Content you provide: journal entries, mood logs, messages to our assistant (only for providing the Service).
Usage & device data: activity within the app, device/browser information, IP address, timestamps, cookies.
Billing data: payment method and transaction details are processed by our payment processor (Stripe). We do not store full card numbers.
3) Purposes and Legal Bases (GDPR)
Purpose
Examples
Legal basis
Provide and maintain the Service
Authentication, saving entries, subscriptions
Contract (Art. 6(1)(b) GDPR)
Payments and invoicing
Checkout, receipts, fraud prevention
Contract; Legitimate interests; Legal obligation
Support and communications
Emails, notices about your account
Contract; Legitimate interests; Consent where required
Improve the Service
Analytics, debugging
Legitimate interests; Consent where required
Legal compliance
Tax, accounting, responding to lawful requests
Legal obligation
4) Data Sharing
Processors: trusted vendors who process data on our behalf (e.g., cloud hosting, analytics, payment processing such as Stripe).
Legal: where required by law or to protect rights, safety, and security.
Business transfers: in connection with a merger, acquisition, or asset sale, with appropriate safeguards.
5) International Transfers
Your data may be processed outside your country, including in Canada and the United States. Where required, we use appropriate safeguards (e.g., Standard Contractual Clauses) to protect your data.
6) Data Retention
Account and journal data: retained while your account is active. You can delete entries or your account at any time.
Billing records: retained as required by law (e.g., tax and accounting).
Backups and logs: retained for limited periods for security and continuity.
7) Your Rights (GDPR)
Access, rectification, erasure (“right to be forgotten”).
Restriction and objection to processing.
Data portability.
Withdraw consent at any time (where processing is based on consent).
Lodge a complaint with your local supervisory authority.
8) Children’s Privacy
The Service is not intended for children under 18. We do not knowingly collect personal data from children under 18.
9) Security
We use administrative, technical, and organizational measures designed to protect personal data (e.g., transport-layer encryption, access controls). However, no method of transmission or storage is 100% secure.
10) Cookies and Similar Technologies
We may use cookies and similar technologies to operate and improve the Service. Where required, we will request your consent.