JournalScan

Privacy Policy

Last updated: 21 May 2026

What we collect

  • Account data — email (magic link sign-in) and, if you choose social login, basic profile fields from that provider (e.g. name, email, profile picture URL from Google or Facebook).
  • Journal activity — upload dates, template names, categories, tags, streak statistics, and optional OCR text derived from your scans.
  • Journal archive — encrypted OAuth tokens and folder identifiers for Google Drive, Dropbox, or OneDrive when you connect a cloud vault; a local folder handle is stored only in your browser (IndexedDB) for desktop/Android Obsidian vault sync.
  • Notion connection (optional) — encrypted OAuth tokens and workspace/database identifiers when you enable Notion mirroring.
  • Billing — if you subscribe, payment-related identifiers handled by Stripe (we do not store full card numbers).
  • Scan images — temporarily stored so attachments can be written to your vault or Notion during an upload; we remove them after the flow completes.

How we use data

We use your data to authenticate you, save journal entries to your chosen archive (Obsidian-compatible Markdown in a local or cloud vault), optionally mirror entries to Notion, show your dashboard (streaks, activity calendar, history), run OCR and AI-assisted tagging when you upload, process subscriptions, and respond to support requests. We do not sell your personal data.

Service providers

We rely on trusted processors, including:

  • Supabase (authentication and database)
  • Notion (optional mirror when enabled)
  • Google Drive, Dropbox, or Microsoft OneDrive (when you connect a cloud vault)
  • Anthropic (server-side vision/OCR and coaching when enabled)
  • Stripe (payments)
  • Resend (contact form and product-update email, if you use those features)
  • Sentry (error monitoring — stack traces and technical diagnostics; we do not send journal text or images)
  • PostHog (product analytics — page views and usage events; we do not log OCR text or journal content)

If you sign in with Facebook, Facebook processes your login according to Meta's Privacy Policy. We only receive what you authorize through Facebook Login.

Your choices

You can export upload history from Settings (when available), disconnect archive or Notion integrations, sign out, or delete your account and server-side data. See our data deletion instructions. Content already written to your vault or Notion workspace remains under your control in those services.

Contact

Questions about this policy: use the contact page.

Contact us · Privacy policy · Data deletion