Best Journal App
Privacy Policy
Best Journal App ("we," "us," "our," "the App," "the Service") is operated as a personal journaling and AI-powered self-insight product. This Privacy Policy explains what data we collect, why we collect it, how we use it, how we protect it, and what rights you have over it.
Last Updated: August 29, 2026
Agreement
By creating an account or using Best Journal App in any way, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree, do not use the Service.
1. Who We Are
Best Journal App is a chat-first journaling application that allows users to submit text, images, and other content ("Entries"), which the Service processes using artificial intelligence to categorize, tag, summarize, and generate insights over time.
Contact for all privacy matters: bestjournalapp@gmail.com
2. What Data We Collect
We collect the following categories of data:
2.1 Account Data
- Name, email address, and profile information provided during signup
- Authentication data processed through our authentication provider (Clerk), including login method (email, Google, or other supported providers)
- Account status, subscription tier, and billing status
2.2 Content You Provide ("Entry Data")
- Journal entries you type or dictate
- Images or files you upload
- Any text, metadata, or context you submit through the chat interface
- Voice notes or audio, if and when that feature is enabled
2.3 AI-Derived Data
- Tags, categories, moods, topics, and patterns generated automatically by our AI systems based on your Entry Data
- Vector embeddings (mathematical representations of your entries) generated to enable search and pattern recognition
- Summaries, insights, and any other derivative analysis generated from your Entry Data
2.4 Payment Data
Subscription plan, billing cycle, and transaction history. Payment processing itself is handled entirely by our third-party payment processor, Dodo Payments. We do not store your raw card numbers, CVV, or full payment credentials on our servers.
2.5 Technical & Usage Data
- IP address, device type, browser type, operating system
- Log data: timestamps, pages visited, features used, crash reports, error logs
- Cookies and similar tracking technologies (see Section 8)
2.6 Data We Do Not Intentionally Collect
We do not knowingly collect government ID numbers, biometric data, or precise geolocation unless you voluntarily include such information within your journal entries. If you choose to write such information into your entries, you do so at your own discretion and it is treated the same as any other Entry Data described in this policy.
3. How We Use Your Data
We use collected data strictly for the following purposes:
- To provide the core Service - storing, retrieving, and displaying your entries back to you.
- To generate AI insights - processing your entries through automated systems (including local embedding models and third-party AI inference providers) to detect tags, moods, patterns, habits, and generate responses to your questions about your own data.
- To operate and improve the Service - debugging, performance monitoring, feature development, and quality assurance.
- To process payments and manage subscriptions via Dodo Payments.
- To communicate with you - service updates, security alerts, billing notices, and (only with your consent, where legally required) product updates or marketing.
- To enforce our Terms of Service and protect against fraud, abuse, or security threats.
- To comply with legal obligations, including responding to lawful requests from courts, regulators, or law enforcement.
We do not sell your personal data or journal content to third parties. We do not use your journal content to train third-party foundation models unless a specific AI processing vendor's terms are disclosed to you separately and you are given the ability to opt out where feasible.
4. AI Processing & Third-Party Sub-Processors
Your Entry Data may be transmitted to and processed by third-party AI infrastructure providers for the purpose of generating tags, summaries, embeddings, and conversational responses. These providers process data strictly as service providers under their own data processing and security terms, and are contractually and technically restricted from using your content for purposes other than providing the requested processing to us.
By using the Service, you expressly consent to this processing as a necessary part of how the Service functions. If you are not comfortable with your journal content being processed by automated AI systems, including third-party AI infrastructure, you should not use this Service.
We currently rely on the following categories of sub-processors, which may change over time:
- Authentication provider (Clerk)
- Payment processor (Dodo Payments)
- Cloud hosting and database infrastructure providers
- AI inference and embedding providers
We will make reasonable efforts to keep this list current but do not guarantee real-time disclosure of every infrastructure change, provided such changes do not materially reduce the protections described in this Policy.
5. Legal Basis for Processing (Where Applicable)
Where privacy laws such as the GDPR or India's Digital Personal Data Protection Act apply to you, our legal bases for processing your data include:
- Consent - for optional features, marketing communications, and AI processing of your entries, granted at signup and revocable at any time.
- Contractual necessity - to provide the Service you signed up for.
- Legitimate interest - for security, fraud prevention, and Service improvement.
- Legal obligation - where required to comply with applicable law.
6. Data Storage and Security
We take reasonable and industry-standard measures to protect your data, including:
- Encryption of data in transit (TLS/HTTPS)
- Access controls restricting internal access to production data to authorized personnel only
- Regular security review of our infrastructure and dependencies
- Isolated storage of authentication credentials via our third-party authentication provider (we do not store raw passwords)
However, no method of electronic storage or transmission is 100% secure. Despite our reasonable efforts, we cannot guarantee absolute security of your data, and you acknowledge and accept this inherent risk by using the Service.
6.1 Limitation on Liability for Data Incidents
To the maximum extent permitted by applicable law:
- We are not liable for unauthorized access, data loss, or data breach resulting from circumstances outside our reasonable control, including but not limited to: third-party infrastructure failures, sophisticated cyberattacks, zero-day vulnerabilities, or acts of third parties.
- We are not liable for data loss, unauthorized access, or damages resulting from your own actions, including but not limited to: weak or reused passwords, failure to secure your device, sharing your account credentials, falling victim to phishing, or using the Service on compromised or public devices.
- In the event of a data incident, our sole obligations are to (a) take reasonable steps to contain and investigate the incident, and (b) notify affected users and/or relevant authorities where required by applicable law, within the timeframe required by such law.
- Our aggregate liability for any data incident, to the extent liability is found despite the above, is limited as set out in our Terms of Service.
We encourage you to use a strong, unique password and enable any additional security features made available through our authentication provider.
7. Data Retention
- We retain your Account Data and Entry Data for as long as your account remains active.
- If you delete your account, we will delete or anonymize your personal data and Entry Data within a commercially reasonable period, generally within 30 days, except where we are required to retain certain data for longer periods to comply with legal, tax, accounting, dispute-resolution, or security obligations (for example, billing records).
- Backup copies of data may persist in encrypted backups for a limited additional period before being purged as part of routine backup rotation.
- Derived, fully anonymized, and aggregated data (data that can no longer be linked back to you) may be retained indefinitely for product analytics and improvement purposes.
8. Cookies and Tracking
We use cookies and similar technologies to:
- Keep you logged in
- Remember preferences
- Understand aggregate usage patterns to improve the Service
You can control cookies through your browser settings. Disabling essential cookies may prevent core features of the Service (such as staying logged in) from working correctly.
9. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access - request a copy of the personal data we hold about you.
- Correction - request correction of inaccurate data.
- Deletion - request deletion of your account and associated data ("right to be forgotten"), subject to Section 7 above.
- Export/Portability - request your Entry Data in a portable format.
- Withdraw consent - for optional processing (such as marketing), at any time.
- Object or restrict - object to certain types of processing, where applicable law grants this right.
How to Exercise These Rights
Email bestjournalapp@gmail.com with the subject line "Privacy Request" and specify which right you are exercising. We will verify your identity before processing the request and will respond within the timeframe required by applicable law (generally within 30 days).
Account & Data Deletion: You may request full deletion of your account and all associated Entry Data, tags, embeddings, and derived insights at any time by emailing us or using the in-app deletion option, where available. Deletion is generally irreversible. We are not responsible for data you fail to export prior to requesting deletion.
10. Children's Privacy
The Service is not directed at, and not intended for, individuals under the age of 16 (or the applicable minimum age of digital consent in your jurisdiction, if higher). We do not knowingly collect personal data from children. If we become aware that we have collected data from a child in violation of this policy, we will delete it promptly. If you believe a child has provided us data, contact us immediately at bestjournalapp@gmail.com.
11. International Data Transfers
Your data may be transferred to, stored, and processed in countries other than your own, including countries that may have different data protection laws. By using the Service, you consent to such transfers. We take reasonable steps to ensure adequate protection for such transfers consistent with applicable law.
12. Third-Party Links and Services
The Service may reference or link to third-party services (such as our authentication and payment providers). This Privacy Policy does not cover the privacy practices of those third parties. We encourage you to review their respective privacy policies.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. We will update the "Last Updated" date at the top of this page. Material changes will be communicated via email or in-app notice where required by law. Continued use of the Service after changes take effect constitutes your acceptance of the revised policy.
14. Disclaimer Regarding Sensitive Content
Best Journal App is a self-reflection tool, not a medical, psychiatric, or therapeutic service. Any patterns, moods, or insights generated by the AI are automated outputs based on statistical and language processing methods, and are not professional advice of any kind. Do not rely on the Service as a substitute for professional mental health support. If you are in crisis, please contact a licensed professional or emergency services in your area.
15. Contact Us
For any questions, concerns, or requests regarding this Privacy Policy or your data:
Email: bestjournalapp@gmail.com
By signing up for or using Best Journal App, you acknowledge that you have read and understood this Privacy Policy in full and consent to the collection, processing, storage, and use of your data as described herein.
Back to home