Privacy Policy
ZenJournal ("the App", "we", "us", "our") is operated by MISEON PYO, a sole proprietor registered in the Republic of Korea (Business Registration No. 226-04-37766). This Privacy Policy explains how we collect, use, store, and share information when you use ZenJournal on iOS or Android.
By installing or using the App, you agree to the practices described below. If you do not agree, please uninstall the App and stop using our services.
Summary (TL;DR)
- Your journal entries are stored on your device, encrypted with AES-256 (SQLCipher). We never see them in plain text on our servers.
- AI Reflection sends a sliding 7-day window of your entries to our backend so the AI can generate context-aware feedback. The text is processed in memory, not retained beyond the response.
- We collect anonymized usage analytics (Firebase Analytics) and crash reports (Firebase Crashlytics) to fix bugs and improve the App.
- We use Google AdMob to show ads to free users and RevenueCat to manage subscriptions.
- You can export, delete, or back up your data at any time. Deleting the App or your account erases all locally stored data immediately.
- We comply with GDPR (EU/UK), CCPA/CPRA (California), PIPA (Korea), and COPPA (children under 13).
1. Information We Collect
1.1 Information You Provide Directly
| Category | Data | Purpose | Stored Where |
|---|---|---|---|
| Journal content | Text, mood selection (5-level), photo attachments, voice notes | Core app functionality | Encrypted on your device only |
| Onboarding inputs | Goal selection, preferred notification time | Personalization | On your device |
| Backup data (optional) | Encrypted journal archive | Restore on new devices | Google Drive or iCloud (your account, end-to-end encrypted by us before upload) |
| Support correspondence | Email content if you contact us | Reply to your inquiry | Our email inbox |
1.2 Information Collected Automatically
| Category | Examples | Source |
|---|---|---|
| Device identifiers | Advertising ID (GAID/IDFA), Vendor ID (IDFV), Firebase Installation ID | OS-provided |
| Device information | Model, OS version, locale, time zone, screen size | OS-provided |
| Usage events | Screen views, button taps, feature usage frequency, session length | Firebase Analytics SDK |
| Crash & performance data | Stack traces, ANR reports, memory state at crash | Firebase Crashlytics SDK |
| Subscription state | Anonymous user ID, entitlement status, transaction receipts | RevenueCat SDK |
| Push token | FCM registration token (if you grant notification permission) | Firebase Cloud Messaging |
| Approximate location | Country-level only, derived from IP | Firebase Analytics |
We do not collect precise location, contacts, photo library (beyond what you explicitly attach), microphone audio (beyond what you record for voice notes), camera roll, or browsing history.
1.3 Information Sent for AI Reflection
When you tap "Generate AI Reflection":
- The App sends the text of your last 7 days of journal entries (sliding window) to our backend at
api.zen-journal.app. - Our backend forwards the text to Anthropic's Claude API (model: Haiku) under a service agreement that prohibits training on the content.
- The reflection is returned and shown in the App.
- The transmitted text is processed in memory and not stored beyond the response. Server logs retain only metadata (request timestamp, response time, error code) — never journal content.
If you do not want any data leaving your device, simply do not tap the AI Reflection button. All other features (writing, mood tracking, calendar, stats, export) work fully offline.
2. How We Use Your Information
| Data | Purpose | Legal Basis (GDPR) |
|---|---|---|
| Journal content (on device) | Core functionality | Performance of contract |
| AI Reflection text (transient) | Generate personalized feedback you requested | Performance of contract |
| Usage analytics | Improve UX, fix bugs, prioritize features | Legitimate interest (you can opt out — see §7) |
| Crash reports | Diagnose crashes and stability issues | Legitimate interest |
| Advertising ID | Show personalized ads to free users | Consent (opt-in via ATT on iOS) |
| Subscription receipts | Verify entitlement, prevent fraud | Performance of contract |
| FCM push token | Deliver reminders you opted into | Consent |
| Email (support) | Respond to your inquiry | Legitimate interest |
We do not:
- Sell your personal data.
- Use journal content to train AI models, ours or anyone else's.
- Build advertising profiles based on the content of your journal.
- Share journal content with any third party other than as described in §4.
3. Data Retention
| Data | Retention Period |
|---|---|
| Journal entries (on device) | Until you delete them or uninstall the App |
| Backup files (Google Drive / iCloud) | Until you delete them from your cloud account |
| AI Reflection request logs (server) | 30 days for abuse detection, then automatically deleted |
| Firebase Analytics events | 14 months (Google default) |
| Firebase Crashlytics records | 90 days |
| RevenueCat customer records | Lifetime of the subscription + 7 years (tax compliance) |
| Support emails | Up to 3 years after the last reply |
You can request deletion at any time (see §7).
4. Third-Party Service Providers
We share limited data with the following providers solely to operate the App. Each provider is bound by a Data Processing Agreement.
| Service | Purpose | Data Shared | Privacy Policy |
|---|---|---|---|
| Anthropic (Claude API) | AI reflection generation | Last 7 days of journal text (transient) | Link |
| Firebase (Google LLC) | Analytics, Crashlytics, Cloud Messaging | Usage events, crash data, FCM token | Link |
| Google AdMob | Show ads to free users | Advertising ID, device info, IP | Link |
| RevenueCat | Manage subscriptions across iOS/Android | Anonymous user ID, transaction receipts | Link |
| Apple App Store | App distribution, in-app purchases | Apple ID purchase data | Link |
| Google Play Store | App distribution, in-app purchases | Google account purchase data | Link |
| Cloudflare | Backend hosting (api.zen-journal.app) | IP address (transient routing) | Link |
We do not share data with data brokers, advertising networks beyond AdMob, or any other third parties.
5. International Data Transfers
ZenJournal is operated from the Republic of Korea. The third-party services listed in §4 may process data in the United States, the European Union, and other regions. Where applicable:
- Transfers from the EU/UK rely on Standard Contractual Clauses (SCCs) as the lawful transfer mechanism.
- Transfers from California rely on the service provider exception under CPRA.
- Transfers from Korea comply with PIPA Article 28-8 cross-border data transfer requirements.
6. Data Security
- All journal content on your device is encrypted at rest using AES-256 via SQLCipher.
- Backup files uploaded to Google Drive / iCloud are end-to-end encrypted with a key derived from your device. Cloud providers cannot read them.
- All network traffic uses TLS 1.3 (HTTPS).
- The encryption key is stored in iOS Keychain / Android Keystore — protected by hardware-backed secure enclave when available.
- We follow the principle of least privilege: backend services have access only to the minimum data needed for their function.
No system is 100% secure. If you suspect unauthorized access to your account, contact us immediately at the address in §10.
7. Your Rights
Depending on where you live, you may have one or more of the following rights. To exercise any right, email ad1zhxjf20@gmail.com with the subject line "Privacy Request — [your right]".
7.1 Universal Rights (all users)
- Access — Get a copy of the personal data we hold about you.
- Correction — Ask us to fix inaccurate data.
- Deletion — Ask us to delete your data. (For locally stored journal content, simply delete from within the App.)
- Export — Use the in-app Export feature (Settings → Export) to download your journal in TXT, JSON, CSV, or PDF format.
- Opt out of analytics — Settings → Privacy → "Send Anonymous Usage Data" (toggle off).
- Opt out of personalized ads — Settings → Privacy → "Personalized Ads" (toggle off). On iOS, you can also revoke ATT permission in System Settings.
7.2 GDPR Rights (EU/UK Residents)
In addition to §7.1, you have the right to:
- Restrict processing of your data.
- Data portability — receive your data in a machine-readable format.
- Object to processing based on legitimate interest.
- Withdraw consent at any time, where processing is based on consent.
- Lodge a complaint with your local data protection authority.
7.3 CCPA/CPRA Rights (California Residents)
- We do not sell your personal information.
- We do not share personal information for cross-context behavioral advertising outside of AdMob (which you can disable in §7.1).
- You may request the categories of personal information collected in the past 12 months.
- You may designate an authorized agent to make a request on your behalf.
7.4 PIPA Rights (Korean Residents)
You may request 열람·정정·삭제·처리정지 of your personal data. We respond within 10 days. Contact our Privacy Officer at the address in §10.
8. Children's Privacy
ZenJournal is not directed to children under 13 (or under 16 in the EU/UK, where applicable). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it within 30 days.
9. Changes to This Privacy Policy
We may update this Policy from time to time. When we do:
- We will revise the Last Updated date at the top.
- For material changes, we will notify you in the App at least 30 days before the change takes effect.
- Continued use of the App after the effective date constitutes acceptance of the revised Policy.
10. Contact Information
| Operator | MISEON PYO (sole proprietor) |
| Business Reg. No. | 226-04-37766 |
| Address | 105dong 704ho, 424 Gobong-ro, Ilsandong-gu, Goyang-si, Gyeonggi-do, 10336, South Korea |
| Privacy Officer | MISEON PYO |
| ad1zhxjf20@gmail.com | |
| Response Time | Within 10 business days |
If you are not satisfied with our response, you may contact your local data protection authority:
- EU/UK: European Data Protection Board
- California: California Attorney General — Privacy
- Korea (PIPC): 개인정보보호위원회 (privacy@korea.kr)