Legal
This policy covers the Private Health Journal app and this website. It says what is collected, where it is kept, who can read it and how you delete it — category by category, matching the answers we file in the App Store and Google Play privacy forms.
Effective date: [TODO: effective date pending] · Publisher and data controller: [TODO: legal entity pending], [TODO: registered address pending] · Contact: [TODO: contact email pending]
The controller for the processing described here is [TODO: legal entity pending], [TODO: registered address pending]. Privacy questions and data-subject requests go to [TODO: contact email pending].
No publishing entity has been registered yet, so the fields above are placeholders. They must be completed, and this document reviewed by counsel, before the app is submitted to either store.
Private Health Journal is not a medical device. It does not diagnose, treat, cure or prevent any medical condition, and it makes no clinical recommendation. It is a private journal and an organiser, offered for informational and educational purposes.
That regulatory status changes nothing about how we handle your data. What you write in your health journal is health data, and health data is special-category personal data under Article 9 of the GDPR and under Ukrainian data-protection law. Being a non-regulated wellness app does not downgrade that classification, and we do not treat it as if it did.
So everything below — explicit consent, storage on your own device by default, encryption in transit and at rest, a deletion route you can walk without asking us — is the standard that classification demands, not a marketing flourish.
Your account email address and user ID. These are always collected, because the app needs an account to sign you in. They are linked to your identity, and they run the account, the sign-in, and the record of who granted whom access to something shared.
Health data — but only for a journal profile you have switched to cloud sync. Sync is off by default and is turned on for one profile at a time, as a separate step you consent to explicitly. A profile you never sync stays on your device and is not collected.
We collect no diagnostics and no crash reports: the app ships no analytics or crash-reporting SDK. We do not track you across other apps or websites, we use nothing for advertising, and we sell nothing to data brokers.
A blanket “we collect nothing” would be untrue, and we will not print it. Your email address and user ID are collected the moment you have an account.
Your entries are kept on your device, in storage backed by the iOS Keychain and the Android Keystore. Files such as a photograph of an insurance card are held inside the app's own sandbox, encrypted with AES-256-GCM under a key kept in that same secure storage.
The app's data directories are excluded from device backups and from Android device-to-device transfer, and Keychain items are marked device-only. Your journal is therefore not copied into an iCloud or Android backup, and nothing from it is written to iCloud in any form.
The trade-off is deliberate, and you should know it: because backups do not carry your journal, a new phone does not bring it back by itself. Cloud sync, or an export you made in time, is what carries a journal forward.
Sync sends that profile's entries over HTTPS to our own backend. They do not go to iCloud, to Google Drive or to Firebase — earlier drafts of our store material said otherwise and were wrong.
On the server each synced payload is stored as a single AES-256-GCM encrypted blob. Today the server holds the key to that blob, which means we can technically read it. That is exactly why we declare synced health data as collected in both stores' privacy forms rather than claiming otherwise.
You can turn sync off, and you can keep any profile local-only. A local-only profile never reaches our servers at all.
The app uses the device camera only for on-device text recognition (OCR). Photographs of documents, results and prescriptions are processed locally in the memory of your phone, are not transmitted to any third-party server, are not collected by the developer, and are discarded as soon as the text has been read.
Only the text or the number you confirm is saved into your journal. Images are never uploaded — including the card photos the app keeps for you, which stay encrypted on the device.
Text recognition can misread a printed page. Check what it read against the paper in front of you before you save it.
What you choose to share is sealed on your device before it leaves: an X25519 key agreement, HKDF key derivation, then AES-256-GCM encryption. Our relay carries the ciphertext only and cannot read it. A share expires by itself — ten minutes by default, one hour at the most.
Because that traffic is end-to-end encrypted and unreadable by us, it is not declared as collection under Google's end-to-end-encryption carve-out.
The app makes no third-party requests while it runs. Fonts are bundled into the app rather than fetched from a font service. There is no advertising network, no analytics provider and no data broker in the app or on this site.
If you sign in with Apple or with Google, that provider acts as your identity provider for the sign-in itself; we receive the account identifiers needed to create and recognise your account, and nothing beyond them.
Processing health data in the cloud rests on your explicit consent, given in the app before anything is synced and versioned so we can show which text you agreed to. You withdraw it by turning cloud sync off for that profile.
Reading your own journal, exporting a portable copy of it and deleting your account are free on every plan and never require you to contact support. Emergency information and crisis contacts are never behind a plan or a sign-in prompt.
You may also ask us to correct data, to restrict or object to processing, and to complain to the supervisory authority with jurisdiction over [TODO: legal entity pending].
Deleting your account takes effect immediately: every session is revoked, push tokens are revoked, plan entitlements are switched off, and the account can no longer be used to sign in.
A scheduled job then hard-deletes the account after a retention window of 30 days, and the database cascade takes every profile and every entry with it. That step is irreversible. The window exists so support can undo an accidental deletion; local law may require a longer one for some categories of data.
Audit-log entries survive that purge without any health data in them and with the acting user anonymised. A security log that any request can erase is not a security log.
The step-by-step route, in the app and here on the web, is on our account deletion page.
One account can hold several journal profiles, including profiles for members of your family. The account holder creates and controls them, and is responsible for having the right to keep those entries.
Some sections of the app open only after an adult age check. The minimum age for holding an account is one of the questions still with counsel.
If this policy changes we update the effective date at the top of the page, and where the change is material we say so in the app before it takes effect.