DeepJournal Privacy Policy
Last updated: July 15 2026
1. Introduction
DeepJournal is a privacy-first AI journaling application. It combines an encrypted local database, end-to-end encryption (E2EE) for synced sensitive content, and confidential-computing protections for AI request and response bodies.
These protections do not make all account, synchronization, or usage metadata invisible. This Policy explains both the protections and their limits.
This Privacy Policy explains how Andicop (“DeepJournal”, “we”, “us”, or “our”) collects, uses, stores, and protects personal data when you use DeepJournal’s applications, website, and related services (the “Service”).
This Policy is designed to comply with:
- The EU General Data Protection Regulation (GDPR)
- The French Data Protection Act
- The Swiss Federal Act on Data Protection (FADP)
- Applicable US state privacy laws
By using the Service, you acknowledge that you have read and understood this Privacy Policy.
2. Who We Are
Company name: Andicop
Country of incorporation: France
Andicop is the data controller for personal data processed through DeepJournal.
For privacy-related inquiries:
We are not required to appoint a Data Protection Officer under Article 37 GDPR.
3. Minimum Age
DeepJournal is not intended for users under 16 years of age.
We do not knowingly collect personal data from children under 16. If we become aware of such data collection, we will delete the data and close the account.
4. Personal Data We Collect
A. Account Data
- Email address
- Authentication credentials (password hashes)
- OAuth identifiers (Google, Apple, Microsoft if used)
- Subscription status and billing identifiers
Payments are processed by Stripe. We do not store full payment card details.
B. Journal Content and Encrypted Fields
- Journal entry content
- Names, summaries, descriptions, and importance fields for selected memories and threads
- Chat names, message content, and citations
- Local encrypted database files
- Wrapped encryption keys and recovery-wrapped key material
Configured sensitive fields are encrypted on your device before synchronization. DeepJournal's synchronization service stores ciphertext for those fields and does not receive the plaintext data-encryption key.
Some operational fields and tables are not covered by field-level E2EE. These include record identifiers, account identifiers, dates and timestamps, word counts, relationship records, settings, analysis status, chat roles, selected model names, and similar synchronization metadata.
The local journal database is encrypted at rest. Content is necessarily available to the application while the journal is unlocked, so local encryption cannot protect against an attacker controlling an unlocked device.
C. Technical and Usage Data
- App version
- Feature usage (non-content metadata only)
- Crash and error reports
- Basic web analytics
- AI model selection, request timing, request size, token usage, and cost metadata
We do not log IP addresses at the application level.
D. Communication Data
- Messages sent to support
- Email correspondence
- Marketing preferences (opt-in / opt-out status)
5. Lawful Basis for Processing
We process personal data under the following legal bases:
Contractual Necessity
To provide the Service (account management, authentication, syncing, AI features).
Legitimate Interests
To ensure security, prevent abuse, improve reliability, and maintain performance.
Legal Obligations
To comply with tax, accounting, and regulatory requirements.
Consent
For sending marketing or product update emails (see Section 9).
You may withdraw consent at any time.
6. How We Use Personal Data
We use personal data to:
- Provide and maintain the Service
- Authenticate users
- Process subscriptions
- Enable encrypted synchronization
- Provide customer support
- Improve performance and reliability
- Ensure security
- Send essential service communications
- Send optional product updates if you opt in
We do not use journal content for marketing purposes.
We do not train AI models on user journal data.
7. End-to-End Encryption & Data Access Limitations
DeepJournal uses end-to-end encryption for configured sensitive synced fields:
- Those fields are encrypted locally before upload and decrypted locally after download
- The synchronization service stores wrapped key material but not the plaintext data-encryption key
- Your encryption password is separate from your account password
- Operational metadata and unconfigured fields are not covered by this E2EE layer
If you lose your encryption password and recovery key, your data cannot be recovered.
We cannot provide plaintext copies of E2EE-protected fields on your behalf. Export functions that run inside your unlocked application may still allow you to export your own data.
8. AI Features and Data Processing
Confidential AI Mode
DeepJournal's supported AI path encrypts request and response bodies between the desktop client and an attested trusted execution environment. The DeepJournal proxy forwards the encrypted body and does not parse ordinary AI prompt content.
Request headers and surrounding service metadata are not part of the encrypted body. Authentication, routing, selected endpoint, rate-limit state, timing, approximate request size, token usage, and billing information may therefore remain visible.
Plaintext is available inside the verified enclave while the model processes it. Confidential computing reduces access outside that environment; it does not eliminate trust in the client, verified enclave code, cryptographic protocol, hardware, or model behavior.
Third-Party AI Providers
If enabled by you, data may be processed under the privacy policies of those providers. End-to-end encryption protections do not apply.
9. Email Communications
A. Service Emails (No Consent Required)
We send essential service emails, including:
- Account verification
- Security notifications
- Subscription updates
- Legal or policy changes
These emails are necessary for providing the Service.
B. Product Updates and Marketing Emails (Consent Required)
We may send:
- Product updates
- Feature announcements
- Beta news
- Journaling-related educational content
These emails are sent only if you provide explicit consent.
Consent is obtained via an unchecked opt-in checkbox during account registration or within account settings.
You may withdraw consent at any time by:
- Clicking the unsubscribe link in any marketing email
- Updating your preferences in your account
- Contacting us directly
Unsubscribing from marketing emails does not affect service-related emails.
C. No Content-Based Marketing
We do not analyze or use your private journal content to generate marketing communications.
Marketing emails are based only on account-level information (such as subscription status or feature usage metadata).
D. Email Processing Providers
Marketing and service emails are delivered through:
- Resend (email delivery provider)
These providers process personal data strictly under our instructions and in accordance with data protection laws.
10. How We Share Personal Data
We do not sell personal data.
We share limited data only with trusted service providers necessary to operate DeepJournal:
- Hosting and infrastructure providers
- Payment processor (Stripe)
- Email delivery provider (Resend)
All providers are bound by contractual safeguards.
11. Data Retention
We retain:
- Account data until account deletion
- Encrypted journal data until deletion
- Marketing consent records for as long as required to demonstrate compliance
- Suppression lists (unsubscribed emails) to ensure we do not resend marketing emails
Technical logs are retained only as necessary for security and debugging.
12. Security Measures
We use industry-standard safeguards including:
- End-to-end encryption
- Encrypted local database storage
- Confidential-computing protections for supported AI processing
- Strong cryptographic algorithms
- Secure infrastructure
- Access controls
- Encryption in transit
No system can guarantee absolute security, but DeepJournal minimizes data exposure by design.
13. Your Rights
Depending on your location, you may have the right to:
- Access your personal data
- Rectify inaccurate data
- Delete your data
- Export your data (subject to encryption limits)
- Object to processing
- Restrict processing
- Withdraw consent
- Lodge a complaint with a supervisory authority
Requests can be made via:
14. International Transfers
Infrastructure is primarily located in the European Union.
Where data is transferred outside the EU, we rely on:
- Contractual safeguards
- EU adequacy decisions where applicable
- Encryption as an additional technical measure
15. US State Privacy Disclosures
We do not:
- Sell personal data
- Engage in targeted advertising
- Profile users for automated legal decisions
California residents may request disclosure of categories of personal data processed.
16. Changes to This Policy
We may update this Privacy Policy periodically.
The updated version will be published on our website with a revised “Last updated” date.
17. Contact
For questions regarding privacy or data protection: