Privacy Policy
Overview
JournaLock is a local-first journaling and records application for Windows, Android, Mac, and iPhone. We do not operate user accounts for journal content. We do not collect, receive, or store your journal content on our servers as part of the standard product experience.
Information stored on your device
- Journal entries, attachments, and vault data are encrypted locally using AES-256.
- Encryption keys, PIN settings, and unlock preferences are stored in your device’s secure storage.
- Application preferences and any API credentials you choose to enter are stored locally on your device.
- Optional local backup copies are written to folders you designate.
Information we do not collect
We do not access, transmit, or maintain server-side copies of your journal content unless you explicitly enable optional features described below. We do not sell personal information. We do not use your journal content for advertising or analytics.
Biometric authentication
Face ID, fingerprint, and Windows Hello are provided entirely by your operating system. Biometric data never leaves your device and is not accessible to JournaLock or its developer.
Optional third-party services (user-initiated only)
Payments (Stripe): Optional subscriptions and add-on purchases open Stripe Checkout in your web browser. Payment card and billing data are processed by Stripe, not collected or stored inside the JournaLock application.
Cloud backup (AWS S3): If you configure your own Amazon Web Services credentials, encrypted backups may be uploaded to an S3 bucket under your control. JournaLock does not provide or access your AWS account unless you supply credentials. Store builds may use platform-mediated cloud features when configured by JournaLock without embedding your private keys in the app binary.
AI transcription (Groq and similar): If you provide your own API key, audio or text you submit is processed by that third-party provider under their privacy policy. We do not have access to your API keys on our servers in the standard local configuration.
Trusted timestamping: When you request certification features, a cryptographic hash of your content (not the readable journal text) may be sent to a trusted timestamp authority such as DigiCert, and optionally to OpenTimestamps services, solely to create a verifiable timestamp.
Attorney and inventor linking: If you use matter-linking features with cloud handshake enabled, limited pairing metadata may be exchanged through storage you configure (for example, S3). Journal content is not automatically shared without your explicit actions.
Website
This website (journalock.com) may be served via standard web hosting and a content delivery network. Server access logs (IP address, user agent, requested URL, time) may be retained by the host for security and reliability. We do not use the marketing site to collect journal content. If contact forms are added later, they will only collect what you voluntarily submit.
File system access
JournaLock requests access to folders you designate for your vault, exports, and backups. The application does not scan unrelated files on your computer.
Your choices and data deletion
You may export or delete your journal data at any time from within the application. Uninstalling the app removes local application data subject to your operating system’s behavior. We do not maintain server-side backups of your journal. There is no remote account recovery; this is by design for security.
Children’s privacy
JournaLock is not directed at children under 13, and we do not knowingly collect personal information from children.
Changes to this policy
We may update this policy from time to time. The “Last updated” date above will change when we do. Continued use of the application after changes constitutes acceptance of the updated policy.
Contact
For privacy questions or support, contact: support@journalock.com