Hearth

Privacy Policy

Last updated 2026-07-31

The short version: Every entry is encrypted before it's stored, and we don't read your journal. AI features see an entry only for the moment it takes to help you, and nothing on that path is kept — by us, or for training. And if "we don't" isn't enough for you, one free switch — Private Vault — deletes our copy of your key so that not even we can read it, with one exception you turn on yourself, per letter, described below.

This policy explains exactly what we store, when content is processed, and the choices that are yours to make.

Encryption and your key — the two modes

All of your writing (journal entries, Unsent Vault messages, Future Me letters) is envelope-encrypted in your browser and stored only as ciphertext, in both modes. The difference is who holds the key:

  • Managed (the default). Your device creates your key and gives us one sealed spare copy. That's what lets signing in unlock your journal (nothing to memorize, nothing to lose) and lets the AI features below work. We use the spare key only to unlock your vault for your session and to answer the questions you route through the AI connector — each use is transient, logged as a content-free audit event, and nothing decrypted is ever stored.
  • Private Vault (free, on every plan). You set a passphrase, and our spare key is deleted in the same moment. From then on we are cryptographically unable to read or recover your journal — not our team, not our servers, not an AI, not anyone who might compel or breach us. The trade: if you lose your passphrase and recovery key, your data is gone, by design, and server-side AI features stop working.

There is one deliberate exception, and it only happens if you ask for it: a Future Me letter you choose to have emailed to you in full. When you pick that option — per letter, never as a default, and spelled out on the compose screen at the moment you choose — your device hands us a key to that one letter and nothing else, so we can post it to you on its delivery day. We open it for that one send, then destroy the key. Every other entry stays sealed, your main key is never involved, and letters left on the default setting are never readable by us at all. Email isn't encrypted, so treat a letter delivered that way like any other letter in your inbox.

You can switch modes either way in Settings, anytime.

What we store

  • Your account: your email address, and your password kept only as a one-way Argon2id verifier (never the password itself). If you sign in with Google, a Google account identifier instead.
  • Encrypted content + wrapped keys: the ciphertext of your entries and the sealed copies of your key (including, in managed mode, the spare copy described above). If you opted a Future Me letter into full-text email delivery, we also store the single-letter key described above until that letter is sent, and then delete it.
  • Minimal metadata: which kind of entry (journal, unsent, future), timestamps, a Future Me delivery date, your plan, and your language. This is what makes lists, limits, delivery, and streaks work. It contains no content and no inferred mood or sentiment.
  • Consent records: the timestamps of your terms attestation and your AI disclosure choice.
  • Support tickets: if you write to us, we keep your message and basic technical context (page, browser, language) so we can actually help. Please don't paste private journal text into one — we never attach your entries, and we never attach a screenshot. If you write from the help page without signing in, we store a one-way hash of your IP address rather than the address itself. We delete tickets 180 days after they're resolved, and in any case 365 days after they're opened.
  • Billing: handled by Dodo Payments, our Merchant of Record. Dodo Payments sells our subscriptions and processes payments, billing, and sales tax; we keep only a customer/subscription reference and your plan status, and we never see or store your card details.

The AI features (on by default, with your explicit consent first)

Hearth is an AI journal. Before you can write a word, a consent screen explains the following and records your choice — nothing is processed until you've made it, every feature has an off switch in Settings, and accounts registered as 16–17 start with AI off and must turn it on explicitly.

  • Inkling's memory: each new entry is sent briefly to our AI provider to update a short private summary of what's going on with you. Nothing on that path is logged or kept by us or the provider — the provider processes it with zero retention and no training; the summary is re-encrypted on your device and stored only as ciphertext. Free accounts get a daily allowance; paid plans get more.
  • Ask your journal (MCP connector, paid plans): you can link your own AI assistant (e.g. ChatGPT or Claude) and let it ask your journal questions. To answer, our server decrypts the relevant entries transiently using the managed spare key — never storing the plaintext, never logging it, with a daily budget on how much can be read. What the assistant reads becomes part of your conversation history with that provider — that's your provider relationship, governed by their terms. Works in managed mode only; you approve the exact permission ("read your full journal") on a consent screen when you connect the app, and you can disconnect it anytime.
  • Explicit sharing: independently of the above, you can publish a specific slice (a summary or hand-picked entries) for your assistant to read. What you publish is plaintext to that assistant, expires automatically, and can be revoked in one tap.

Turning AI off stops all server-side processing of your content. Switching to Private Vault additionally makes it impossible.

Who else is involved

We use a small set of processors, each under a data-processing agreement:

  • Dodo Payments — our Merchant of Record. It sells our subscriptions and handles payment, billing and sales tax, receiving your billing details and purchase history. Never journal data.
  • Resend — transactional and opt-in email (login codes, the weekly report).
  • Google Cloud — our hosting and database provider (servers in the EU), and Google Cloud Vertex AI as the AI provider on the paths above.
  • Google — Google sign-in, if you choose it.
  • RevenueCat — subscription receipts for purchases made inside the mobile apps.
  • Expo — relays push notifications for the mobile apps. It receives your device push token; notification content is metadata-only by construction (dates and counts, never your words).
  • Your browser vendor's push service — a web push notification is delivered through the endpoint your own browser gives us (Google, Mozilla or Apple, depending on your browser). The payload carries dates and counts only.
  • Discord — receives our operational error alerts. These carry technical metadata (which route failed, a pseudonymous account identifier) and never your email address or journal content.

We don't sell your data, use it for advertising, or allow any processor to train on it.

Zero retention, precisely. Our AI provider is configured not to retain or train on what we send it for Inkling's memory, Inkling Chat, and voice transcription — those are processed and discarded. That is not the whole picture, and the exception matters: if you build an AI Twin and upload documents to it, those documents are stored in an AI search index at that provider for as long as your twin exists, because that is what lets your twin answer from them. They are material you chose to publish, never your journal.

Where your data is processed

We host in the European Union and choose EU regions for our processors where they offer them. Some of the companies above are US-based or have US parent companies, so some processing may involve a transfer outside the EEA/UK. Where that happens we rely on the safeguards each provider offers — an EU-US Data Privacy Framework certification where they hold one, and Standard Contractual Clauses otherwise. (Per-vendor safeguards are being confirmed with counsel; this section will name each one.)

Why we're allowed to do this (lawful bases)

Under the GDPR we rely on:

  • Your consent for the AI features. Journal content is special-category data in practice — people write about their health, their beliefs, their relationships — so the AI paths run on your explicit consent, asked for on a screen before your first entry and withdrawable at any time in Settings (or absolutely, by switching to Private Vault).
  • Performance of our contract with you for running the service itself: your account, storing your ciphertext, delivering a Future Me letter, billing your subscription.
  • Our legitimate interests for keeping the service up and safe: rate limiting, abuse prevention, error alerting, and the technical logs that make an outage debuggable. These are metadata-only by design.
  • Legal obligation where one applies, such as tax records for a purchase.

The AI Twin (only if you make one)

The AI Twin is opt-in and public by design: a chatbot that answers as you, on a page anyone can visit. Because it is public, it works differently from the rest of Hearth and it is worth being exact:

  • It speaks only from what you gave it — the persona profile you wrote and the documents you uploaded. Your journal is not part of it. (There is one exception, separately consented and step-up-gated, which you switch on yourself: live grounding, managed mode only.)
  • Uploaded twin documents persist in an AI search index at our AI provider for as long as your twin exists, and are deleted when you delete the twin or your account. This is the one place we hold text that is not encrypted-at-rest ciphertext — because you published it.
  • We keep no visitor transcripts. Messages people send your twin are processed to answer and not stored.
  • Visitors are rate-limited by IP, and if someone reports your twin we store a one-way hash of their IP address rather than the address.
  • Every reply is labelled as coming from an AI. That is not configurable.

How long we keep things

  • Your entries, and your account: until you delete them. We don't expire your journal.
  • Deleting your account is crypto-erasure: we destroy every stored copy of your key, so the ciphertext that remains anywhere is permanently undecryptable — by us or anyone else.
  • Backups are kept on a rolling short-term schedule for disaster recovery and age out on their own. Because a backup contains ciphertext and the keys are destroyed on deletion, a deleted account's content is unreadable in a backup too.
  • Devices: a device you have signed out of, or stopped using, disappears from your device list 180 days after it was last seen. A device you are still signed in on stays.
  • Support tickets: 180 days after they're resolved, and in any case 365 days after they're opened.
  • Login codes, sessions and security counters: hours to days, swept automatically.
  • AI-share slices and staged drafts: short-lived by design, physically deleted on expiry.

The mobile apps

The iOS and Android apps follow the same architecture as the web app — entries are encrypted on your device before upload, and the two custody modes work identically. Mobile-specific details: your sign-in session and (if you enable biometric unlock) your vault key live in the device's hardware-backed secure storage (Keychain / Android Keystore), protected by Face ID / biometrics on your device — biometric data itself never leaves your phone and we never see it. Push notifications are optional, asked in context, and carry only dates and counts. You can delete your account from inside the app (Settings → Delete my account) or from the web; both perform the same crypto-erasure.

Cookies & local storage

We use a single strictly-necessary cookie to keep you signed in (an httpOnly session cookie). We store small preferences — your language, theme, and similar — in your browser's local storage. No advertising or third-party tracking cookies.

Two things also live in your browser's sessionStorage, which is per-tab and cleared when you close it: your vault key while you are signed in (so a reload doesn't ask you to unlock again), and any entry you are part-way through writing — the draft is encrypted with your own key before it is stored, so what sits there is ciphertext, not your words. Both are wiped when you lock, sign out, or close the tab.

Keeping and deleting your data

You can export your decrypted data at any time, from your device. When you delete your account, we perform crypto-erasure: we destroy every stored copy of your key — including the managed spare copy — which makes all of your stored ciphertext permanently undecryptable, by anyone, including us; and we cascade-delete your sessions, connected apps, and AI data. The short-lived plaintext used by explicit sharing is auto-expired and swept. Support tickets are kept but anonymised — your email is scrubbed from the ticket and from any reply we sent, and the account link is removed — and they are deleted entirely on the schedule above.

Your rights

Subject to applicable law (including the GDPR), you can access, export, correct, or delete your data, object to or restrict certain processing, and withdraw your AI consent at any time — with the Settings toggle, or absolutely, by switching to Private Vault. Some of these you exercise directly from your device. To make a request, contact us at privacy@usehearth.ink.

Age

Hearth is intended for people aged 16 and older. It is not directed at children under 16, and we don't knowingly create accounts for them. Accounts registered as 16–17 start with all AI features off.

A note on care

Hearth is a journaling space, not a medical service, crisis line, or substitute for professional help. A link to crisis resources is always one tap away. We do not monitor the content of your journal — and in Private Vault mode, we cannot.

Where your data lives

We host in the European Union and use processors configured for EU data residency where applicable.

Changes

We may update this policy; we'll change the "last updated" date above and, for material changes, let you know in the app.

Contact

Hearth — privacy@usehearth.ink. If you're in the EU/UK and have concerns, you also have the right to complain to your local data-protection authority.