Privacy Policy
Last updated 13 September 2026
1. Who we are
Gratitude Journal Diary ("the app") is a mobile application published by Flit Soft. The app lets you write down moments you are grateful for, attach photographs to them, look back over them, talk them through with an AI companion, and — only if you choose to — share individual entries with friends.
This policy explains exactly what the app collects, where it is stored, who it is sent to, and how to get rid of it. Questions go to flitsoft.dev@gmail.com.
2. Information you give us
Account details. When you sign in, we receive your email address, your display name and your profile picture from the sign-in provider, and we store them together with the account identifier that provider issues. We never see or store your password.
Journal entries. The text you write, the mood you tag it with, the moment you say it happened, and whether you marked it a favourite. You can write as many entries in a day as you like.
Photographs. Up to ten images per entry. They are stored under your account and shown only in your own journal, unless you share that entry.
Focus Room conversations. The messages you send to the Focus Room and the replies it sends back are stored so the conversation is still there when you return to it.
Social activity, if you use it. An entry you choose to post, whether you posted it under your name or anonymously, likes and comments you leave, the friends you connect with, invites you send, and anyone you block or report.
Settings. Your reminder time, your notification switches, your quiet hours, and who is allowed to see your streak.
3. What the Focus Room sends to an AI model
This is the part you should read carefully.
When you send a message in the Focus Room, that message is sent to OpenAI and processed by the model gpt-5.4 to write a reply. Along with it we send a short profile summary — things like how many entries you have written and your recent moods — and, when answering your question requires it, the text of specific entries of your own. Entries reach the model only through that request; the model has no standing access to your journal.
Only your own entries are ever sent. An entry belonging to another member is never sent to the model on your behalf, and any entry the reply quotes is checked against the entries you own before it is shown to you.
Photographs are not sent to the AI model. The Focus Room works on text only.
Before your message reaches the model, it is screened for signs that you may be in danger. If it matches, the app shows you helpline information. This screening happens on our server and runs whether or not the model is reachable.
The Focus Room is not a therapist, a doctor or a crisis service, and its replies are not medical advice.
There is a limit of 60 Focus Room messages per account per day.
4. Information we do not collect
The app contains no analytics SDK, no advertising SDK and no third-party tracking. We do not collect your location — the app requests no location permission at all. We do not access your microphone. We do not read your photo library in the background; the system photo picker and camera hand us only the specific images you choose.
5. Where your data is stored
Image files are stored in Google Firebase Storage. The database only ever holds the address of an image, never the image bytes.
Everything else — your account record, entries, Focus Room conversations, posts, comments, friends and settings — is stored in a PostgreSQL database hosted by Supabase, in the United States (US East, N. Virginia).
Authentication is handled by Google Firebase Authentication.
Traffic between the app and our servers is encrypted in transit with HTTPS.
6. Third-party services
Google Firebase Authentication — signs you in and issues the token that identifies you to our backend.
Google Firebase Storage — stores your image files.
Supabase — hosts the PostgreSQL database holding your journal and account records.
OpenAI — processes Focus Room messages, as described in section 3.
Apple Push Notification service and Firebase Cloud Messaging — deliver the notifications you have switched on. We store the push token your device issues so we can reach it.
Each of these providers operates under its own privacy policy and processes your data on our instructions in order to run the app.
7. Who else sees your journal
By default, nobody. Your entries are private to your account. We do not sell them, we do not publish them, and we do not show them to other members.
Sharing is per entry and always a deliberate act. When you post an entry to the timeline you choose whether it carries your name or is anonymous. An anonymous post hides your identity from other members; we still know it is yours, because you must be able to delete it. Delete a shared entry and its post goes with it.
Your streak has its own visibility setting — everyone, friends only, or nobody — and it is separate from your entries. Making your streak visible never reveals what you wrote.
You can block another member at any time. A block is mutual: they cannot see you and you cannot see them.
If you create an API key inside the app for your own programmatic access, that key can read your own data and nobody else's. We store only a SHA-256 hash of the key and a short visible prefix; you see the full key once, when you create it. You can revoke a key at any time.
8. How long we keep it
We keep your data for as long as your account exists. Delete an entry, a photo or a post and it is removed. Delete your account and we remove the stored image files first, then the account record and everything attached to it — entries, photos, Focus Room conversations, posts, comments, friendships and API keys.
Account deletion is permanent and is not reversible.
9. Your rights
You can read every entry the app holds about you from inside the app, edit or delete any individual entry, photo, comment or post, change who can see your streak, and delete your whole account at any time from the account settings screen.
Depending on where you live you may also have the right to request a copy of your data, to have it corrected, or to object to its processing. Write to flitsoft.dev@gmail.com and we will respond within 30 days.
10. Children
The app is not directed at children under 13 and we do not knowingly collect their data. If you believe a child has created an account, contact us and we will delete it.
11. Changes to this policy
If we change how the app handles your data — in particular if we add a service that receives your entries — we will update this page and change the date at the top. Material changes will also be announced inside the app.
12. Contact
Email flitsoft.dev@gmail.com for anything at all: a privacy question, a data request, or a mistake you spotted on this page.