entry from the entry detail view
- Delete your journal via Settings → Your Data → Delete your journal
- Erase everything — journal, profile, affirmations, settings, and this device’s anonymous ID — via Settings → Your Data → Delete everything
- Export your journal text and details via Settings → Your Data (exports don’t include audio — the encrypted backup does)
- Turn off cloud features, usage analytics, or crash reports
By law, you also have the right to access the data we hold, correct it, have it erased, receive it in a portable form, object to or restrict its processing, withdraw consent, and complain to your data protection authority (in the UK, the ICO; in the EEA, your national authority).
How to exercise them. Email support@smart-journaling.com with the install ID from Settings → Privacy → Install ID — it’s the only thing that identifies your device to us. We’ll respond within 30 days. Because your journal never reaches our server, an access or erasure request covers the technical records listed above; everything else is already in your hands, on your phone.
For anything on this website, write from the address you signed up with, or quote it — that address is the only identifier we hold. We’ll send you what we have and delete it on request; the unsubscribe link at the foot of any of our emails stops the mail immediately, without waiting for us.
California residents. We do not sell or share your personal information, and we never have. We do not offer financial incentives for data, and we will not treat you differently for exercising any right above.
Changes to this policy
We may update this policy as the app changes. The effective date at the top always reflects the current version. If a change materially affects what we collect or how we use it, the app will tell you the next time you open it rather than relying on you to check. Continuing to use the app after that means you accept the updated policy.
Contact
Questions, requests, or corrections: support@smart-journaling.com
© 2026 Smart Journaling. All rights reserved.