Privacy Policy
Last updated August 26, 2026
A journal is one of the most private things a person can keep. This policy explains what we collect, how we use it, and the choices you have. For a shorter, friendlier version, see the Privacy Pledge in your Settings.
1. What we collect
- Account info: your email address (and basic profile info if you sign in with Google).
- Journal content you create: entries, photos, tags, and mood ratings.
- Optional integrations you turn on yourself — location, calendar, music, app usage, and similar — each one opt-in individually. Nothing here is collected unless you explicitly enable it.
2. How we use it
- To provide the core app — saving, organizing, and showing you your own entries.
- To power AI features (drafting, insights, the feelings chat) only when you choose to use them.
- We never use your journal content to train AI models — ours or anyone else's.
3. Who we share it with
We don't sell, rent, or share your journal data with advertisers or data brokers — there's nothing to monetize here except your own subscription. We do use a small number of service providers to run the app:
- Supabase — our database and authentication provider, which stores your account and journal data (encrypted).
- Anthropic — our AI provider, which processes an entry only in the moment you use an AI feature, and does not use that data to train its models.
- Vercel — hosts the app itself.
4. AI provider safety systems
Separately from our own no-monitoring policy: when an entry is processed by AI (for drafting, insights, or the feelings chat), that request passes through our AI provider's own systems, which maintain independent safety mechanisms for a narrow category of content they're legally required to detect and report — such as child sexual abuse material. This isn't something we control or see ourselves; it's a safeguard built into the underlying AI infrastructure, separate from our own no-monitoring policy.
5. Where your data lives
Our servers are located in the United States. If you're using Ayyami from outside the US — including the EU or UK — your data will be transferred to and processed in the US, under the safeguards described in this policy.
6. Your rights
- Export your data anytime from Settings.
- Delete your account anytime — you'll have 30 days to change your mind and log back in before it's permanently erased.
- If you're in the EU, UK, or a similar jurisdiction, you have rights to access, correct, or delete your data, and to object to certain processing. Contact us to exercise these rights.
7. When the law requires it
Like every company, we're required to comply with valid legal process — a subpoena, warrant, or court order from law enforcement. If we receive one that's legally valid, we're obligated to comply, and no privacy promise, ours or anyone else's, can override that. We'll disclose only what's specifically and legally required, nothing more, and we'll push back on anything that looks overbroad.
8. Security
Your journal entries are encrypted before they're ever stored. Every connection to Ayyami is encrypted (HTTPS). There's no "browse user entries" tool — we never read your journal ourselves.
9. Children's privacy
Ayyami is not directed at children under 13, and we don't knowingly collect data from anyone under that age. If you believe a child has created an account, contact us and we'll remove it.
10. Changes to this policy
We may update this policy as the app evolves. If we make a material change, we'll let you know before it takes effect.
11. Contact
Questions about this policy, or want to exercise any of the rights above? Reach us at hello@ayyami.app.