Legal
Privacy Policy
Your journal can contain some of your most personal and sensitive information. Protecting it—and being honest about how it is handled—are core values of Active Journal. This policy explains our safeguards and limits, the optional tools that send content elsewhere, and the controls available to you.
- Effective
- September 16, 2026
- Version
- 2026-09-16.2
1. Scope, operator, and contact
mywalnut, Inc., a Delaware corporation, operates Active Journal and controls the personal information described in this policy. This policy applies to the Active Journal website, private beta, account, journal, exploration, research, dictation, feedback, and support features.
Privacy questions and requests can be sent to privacy@activejournal.app. Do not email journal text or account credentials. We may need to verify that a request comes from the account holder before acting on it.
We limit operational access, keep journal text out of advertising and operational telemetry, and disclose when an optional feature sends content to another provider. No online service can eliminate every risk, and cloud journal content is not end-to-end encrypted. The security and access measures described below explain the care we take and the limits users should understand.
2. Information we handle
- Account and authentication
- Email address, account identifier, sign-in and session information, password verifier, and optional multifactor-authentication records. If you choose Google sign-in, Google and our authentication provider supply a stable Google account identifier, email, and basic profile claims. Active Journal does not request Google Drive, Docs, Calendar, or journal access.
- Journal and related content
- Entry titles, text and formatting; selected excerpts; exploration notes and discussions; Insights and Pursuits items; research questions, summaries, source links, and citations; and transcripts you choose to insert. Cloud content is stored in ordinary application database fields protected by account access controls. It is not end-to-end encrypted or a zero-knowledge service.
- Plan and billing information
- We store your plan, trial dates, complimentary grants and their history, and subscription identifiers, status, and billing-period dates. Stripe handles payment details and billing contact information you enter at checkout. We do not store card numbers or send journal writing, titles, AI conversations, or reminder content to Stripe. Your account identifier connects your billing account to Active Journal. Stripe processes payment information under its Privacy Policy.
- Optional journaling reminders
- If you set a reminder, we store its verified email or phone number, schedule, time zone, consent, delivery status, two-week practice end, and content-free setup or notification dismissal times. An optional onboarding goal stays in your account and is not included in messages. Resend delivers email; when enabled, Sendblue delivers texts. These providers receive the destination and a generic reminder or verification message, never journal writing. Reply STOP to stop texts; email reminders include an unsubscribe link. Other text replies are discarded by Active Journal after checking for the account-bound verification message or STOP/START, though the provider may retain them. Verification records expire from our database after one day and delivery records after 30 days. Verified destinations and your goal remain until account deletion; minimal hashed opt-out records remain to honor delivery restrictions. Provider retention is separate.
- Community submissions
- If you explicitly submit a reflection to Community, Active Journal stores the exact reviewed excerpt, its review/publication status, timestamps, and an internal connection to your account. Reviewers receive the excerpt without your identity or journal provenance. If featured, other members see the excerpt anonymously. Your words may still identify you. Private Resonate and journal-start actions are stored with your account for one-person/one-count behavior, while members see only aggregate totals and their own action state.
- Beta, feedback, and support
- A beta request includes an email address and request timing/count. Request receipts and invitations add content-free delivery status. Membership records include invitation and access status. Signed-in feedback includes your account identifier, message, and submission time. Feedback can contain anything you type, so avoid pasting journal text unless you want us to review it. A message sent to our privacy address includes the sender, delivery headers, subject, and content and remains in the monitored mailbox until deleted; no fixed automatic mailbox expiry has been established.
- Reliability, security, and request metadata
- Content-free save counts, timing bands, conflict/recovery counts, safe failure categories, provider/model name, token counts, request status, random request references, usage-limit flags, temporary account allowances, and administrative security events. These usage controls use account identity, tool/provider names, counts, limits, retry timing, and timestamps—not journal content. Hosting and authentication providers also process ordinary technical information such as IP address, request path, browser or device headers, timestamps, and status codes. The beta request and authentication forms use bot verification, which evaluates ordinary network, browser, site, and interaction signals without receiving journal content.
Active Journal has no current advertising system or product-analytics SDK. A historical marketing-events table exists in the database, but we found no current application code writing to it. We do not place journal titles or text in analytics or URLs.
3. How we use information
We use information to:
- create, authenticate, and secure accounts;
- provide saving, syncing, recovery, export, deletion, and beta access;
- run an optional AI, research, or dictation action you request;
- respond to feedback, support, privacy, and security requests;
- measure content-free reliability, prevent abuse, and investigate incidents;
- maintain and improve the Service without using private journal content for advertising; and
- comply with law and enforce the Terms of Service.
4. Service providers and disclosure
We disclose information only to provide the Service, follow your direction, protect users or the Service, complete a corporate transaction subject to appropriate safeguards, or comply with law. Current providers include:
- Supabase for authentication, current authentication email, database hosting, and scheduled database jobs;
- Vercel for site hosting, server routes, and runtime infrastructure;
- Resend for beta, authentication, reminder verification, and optional journaling reminder email;
- Sendblue, when text reminders are enabled, for phone verification, generic reminders, replies, and delivery metadata;
- Cloudflare for domain and DNS administration and bot verification on beta request and authentication forms;
- Google for optional Google sign-in and Google Workspace email sent to our public privacy and security addresses;
- Anthropic only for optional AI and research actions described below; and
- Deepgram only when you start live dictation.
This provider list describes the audited Service as of the effective date. We will update it when a provider is added or its role materially changes. Providers may process information in the United States and in other places where they or their subprocessors operate, subject to applicable contractual and legal safeguards.
As of this policy's effective date, we do not sell personal information, and the audited Service has no flow for sharing personal information for cross-context behavioral advertising or targeted advertising. Before activating advertising or cross-site tracking that materially changes these practices, we will complete a privacy review, update this policy, and provide any consent or opt-out the law requires.
5. Optional AI, research, and dictation
You can use the core journal without AI. Writing, saving, editing, organizing, exporting, and deleting journal content do not send it to an AI provider. AI and AI-assisted research features are optional and identified in the product. Active Journal sends content to Anthropic only after you choose one of those features, accept the in-product disclosure, and deliberately send or approve a request. You can continue using the journal without accepting or using those features.
AI conversations
After you accept the in-product disclosure and deliberately send a request, Active Journal may send Anthropic the current message, recent conversation, selected passage, exploration note, and, only when you enable it, more of the source entry. A normal conversation turn may send substantially the same context once for safety classification and again to generate the response. Saved exploration discussions remain in your Active Journal account; an unfinished browser-local AI-assisted reflection conversation remains in your browser until cleared as described below.
Journal deeper
If you choose to find ideas from your writing, Active Journal sends Anthropic the titles and text of up to eight recent saved journal entries. It saves the resulting private summaries and links to their source entries in your account. Visiting Home or writing a new entry does not send journal content to Anthropic; you choose when to update the suggestions.
Research
If you ask AI to propose a search query, the selected passage, exploration note, and optional direction are sent to Anthropic to draft that proposal. Web research occurs only after you review and approve a query. The approved query and requested source categories are then sent to Anthropic's web-search tool, where Anthropic and relevant search or destination sites may process them. Active Journal saves the resulting report, citations, source links, and request metadata in your account.
Provider retention and training
Anthropic states that commercial API inputs and outputs are not used to train its models by default unless the customer opts in, provides feedback, or has another agreement. Anthropic says standard API inputs and outputs are normally deleted within 30 days, but it describes longer retention for matters such as usage-policy enforcement, legal requirements, or different service or contract settings. Active Journal has not verified Zero Data Retention and cannot delete an individual API request from Anthropic on demand.
Live dictation
Dictation begins only after you use the microphone control and grant browser permission. Vercel exchanges a server credential for a short-lived browser token, then audio streams directly from your browser to Deepgram. Active Journal does not intentionally store the audio. It inserts the transcript into the writing surface, where the ordinary storage rules apply. Requests set Deepgram's model-improvement opt-out parameter; Deepgram says opted-out data is excluded from its model-improvement program and retained only as necessary to process the request. Recording stops when you stop it or after 10 minutes.
6. Browser storage and tracking choices
Active Journal uses browser storage needed to keep you signed in, remember product state, and protect work from data loss. Supabase session tokens persist in local storage by default. Unsaved journal, exploration, Insight, and Pursuits recovery copies are stored as AES-GCM encrypted envelopes in local storage using a non-exportable key in IndexedDB. Drafts are eligible for pruning after seven days and conflict copies after 30 days, but pruning occurs when the app next reads or cleans that storage—not at a guaranteed moment. The device recovery key may remain after sign-out until site data is cleared.
An unfinished browser-local AI-assisted reflection session—including its draft, messages, and result—is stored as an AES-GCM encrypted recovery envelope in local storage using the same non-exportable browser key. It is eligible for pruning after seven days, but pruning occurs when the app next reads or cleans that storage—not at a guaranteed moment. It clears sooner when you begin writing from the result, sign out and account-scoped data is cleaned up, delete the account, or clear site data. Anyone or any software with access to an unlocked browser profile may be able to access browser-local data.
Active Journal does not currently use advertising cookies or cross-site advertising trackers. Because we do not currently sell or share personal information for targeted advertising, browser "Do Not Track" signals and legally recognized opt-out preference signals do not change the Service's current data flow. If we later introduce advertising or cross-site tracking that materially changes these practices, we will update this policy before activation and honor consent, opt-out, and preference signals as required by law. You can use browser controls to clear local storage and cookies, but doing so may sign you out or remove recovery copies.
Plan records and complimentary-access history remain while your account exists and are included in structured export. Account deletion removes these application records and closes the Stripe customer account. Stripe may retain transaction records under its own retention obligations. Deleting only journal data does not cancel subscriptions or delete plan records.
7. Retention, export, and deletion
Active Journal records generally remain while your account is active and until you delete them. Journal entries in Trash can be restored or permanently deleted during a 30-day window. Soft-deleted explorations, Insights, and saved sources are scheduled for deletion after 30 days, but the product does not currently provide the same restore controls for them. Soft-deleted Pursuits items are permanently deleted after 30 days. Any connected Insights remain saved without that relationship. Deleting an entry does not automatically delete a separate exploration and excerpt you intentionally preserved from it.
A Community excerpt remains while it is awaiting review, approved, or featured. You can withdraw it at any time, which removes the submitted copy and any Community publication. A declined excerpt is also deleted. Withdrawal cannot remove an exact, read-only source copy that another journaler already chose to retain with a private journal entry. Content-free moderation audit events may retain the administrator ID, action, timestamp, and former submission identifier for up to 90 days.
Feedback and untouched beta requests ordinarily remain until account deletion or an applicable privacy request. Save-reliability batch receipts are deleted after 8 days, save-reliability aggregates after 31 days, content-free provider-request metadata after 30 days, usage-limit metadata after 30 days, and historical marketing-event metadata after 90 days. Historical landing-page signup email records are not part of that schedule and have no fixed automatic expiry; they may be deleted in response to an applicable privacy request or a separately approved lifecycle. General admin security events are also scheduled for deletion after 90 days. These application schedules do not control provider backups, platform logs, provider-held optional-tool data, or monitored mailbox messages, which follow their separately described rules.
After a warning and recent-sign-in check, the account tools can download a structured JSON export with broad journal, account, product, and browser-recovery data, or open a formatted journal-focused reading copy that your browser can save as PDF. The formatted copy omits technical account, security, and browser-recovery records. The structured export includes recovery copies that the current browser can open, but it does not necessarily include every item held in provider backups or platform logs, every security or administrative record relevant to a verified privacy request, or data stored only on another device. Both copies are assembled on your device and are not encrypted by Active Journal.
Account deletion removes the authentication user and associated active-service rows handled by our application. Deletion may not be immediate in provider backups, platform logs, security records required by law, or information already processed by an optional provider. Those copies age out under provider and legal rules. We do not state a fixed backup period because the exact hosted plan and settings can change.
8. Security and limited operational access
We use measures including encrypted network transport, owner-scoped database rules, recent-authentication checks for account deletion, optional multifactor authentication, restricted administrative access, content-free operational telemetry, and environment separation.
No online service can guarantee security. Cloud journal content is not end-to-end encrypted, so authorized provider personnel and narrowly authorized Active Journal operators may be technically capable of access when necessary for support, security, legal compliance, or service operation. The owner's ordinary administrative dashboards are designed not to display journal titles, writing, recovery text, or excerpts.
9. Your choices and privacy requests
- Edit, move to Trash, restore, or permanently delete supported records.
- Export saved journal and related product records.
- Choose whether to use Google sign-in, AI, research, full-entry context, or dictation.
- Stop microphone access through the control or browser permissions.
- Sign out on your current device or clear Active Journal site data using your browser settings.
- Delete the account after a recent sign-in and email confirmation.
Depending on where you live, you may have rights to know, access, correct, delete, or receive a copy of personal information, and to appeal a denied request. Send a request to privacy@activejournal.app. We will verify and respond as applicable law requires. Authorized agents must provide evidence of authority, and we may still verify the request with the account holder. We will not discriminate against you for making a privacy request.
10. United States service and children
Active Journal is offered only to people who reside in the United States outside Washington and use the Service only while physically outside Washington. It is not directed to anyone under 18, and we do not knowingly allow children to create accounts. If you believe a person under 18 has provided information, contact us so we can investigate and delete it where appropriate.
Journal content may include information that state law treats as sensitive, including health-related information. Additional state notices or consent may apply before the Service is offered in a jurisdiction with special requirements for that information.
11. Changes to this policy
We may update this policy when the Service, providers, or legal requirements change. We will update the effective date and version above. For a material change, we will provide proportionate notice in the Service or by another reasonable method before it takes effect. We will not silently turn private journal content into advertising data or use it for a materially different purpose without appropriate notice and any consent the law requires.
Questions or requests may be sent to mywalnut, Inc. at privacy@activejournal.app.