Privacy Policy
Luna Journal ("the App", "we", "our") is a voice journaling application developed by Benjamin Jacquet, trading as Novaire Digital (ABN 24 349 309 268) ("Developer"). This Privacy Policy explains what data we collect, how we use it, and your rights as a user.
1. Who we are
Luna Journal is an independent application. For privacy questions, contact contact@novairedigital.com.
2. Data we collect and why
2.1 Audio recordings
- What: When you use the recording feature, the App captures audio through your device microphone.
- Why: To transcribe your journal entries into text.
- How it is processed: The audio is sent over an encrypted connection to our processing service (a Cloudflare Worker operated by Novaire Digital), which forwards it to the OpenAI Whisper API and returns the text. Our service does not store your audio or transcript; it retains only anonymous usage counts (see 2.6).
- Storage: Audio files are stored locally on your device, not on our servers. Transcribed audio older than 30 days is automatically deleted from your device (the transcript is kept).
- Retention: Audio remains on your device until it ages out (30 days after transcription), or until you delete the entry or uninstall the App.
2.2 Journal entries, transcripts and AI reflections
- What: The text of your entries, whether spoken (transcribed) or typed directly, plus AI-generated reflections (persona voices, title, emoji, mood summary, tags) and weekly and monthly recaps.
- Why: To power the journaling experience: storing your entries locally and generating personalised reflections.
- Storage: All journal data is stored in a local database (Isar) on your device. It is not stored on our servers.
- Third-party AI:Entry text is sent, via our processing service, to the OpenAI API. Our service does not retain this text. OpenAI's privacy policy applies: openai.com/policies/privacy-policy.
2.3 Photos (optional)
- What: Images you choose to attach to a journal day, from your photo library or your camera.
- Why: To let you keep photos alongside the day you journaled.
- Storage: Photos are stored locally on your device. If you enable Google Drive backup (2.7), your photos are also uploaded to your own Google Drive, in a folder only the App can access. Photos are not stored on our servers. Deleting a photo in the App also removes it from your Drive on the next backup.
2.4 Google Sign-In and account data
- What: Your Google account email, display name, and unique user ID. On iOS you may sign in with Apple instead, or use the App as a guest.
- Why: To authenticate you securely via Firebase Authentication without storing passwords, and to associate usage counts with an account so daily limits apply. Guest use runs on an anonymous Firebase identity that carries no personal details.
- Storage:Firebase Authentication processes this data. We store only a local reference to your user ID. Firebase's privacy policy applies: firebase.google.com/support/privacy.
2.5 App lock (optional)
- What: If you enable the app lock, a PIN you choose (stored only as a salted one-way hash) and, if you turn it on, use of your device biometrics (fingerprint or face) to unlock the App.
- Why: To keep your journal private on your device.
- Storage:The PIN hash is stored only in your device's secure keystore. It never leaves your device and is never included in any backup. Biometric matching is performed by your device's operating system; the App never receives your biometric data.
2.6 Usage and cost metering
- What: Per-user daily counts of transcription seconds and reflection requests, an estimated processing cost, and your Firebase user ID. No entry content, audio, transcript, or photo is included.
- Why: To enforce fair daily usage limits and to understand aggregate processing costs.
- Storage: Held by our processing service on Cloudflare infrastructure, keyed to your Firebase user ID, and retained only briefly (daily counters expire automatically). Not used for advertising or profiling.
2.7 Google Drive backup (optional)
- What: A backup of your journal entries and reflections plus your attached photos.
- Why: To provide cloud backup and restore, if you enable Drive integration.
- Storage:Files are written to your personal Google Drive account under a "Luna Journal" folder. We access only files the App creates. Google's privacy policy applies: policies.google.com/privacy.
2.8 Notion integration (optional)
- What: Your Notion authorisation token and destination database ID, if you choose to connect Notion.
- Why: To sync your journal entries, reflections and photos to a Notion database of your choice.
- Storage:The token is stored in your device's encrypted secure storage. It is never sent to our servers. Notion's privacy policy applies: notion.so/Privacy-Policy.
2.9 Subscription data (RevenueCat)
- What: Purchase receipts and subscription status for premium features.
- Why: To verify your subscription entitlement.
- Storage:Processed by RevenueCat. We receive only an entitlement status (premium or free). RevenueCat's privacy policy applies: revenuecat.com/privacy.
2.10 Analytics
We do not collect analytics, advertising identifiers, or crash telemetry beyond the sign-in events Firebase Authentication inherently records and the anonymous usage counts described in 2.6.
3. How we share your data
We do not sell, rent, or share your personal data with third parties for marketing or advertising purposes.
Data is shared with the following services only as described above:
- Novaire Digital processing service (Cloudflare Worker): relays audio and text to OpenAI and stores anonymous usage counts; stores no entry content
- OpenAI: audio (transcription) and text (reflections), via our processing service
- Google / Firebase: authentication
- Google Drive: if you enable Drive backup (entries and photos, to your own account)
- Notion: if you enable the integration
- RevenueCat: subscription management
4. Permissions
The App may request the following permissions:
We do not request access to your contacts, location, or calendar.
5. Data storage and security
- All journal data (entries, transcripts, reflections, recaps, photos) is stored locally on your device. Entry content is never stored on our servers.
- Our processing service relays AI requests and stores only anonymous per-user usage counts (see 2.6). It does not store or log your entry content.
- Secrets such as your Notion token are stored in your device's secure keystore.
- The optional app-lock PIN is stored only as a salted hash in the secure keystore and is never backed up.
- All network communication uses HTTPS (TLS). Cleartext HTTP is disabled.
6. Children's privacy
The App is not directed at children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us and we will delete it.
7. Your rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you
- Request deletion of your data
- Withdraw consent at any time
Since journal data is stored locally on your device, you can delete it at any time by deleting entries, using the in-App "Delete account" option, clearing the App's data, or uninstalling the App. For data held by third-party services (OpenAI, Firebase, RevenueCat, Google Drive, Notion), refer to their respective privacy policies.
Deleting your account and data
If you signed in with Google, you can permanently delete your account and all associated data directly in the App: go to Settings, then "Delete account". This removes your authentication record and erases the journal data stored on your device. Uninstalling the App also removes all local data. To request deletion by email instead, contact contact@novairedigital.com and we will action your request.
For any privacy requests, contact contact@novairedigital.com.
8. Changes to this policy
We may update this Privacy Policy from time to time. We will notify you of significant changes via an in-app notice or by updating the "Last updated" date above.
9. Contact
Developer: Benjamin Jacquet, trading as Novaire Digital
ABN: 24 349 309 268
Email: contact@novairedigital.com