Privacy Policy
Effective August 30, 2026
Our approach
Balm is built privacy-first. We don't show ads, we don't sell your data, and we don't read your journal. This policy explains what we collect, why, and the choices you have. [Your Legal Name / Company](“we”) operates Balm.
What we collect
- Account information: your email address (and an optional display name) so you can sign in.
- Your journal: entries, mood, tags, folders, optional location, and any photos or videos you add. How this is stored depends on encryption (see below).
- Push subscriptions: if you turn on reminders, the browser push token needed to deliver them.
- Technical logs: standard server logs kept by our hosting and database providers (e.g. IP address, timestamps) to run and secure the service. We do not run third-party advertising or cross-site tracking.
Encryption & how your entries are stored
You can turn on a passphrase to enable end-to-end encryption. When it's on, your entry title, body, and location are encrypted on your device before they reach our servers, using a key derived from your passphrase that never leaves your device. This is zero-knowledge: we cannot decrypt or read that content.
- Encrypted (when enabled): entry title, body, and location.
- Not encrypted (by design, so search and filtering work): mood, tags, and folder names.
- Media: photos and videos are stored in a private bucket and served via short-lived signed URLs. They are protected by access controls but are not end-to-end encrypted.
- If you don't enable a passphrase, entries are stored unencrypted but still private to your account and protected by database access rules.
No recovery: if you enable encryption and forget your passphrase, your encrypted entries cannot be recovered by anyone — including us. That is what makes them private.
AI features (opt-in)
By default, nothing you write is sent to any AI model. When you explicitly opt in — by letting the companion read a recent entry, asking for a weekly reflection, or requesting tag suggestions — the relevant text is decrypted on your device and sent to our AI provider, OpenAI, to generate that response. This applies only to the specific text and request you initiate; entries you don't share are never sent. OpenAI processes the request under its API terms and, per its policy, does not use API data to train its models.
Service providers (subprocessors)
We rely on a small number of providers to run Balm:
- Supabase — database, authentication, and media storage.
- Vercel — application hosting.
- OpenAI — powers the opt-in AI features described above.
- BigDataCloud — converts coordinates into a place name when you add a location.
How we use your information
- To provide, secure, and improve the service.
- To deliver the AI features you opt into.
- To send reminders you turn on, and essential account emails.
We do not sell your personal information.
Retention & deletion
Your entries are kept until you delete them or close your account. Deleting an entry removes it (and its media) from our systems. You can request deletion of your account and associated data by contacting us at hello@balm.app.
Your rights
Depending on where you live (e.g. under GDPR or CCPA), you may have the right to access, correct, export, or delete your personal data, and to object to certain processing. To exercise these rights, contact us at hello@balm.app. Note that we cannot recover or provide content that is end-to-end encrypted, because we do not hold the key.
Children
Balm is not intended for children under 13 (or the minimum age required in your country). We do not knowingly collect data from children.
Security
We use encryption in transit, database access controls, and optional end-to-end encryption for your entries. No method of storage or transmission is 100% secure, but we design to minimize what we can access in the first place.
Changes
We may update this policy. If we make material changes, we'll update the effective date above and, where appropriate, notify you.
Contact
Questions? Email us at hello@balm.app.