Privacy Policy
Effective 26 September 2026
- DayJournal works without an account. Signed out, nothing you write leaves your device.
- If you sign in, your handwriting and notes are stored on our sync server so they reach your other devices. That is the only reason we hold them.
- Your calendar events never reach our server.
- No ads, no analytics, no tracking, and we never sell or share your data for advertising.
- You can delete your account, and everything synced to it, from inside the app at any time.
Who we are
This policy covers the DayJournal app for iPhone and iPad, its sync server, and this website, dayjournal.app. DayJournal is made by Pathompong Puengrostham (“we”, “us”), who is responsible for your data under this policy. You can reach us at support@dayjournal.app.
On your device
Everything you make in DayJournal — handwriting, text boxes, pages, notebooks, folders — and your settings are stored in the app’s own storage on your device. It is included in your device’s backups (iCloud Backup or a computer backup) the way any app’s data is, under your Apple account and not ours.
Your calendar
If you allow calendar access, DayJournal reads and writes events through iOS’s Calendar, so the events you see and make go to the calendar accounts you have already set up on your device (such as iCloud, Google or Exchange). DayJournal does not send your events, or anything about them, to our server. You can turn calendar access off at any time in iOS Settings › Privacy & Security › Calendars.
If you sign in to sync
Signing in is optional. It exists to carry your handwriting between your own devices. When you sign in, we collect:
| What | Why |
|---|---|
| Your email address | To send you a sign-in code if you sign in with email, and to show you which address each sign-in method uses. If you sign in with Apple or Google, they tell us the address on that account — with Apple, you can choose to share a private relay address instead of your own. |
| An account identifier, and the identifier Apple or Google gives your account with them | To recognise your account when you sign in again. We never see your Apple or Google password, and we ask them for nothing beyond your identity and email address. |
| If you sign in with Apple, a token Apple issues for your sign-in | For one thing only: to tell Apple to withdraw DayJournal’s access to your Apple sign-in when you delete your account. We never use it to ask Apple for anything about you. |
| A device identifier | A random identifier the app creates when it is installed, so the server can tell your devices apart and keep each one’s sign-in separate. It is not your device’s advertising identifier. |
| Your handwriting and notes | The strokes, text boxes, pages, notebooks and folders you create, with the dates they belong to and when they were changed — so they can appear on your other devices. |
All of it travels to our server over an encrypted connection (HTTPS) and is stored there. It is not end-to-end encrypted: our server can read what you sync, because it has to store it and send it back to your devices. We do not read, analyse or use your notes for anything other than syncing them.
Sign-in codes
When you ask for an email sign-in code, we record the address it was sent to, a one-way fingerprint of the code (never the code itself), and the IP address the request came from, so we can limit how often codes are sent and stop abuse. These records are deleted after one day. The code is emailed to you through our email delivery provider. The request also says which language the app is shown in, so the email can be written in it; that is used for nothing else and is not kept.
Server records
Like most servers, ours keeps an operational log of the requests it handles — the time, the kind of request, whether it succeeded, and an identifier for the request — so we can keep the service running and fix problems. These logs do not include the contents of your notes. We also keep aggregate counts (for example, how many sign-ins succeeded) that are not tied to any person.
Crash reports
If you have chosen to share analytics with app developers — in iOS Settings › Privacy & Security › Analytics & Improvements — Apple sends us reports of DayJournal’s crashes and hangs. Apple collects these under its own privacy policy. They tell us where in the app’s code a problem happened, with the app version, the device model and the iOS version, so we can fix it; they do not include your notes, your events or your account. DayJournal itself does not collect or send crash data. You can turn sharing off in that same setting at any time.
What we don’t do
- We don’t show ads, and we don’t use your data for advertising.
- We don’t put analytics, crash-reporting or tracking services in the app, and we don’t track you across other companies’ apps or websites.
- We don’t sell your data, and we don’t share it with anyone except the service providers below, who handle it only on our behalf.
Service providers
- Hosting — the company that runs the server your synced data is stored on.
- Email delivery — sends sign-in codes to the address you give.
- Monitoring — stores the server’s operational logs and aggregate counts.
- Apple — if you choose “Continue with Apple”, Apple handles that sign-in under its own privacy policy.
- Google — if you choose “Continue with Google”, Google handles that sign-in under its own privacy policy.
- Cloudflare — serves this website and protects our servers from attacks. It processes the IP address of anyone who connects, under its own privacy policy.
Your data may be processed in countries other than your own. Wherever it is, it is protected as this policy describes.
How long we keep it
- Your account and synced notes: until you delete your account. Something you delete in the app is deleted from your other devices and marked deleted on the server.
- Sign-in code records (the address, the code’s fingerprint and the requesting IP address): one day.
- Sign-ins: a device stays signed in for up to 60 days without being used; after that it has to sign in again.
- Deleted accounts: removed from the server at once. So that your other devices can be told the account was deleted, we keep a one-way fingerprint of each of their sign-ins, with nothing that links it to you, until that sign-in would have expired (at most 60 days). If you signed in with Apple, the token Apple issued is kept only until Apple confirms it has withdrawn DayJournal’s access — normally seconds, and never more than two weeks if Apple cannot be reached. If we hold backups of the server, deleted data is removed from them within 30 days.
Deleting your data
In the app, open Settings and choose Delete account. This permanently deletes your account, its sign-in methods and everything synced to it from our server, straight away, and if you signed in with Apple it withdraws DayJournal’s access to your Apple sign-in. It does not delete what is on your devices: your handwriting stays on each device until you delete it or remove the app. Your other devices are signed out the next time they connect.
Signing out, rather than deleting, stops sync on that device and leaves your account and your notes where they are.
Your rights
Depending on where you live, you may have the right to ask for a copy of your data, to correct it, to have it deleted, or to object to how it is used. You can delete everything yourself from the app; for anything else, email support@dayjournal.app from the address on your account and we will answer within 30 days. You can also complain to your local data protection authority.
Children
DayJournal is not directed at children under 13, and we do not knowingly collect personal information from them. If you think a child has given us information, contact us and we will delete it.
This website
dayjournal.app sets no cookies and runs no analytics or third-party scripts. Cloudflare, which serves it, sees the IP address and browser details of each visit in order to deliver the page and keep the site secure.
Changes
If we change this policy, we will update the date at the top of this page, and tell you before a change that affects data we already hold takes effect.