This is a development environment. For the production version, please visit mindfulflowjournal.com.

MindfulFlow Journal Logo

Privacy Policy

Last updated: October 8, 2026

Welcome to MindfulFlow Journal ("we," "our," or "us"). We are committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our application.

1. Information We Collect

We may collect information about you in a variety of ways. The information we may collect on the Service includes:

  • Personal Data: Personally identifiable information, such as your name and email address, that you voluntarily give to us when you register for an account.
  • Journal and Mood Data: The content of your journal entries, mood logs, goals, and any other information you provide while using the core features of the app. This information is your private data.
  • AI Analysis Data: To provide our AI-powered features, the text from your journal entries, mood logs, or journaling conversations is first processed on your own device by an on-device pseudonymization tool that detects and replaces personally identifying details (such as names, locations, and contact information) with generic placeholders. Only this pseudonymized text—never your original, identifiable journal content—is sent to our AI service provider, Google's enterprise Vertex AI platform (Gemini models), for processing. We use Google Cloud's enterprise Vertex AI service rather than consumer AI products specifically because Google contractually commits not to use data processed through Vertex AI to train or improve its models, and does not subject it to human review. The results of this analysis may be stored to be displayed to you within the app.
  • Payment Data: We may collect data necessary to process your payment if you make a purchase, such as a subscription. All payment data is stored by our payment processor, Stripe. You should review their privacy policy and contact them directly for responses to your questions.
  • Usage Data: Information our servers automatically collect when you access the Service, such as your IP address, your browser type, your operating system, your access times, and the pages you have viewed directly before and after accessing the Service.

2. Use of Your Information

Having accurate information about you permits us to provide you with a smooth, efficient, and customized experience. Specifically, we may use information collected about you via the Service to:

  • Create and manage your account.
  • Provide the AI-powered journaling features, including generating insights, summaries, and suggestions.
  • Process payments and subscriptions.
  • Communicate with you about your account or our services.
  • Monitor and analyze usage and trends to improve your experience.
  • Protect the security and integrity of our Service.

3. Disclosure of Your Information

We do not sell or rent your personal information. We may share information we have collected about you in certain situations. Your information may be disclosed as follows:

  • By Law or to Protect Rights: If we believe the release of information about you is necessary to respond to legal process, to investigate or remedy potential violations of our policies, or to protect the rights, property, and safety of others, we may share your information as permitted or required by any applicable law, rule, or regulation.
  • Third-Party Service Providers: We may share your information with third parties that perform services for us or on our behalf, including AI processing (Google Cloud Vertex AI), analytics and advertising (Google Analytics, Meta — see "Cookies and Tracking Technologies" below), payment processing (Stripe), data storage (Firebase), and email delivery. We only share the minimum information necessary for them to perform their designated functions.
  • Business Transfers: We may share or transfer your information in connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company.

4. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to help customize the Service and improve your experience. Most browsers are set to accept cookies by default. Analytics and advertising tracking is described under "Analytics and Advertising" below.

We use cookies for essential functions such as:

  • Authentication: To keep you logged in to your account.
  • Security: We use Google reCAPTCHA to protect our forms from spam and abuse, which itself uses cookies to function.
  • User Preferences: To remember your choices, such as whether you have accepted our cookie policy.

Because these cookies are strictly necessary for the operation of the website, they do not require prior consent under GDPR. By using our Service, you agree that we can place these types of cookies on your computer or device.

Analytics and Advertising

In your browser. If you allow analytics and advertising cookies in our cookie banner, Google Tag Manager loads Google Analytics 4 (GA4) and the Meta (Facebook/Instagram) Pixel. This is one choice that covers Google and Meta together; you cannot currently allow one and not the other.

From our servers. Our servers also send events directly to Google (GA4 Measurement Protocol) and Meta (Conversions API) when you sign up, start a checkout, or complete a purchase. These events can include:

  • To Meta: a SHA-256 hash of your email address and a SHA-256 hash of your account ID. For signup and checkout events, the event reference Meta uses to avoid counting an event twice also contains your account ID itself.
  • To Google: a SHA-256 hash of your account ID (for purchases, of your payment customer ID if no account ID is available), used as the analytics client ID.
  • Event details: the signup method; the plan and where checkout started; for purchases, the amount, currency and payment transaction reference.

A hashed identifier is pseudonymous, not anonymous: Google or Meta may be able to match it to data they already hold. These signup, checkout and purchase events are sent whether or not you have allowed analytics and advertising cookies, including after you withdraw that choice.

Signup attribution. If you had allowed analytics and advertising cookies on the device you signed up from, we may also hold browser and campaign identifiers from that device (Meta's _fbp/_fbc values, Google's analytics client and session IDs, and UTM source, medium and campaign values) on our servers. They are added to the signup event only if the browser that completes email verification also has analytics and advertising cookies allowed, and only within 7 days of signup. A Meta click identifier is used only if the ad click was no more than 90 days earlier. This record is deleted when your email is verified, or when our servers confirm a withdrawal you make while signed in. Otherwise it can no longer be used 7 days after signup and is marked to expire then. Expired records are automatically deleted after expiry. Deletion is asynchronous, so it happens some time after expiry rather than at an exact time.

Withdrawing consent. You can withdraw through the cookie banner, from Privacy in the account menu once your email is verified, or on the Withdraw tracking consent page, which also works before verification. This stops browser tracking on that device; if your browser does not let us save the choice, it may apply only to the page you are on. If you are signed in, we also ask our servers to delete any pending signup-attribution record and record the withdrawal against your account, so the attribution record cannot be used even if you verify on another device. From the cookie banner this request is made in the background and may fail without telling you; the Withdraw tracking consent page tells you whether our servers recorded it. The withdrawal record is marked to expire after 7 days; as above, expired records are automatically deleted after expiry, and deletion is asynchronous, so it happens some time after expiry rather than at an exact time. Withdrawing while signed out affects only that browser, and a browser that has never signed in to your account cannot be linked to your withdrawal. Withdrawal does not stop the server events described above, and it cannot recall data already sent to Google or Meta; their own retention and deletion policies apply to it.

The events described in this section do not include your journal entries, mood logs, or AI analysis results.

5. Security of Your Information

We use administrative, technical, and physical security measures to help protect your personal information. We leverage secure cloud infrastructure provided by Google Firebase to store your data. While we have taken reasonable steps to secure the personal information you provide to us, please be aware that despite our efforts, no security measures are perfect or impenetrable, and no method of data transmission can be guaranteed against any interception or other type of misuse.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply. We use this service to protect against spam and abuse.

6. Your Rights and Choices

You have certain rights regarding your personal information:

  • Account Information: You may at any time review or change the information in your account or terminate your account by logging into your account settings.
  • Data Deletion: You can delete your journal entries, mood logs, and analysis history directly within the application.
  • Account Deletion: Deleting your account from within the app cancels any active subscription immediately — there is no refund for unused subscription time — and deactivates your account immediately, so you can no longer sign in. Your journal entries, mood logs, analysis history, and the encryption keys that protect them are permanently erased approximately 7 days after your request. Destroying the keys, not the later deletion of the already-opaque ciphertext, is what makes your entries unreadable. As with the records described in Section 4, this erasure is asynchronous, so it happens some time after the 7-day period rather than at an exact time. We separately retain your signup-attribution record and, if applicable, your consent-withdrawal record for compliance purposes (see "Cookies and Tracking Technologies" above); your Firebase Auth identity record is kept only in a disabled, sanitized form (no password or personal profile fields) so that record stays linked to an identity, and it cannot be used to sign in. Backups are retained separately for up to 30 days, so a deleted account may remain in backups for up to 37 days in total before it is fully removed from all of our systems.

7. Policy for Children

We do not knowingly solicit information from or market to children under the age of 13. If you become aware of any data we have collected from children under age 13, please contact us using the contact information provided below.

8. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date. You are advised to review this Privacy Policy periodically for any changes.

9. Contact Us

If you have questions or comments about this Privacy Policy, please contact us at: support@mindfulflowjournal.com.

    MindfulFlow

    We use essential cookies for security (like reCAPTCHA), and — with your permission — analytics cookies to understand how the site is used. You can change your mind any time. See our Privacy Policy.