Privacy by design

Private by design, and plain about it.

Jurnl is coming to iPhone, and it’s being built so your journal lives on your iPhone and in your own private iCloud, with no Jurnl account to write. When the companion writes a note or a question, it’s designed to use only the writing it needs, and Jurnl’s own service is designed to keep none of it. Here is how.

This page describes how the app is designed. Jurnl’s privacy notice will confirm the details, including the service providers involved, when the app is released. For this website, see the website privacy notice.

01

Where your journal lives.

Your entries are saved on your iPhone, with sync to your own private iCloud. There’s no Jurnl account: you don’t sign in to write, and Jurnl holds no copy of your journal.

An open page is kept the same way until you close the book on it or tear it up. A page you leave open is saved, but isn't sent for AI reflection while it's unfinished.

02

What a note needs.

When you close the book, the companion may read that entry to write a note. Where they’re relevant, it can add up to two recent short passages and one older one that you wrote before. They’re chosen on your iPhone and sent as you wrote them, without dates or page identifiers.

A note about a longer view (the recent weeks of This stretch, a closed Season or a Chapter) sends a few short passages from that stretch instead. What stays looks further back, and may send a few short passages from different parts of your journal, so what it says is grounded in what you actually wrote.

A guided question can use how you’re arriving, a broad part of your local day such as morning or evening, and a little continuity from your recent writing, so the question fits the moment.

Your photos stay part of the journal; they aren’t sent for AI analysis, and adding or changing them doesn’t generate a new reflection.

Nothing identifying is added: no name, no account, no device identifier, no lasting session. Your own words can still be personal, naming a person or a place, which is why only what the note needs is sent, and why we don’t call the request anonymous.

03

Who keeps what.

Jurnl’s own service is designed to keep none of your writing: no journal, no transcript, no copy of the request, and no log of what is sent or returned. If a request to the AI provider fails, it’s designed to record only a short operational line (which kind of note, which provider, the error status) with none of your writing in it.

The AI provider that writes the notes, its data settings and how long it may keep a request will be named and set out in Jurnl’s privacy notice before the app is released.

04

Locking your journal.

Turn on journal lock, and Jurnl asks for Face ID, Touch ID or your device passcode before your journal opens. It uses your iPhone’s own authentication, so there’s no separate Jurnl passcode to remember.

Journal lock controls who can open Jurnl on your iPhone. It doesn’t add encryption or change how your journal is stored.

05

Without a connection.

Writing, reading back and your count of days don’t need a network. With no connection you can still write, and your entry is saved on your iPhone just the same.

AI-generated notes and questions need a connection; locally available starting questions can still help you begin offline. Sync to your iCloud and App Store purchase checks also use a connection. The list of support services is built into the app, so it opens offline, though calling, texting or visiting a service still needs a connection.

06

Good to know.

An entry that hasn’t synced can be lost if you delete the app, whether you’re signed out of iCloud, offline, or it simply hasn’t synced yet.

Buying Jurnl will create a purchase record with Apple, and with any service that handles subscriptions for us, including an identifier tied to that purchase history. That record is about the purchase, not your journal.