This text is a draft. It will be replaced with the final wording after professional review, before launch.

Privacy Policy

Last updated 2026-09-26 · About 11 min read

This policy separates what we hold from what we do not. Once saved, your diary text is stored in a form we cannot read.

1. What we hold

Account data: your email address, the identifier of the Google account you sign in with, the country you declared, your language setting, and when you confirmed you are 18 or over.

Usage data: plan type and status, trial start date, notification settings, and the number of AI operations used (never their content).

Encrypted diary data: text, photos, audio, threads, interview answers, monthly recaps, and visited places are held in the encrypted form produced on your device. We do not hold the keys.

Waitlist: the email address, language, and country you gave us before launch.

2. What we do not hold

The keys that decrypt your diary (recovery key, passphrase).

Location data embedded in photos (EXIF). It is removed on your device before upload. We never collect or store GPS or other location data.

Estimates or scores of your mood or condition. The Service does none of this.

Results of safety checks. If content suggesting self-harm is detected, the Service does not produce an AI draft and shows support contacts instead, but the fact of detection and the content are not stored, counted, or logged.

3. AI processing

To draft, recap, extract threads, suggest chapters, translate, or read aloud, only the content needed for that operation is sent over an encrypted connection to Google Cloud Vertex AI. It is not stored afterward and is never used for training.

The first time you use an AI draft we explain this and record the time of your consent. What is sent is shown at the entrance of each feature, every time.

4. Purposes

Providing and improving the Service, sign-in and account management, payment processing, notifications and email (with your consent), support, preventing abuse, and meeting legal obligations.

We do not use your data for advertising, sell it to third parties, or use it to train AI.

5. Processors and international transfers

We use the following processors, each bound by contract to handle data in line with this policy.

Google LLC (United States): AI processing (Vertex AI) and sign-in (Google account).

Supabase, Inc. (United States; data region set to Japan or the United States): authentication, storage and sync of encrypted data.

Vercel Inc. (United States): hosting and delivery of the website and app.

Paddle.com Market Limited (United Kingdom): sale of paid plans and payment processing.

Email delivery provider (to be decided; name and country will be added here): sending notification emails.

These processors are located in the United States or the United Kingdom. We confirm through contracts and their certifications (such as SOC 2 and ISO 27001) that they apply safeguards equivalent to those required by Japanese law.

6. Notifications and email

Push notifications and emails never contain diary, thread, or interview content. They carry only generic wording such as "Write today's minute?".

Email notifications are opt-in, and every email includes an unsubscribe link.

7. Retention and deletion

We keep your data while your account is active. After you delete your account and the 30-day undo period passes, all data is erased from our servers. Including backups, erasure completes within 45 days at most.

Waitlist email addresses are deleted after we send the launch announcement, or two years after signup, whichever comes first.

8. Your rights

You can export your data anytime from Settings, and you can ask us to correct, delete, or stop using it. Contact us at the address below.

Rights under U.S. state laws (access, deletion, correction, opting out of sale or sharing, and others) can be exercised through the same contact. We do not sell or share personal information.

9. Security

Diary content is encrypted on your device (XChaCha20-Poly1305, with keys derived using Argon2id) before it is stored or sent. Servers store only encrypted data, and the database is protected by row-level access control.

Diary content and AI inputs and outputs are never written to server logs, error monitoring, or analytics.

10. Changes and contact

If we change this policy, we will notify you of material changes in advance in the app and by email.

Contact: support@example.com (operated by (TBD: business name))

Back to top