Privacy policy

Your diary is none of our business.

What we will never do

These are commitments, not settings you have to find:

No person can read your diary

Your entries are encrypted on their way to our servers and encrypted where they are stored. They are not end-to-end encrypted, and we won’t pretend otherwise: our servers can decrypt your entries, because Buddy has to read what you wrote in order to write back. What we promise is that no person does. There is no admin view of your diary, no support tool that opens entries, and no human review of anything you write.

One thing has to be said plainly, though: Buddy is A journal that talks back, and to talk back, software has to read what you just wrote. Here is exactly how that works.

How Buddy writes back

When you finish an entry, your app sends it to our servers over an encrypted connection. At the moment a reply is needed, the relevant text is decrypted in server memory and passed to an AI language model, which composes Buddy’s answer. The answer returns to your app, and everything is stored encrypted again.

The models are run by outside AI providers — Anthropic, OpenAI, and Google — reached through OpenRouter, a routing service. Everything the AI works with passes through OpenRouter: chat messages, photos you share, entry summaries, memory items, and pattern reports. Every single request we send carries OpenRouter’s strictest no-data-collection setting (provider.data_collection: 'deny'), which means your content is only ever routed to model providers that neither retain it nor train on it. That is a commitment, not a default we might quietly change.

So the honest summary is: no person ever reads your diary, and no AI keeps it — but an AI model does read the entry it is replying to. That is the trade that makes Buddy possible, and we want you to make it with open eyes.

Where your data lives

Your diary is stored in encrypted form on secured servers and synced — still encrypted — across your devices, so it is wherever you are. Data is encrypted in transit and at rest, though — as said above — not end-to-end: the server can read entries at the moment Buddy needs to reply.

Crash reports carry no diary content

We use two outside services to keep the app healthy: Sentry, for crash reports, and PostHog, for basic usage analytics. Both are configured to scrub aggressively. Sentry is set to send no personal information by default; request bodies, headers, cookies, and query strings are stripped, and any extra or breadcrumb field we have not explicitly allowed is dropped before a report is sent. What you write never appears in a crash report or an analytics event.

What we do collect

The short list of what BUDDY needs to work:

Buddy’s memory is yours to edit

What Buddy remembers about you is written in plain language inside the app. You can read it, change it, or delete any part of it at any time — and deleted means deleted.

Deleting your account

You can delete your account whenever you like, from inside the app. When you do, your entries, check-ins, and Buddy’s memory are permanently removed from our servers.

Security

BUDDY requires a passcode — there is no way to skip the lock. The passcode locks Buddy on this device; it is not a second factor for your account. Signing in with Google or Apple on a new device, or resetting the passcode by email, sets a fresh one. The passcode is stored only as a salted PBKDF2-HMAC-SHA256 verifier — never in plaintext — and for Google and Apple accounts it never leaves your device. Sign-in itself is handled by Apple or Google, so we never see or store a password.

The record, for the careful reader

The same facts as above, in the compact form reviewers and regulators look for:

Questions

If anything here is unclear, write to us at hello@journalingbuddy.com and a person will answer. If we ever change this policy, we will say so plainly in the app before the change takes effect — never quietly.