Dear Thoughts
Join waitlist

Legal

Privacy Policy

Last updated: July 14, 2026

This Privacy Policy explains how Dear Thoughts ("we", "us", "our") collects, uses, and protects your information when you use our mobile application and website.

We have written this in plain language wherever possible. If anything here is unclear, email us at privacy@dearthoughts.com.

1. What we collect

1.1 Account information

When you create an account, we collect your email address for authentication, and any display name you choose to set. We do not collect your phone number, address, or government ID. We also store a small set of account-state flags on our servers (for example, whether you have completed onboarding) so a reinstall or a second device picks up where you left off.

1.2 Journal content

When you turn on end-to-end encryption (Privacy Center → set up encryption), the text of your journal entries is encrypted on your device (AES-256-GCM) before it is transmitted to our servers. We cannot read those entries. Our staff cannot read them. Database administrators cannot read them.

Some journal data is not sealed with your passphrase, because the app needs it to work across features and devices: entry titles, mood selections, tags, and Foundation check-in answers. This data is protected in transit (TLS), encrypted at rest, and locked to your account by row-level access controls — but unlike encrypted entry text, it is technically readable by our infrastructure.

The key that encrypts your journal is itself protected by your passphrase. We store only this wrapped (encrypted) key on our servers, so that signing in on a new device and entering your passphrase unlocks your journal there. The wrapped key is useless without your passphrase — and your passphrase never leaves your device.

When you set up encryption, the app shows you a one-time recovery key. It is the only way to regain access if you forget your passphrase. If you lose both your passphrase and your recovery key, we cannot decrypt your entries — by design. You can change your passphrase at any time without re-encrypting your journal; your existing recovery key remains valid.

1.3 Voice notes and photos

Voice recordings and photo attachments are uploaded to private, access-controlled storage tied to your account so they can sync between your devices. They are protected in transit and at rest, but they are not sealed with your encryption passphrase.

Voice transcription is a cloud feature. When you save a voice note, the app automatically requests a transcript: our server retrieves the recording and passes it to OpenAI (the Whisper speech-to-text API) for processing. The resulting transcript is stored alongside the recording. Under OpenAI’s API terms, audio sent this way is not used to train their models. Transcription is capped per user per day. Voice journaling is entirely optional — if you would rather nothing you say leave your device, simply write instead.

1.4 Usage data

We collect minimal, anonymised usage signals to keep the app working:

  • App version, device platform (iOS or Android), preferred language
  • Crash reports and error logs, sanitised before sending — journal content is never included, and personal identifiers are stripped
  • Anonymous feature usage counts (e.g. "user opened Foundation 4 times this week") — never the content of what you wrote

Usage analytics are optional. You can turn them off at any time in the app under Profile → Usage analytics. When the toggle is off, no product analytics events are sent. Sanitised crash reports remain on, because they carry no behavioural data and are needed to keep the app reliable.

1.5 AI features

When an AI feature runs, the specific journal text it needs is sent through our server to Anthropic for processing, then discarded. It is not stored on our servers beyond the duration of the request, and is never used to train any AI model. Requests are capped per user per day.

Two kinds of AI features exist, and they behave differently:

  • Reflections you invoke — Ask your journal (up to 20 matching entries per question), the weekly letter, the future-self letter, the mood archetype, the compassion rewrite, and the body signal. These send text only when you open or request them.
  • Writing assistance — continue-writing suggestions and title suggestions. While AI assistance is switched on, these send the entry you are currently composing to the gateway automatically as you pause, so a suggestion can be ready.

AI assistance is on by default and has a single off switch (Profile → AI assist). When it is off, no journal text is sent to any AI provider — suggestions stay silent and reflection features fall back to summaries composed locally on your device.

2. How we use your data

  • To provide and operate the app (sync entries, send notifications you enabled)
  • To improve reliability (crash reports, anonymised diagnostics)
  • To respond to your support requests
  • To comply with legal obligations where applicable

3. What we do NOT do

  • We do not sell your data to anyone. Ever.
  • We do not use your journal entries to train AI models.
  • We do not show you ads.
  • We do not share your journal content with third parties, except as needed to run the service: storage and sync via Supabase, AI processing via Anthropic, and voice transcription via OpenAI — each described in this policy.

4. Third-party services

We use a small set of trusted providers to run the service:

  • Supabase — encrypted database hosting and authentication. supabase.com/privacy
  • Anthropic — AI processing for the AI features described in section 1.5 (can be switched off entirely). anthropic.com/privacy
  • OpenAI — speech-to-text (Whisper) for voice-note transcription, described in section 1.3. openai.com/policies/privacy-policy
  • Expo — push notification delivery (if you enabled notifications). expo.dev/privacy
  • PostHog — anonymised product analytics (optional; can be turned off in the app) and sanitised crash reporting (entry text never included). posthog.com/privacy
  • Vercel — hosting for this website, with cookie-less, aggregate page analytics (website only, never the app). vercel.com/legal/privacy-policy

5. Data retention

Your journal entries are retained until you delete them or delete your account. When you delete your account, we permanently remove all your data from our servers within 30 days, and from backup archives within 90 days.

6. Your rights

Under GDPR (if you are in the EU/EEA/UK) and similar laws elsewhere, you have the right to:

  • Access — request a copy of all data we hold about you
  • Export — download your journal as a typeset keepsake PDF book from the app, or request a full copy of your data by emailing us
  • Correction — update or correct any inaccurate information
  • Deletion — delete your account and all associated data
  • Portability — take your data with you in a standard format
  • Object — to certain processing activities

To exercise any of these rights, email privacy@dearthoughts.com. We respond within 30 days.

7. Children

Dear Thoughts is not directed at children under 13 (or 16 in the EU). We do not knowingly collect data from children. If you believe a child has created an account, contact us and we will remove the account.

8. Security

We use end-to-end encryption for journal entry text (AES-256-GCM, with a passphrase-protected key and a one-time recovery key), TLS for all data in transit, biometric locks for app access, and a hold-to-confirm panic wipe that removes all data from your device. The app lock asks for Face ID or your device passcode when you return after genuinely leaving the app, and a visual cover hides your words in the system app switcher in the meantime. The panic wipe is local: it clears the device you are holding, while data on our servers is removed by deleting your account. No system is perfectly secure, but we have designed for the threat model of a personal journal.

9. International transfers

Our infrastructure is hosted in the European Union (Supabase EU region). When AI features or voice transcription are used, the relevant text or audio may transit (over TLS) to Anthropic's or OpenAI's infrastructure in the United States, processed under Standard Contractual Clauses.

10. Changes to this policy

We will notify you via the app and email of any material changes at least 30 days before they take effect. Your continued use after the change indicates acceptance.

11. Contact

Privacy questions: privacy@dearthoughts.com
General support: support@dearthoughts.com

Data controller: Dear Thoughts, Romania.