DeepJournal Privacy Policy

Last updated: July 15 2026


1. Introduction

DeepJournal is a privacy-first AI journaling application. It combines an encrypted local database, end-to-end encryption (E2EE) for synced sensitive content, and confidential-computing protections for AI request and response bodies.

These protections do not make all account, synchronization, or usage metadata invisible. This Policy explains both the protections and their limits.

This Privacy Policy explains how Andicop (“DeepJournal”, “we”, “us”, or “our”) collects, uses, stores, and protects personal data when you use DeepJournal’s applications, website, and related services (the “Service”).

This Policy is designed to comply with:

  • The EU General Data Protection Regulation (GDPR)
  • The French Data Protection Act
  • The Swiss Federal Act on Data Protection (FADP)
  • Applicable US state privacy laws

By using the Service, you acknowledge that you have read and understood this Privacy Policy.


2. Who We Are

Company name: Andicop

Country of incorporation: France

Andicop is the data controller for personal data processed through DeepJournal.

For privacy-related inquiries:

👉 support@deepjournal.app

We are not required to appoint a Data Protection Officer under Article 37 GDPR.


3. Minimum Age

DeepJournal is not intended for users under 16 years of age.

We do not knowingly collect personal data from children under 16. If we become aware of such data collection, we will delete the data and close the account.


4. Personal Data We Collect

A. Account Data

  • Email address
  • Authentication credentials (password hashes)
  • OAuth identifiers (Google, Apple, Microsoft if used)
  • Subscription status and billing identifiers

Payments are processed by Stripe. We do not store full payment card details.


B. Journal Content and Encrypted Fields

  • Journal entry content
  • Names, summaries, descriptions, and importance fields for selected memories and threads
  • Chat names, message content, and citations
  • Local encrypted database files
  • Wrapped encryption keys and recovery-wrapped key material

Configured sensitive fields are encrypted on your device before synchronization. DeepJournal's synchronization service stores ciphertext for those fields and does not receive the plaintext data-encryption key.

Some operational fields and tables are not covered by field-level E2EE. These include record identifiers, account identifiers, dates and timestamps, word counts, relationship records, settings, analysis status, chat roles, selected model names, and similar synchronization metadata.

The local journal database is encrypted at rest. Content is necessarily available to the application while the journal is unlocked, so local encryption cannot protect against an attacker controlling an unlocked device.


C. Technical and Usage Data

  • App version
  • Feature usage (non-content metadata only)
  • Crash and error reports
  • Basic web analytics
  • AI model selection, request timing, request size, token usage, and cost metadata

We do not log IP addresses at the application level.


D. Communication Data

  • Messages sent to support
  • Email correspondence
  • Marketing preferences (opt-in / opt-out status)

5. Lawful Basis for Processing

We process personal data under the following legal bases:

Contractual Necessity

To provide the Service (account management, authentication, syncing, AI features).

Legitimate Interests

To ensure security, prevent abuse, improve reliability, and maintain performance.

To comply with tax, accounting, and regulatory requirements.

For sending marketing or product update emails (see Section 9).

You may withdraw consent at any time.


6. How We Use Personal Data

We use personal data to:

  • Provide and maintain the Service
  • Authenticate users
  • Process subscriptions
  • Enable encrypted synchronization
  • Provide customer support
  • Improve performance and reliability
  • Ensure security
  • Send essential service communications
  • Send optional product updates if you opt in

We do not use journal content for marketing purposes.

We do not train AI models on user journal data.


7. End-to-End Encryption & Data Access Limitations

DeepJournal uses end-to-end encryption for configured sensitive synced fields:

  • Those fields are encrypted locally before upload and decrypted locally after download
  • The synchronization service stores wrapped key material but not the plaintext data-encryption key
  • Your encryption password is separate from your account password
  • Operational metadata and unconfigured fields are not covered by this E2EE layer

If you lose your encryption password and recovery key, your data cannot be recovered.

We cannot provide plaintext copies of E2EE-protected fields on your behalf. Export functions that run inside your unlocked application may still allow you to export your own data.


8. AI Features and Data Processing

Confidential AI Mode

DeepJournal's supported AI path encrypts request and response bodies between the desktop client and an attested trusted execution environment. The DeepJournal proxy forwards the encrypted body and does not parse ordinary AI prompt content.

Request headers and surrounding service metadata are not part of the encrypted body. Authentication, routing, selected endpoint, rate-limit state, timing, approximate request size, token usage, and billing information may therefore remain visible.

Plaintext is available inside the verified enclave while the model processes it. Confidential computing reduces access outside that environment; it does not eliminate trust in the client, verified enclave code, cryptographic protocol, hardware, or model behavior.

Third-Party AI Providers

If enabled by you, data may be processed under the privacy policies of those providers. End-to-end encryption protections do not apply.


9. Email Communications

We send essential service emails, including:

  • Account verification
  • Security notifications
  • Subscription updates
  • Legal or policy changes

These emails are necessary for providing the Service.


We may send:

  • Product updates
  • Feature announcements
  • Beta news
  • Journaling-related educational content

These emails are sent only if you provide explicit consent.

Consent is obtained via an unchecked opt-in checkbox during account registration or within account settings.

You may withdraw consent at any time by:

  • Clicking the unsubscribe link in any marketing email
  • Updating your preferences in your account
  • Contacting us directly

Unsubscribing from marketing emails does not affect service-related emails.


C. No Content-Based Marketing

We do not analyze or use your private journal content to generate marketing communications.

Marketing emails are based only on account-level information (such as subscription status or feature usage metadata).


D. Email Processing Providers

Marketing and service emails are delivered through:

  • Resend (email delivery provider)

These providers process personal data strictly under our instructions and in accordance with data protection laws.


10. How We Share Personal Data

We do not sell personal data.

We share limited data only with trusted service providers necessary to operate DeepJournal:

  • Hosting and infrastructure providers
  • Payment processor (Stripe)
  • Email delivery provider (Resend)

All providers are bound by contractual safeguards.


11. Data Retention

We retain:

  • Account data until account deletion
  • Encrypted journal data until deletion
  • Marketing consent records for as long as required to demonstrate compliance
  • Suppression lists (unsubscribed emails) to ensure we do not resend marketing emails

Technical logs are retained only as necessary for security and debugging.


12. Security Measures

We use industry-standard safeguards including:

  • End-to-end encryption
  • Encrypted local database storage
  • Confidential-computing protections for supported AI processing
  • Strong cryptographic algorithms
  • Secure infrastructure
  • Access controls
  • Encryption in transit

No system can guarantee absolute security, but DeepJournal minimizes data exposure by design.


13. Your Rights

Depending on your location, you may have the right to:

  • Access your personal data
  • Rectify inaccurate data
  • Delete your data
  • Export your data (subject to encryption limits)
  • Object to processing
  • Restrict processing
  • Withdraw consent
  • Lodge a complaint with a supervisory authority

Requests can be made via:

👉 support@deepjournal.app


14. International Transfers

Infrastructure is primarily located in the European Union.

Where data is transferred outside the EU, we rely on:

  • Contractual safeguards
  • EU adequacy decisions where applicable
  • Encryption as an additional technical measure

15. US State Privacy Disclosures

We do not:

  • Sell personal data
  • Engage in targeted advertising
  • Profile users for automated legal decisions

California residents may request disclosure of categories of personal data processed.


16. Changes to This Policy

We may update this Privacy Policy periodically.

The updated version will be published on our website with a revised “Last updated” date.


17. Contact

For questions regarding privacy or data protection:

👉 support@deepjournal.app