Privacy policy
Last updated: 8 August 2026
The short version
Your journal is yours. We use what you write only to provide the features you choose, including an AI reflection only when you switch that option on. We never sell data, never show ads, and never use your writing to train AI models. You can download your data or delete your account yourself at any time.
A correction for beta testers
An earlier version of this policy said a custom encrypted backup ran with a retention window of up to 90 days. An infrastructure review found that job was not operating. We replaced that promise with verified automatic Prisma Postgres snapshots: one snapshot each day, retained for seven days. We have also completed a restore rehearsal. We found no indication that journal data was lost or accessed, and we are telling existing beta testers directly rather than silently changing the wording.
Who is responsible
Soul of Change is run by David Hoogland, based in the Netherlands. For anything about your data, write to hello@davidhoogland.com.
What we store
- Account information. Your email address and sign-in credentials, managed by our authentication provider (Clerk). We never see or store your password.
- What you write. Journal entries, daily reviews, therapy session notes, hard-conversation preparations, vow evidence, your characters, kept reading lines, and your settings. This includes reflections on your mental and emotional life — sensitive data that we process only because you choose to write it here, and only to provide the app to you.
- Pseudonymous usage events. Structure-only events (for example, that an entry was completed or a step was skipped) keyed by a pseudonym rather than your name or email. They never contain your words. The app can reproduce your pseudonym while your account exists so these events can be exported and deleted with it. The full list of what we measure — and cannot see →
- Notification subscription. If you turn on the morning notification, your device's push address and your chosen hour. No journal content is ever sent in a notification.
- Short-lived operational logs. For important actions such as export and account deletion, we log the action, your account identifier, and the time — never your journal content. On our current Vercel plan, runtime logs are retained for up to one hour.
Where it is stored, and who processes it
- Clerk — sign-in and account management.
- Vercel — application hosting.
- Prisma Postgres — the managed database and automatic daily provider snapshots.
- Anthropic — only if you switch on AI reflections in settings. A summary of your entries is then sent per request to generate a reflection, scoped to you alone, and not used to train models. Leave the toggle off and nothing is ever sent.
These providers process data on our behalf to run the service — they are not permitted to use it for their own purposes.
Why we use it
- Account data: to provide and secure the invited beta service.
- Your journal and other sensitive reflections: only with your explicit consent, to provide the journaling features you choose. You can withdraw that consent by deleting your account.
- Pseudonymous usage events: our legitimate interest in understanding whether the beta works and fixing it, using structure-only data that is kept separate from journal content.
- Optional AI reflections: only when you deliberately enable and request them.
How long we keep it
- Your live content: until you delete an entry or your whole account.
- Notification subscription: until you turn notifications off or delete your account.
- Operational logs: up to one hour on our current Vercel plan.
- Provider snapshots: Prisma Postgres creates one automatic snapshot each day and retains snapshots for seven days. Content deleted from the live database can therefore remain in a recovery snapshot for up to seven days before it expires.
- Pseudonymous usage events: at most 24 months, and deleted sooner when you delete your account.
Your rights
- See and take your data: Settings → Your data downloads a complete JSON copy, including your pseudonymous usage events. CSV and readable Markdown are journal-only formats. No email request is required.
- Delete your account: Settings → Delete account removes your journal, other content, notification subscription, pseudonymous usage events, and Clerk account from the live systems. The deletion event can remain in a short-lived operational log for up to one hour, and recently deleted content can remain inside expiring provider snapshots for up to seven days. Deleting the account also withdraws your consent.
- Correct anything: every entry can be edited or deleted in the app.
- Complain: if you believe we handle your data wrongly, contact us — and you always have the right to complain to your data-protection authority (in the Netherlands: Autoriteit Persoonsgegevens).
What we never do
- Sell or share your data for advertising. There are no ads and no third-party trackers.
- Use your writing to train AI models.
- Browse your journal for curiosity, evaluation, or research. Production access is limited to what is necessary to keep the service running or respond to a request or security incident.
Cookies
Only the cookies needed to keep you signed in (set by Clerk). No advertising or cross-site tracking cookies.
Changes
If this policy changes in a way that matters, we will tell current users directly or prominently in the app. The date at the top always tells you when it last changed.