How we protect your data
Your diary is about your health, so we look after it with great care. Here’s how, in plain English.
Your own key
Everything you write is encrypted with a key that belongs to your account alone. Even in our own database, your diary can only be read with that key. When you delete your account, the key is destroyed, so any copies in our backups can never be read again.
No adverts, no tracking, never sold
There are no adverts, no tracking pixels and no third-party analytics, in the app or on this website. We never sell your information or share it for marketing. We don’t use it to train AI.
Signing in safely
- Passwords are checked against lists of known leaked passwords.
- You can sign in with Face ID or a fingerprint instead (passkeys).
- You can lock the app with a PIN on your phone.
- You can see every device that’s signed in, and sign them out.
- Repeated wrong guesses are slowed down and blocked.
Family helpers see only what you choose
Everything is off until you turn it on. Helpers never see your private notes, symptoms or mood, and every time they look, it’s written in a log you can read.
Where it’s kept
The Journal runs on Cloudflare, with your data stored in Western Europe. It’s backed up every night, and backups are encrypted and kept for 30 days.
It’s yours
- Download everything at any time, in common formats.
- Delete your account and everything in it, straight away.
- Withdraw your permission to keep health information, whenever you like.
Found a problem?
If you think you’ve found a security problem, please email hello@ontheday.app. We’ll reply quickly and keep you updated.
For the full details, read our privacy notice.