How do we use your data?
To securely manage your journal & personalize your experience
Over the course of journaling, you may choose to write about sensitive information like your sexual orientation, religious or philosophical beliefs, education & work history, political opinions, ethnic origin, and/or mental health. Like every entry, this information is securely saved in our database, encrypted at rest with AES-256 and in transit via TLS, is accessible only to you, and is never read by another human.
However, AI-powered algorithms do analyze your entries to help generate personalized follow-up questions and psychological insights for you, as well as convert them into a multi-dimensional vector space to enable semantic search & unlock the ability to ask your journal questions. Don't worry though, machines are incapable of judging you.
If at any time you don't want a particular entry to be analyzed or included in search, you can disable these features with one click. And while we use the highest security available and our infrastructure has never been breached, no solution is 100% guaranteed against data theft: if that keeps you up at night, we'd suggest sticking to pen and paper.
To help improve our app
We use tools like Sentry and PostHog to track usage information like how often you log in, what features you use, and any performance issues you may be encountering. This helps us refine our product features, debug errors, and convince prospective venture capitalists that this is an idea worth investing in. These tools can't read your entries or generated insights, and personally identifiable data isn't shared with anyone outside our (very) small team.
To contact or notify you
We'll send you essential emails about your account, subscription renewals, and policy updates, along with any reminders you set. From time to time, we'll also send marketing emails announcing new features or special offers (but you can always opt out of these by clicking the unsubscribe link at the bottom).
To process your subscription
Like millions of other companies, we use a platform called Stripe to store your payment information and process transactions. If you're like 90% of the U.S. population, you've already used Stripe to process your online payments, and can rest assured your card data is in good hands.
To not bother you with redundant ads & help find new users
As a small business, wasting our limited marketing budget on someone who's already a customer, or isn't likely to become one, hurts. And as a consumer, what's more annoying than getting ads for something you already paid for, or will never pay for?
While we pride ourselves on not installing tracking pixels within our application itself, we do use them on our marketing pages to track the effectiveness of our ads. We also provide ad networks with a list of our customers to exclude from future targeting, and these networks may also use the data they already have from other sources to help us reach similar potential customers (but they don't share any of those specifics with us).
Upon request, we can remove your email from these lists. And if you use a browser or plugin that limits third-party tracking pixels, that's totally okay too. But if you're super serious about privacy, we'd recommend contacting Google or Meta directly to understand the data they already have about you (it's a lot).
How don't we use your data?
To train AI models
Using apps like ChatGPT as a self-therapy tool means your reflections contribute to the ongoing training of their underlying AI models. Our agreements with our AI providers ensure analyzed entries are not saved long-term and never used in training. You can also opt out of AI features for particularly sensitive entries with one click.
To share with, or sell to, third parties
While it'd be much more lucrative to offer our app for free and then sell your anxieties to advertisers, we believe that's a pretty dystopian world that we certainly want no part of. Ad networks, advertisers and data brokers will never know how often you journal, what you journal about, or any inferences into your psychology that are derived from your journal entries.
What are your privacy rights?
Easy data deletion
Every entry has a delete button, which removes this data and related insights from our servers. You can go even further and make us forget everything we know about you and wipe our database clean by contacting us to request deletion. Just note, any deletion of any kind is not recoverable, so ensure you have a local backup.
Data access & portability
Prefer to use a different journaling app down the road? We'll be sad to see you go, but you can export all of your entries at any time in the universally-recognized JSON standard format. While we're working on making this automated and self-service in the future, you can always contact us right now to get this done within fifteen (15) days.
Everyone deserves these rights
We don't believe only residents of certain regions should have privacy rights just because their government got their sh*t together. We extend GDPR & CCPA rights to all of our customers worldwide. However, exercising some of these rights (like restricting data processing) means we can no longer provide you with a working application or any further customer support.
What information do we collect?
What you provide to us
Personal Information
We collect personal information that you voluntarily provide to us when you register for an account, reach out to us, and/or use our application. The personal information we collect depends on the context of your interactions with us and our application, the choices you make, and the features you use. The personal information we collect may include the following:
Names
Email addresses
Usernames
Passwords
Contact preferences
We may also collect other personal information outside of these categories through instances where you interact with us in the context of receiving customer support, participation in customer surveys, or the facilitation in the delivery of our services.
Sensitive Information
Over the course of using our application and journaling about your life, you may be providing us with other sensitive information, or other personal information as defined by the California Consumer Records statute, that reveals:
Your sex life and/or sexual orientation
Your gender and date of birth
Your race or ethnic origin
Your political opinions
Your religious or philosophical beliefs
Your education or professional history
Your mental & physical health
Your voice when using speech-to-text services
Billing Information
When you subscribe to our application, we will collect data necessary to process your payment, such as your credit/debit card number, expiration date, security code, and billing address. All payment data is securely stored by Stripe, Inc. and not by us, however we do store & retain your transaction data to adhere to tax law.
What's automatically collected
We automatically collect certain information when you visit, use, or navigate our application. This information does not reveal your specific identity, but may include identifiers and usage data such as:
Your IP address, country/region, and ISP
Browser, device, and operating system characteristics
Language preferences
Referring URLs
Device name
How & when you use our application
This information is primarily needed to maintain the security & operation of our application, and for our internal analytics and reporting purposes.
Like many businesses, we collect information through the use of cookies and similar technologies. The information we collect includes:
Log and Usage Data: Log and usage data is service-related, diagnostic, usage, and performance information our servers automatically collect when you access or use our application and which we record in log files. Depending on how you interact with us, this log data may include your IP address, device information, browser type, and settings and information about your activity in the application (such as the date/time stamps associated with your usage, pages viewed, and other actions you take such as which features you use), device event information (such as system activity and error reports), and hardware settings.
Device Data: We collect device data such as information about your computer, phone, tablet, or other device you use to access our application. Depending on the device used, this device data may include information such as your IP address or proxy server, device & application identification numbers, location, browser type, hardware model, internet service provider and/or mobile carrier, operating system, and system configuration information.
Location Data: We collect data about your device's location, which is largely imprecise and is based on your IP address for the purposes of "geo-fencing" access to certain countries where we are allowed to operate.
How do we process & retain your information?
We have not sold or shared any personal information to third parties for a business or commercial purpose in the preceding twelve (12) months, nor will we in the future, but we have disclosed identifiers, commercial information, and internet activity to our third-party vendors as necessary to provide services.
We process & disclose your personal information for a variety of reasons, depending on how you interact with our application, including:
To facilitate account creation and authentication, and otherwise manage user accounts. This is so you can create and login to your account, as well as keep your account secure & in working order. We use a vendor called Supabase to manage this data for us.
To deliver, and facilitate the delivery of, application features to you, such as storing your entries (which may include sensitive information) in our database and using AI models to analyze them and convert them into vector embeddings so that we can personalize your experience, generate relevant follow-up questions, enable semantic search, and help you uncover psychological insights. No humans can ever read your entries, and you can disable AI analysis for any entries you may deem particularly sensitive. We currently use a database solution administered by Supabase, and leverage AI models provided by OpenAI and Microsoft (with agreements that your data cannot be retained or used in future training).
To respond to your inquiries & offer support, which helps us solve any potential issues you might have with our application.
To send administrative information to you, such as details about application updates, changes to our terms & policies, and other similar information.
To fulfill and manage your subscription orders, which allows us to process payments and refunds.
To request feedback, where we may contact you about your use of our application to improve it.
To protect our application, we implement fraud monitoring and prevention.
To identify usage trends, so we can better understand how features are being used to improve our application, and undergo cohort analysis that may be shared with prospective investors.
To send you marketing communications, if this is in accordance with your marketing preferences. You can opt out of these emails at any time.
To determine the effectiveness of our marketing campaigns, we track clicks & open rates within our marketing emails.
To save or protect your vital interests, where we may process information to prevent harm.
We retain personal information collected as long as you have an account with us, or manually delete specific journal entries that include personal/sensitive information (however, inferences already drawn from this information such as AI-generated insights may be retained until account deletion).
What legal bases do we rely on to process your information?
We only process your personal information when we believe it is necessary and we have a valid legal reason to do so under applicable law, like with your consent, to comply with laws, to provide you with services to fulfill our contractual obligations, to protect your rights, or to fulfill our legitimate business interests.
For Canadian residents
We may process your information if you have given us specific permission (express consent) to use your personal information for a specific purpose, or in situations where your permission can be inferred (implied consent). You can withdraw your consent at any time.
In some exceptional cases, we may be legally permitted under applicable law to process your information without your consent, including, for example:
If collection is clearly in the interests of an individual and consent cannot be obtained in a timely way
For investigations and fraud detection/prevention
For business transactions provided certain conditions are met
If it is contained in a witness statement and the collection is necessary to assess, process, or settle an insurance claim
If it is reasonable to expect collection and use with consent would compromise the availability or the accuracy of the information and the collection is reasonable for purposes related to investigating a breach of an agreement or a contravention of the laws of Canada or a province
If disclosure is required to comply with a subpoena, warrant, court order, or rules of the court relating to the production of records
For European residents
The GDPR requires us to explain the valid legal bases we rely on in order to process your personal information, which include:
Consent: we may process your information if you have given us permission to use your information for a specific purpose. You can withdraw this consent at any time.
Performance of a Contract: we may process your information when we believe it is necessary to fulfill our contractual obligations to you.
Legitimate Interests: we may process your information when we believe it is reasonably necessary to achieve our legitimate business interests, and those interests do not outweigh your interests and fundamental rights & freedoms. For example, we may send information about special offers, analyze how our application is being used to improve the experience & better retain users, support our marketing activities, diagnose problems, and prevent fraudulent activities.
Legal Obligations: we may process your information where we believe it is necessary for compliance with our legal obligations, such as to cooperate with a law enforcement body or regulatory agency with a warrant, exercise or defend our legal rights, or disclose information as evidence in litigation in which we are involved.
Vital Interests: we may process your information where we believe it is necessary to protect your vital interests or the vital interests of a third party, such as situations involving potential threats to the safety of any person.
When do we share your information, and with whom?
As we are a small company, we share data with third-party vendors, service providers, contractors, or agents ("third parties") who perform services for us or on our behalf and require access to such information to do that work.
We have contracts in place with these third parties, which are designed to help safeguard your personal information. All infrastructure providers we work with are certified SOC2 compliant. This means they cannot do anything with your personal information unless we have instructed them to do it. They will also not share your information with any organization apart from us. They also commit to protect the data they hold on our behalf and to retain it for the period we instruct.
These third parties include:
User account registration, authentication, and database services. We currently use Supabase to manage our secure databases, which is hosted on world-class data infrastructure managed by Amazon Web Services & Google.
Payment processors. We use Stripe to store and process payment information, who is the industry leader in e-commerce transactions. You can read more about their privacy policies at https://stripe.com/privacy
Data analytics and testing tools. We currently use PostHog Cloud to track product usage which helps us track what features are being used and when to improve our application.
Performance and error monitoring. We currently use Sentry to track bugs and reduce performance issues with our application.
Advertising networks. Like many businesses, we share customer emails with Google and Meta to exclude you from seeing future digital advertisements from us. We do not utilize their tracking pixels within our application itself – only on our marketing pages – so these providers do not receive data on how often you journal, what you journal about, or any inferences made based on the content of your journal entries.
In the event of a merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company, we may share some personal information like names & usage patterns in connection to these transactions. We will never share your entries, sensitive data, or insights – all of which remain encrypted.
Do we use cookies or other tracking technologies?
We use internal cookies only to support vital functionality of our app (like keeping you logged in, or remembering your latest dark/light mode preference). We use tracking technologies to monitor our application for performance issues & bugs and track usage patterns, but do not implement advertiser pixels within our application itself (they may be present on our marketing pages to assess the effectiveness of our ads).
Most web browsers are set to accept cookies by default. If you choose to remove or reject cookies, this could impact your ability to log in to the application.
Is your information transferred internationally?
Our servers are located in the United States. If you are accessing our application from outside of the United States, please be aware that your information may be transferred to, stored, and processed in the United States by us and the third parties we contract to manage our data infrastructure, payment processing, and performance monitoring.
If you are a resident of the European Economic Area (EEA), United Kingdom (UK), or Switzerland, then the United States may not necessarily have data protection laws as comprehensive as those in your country. However, we will take all necessary measures to protect your personal information in accordance with this privacy notice and applicable law. We have implemented measures to protect your personal information, including by using the European Commission's Standard Contractual Clauses for transfers of personal information between our group companies and between us and our third-party providers. These clauses require all recipients to protect all personal information that they process originating from the EEA or UK in accordance with European data protection laws and regulations. These can be provided upon request. We have implemented similar appropriate safeguards with our third-party service providers and partners, which can also be provided upon request.
How long do we keep your information?
Only as long as it is necessary for the purposes set out in this privacy notice, unless a longer retention period is required or permitted by law (such as tax, accounting, or other legal requirements). No purpose in this notice will require us keeping your personal information for longer than three (3) months past the termination of your account.
When we have no ongoing legitimate business need to process your personal information, we will either delete or anonymize such information, or, if this is not possible (for example, because your personal information has been stored in backup archives), then we will securely store it and isolate it from any further processing until deletion is possible.
How do we keep your information safe?
We've implemented appropriate and reasonable technical and organizational security measures designed to protect the security of any personal information we process. This includes use of the latest encryption technologies like TLS & AES-256, and only working with providers who have the highest security compliance available in the market today. However, despite our safeguards and efforts to secure your information, no electronic transmission over the Internet or information storage technology can be guaranteed to be 100% secure, so we cannot promise or guarantee that hackers, cybercriminals, or other unauthorized third parties will not be able to defeat our security and improperly collect, access, steal, or modify your information. Although we will do our best to protect your personal information (and we, and our third-party providers, have never experienced such a breach), transmission of personal information to and from our application is at your own risk. You should only access the application within a secure environment (e.g. avoiding public internet networks without the use of a VPN).
Do we collect information from minors?
No, we do not knowingly solicit data or market to children under 18 years of age. By using our application, you represent that you are at least 18 years old. If we learn that personal information from users under 18 years of age has been collected, we will deactivate the account and take reasonable measures to promptly delete such data from our records. If you become aware of any data we may have collected from children under age 18, please contact us.
What are your privacy rights?
For European & Canadian residents
In some regions (like the EEA, UK, Switzerland, and Canada), you have certain rights under applicable data protection laws. These may include the right to request access and obtain a copy of your personal information, to request rectification and erasure, to restrict the processing of your personal information, to move your data off the application, and to not be subject to automated decision-making. You can make such a request by contacting us, and we will consider and act upon any request in accordance with applicable data protection laws.
If you are located in the EEA or UK and you believe we are unlawfully processing your personal information, you have the right to complain to your Member State data protection authority or UK data protection authority. If you are located in Switzerland, you may contact the Federal Data Protection and Information Commissioner.
If we are relying on your consent to process your personal information, which may be express and/or implied depending on the applicable law, you have the right to withdraw your consent at any time by contacting us. However, please note that this will not affect the lawfulness of the processing before its withdrawal, nor when applicable law allows, will it affect the processing of your personal information conducted in reliance on lawful processing grounds other than consent.
You can opt-out of marketing and promotional communications by clicking the unsubscribe link in the emails we send, or by contacting us. You will be removed from marketing lists, but we may still communication with you about application-related messages necessary for the administration & use of your account, to respond to service requests, and for other non-marketing purposes.
If you would at any time to like to review or change the information in your account, or terminate your account, you can log in to your account settings and make the appropriate updates.
For California residents (CCPA Privacy Notice)
The California Code of Regulations defines a "resident" as every individual who is in the State of California for other than a temporary or transitory purpose and every individual who is domiciled in the State of California who is outside the State of California for a temporary or transitory purpose. All other individuals are defined as "non-residents." If this definition of "resident" applies to you, we must adhere to certain rights and obligations regarding your personal information:
California Civil Code Section 1798.83, also known as the "Shine the Light" law permits our users who are California residents to request and obtain from us, once a year and free of charge, information about categories of personal information (if any) we disclosed to third parties for direct marketing purposes and the names and addresses of all third parties with which we shared personal information in the immediately preceding calendar year. If you are a California resident and would like to make such a request, please contact us.
You can ask for the deletion of your personal information. If you ask us to delete your personal information, we will respect your request and delete it, subject to certain exceptions provided by law, such as (but not limited to) our compliance requirements resulting from a legal obligation or any processing that may be required to protect against illegal activities.
Depending on the circumstances, you have a right to know whether we collect and use your personal information, the categories of personal information we collect, the purposes for which the collected personal information is used, whether we sell or share your personal information to third parties, the categories of personal information we sold, shared, or disclosed for a business purpose, the categories of third parties to whom the personal information was sold, shared or disclosed for a business purpose, the business or commercial purpose for collecting, sharing, or selling personal information, and the specific pieces of personal information we collected about you. In accordance with applicable law, we are not obligated to provide or delete consumer information that is de-identified in response to a consumer request or to re-identify individual data to verify a consumer request.
We will not discriminate against you if you exercise your privacy rights.
You have the right to direct us to limit the use of your sensitive personal information to the use which is necessary to perform services (which we already do).
Upon receiving any request, we will need to verify your identity to determine you are the same person about whom we have the information in our system. These verification efforts require us to ask you to provide information so that we can match it with information you have previously provided us. For instance, depending on the type of request you submit, we may ask you to provide certain information so that we can match the information you provide with the information we already have on file, or we may contact you through the email you've provided to us. We may also use other verification methods as the circumstances dictate.
We will only use personal information provided in your request to verify your identity or authority to make this request. To the extent possible, we will avoid requesting additional information from you for the purposes of verification. However, if we cannot verify your identity from the information already maintained by us, we may request that you provide additional information for the purposes of verifying your identity and for security or fraud-prevention purposes. We will delete such additionally provided information as soon as we finish verifying you.
You may object to the processing of your personal information. You may request correction of your personal data if it is incorrect or no longer relevant, or ask to restrict the processing of the information. You can designate an authorized agent to make a request under the CCPA on your behalf, but we may deny a request from an authorized agent that does not submit proof that they have been validly authorized to act on your behalf in accordance with the CCPA. You may request to opt out from future sharing of your personal information to third parties. Upon receiving such a request, we will act upon it as soon as feasibly possible, but no later than fifteen (15) days from the date of submission. We will honor your opt-out preferences if you enact the Global Privacy Control opt-out signal on your browser.
To exercise any of these rights, you can contact us. If you have a complaint about how we handle your data, we would like to hear from you.
For other U.S. residents
Under the Colorado Privacy Act (CPA), Connecticut Data Privacy Act (CTDPA), the Utah Consumer Privacy Act (UCPA), and Virginia Consumer Data Protection Act (VCDPA), certain residents have the legal rights listed below. We extend these rights to all of our customers, despite not being legally required to do so.
Right to be informed whether or not we are processing your personal data
Right to access your personal data
Right to correct inaccuracies in your personal data
Right to request deletion of your personal data
Right to obtain a copy of the personal data you previously shared with us
Right to opt out of the processing of your personal data if it is used for targeted advertising, or profiling in furtherance of decisions that produce legal or similarly significant effects.
To submit a request to exercise these rights, please contact us. Upon receiving any request, we will respond without undue delay, but in all cases, within fifteen (15) days.
For residents of Australia & New Zealand
We collect and process your personal information under the obligations and conditions set by Australia's Privacy Act 1988 and New Zealand's Privacy Act 2020. This privacy notice satisfies the requirements defined in both acts, in particular: what personal information we collect from you, from which sources, for which purposes, and other recipients of your personal information. If you do not wish to provide the personal information necessary to fulfill their applicable purpose, it may affect our ability to provide you with a working application, respond to/help with your requests, manage your account with us, and confirm your identity to protect your account. At any time, you have the right to request access to or correction of your personal information. If you believe we are unlawfully processing your personal information, you have the right to submit a complaint about a breach of the Australian Privacy Principles to the Office of the Australian Information Commissioner and a breach of New Zealand's Privacy Principles to the Office of New Zealand Privacy Commissioner.
For residents of the Republic of South Africa
At any time, you have the right to request access to or correction of your personal information. You can make such a request by contacting us. If you are unsatisfied with the manner in which we address any complaint with regard to our processing of personal information, you can contact the office of the regulator at PAIAComplaints@inforegulator.org.za.
Do we make updates to this notice?
We may update this privacy notice from time to time. The updated version will be indicated by an updated "Revised" date and the updated version will be effective as soon as it is accessible. If we make material changes to this notice, we may notify you either by prominently posting a notice of such changes or by directly sending you a notification. We encourage you to review this page frequently to be informed of how we are protecting your information.
How can you contact us about this notice?
If you have any questions or comments about this notice, or would like to exercise your rights stated above, you may contact our CEO, Sean Finnell, by email via sean@99questions.ai.