Your diary is none of our business.
Effective 27 July 2026
A diary only works if it is truly private. That is the promise BUDDY is built on, and this page spells it out in plain language — the same language the app speaks.
What we will never do
These are commitments, not settings you have to find:
- We never sell your data. Not your entries, not your check-ins, not your email address. To anyone, for any reason.
- We never use your data for advertising. There are no ad networks, no advertising trackers, and no advertising profiles in BUDDY — and there never will be.
- We never share what you write with third parties for their own purposes.
- We never keep your voice. Voice notes are transcribed to text and the raw audio is discarded. The sound of your voice is not stored anywhere.
- We never let AI train on your diary. The AI services that help Buddy write back are contractually barred from training their models on your content or keeping it.
No person can read your diary
Your entries are encrypted on their way to our servers and encrypted where they are stored. They are not end-to-end encrypted, and we won’t pretend otherwise: our servers can decrypt your entries, because Buddy has to read what you wrote in order to write back. What we promise is that no person does. There is no admin view of your diary, no support tool that opens entries, and no human review of anything you write.
One thing has to be said plainly, though: Buddy is A journal that talks back, and to talk back, software has to read what you just wrote. Here is exactly how that works.
How Buddy writes back
When you finish an entry, your app sends it to our servers over an encrypted connection. At the moment a reply is needed, the relevant text is decrypted in server memory and passed to an AI language model, which composes Buddy’s answer. The answer returns to your app, and everything is stored encrypted again.
The models are run by outside AI providers — Anthropic, OpenAI, and Google — reached through OpenRouter, a routing service. Everything the AI works with passes through OpenRouter: chat messages, photos you share, entry summaries, memory items, and pattern reports. Every single request we send carries OpenRouter’s strictest no-data-collection setting (provider.data_collection: 'deny'), which means your content is only ever routed to model providers that neither retain it nor train on it. That is a commitment, not a default we might quietly change.
So the honest summary is: no person ever reads your diary, and no AI keeps it — but an AI model does read the entry it is replying to. That is the trade that makes Buddy possible, and we want you to make it with open eyes.
Where your data lives
Your diary is stored in encrypted form on secured servers and synced — still encrypted — across your devices, so it is wherever you are. Data is encrypted in transit and at rest, though — as said above — not end-to-end: the server can read entries at the moment Buddy needs to reply.
Crash reports carry no diary content
We use two outside services to keep the app healthy: Sentry, for crash reports, and PostHog, for basic usage analytics. Both are configured to scrub aggressively. Sentry is set to send no personal information by default; request bodies, headers, cookies, and query strings are stripped, and any extra or breadcrumb field we have not explicitly allowed is dropped before a report is sent. What you write never appears in a crash report or an analytics event.
What we do collect
The short list of what BUDDY needs to work:
- Your account: the email address from your Apple or Google sign-in, used only to identify your account.
- Your content: entries, check-in numbers, and Buddy’s memory of you — encrypted, as described above, and used only to run the app for you.
- Basic technical information — device type, app version, crash reports, and which features are used — so the app works reliably. Scrubbed as described above; never your content, and never for advertising.
Buddy’s memory is yours to edit
What Buddy remembers about you is written in plain language inside the app. You can read it, change it, or delete any part of it at any time — and deleted means deleted.
Deleting your account
You can delete your account whenever you like, from inside the app. When you do, your entries, check-ins, and Buddy’s memory are permanently removed from our servers.
Security
BUDDY requires a passcode — there is no way to skip the lock. The passcode locks Buddy on this device; it is not a second factor for your account. Signing in with Google or Apple on a new device, or resetting the passcode by email, sets a fresh one. The passcode is stored only as a salted PBKDF2-HMAC-SHA256 verifier — never in plaintext — and for Google and Apple accounts it never leaves your device. Sign-in itself is handled by Apple or Google, so we never see or store a password.
The record, for the careful reader
The same facts as above, in the compact form reviewers and regulators look for:
- Content processed: diary entries (typed or transcribed from voice), photos and videos shared with Buddy, check-in numbers, and Buddy’s memory of you.
- When content is decrypted: on your devices, and transiently in server memory at the moment Buddy generates a reply or updates its memory. Never for human review, analytics, or advertising.
- AI subprocessors: OpenRouter (request routing), which receives every chat message, photo, entry summary, memory item, and pattern report and fans requests out to the model providers Anthropic, OpenAI, and Google. Every request carries OpenRouter’s
provider.data_collection: 'deny'policy, so content is routed only to providers that neither retain it nor train on it. - Other processors: Sentry (crash reporting) and PostHog (usage analytics). Both Sentry clients run with
sendDefaultPiioff; request bodies, headers, cookies, and query strings are dropped, as is any extra or breadcrumb field not on an explicit allow-list. No diary content reaches either service. - Storage: encrypted at rest on secured cloud servers, encrypted in transit with TLS. Not end-to-end encrypted — the server can decrypt entries so Buddy can reply.
- Passcode: a device-level lock, stored as a salted PBKDF2-HMAC-SHA256 verifier, never in plaintext. For Apple and Google sign-ins it never leaves the device.
- Retention: your content stays until you delete it. Deleting an entry, a memory, or your account permanently removes it from our servers.
- Company details: BUDDY is pre-launch. The operating legal entity, registered address, and data-protection contact will be published here before the app ships.
Questions
If anything here is unclear, write to us at hello@journalingbuddy.com and a person will answer. If we ever change this policy, we will say so plainly in the app before the change takes effect — never quietly.
The short version: your diary is encrypted, no person reads it, the AI that writes back may not keep it or learn from it, we don’t sell it, and no advertiser will ever touch it. That is the whole point of BUDDY.