JotMood ("we", "our", or "the app") is operated by MB Djump, registered at Šilutės pl. 35G-36, LT-94105 Klaipėda, Lithuania. this policy explains what information we collect, how we use it, and how we keep your journal yours.
1. information we collect
| data type | purpose |
|---|---|
| email address | account creation and authentication |
| display name | user profile inside the app |
| mood entries, tags, gratitude text, journal text | core journaling functionality and AI insight generation |
| AI-generated insights | stored per user so you can revisit them |
| push notification token | optional daily journaling reminders |
| app usage events and device details (device type and maker, operating system, app version, screen size, approximate location derived from your IP address) | usage analytics, so we can see which features are used and improve them — PostHog, see section 5 |
| crash and error reports | finding and fixing crashes — Sentry, see section 5 |
2. information we do not collect
- we do not collect payment or card details. all payments are processed by Apple, Google, or RevenueCat.
- we do not access your contacts, photo library, or location.
- we do not read your journal entries. access is restricted to automated systems (database storage and the AI insight pipeline).
3. how we use your information
- to provide the core journaling features (moods, gratitude, freeform entries).
- to generate AI insights about your mood patterns and gratitude themes.
- to authenticate your account and sync data across your devices.
- to send the daily reminder, only if you opt in.
- to understand how the app is used (usage analytics) and to find and fix crashes (crash reports), so we can improve it.
4. data storage and security
your data is stored using Supabase with multiple layers of protection:
- row-level security (RLS) — every query is scoped to your authenticated user id; one user cannot reach another's entries at the database level.
- HTTPS / TLS — all data in transit between your device and our servers is encrypted.
- JWT authentication — every API request requires a valid token; anonymous access to journal data is impossible.
- we do not sell, rent, or share your personal data with any third parties.
5. third-party services
- Supabase — authentication, database hosting (with RLS), edge functions.
- OpenAI — AI insight generation, called via server-side edge functions only when you request an insight. your data is not used for model training.
- RevenueCat — subscription and payment management.
- PostHog (EU region) — usage analytics in the mobile app only. it records which screens you open and which features you use (for example: an entry was saved, an insight was requested, a purchase was started), with the app version, device and operating system details, and an approximate location (country, region, city) derived from your IP address — the IP address itself is not stored. the event for a saved entry also contains the mood and tags you picked; it never contains your gratitude or journal text. while you are signed in, events are linked to your account ID and email address. the website loads no PostHog.
- Sentry (EU region) — crash and error reports from the mobile app only, sent by release versions of the app when it crashes or runs into an error. a report contains the error and where in the code it happened, the app version, device model and operating system, and a short trail of the app's most recent technical events: screens opened, buttons tapped (named by their on-screen label, which can be a mood or tag name) and the web addresses of recent requests to our servers, which include your account's internal ID and — if you had just searched your journal — the search words. reports contain no email address, name or IP address, and never the text of your entries. Sentry also receives a signal when an app session starts and ends, so we can see how often the app crashes.
- Vercel — cookieless website analytics (page views only). this is the only analytics on the website.
- Apple / Google — sign-in providers and app store payments.
- Resend — transactional and contact-form email (sent from djump.io).
6. legal bases (GDPR)
where the GDPR applies, we process your data on these bases:
- contract (art. 6(1)(b)) — account, sync, and the core journaling features you sign up for.
- consent (art. 6(1)(a)) — optional daily reminders; you can withdraw at any time in settings.
- legitimate interest (art. 6(1)(f)) — keeping the service secure and preventing abuse, finding and fixing crashes (crash reports), and understanding how the app is used so we can improve it (usage analytics). you can object at any time. for usage analytics: in app version 1.0.2 and later you can turn analytics off in settings; in any version you can ask us by email to opt you out, and we will also delete the analytics data already linked to your account.
your journal, mood, and gratitude entries can reveal information about your emotional wellbeing, which the GDPR treats as special-category data (art. 9). we process them only to provide the journaling service you explicitly ask for — storage, sync, and the insights you request — on the basis of your explicit consent (art. 9(2)(a)). you withdraw that consent by deleting an entry or your account, and the processing stops with the deletion. two technical records described in section 5 also touch this data: the usage-analytics event for a saved entry includes its mood and tags, and a crash report can name the mood or tag you last tapped. neither ever contains the text of your entries.
7. international data transfers
some of the providers in section 5 process data outside the European Economic Area, primarily in the United States: OpenAI (insight generation), RevenueCat (subscriptions), Resend (email), and Vercel (website hosting and its cookieless analytics). where that happens, the transfer relies on the European Commission's Standard Contractual Clauses and, where the provider is certified, the EU–US Data Privacy Framework. our database (Supabase) is hosted in the EU, in Ireland. the mobile app's usage analytics (PostHog) use PostHog's EU region (eu.i.posthog.com), so that data is not transferred to the US. crash reports (Sentry) are stored in Sentry's EU region (de.sentry.io, Frankfurt, Germany); Sentry is a US company, and any access from outside the EU relies on the same safeguards.
8. data retention
- your account data and journal entries are kept for as long as your account exists.
- deleting an entry, or your whole account, removes the data from our production database immediately and irreversibly.
- JotMood shares its sign-in system with other apps made by MB Djump. deleting your JotMood account removes all JotMood data; your sign-in itself (email address) is removed too, unless you still use another MB Djump app with the same sign-in.
- encrypted infrastructure backups and server logs are kept briefly for security and disaster recovery and expire automatically on a rolling basis.
- text sent to OpenAI to generate an insight is used only to produce that insight and is not used to train models. OpenAI keeps API requests for up to 30 days for abuse monitoring and then deletes them.
- crash reports are deleted by Sentry automatically after its retention period (at most 90 days).
- usage analytics are kept in PostHog until we delete them. deleting your account in the app does not delete them automatically — email us and we will.
9. your rights
you may request access to, rectification, erasure, restriction of, or a portable copy of your personal data, object to processing based on legitimate interest (including usage analytics — see section 6), and withdraw consent at any time. you can delete your account and all associated journal data directly within the app under settings — deletion is immediate and irreversible — or write to start@djump.io. you also have the right to lodge a complaint with a supervisory authority — in our case the Lithuanian State Data Protection Inspectorate (vdai.lrv.lt) — or with the data protection authority of your own country.
10. children's privacy
JotMood is not intended for children under 13. we do not knowingly collect personal data from children under 13. if you believe a child has provided us with information, please contact us and we will delete it.
11. changes to this policy
we may update this privacy policy from time to time. material changes are announced in the app and reflected by updating the effective date at the top of this page.
12. contact
questions about this policy or how your journal data is handled: start@djump.io. this policy is also available in German, French, Japanese and Korean; if the versions ever differ, this English version prevails.