Jottary

Privacy Policy

Last updated: February 18, 2026

Jottary is a personal voice journaling app. Your journal is private, and we treat your data accordingly. This policy explains what we collect, how we use it, and who has access.

What we collect

Account data. When you sign up, we store your email address and name. If you use Google sign-in, we receive your Google profile name and email.

Journal entries. This includes your voice recordings, written text, and any images you attach. We also store AI-generated metadata: transcriptions, titles, mood labels, themes, and people mentioned.

Embeddings. Each entry is converted into a numerical vector (embedding) to power semantic search. These are stored alongside your entries.

Chit-Chat messages. If you use the Chit-Chat feature to have conversations grounded in your journal, those messages are stored.

Usage analytics. We use Vercel Analytics (web performance metrics) and PostHog (pageviews and navigation events). These tools collect anonymous, aggregated usage data. We do not currently display a cookie consent banner — we plan to add one.

How we use your data

Your data is used to provide the features of Jottary and for nothing else. Specifically:

  • Voice recordings are transcribed using OpenAI Whisper.
  • Entry text is analyzed by GPT-4o-mini to generate titles, mood labels, themes, and people mentioned.
  • Embeddings are generated using OpenAI's text-embedding-3-small model for semantic search.
  • Chit-Chat conversations are powered by GPT-4o, with relevant journal entries provided as context.

All AI processing uses the OpenAI API (not ChatGPT). Under OpenAI's current API data usage policy, data sent through the API is not used to train their models.

Storage and security

Your data is stored in Supabase (Postgres database and object storage), encrypted at rest. The application is hosted on Vercel. Audio recordings and images are stored in Supabase Storage buckets.

We use row-level security policies so that each user can only access their own data through the database.

Who we share data with

We do not sell your data. We do not share it for advertising. The only third party that receives your entry content is OpenAI, and only to provide the features described above (transcription, analysis, embeddings, and chit-chat).

Our infrastructure providers (Supabase, Vercel) host and serve your data but do not access its contents.

Data retention

When you delete an entry, it moves to trash (soft delete). Trashed entries are automatically and permanently purged after 30 days. You can also permanently delete entries from trash immediately.

Audio recordings and images associated with permanently deleted entries are removed from storage at the same time.

Account deletion

You can delete your account at any time from the Account settings page. This permanently removes all your data — entries, recordings, images, people, chat threads, insights, and your profile. This action is irreversible.

Age requirement

You must be at least 13 years old to use Jottary. If you are in the EU or EEA, you must be at least 16. We do not knowingly collect data from children under these ages.

Changes to this policy

We may update this policy as Jottary evolves. If we make significant changes, we will notify you through the app. The date at the top of this page reflects the latest revision.

Contact

If you have questions about this policy or your data, reach out at [email protected].