Privacy Policy
Last updated: August 12, 2026
Journaled is a tool for keeping a record of your work. You describe what you did, and Journaled turns it into structured entries and written summaries you can keep, search, and export.
This policy explains what we collect, why, who we share it with, and what you can do about it. It is written to be read, not to be survived.
Journaled is operated by Casey Murguia, a sole proprietor based in Utah, United States. You can reach us at contact@journaled.io.
This policy covers:
- journaled.io — our public website, including the demo you can try without an account
- app.journaled.io — the application, which requires an account
1. What we collect
Account information
When you create an account, we collect:
- Your email address. This identifies your account and is how we would contact you.
- Your name, if you provide one or if it comes from your Google account. This is optional.
- A password hash, if you sign up with a password. We never store your actual password — only a one-way bcrypt hash of it, which cannot be reversed back into your password.
- Your Google account information, if you sign in with Google — your email address, name, and basic profile information. See Section 4 for more on this.
- Subscription status, once paid plans are available.
Your work content
This is the substance of the product, and it is the most sensitive thing we hold:
- The text you type into the capture box describing your work.
- The structured entries produced from that text — activity type, description, and optionally a duration, client, or project.
- Session titles you write.
- Summaries and reports generated from your entries, including any edits you make to them.
Your work content is stored so you can return to it. It is yours, and Section 6 explains the only place it goes.
Usage records
We keep timestamped records of when you capture work, generate a report, or save a session. These records contain the type of action and the time — not the content of the action. We use them to enforce plan limits and to protect the service from abuse and runaway costs.
Technical and operational information
Our servers produce operational logs — records of requests, errors, and performance — used to keep the service running and to diagnose problems. Your IP address is visible to our infrastructure providers in the ordinary course of serving a request.
The public demo (no account)
You can try Journaled on our website without signing up. When you do:
- The text you type is not stored. It is sent for processing, the result is returned to you, and nothing is written to our database. Close the tab and it is gone.
- We store a salted, one-way hash of your IP address and a timestamp, so we can enforce the demo’s daily limits. We do not store your raw IP address, and these records are not linked to any account or to the text you typed.
Analytics
We use Vercel Analytics to count page views and understand which pages people visit. It is cookieless and does not build a profile of you, follow you across other websites, or collect personal information.
Cookies
We use one cookie that matters: your session cookie, which keeps you signed in. It holds an encrypted, signed token and expires after 30 days. It is strictly necessary for the app to work — without it there is no way to know you are signed in.
We do not use advertising cookies or third-party tracking cookies.
2. How we use your information
We use what we collect to:
- Run the service — store your work, generate summaries and reports, show you your history, and let you search and export it.
- Authenticate you and keep your account secure.
- Enforce plan limits and protect against abuse, spam, and costs from automated misuse.
- Communicate with you about your account — for example, verifying your email or resetting your password.
- Improve output quality. See Section 3, because this one deserves its own answer.
- Meet legal obligations and enforce our Terms of Service.
We do not sell your personal information. We do not share it with advertisers. We do not use your work content to build a product for anyone else.
3. Whether we read your work
We are going to be direct about this, because a product that holds your work history should not be vague here.
We may review work content in limited circumstances, specifically:
- To diagnose a problem you have reported to us
- To investigate abuse, security incidents, or suspected violations of our Terms
- To evaluate and improve the quality of the summaries Journaled produces — for example, comparing an original generated summary against your edited version to understand where the writing fell short
Access is limited to people who operate Journaled, which today is one person. We do not read your work out of curiosity, and we do not use it to make decisions about you.
Your work content is never used to train AI models — not ours, not anyone else’s. See Section 6.
If you would rather your content were excluded from quality review entirely, email contact@journaled.io and we will honor that.
4. Google sign-in and Google user data
This section describes exactly how Journaled accesses, uses, stores, and shares information received from Google.
What we access. If you sign in with Google, we request only non-sensitive scopes — email, profile, and openid. That gives us your email address, your name, and basic profile information. We do not request access to your Gmail, Drive, Calendar, Photos, contacts, or any other Google service, and we could not read them if we wanted to.
How we use it. Only to create your account, identify you when you sign in, link you to the work you have recorded, and display your email address in the app so you know which account you are in. We do not use it for advertising, profiling, or any purpose beyond authentication.
How we store it. Your email address and name are stored in our database, hosted on Amazon Web Services in the United States, alongside your account record. They are encrypted at rest and transmitted only over TLS. We do not store Google access tokens or refresh tokens after sign-in, and we do not store your Google profile picture.
How we share it. We do not sell, rent, or transfer Google user data to any third party, other than the infrastructure providers in Section 6 that host our database and application on our behalf, and only for that purpose. We never send it to our AI provider — summaries are generated from your work text alone, not your identity.
How long we keep it. For as long as your account exists. Deleting your account deletes it, as described in Section 8.
Journaled’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
A note on Section 3: the limited review described there applies to work content you create in Journaled — the text you type and the summaries produced from it. It does not apply to information received from Google, which no one reads except as needed to operate authentication, investigate abuse, or comply with the law.
You can revoke Journaled’s access to your Google account at any time from your Google Account permissions page. Doing so stops you from signing in with Google; it does not delete your Journaled account or content. To do that, see Section 8.
5. Legal bases for processing (UK and EEA users)
If you are in the United Kingdom or the European Economic Area, we process your information on these bases:
- Performance of a contract — providing the service you signed up for, authenticating you, securing your account, and sending account and service emails.
- Legitimate interests — enforcing limits, preventing abuse, controlling costs, diagnosing problems, and improving output quality.
- Legal obligation — complying with the law.
Where we rely on legitimate interests, we have considered whether those interests are overridden by your rights, and we limit what we do accordingly.
6. Who we share information with
We use a small number of service providers to run Journaled. Each processes information on our instructions and for no purpose of their own.
- Amazon Web Services — database, application servers, secrets, and operational logs. United States (Ohio).
- Vercel — website and application hosting, cookieless analytics. United States.
- Anthropic — AI processing of your work text, described below. United States.
- Google — sign-in, if you choose it. United States.
- Cloudflare — DNS and email routing. United States.
- Stripe — payments, only once paid plans launch. United States.
- Amazon SES — transactional email, only once email launches. United States.
About AI processing
Generating a summary means sending your work text to Anthropic’s API, which is the model provider Journaled uses. This is essential to the product — there is no version of Journaled that writes summaries without it.
Two things matter here:
- Anthropic does not train its models on data submitted through its commercial API by default. Your work is processed to produce your summary and is not used to make their models better.
- We send only what is needed — the text of your capture and the entries being summarized. We do not send your email address, name, or account identifiers.
We may also disclose information if required by law, to enforce our Terms, or to protect the rights and safety of our users or the public. If we are ever compelled to hand over user data, we will tell you unless we are legally prohibited from doing so.
We have never sold personal information and have no plans to. If we are ever part of a merger, acquisition, or sale of assets, we will give notice before your information becomes subject to a different privacy policy, and you will have the opportunity to delete your account first.
7. How long we keep things
- Your account and work content are kept until you delete them. We do not expire your history — keeping it is the point of the product.
- Usage records are kept for a limited period, long enough to enforce rolling plan limits.
- Demo records (hashed IP and timestamp) are kept only as long as needed to enforce the demo’s daily limits.
- Operational logs are kept for a limited period for debugging and security.
- Backups may contain your information for a short period after deletion, because that is how backups work. They are encrypted, and they age out on their own schedule.
8. Your rights and choices
Whatever your location, you can:
- See your data. Everything you have written is visible in the app.
- Correct it. Every entry, title, summary, and report is editable. Journaled is built on the principle that your text is the truth.
- Export it. Journaled includes a built-in export in JSON and CSV. It is free, it is not limited, and it is not a paid feature. Your record should be portable whether or not you keep paying us.
- Delete it. Delete individual sessions and reports at any time from the app. To delete your entire account, email contact@journaled.io from your account’s email address and we will delete it within 30 days. Deleting your account deletes your sessions, entries, reports, and usage records.
If you are in the UK or EEA
You also have the right to object to or restrict processing, the right to data portability, the right to withdraw consent where we rely on it, and the right to lodge a complaint with your local data protection authority. We will not discriminate against you for exercising any of these.
If you are in California
You have the right to know what personal information we collect and why, the right to delete it, the right to correct it, and the right not to be discriminated against for exercising those rights.
We do not sell or share personal information as those terms are defined under the California Consumer Privacy Act, and we do not use or disclose sensitive personal information for purposes that require an opt-out.
To exercise any of these rights, email contact@journaled.io. We may need to verify that you control the account before acting on a request.
9. Where your data lives
Journaled is operated from the United States, and your information is stored on servers in the United States.
If you use Journaled from outside the United States, you are sending your information to the United States, where privacy laws differ from those in your country. Where transfers from the UK or EEA are involved, our providers rely on Standard Contractual Clauses or an equivalent approved transfer mechanism.
10. Security
We take this seriously, and specifically:
- All traffic is encrypted in transit with TLS, and the database is encrypted at rest.
- Passwords are stored only as bcrypt hashes.
- Database access uses short-lived signed credentials rather than a stored password, and the application’s database user has only the permissions it needs.
- Every request is authenticated and every query is scoped to the account that made it.
- Secrets are held in a managed secret store, never in code.
- Per-account rate limits protect the service from abuse.
No service can promise perfect security, and we will not pretend otherwise. If we ever become aware of a breach affecting your information, we will notify you and any regulator we are required to notify, without undue delay.
11. Children
Journaled is a professional tool and is not intended for anyone under 18. We do not knowingly collect information from children. If you believe a child has created an account, email contact@journaled.io and we will delete it.
12. Changes to this policy
We will update this policy when the product changes. When we do, we will change the date at the top. If a change materially affects how we handle your information — for example, a new category of data or a new provider that receives your work content — we will tell you by email or in the app before it takes effect.
13. Contact
Email: contact@journaled.io
If you have a question about anything in here, ask. A privacy policy nobody can get an answer about is just decoration.