Privacy Policy

Last Updated: October 9, 2026 • Global Privacy Protections

Our Privacy Promise

Your thoughts, images, and voice memos are yours. Euthy Journal is local-first: the persistent journal database is stored on your device. Premium users can optionally create a backup in their personal Google Drive or iCloud account. When you choose a connected AI feature, including an available free text sample, the specific text or images needed for that request are transmitted for processing; Euthy does not add them to its Firestore quota database, while Google Cloud or OpenAI may temporarily retain request data under its service terms. Section 6 explains what is sent and when.

Cookie-Free Website: Our website does not use tracking cookies, analytics scripts, or advertising beacons. Brand fonts and artwork are served directly from euthylabs.com rather than a third-party font service.

1. Data Storage & Cloud Backups

Your journal entries, photos, drawings, voice notes, routines, tags, mood data, and saved health snapshots are stored privately on your device. To protect against data loss, the app offers optional cloud backups. If enabled, a copy of your data is stored securely within your personal Apple iCloud (iOS) or Google Drive (Android) account. Euthy Journal utilizes restricted, app-specific storage; it can only access the files it creates and has no permission to view, read, or modify any other content in your personal cloud storage. We do not operate our own central database and cannot access, read, or share any of this content.

Euthy Journal's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

2. Automated Backups

Automated backups periodically create a ZIP archive of your journal and upload it to your personal iCloud Drive or Google Drive. On iOS, these are stored in a visible folder in your Files app for transparency. On Android, these are stored in a secure, app-specific hidden folder within your Google Drive to prevent accidental deletion. These files are controlled entirely by you via your cloud provider's account management settings.

3. Security & Biometrics

If you enable PIN or Biometric lock (FaceID/TouchID/Fingerprint), the app uses your device's native security systems. Your PIN is stored securely on your device, and your biometric data is never shared with the app or any third parties. Your cloud backups are protected by the security of your Apple or Google account.

4. Health Integration (Apple Health & Health Connect)

If you choose to enable health integration, the app will read specific metrics including steps, sleep, heart rate, and exercise/workouts to provide insights into how your activity affects your mood. This data is read directly from your device's health store and is stored within your journal entries only when you save them. We do not use your health data for advertising, and we never sell it or share it with data brokers.

Health Data and AI Features (Off by Default): Your health data is not included in an AI request unless you explicitly turn on Settings > AI Features > "Share Health Data with AI." This setting is off by default. While it is off, health metrics are removed from context sent to our AI proxy. If you turn it on, steps, sleep, and average heart rate attached to journal entries used as conversation context are transmitted through Euthy's Google Cloud proxy and processed by Google Cloud AI or OpenAI so the companion can offer wellness insights. Euthy does not write those metrics to its Firestore quota database or intentionally include them in application logs; Provider processing and retention are described in Section 6. Turning the setting off immediately excludes health metrics from subsequent requests. If AI Memory was also enabled, health-related facts may already have been saved as memories on your device. Turning off health sharing does not delete those local memories; you can review or permanently delete them under Settings > Memories.

Retention & Deletion: Health data is stored only as long as the journal entry containing it exists. Deleting a specific journal entry permanently removes the associated health data. Deleting the Euthy Journal app from your device will erase all locally stored data.

5. Location & Weather Data

If you choose to use the location tagging, map, or weather features, the app will request access to your device's location services. Your precise location coordinates, tagged places, and retrieved weather conditions are stored locally on your device within your journal entries. To provide address lookup (geocoding), map displays, and current weather conditions, your coordinates are processed by native services (Apple Maps and WeatherKit on iOS, Google Maps and Google Weather API on Android). This only happens when you explicitly trigger these features (e.g., by clicking the location or weather buttons). We do not store your location or weather data on our servers or track your movements in the background.

6. Insights & AI Features

Monthly/yearly AI recaps: When you choose Generate, selected-period dates, moods, activities, tags, saved summaries or bounded text fallbacks, and applicable location/weather descriptions are sent through our proxy to Google Cloud AI. Structured health fields are included only if health sharing is enabled; free text can itself contain sensitive details. Large reviews use bounded extraction/merge batches rather than one unlimited request, with progress saved locally for Stop/Resume. Generated recaps and their checkpoints remain on this device and in backups you choose to create. Large reviews can use substantial monthly AI allowance; stopping does not undo work already processed. Quotes and source references are checked, but observations may still be wrong. Recaps do not run automatically or create saved AI memories.

Compare this with then (when available): A separate, off-by-default Premium AI setting opens a two-entry discussion in AI Companion. You choose one entry and an earlier entry from the same journal using a local paginated picker. Only explicit Send requests share their plain-text titles/dates, excerpts from the two selected entries, your latest message and limited recent discussion history through Euthy's Google Cloud AI proxy with your Support ID. Long entries may be shortened, and older messages may be omitted. No other entries, saved AI memories, profile, media, structured health or location metadata are added; written text may contain sensitive details. Selected excerpts, questions and replies are saved in local Companion history and included in personal backups only when you create one. Deleting either source entry removes its linked comparison chats. Starting a general chat creates a separate conversation without carrying over these excerpts or history. Nothing runs automatically. Requests use Premium AI credits or Eco limits, not free samples. Quotes are checked against the supplied excerpts; interpretations can still be wrong, and two moments do not establish a complete timeline. Google Cloud processing/retention terms below apply.

Reflect on your week: This optional Premium AI feature previews selected sources locally before you choose Generate. With the shared AI permission, generation sends frozen week/time-zone boundaries, titles/dates, local-day labels, a limited selection of entry excerpts and your optional focus, and your Support ID through Euthy's Google Cloud proxy to Google Cloud AI. Replies reuse those frozen sources, the initial reflection and limited recent discussion history. Long entries may be shortened, and older messages may be omitted; the reflection may not cover everything you wrote that week. No broader search, profile, saved memories, media or structured health/location fields are added; writing may itself contain sensitive details. Quotes are checked, but interpretations can be wrong. Excerpts, focus, reflection and replies are saved locally and included in optional chat backups; saved reading remains available offline or after opt-out. Editing/deleting a source removes its dependent discussion on this device. Write about this opens an editable draft using the question and your recent replies, not assistant interpretations; only Save creates an entry. Generation/replies use paid allowance or Eco limits, not free samples. Nothing runs automatically. The separate optional weekly reminder uses generic local notification text and does not generate AI or spend allowance.

Personalized writing prompts: The editor's AI toolbar offers offline starter questions and optional Premium AI personalized suggestions. With personalized prompts enabled and the shared permission accepted, Generate sends selected titles/dates, a limited selection of recent entry excerpts from your selected journal and your optional focus, and your Support ID through Euthy's Google Cloud proxy to Google Cloud AI. Review or exclude sources first. Long entries may be shortened. The current draft/entry, other journals, profile, memories, media and structured health/location fields are excluded; written text may itself be sensitive. Quotes are checked, but questions may make mistaken assumptions. Generation uses paid allowance or Eco limits, not free samples. Suggestions/excerpts are temporary on-screen data, not a saved discussion. Use this question appends only the chosen question to your draft without replacing writing; only Save creates an entry. There is no automatic generation, saving or memory creation.

Local Insights: Core journaling summaries, statistics, and graphs (such as weekly metrics and mood charts) are calculated in the app on your device and do not require cloud AI processing.

Go deeper (when available): This separate, off-by-default Premium AI setting opens a selected-entry discussion in AI Companion where you explicitly request reflection questions and discuss one selected entry. Requests send its plain-text title/date, an excerpt from the selected entry and limited recent reflection conversation to Euthy's Google Cloud AI proxy with your Support ID. Long entries may be shortened, and older messages may be omitted. No other entries, saved AI memories, profile, media, structured health or location metadata are added; your written text may itself contain sensitive information. Nothing runs automatically. Questions, replies and a source-binding excerpt are saved in the local chat database and included in a personal backup only when you choose to create one. Clearing the reflection leaves the entry unchanged; deleting its source entry removes the linked local reflection. Disabling the setting stops new requests without erasing saved chats. The Google Cloud processing and retention terms below also apply.

Shared connected-AI permission: One short, explicit permission covers Google Cloud AI and OpenAI for the writing, chats, images and journal details needed by the features you choose. It is bound to your current app account and can be revoked in Settings. Feature switches, health sharing and automatic analysis/indexing remain separate. A Google-only permission is not silently upgraded to OpenAI: foreground sharing requires renewed approval and automatic uploads pause until approval. A new provider or materially different data use requires a new approval, not a popup for each feature.

Provider processing and retention: Google Cloud may temporarily cache or retain content under its service terms, including encrypted durable caching when supported and enabled; Google states customer data is not used to train models without permission. See Google Cloud retention documentation. Euthy's OpenAI API requests use store: false to disable saved Responses application state and do not opt in to model training. This is not Zero Data Retention: OpenAI may retain abuse-monitoring content for up to 30 days by default, or longer where legally required or under applicable safety rules. See OpenAI API data controls. Processing may occur outside your country under the applicable provider's terms. Local deletion does not automatically erase provider monitoring or legally retained records.

Connected AI Features (Opt-In): Requested writing, chat, entry compilation, journal-history answers, analysis and images pass through Euthy's Google Cloud Run proxy with your pseudonymous Support ID. Eligible text conversations, compilation and journal-history final answers can use OpenAI; Google Cloud AI remains in use for search planning, recaps, selected-entry/weekly reflections, writing prompts, images, embeddings and saved-memory extraction. Eco Mode and older clients may use Google Cloud AI. Your Support ID accompanies requests to Euthy's server; Euthy does not send it as an OpenAI user identifier. No complete journal is uploaded as one chat request. Euthy does not add journal prompts, responses or generated images to its Firestore quota database or intentionally include them in application logs. Successful chats, drafts and images are saved locally where the feature provides saving, and included in personal backups only when you create one.

Free AI text sample: When available, verified Apple or Google sign-in is required before the first of up to 20 successful text AI uses. The allowance is shared across supported text-chat answers and Journal via AI Save as Entry compilations; each successful answer or compilation uses one sample and is a one-time sample, rather than a monthly or per-chat allowance. Save as Entry sends only conversation roles and text from a limited recent portion of your chat, so earlier material in a long conversation may be omitted. It adds no entry context, profile, memories, media or structured health/location metadata, although written text may contain sensitive details. You confirm before generation, then review/edit the draft and choose its journal before saving it on your device. Successful generation uses a sample even if a later local save fails; retrying that save on the same open screen reuses the draft without another AI request. Cancelled confirmations and failed generation do not use a personal sample. It does not include Go deeper, Compare this with then, images, weather, automatic/background AI, or Premium-only settings. A daily service budget counts generation attempts, including failures, and can temporarily pause new sample requests. Opening the Home AI action menu or attempting to send a message can contact our proxy with your Support ID and, when present, sample session token to check availability. Saved conversations remain readable locally after the allowance ends.

Journal-history search and optional semantic indexing: Journal/date-scoped search runs on your device. A bounded selection of matching passages and your question is sent through our proxy for an answer, using Google Cloud AI or OpenAI. Exact-text counts, search candidates and meaning-based suggestions are distinct, not an exhaustive thematic count. You can review another bounded page. Separately enabling Semantic Journal Memory permits Google Cloud embedding requests for entry text and search questions. The expanded index uses overlapping text passages from your entries; exceptionally long entries may be partially indexed. Legacy prefix vectors may remain until the upgrade is approved/completed. Embeddings and progress remain local; uploads require the enabled setting, sharing permission and allowance. Disabling semantic memory stops indexing and removes local vectors; text search remains available. Provider retention conditions above apply.

AI Memory: If you enable AI Memory, Euthy Journal transmits chat and journal text through the same Google Cloud Run proxy to extract discrete facts, preferences, and goals worth remembering (for example, names, relationships, or health-related context you choose to share). Euthy does not add the extraction request to its Firestore quota database or intentionally include it in application logs; Google Cloud processing follows the retention conditions described above. The resulting memories are saved in your local device database, sorted into categories such as Identity, Preference, Relationship, Goal, or Health, and you can review or permanently delete individual memories in Settings > Memories.

AI Safety Feedback: The Flag icon next to AI-generated text or images lets you explicitly submit an issue category, such as inaccurate or harmful. The confirmation explains that submission sends only that selected category and a fixed app screen or mode through Aptabase, alongside its standard technical metadata. It does not send the flagged response, journal content, prompts, images, filenames, file paths, or entry identifiers. This user-initiated feedback remains available when passive usage analytics is disabled. Category-only feedback helps identify recurring issues but does not let us inspect the specific output you flagged.

7. Performance & Crash Reporting

To ensure the app is stable and performing well, we may use analytics, performance monitoring, and crash reporting services. Optional usage analytics is off by default and records fixed feature events and limited funnel metadata, such as app screen, subscription tier and plan, or onboarding step, only when enabled. Analytics does not include journal content, moods, health metrics, location values, media or entry identifiers, exact reminder times, or routine identifiers. Explicit AI safety feedback is separate and described in Section 6. Technical diagnostics may include information such as app version, device model, operating system version, and crash logs.

8. Privacy Rights & Global Compliance (GDPR, LGPD, CCPA, etc.)

While Euthy Journal is designed in alignment with the General Data Protection Regulation (GDPR) and Brazil's LGPD, we choose to extend these privacy rights to all of our users globally, regardless of their location. You have the following rights:

  • Right to Access: You can export your core journal data (text, moods, tags) at any time for free via the JSON Export tool in Settings.
  • Right to Erasure: Settings > Manage data deletion provides separate options for local journal/backups, verified free-sample records, and requesting server-side data deletion. Local deletion does not delete server-side credit records or cancel a subscription.
  • Right to Portability: Your data is exported in standard formats (JSON) for use in other services. Advanced formats (PDF, ZIP) are available through Premium.
  • Right to Object: You can opt out of optional usage analytics and technical monitoring at any time using the toggle in Settings.

To request server-side or processor data deletion, see our data deletion page or contact support@euthylabs.com. Include your Support ID from Settings > About if you still have it; you can request help after uninstalling as well. We verify the relevant sign-in or purchase before deleting account or credit records. A Support ID or email alone does not prove ownership. Do not send passwords, identity tokens, sign-in codes, or journal entries by email. Deleting Euthy data does not cancel a store subscription or automatically erase third-party purchase records.

9. Data Sub-Processors

To provide our services, we use a limited number of trusted third-party sub-processors:

  • Aptabase: Provides privacy-first, anonymized usage analytics.
  • Sentry: Provides technical crash reporting and performance monitoring to ensure app stability.
  • RevenueCat: Manages subscription status and purchase verification.
  • Apple (Sign-In, iCloud, Maps, Location, & WeatherKit) / Google (Sign-In, Drive, Maps, Location, & Weather API): Sign-in is optional for purchasing, using, or restoring Premium AI, but required for the free AI text sample. By default your Support ID is a random identifier generated on your device. If you sign in, the provider identifier is stored locally and hashed to derive a recoverable Support ID. For sample access or identity-verified sample deletion, an Apple or Google identity token is sent to Euthy's proxy and may contain an email claim. We verify the token and use the provider identifier, rather than your email, to derive the pseudonymous sample account key; we do not intentionally persist the raw identity token or email in Firestore. Apple and Google also handle optional backups, maps, geocoding, and weather. Google Drive backup permission is requested separately when you choose Cloud Backup.
  • Google Cloud Platform (GCP & Vertex AI): Hosts Euthy's connected-AI proxy and processes Google Cloud AI routes. Euthy's Firestore database, hosted in the United States, stores pseudonymous subscription credit and sample-use records, hashed sample-session tokens and expiry, request reservations, native usage totals, hashed request/purchase bindings and operational rate/budget counters. It does not store journal prompts, responses, or generated images. Google Cloud may temporarily cache or retain request data under its service terms and states that customer data is not used to train models without permission.

10. Subscriptions

Subscription payments are handled securely by Apple and Google. We use RevenueCat to manage subscription status and verify purchases. RevenueCat acts as a service provider and processes only the information necessary to validate your subscription, such as transaction IDs and device identifiers. They do not have access to your personal journal entries.

OpenAI: Processes eligible connected text chats, entry compilations and journal-history final answers, including eligible samples, through our server-only API integration. Content and bounded context are processed under the OpenAI retention conditions in Section 6. API credentials are never included in the mobile app.

AI Usage & Credit Tracking: We track Premium AI monthly balances against your pseudonymous Support ID and one-time sample use against your verified provider account key in Google Cloud Firestore (United States). These identifiers are pseudonymous rather than anonymous; the database contains no journal content. Premium AI does not require sign-in.

Sample retention and deletion: Sample use records remain to enforce the one-time allowance until you request verified deletion. Sample session records expire after 30 days and are removed asynchronously by Firestore TTL. Verified sample deletion removes usage records, linked installation records, and sessions, retaining only a keyed-hash anti-abuse marker for up to 12 months. The marker prevents that sign-in from immediately reclaiming another sample. Verified deletion attempts use a separate keyed counter removed after approximately 24 hours by TTL; ordinary daily rate-limit records expire after three days. Daily aggregate sample budget counters contain no journal content.

Text-request accounting: Paid OpenAI requests reserve allowance before dispatch, then settle once using verified native usage totals. Unresolved holds are returned after ten minutes on the next balance check or request; uncertain provider costs are absorbed rather than charged without verified usage. Valid terminal usage can consume paid allowance even when output validation fails. Receipts contain opaque hashed request/purchase bindings, times, state and usage totals, not writing. A rolling 24-hour replay/retry window is pruned on ledger access, not by a physical 24-hour TTL. Dormant records remain under premium-ledger retention; verified deletion strips detailed usage while retaining minimum paid-restoration and abuse-prevention information.

Premium AI retention: Active subscribers retain the credit records needed to deliver and restore their entitlement. Expired or transferred records are scheduled for removal 12 months after the recorded expiry or transfer when the backend receives or verifies that state. Automatic cleanup of older or dormant credit records is still being completed; we do not currently promise that every historic ledger is automatically removed. You may request earlier deletion after purchase verification. Apple, Google, and RevenueCat may retain purchase information under their own policies, and an active subscription or later use can recreate a service credit record.

Optional linked-account AI usage cleanup: Where available, you may clear historical Premium AI usage counters using the Google or Apple account already linked to your Support ID. A signed identity token, which may contain an email claim, is sent to Euthy's Google Cloud proxy. We do not intentionally store the raw token or email in Firestore or log it. A private pending confirmation record contains the pseudonymous account ID, exact credit-record version, hashed purchase binding, creation time, and a hashed one-use challenge. The confirmation expires after 15 minutes; you confirm and receive the cleanup outcome in the app, without an email handoff. Pending metadata is scheduled for removal after 24 hours. Completed receipts omit account/proof fields and retain only an opaque case ID, scope, time and aggregate outcome for 30 days. Firestore TTL cleanup is asynchronous. This optional cleanup retains the entire credit ledger and today's request-limit counter, including for expired subscriptions; it does not reset credits, cancel billing, delete local chats, delete the account, or erase processor purchase records. Full account/credit-record deletion is a separate request with separate verification and retention requirements. Premium AI remains usable without sign-in.

Linked account deletion: In supported app versions, this action uses verified Google/Apple identity and separate confirmation, removes local journals, chats and media on the current device, and removes backups from the currently connected cloud account. Apple sends a one-use authorization code through our server for sign-in token revocation; Google authorization is disconnected using its native SDK. Raw tokens, codes and exchanged refresh tokens are not intentionally stored or logged. The server requests RevenueCat profile deletion, which is queued asynchronously and may remove manually granted entitlements; store billing is not cancelled. Minimal pseudonymous paid-balance/purchase fields remain to prevent credit resets and preserve restoration. Active or unknown-expiry records are not automatically treated as expired; verified expired records follow the retention rules above. The 12-month keyed sample marker and today's request-limit counter also remain, with the counter's existing three-day expiry. Private pending/processing cases include a hash binding the verified identity token to its one-use confirmation and are scheduled for removal after 24 hours; account/proof-free outcome receipts after 30 days. Interrupted cleanup can be retried. Disconnected cloud accounts, other devices and exports saved outside Euthy are not erased. Shared or legacy RevenueCat aliases require separate verified support handling rather than client-selected deletion targets.

11. Third-Party Import Names

Euthy Journal may refer to third-party journal apps only to describe compatible export formats. Day One, Journey, Daylio, Diarly, Diarium, and Stoic are trademarks of their respective owners. Euthy Journal is not affiliated with or endorsed by them.

12. Website & Cookies

To respect your online privacy, the Euthy Journal website (https://euthylabs.com) is built without using cookies, web beacons, tracking pixels, or client-side analytics. We do not collect, store, or share any personal tracking information about visitors browsing our website.

13. Contact Support

If you have any questions about this Privacy Policy or how your data is handled, please contact us at: support@euthylabs.com