Privacy Policy - JustYap
Effective Date: June 18, 2026
Last Updated: July 03, 2026
This Privacy Policy explains how JustYap (“we,” “us,” or “our”) collects, uses, processes, and protects your information when you use the JustYap mobile application (“App”). By downloading, installing, or using the App, you consent to the practices described in this Privacy Policy. If you do not agree with any part of this policy, please do not download, install, or use the App.
IMPORTANT NOTICE: LOCAL-ONLY DATA ARCHITECTURE
JUSTYAP OPERATES ON A LOCAL-FIRST STORAGE MODEL. ALL VOICE JOURNAL RECORDINGS, DIARY ENTRIES, TRANSCRIPTS, INSIGHTS, NOTES, AND MOOD DATA ARE RECORDED AND STORED DIRECTLY AND EXCLUSIVELY ON THE LOCAL STORAGE OF YOUR PHYSICAL DEVICE.
WE DO NOT TRANSMIT, SYNC, STORE, BACK UP, OR REPLICATE YOUR JOURNAL DATA OR AUDIO RECORDINGS ON OUR BACKEND SERVERS. WE HAVE NO ACCESS TO, COPIES OF, OR CONTROL OVER YOUR DIARY DATA. IT IS YOUR EXCLUSIVE RESPONSIBILITY TO CREATE AND MANAGE BACKUPS USING THE OPTIONAL GOOGLE DRIVE BACKUP SYSTEM INTEGRATED IN THE APP. WE ASSUME ZERO RESPONSIBILITY OR LIABILITY FOR ANY PERMANENT LOSS, CORRUPTION, DELETION, OR STEAL OF YOUR PERSONAL JOURNAL CONTENT.
1. Who We Are
JustYap is a private voice journaling application owned, developed, and operated by Victor Lougon Sampaio Lopes, operating as JustYap. If you have any inquiries, suggestions, or requests regarding this Privacy Policy or your personal data rights, you may contact us at:
- Email: justyap.app@gmail.com
- Developer Name: Victor Lougon Sampaio Lopes
- Bundle Identifier: com.justyap.app
2. Information We Collect
We collect information in three ways: information you provide, information collected automatically, and device permissions.
2.1 Information You Provide
- Profile Display Name: During the App onboarding, you choose a display name (nickname). This name is stored locally on your device and in your user profile on our database servers.
- Voice Recordings and Text Journal Content (Processed Locally & Temporarily):
- On-Device Custody: All your audio recordings (Yaps), transcripts, summaries, and associated mood logs remain stored inside the App’s private directory on your device.
- Temporary AI Processing: When you request transcription, summarization, or recap generation, your audio files or text entries are securely transmitted via TLS encryption to our Deno Edge Functions (hosted by Supabase) which call third-party APIs (Groq and OpenAI). This content is processed entirely in-memory and is never permanently stored, cached, or saved on our backend servers. Once transcription/summarization is complete, the results are returned to your device and deleted from the RAM of our edge functions.
2.2 Information Collected Automatically
- Anonymous User ID: Upon first launch, the App creates an anonymous account via Supabase Auth and generates a random, non-identifying Unique Identifier (UID).
- User Profile Metadata: We store a basic profile record in our database containing: your UID, display name, subscription tier (
free,plus, orpremium), daily AI usage counts (to monitor and reset API limits), and timestamp details. We do not store your journal content in this profile.
- Device and App Technical Data: We collect basic, anonymous telemetry such as device model, operating system version, app version, and platform type through PostHog Analytics and Supabase to monitor system stability.
- Feature Usage Metrics: We utilize PostHog to track aggregate user interaction events (e.g. screen navigation, buttons clicked, settings toggled). Your private journal text and voice recordings are never sent to PostHog or any other analytics platform.
- Subscription Transactions: In-app transactions and subscription status are managed via RevenueCat. RevenueCat stores your anonymous UID, billing history, active entitlement details, and transactional receipts. RevenueCat never receives your voice recordings or journal entries.
- Daily Reminders: If you enable daily journaling reminders, the alarm time is stored locally on your device. Notification tokens are managed through Expo’s notification delivery network.
2.3 Device Permissions We Request
To provide the App’s core features, we require access to specific device permissions:
| Permission | Purpose |
|---|---|
| Microphone | Required to record your voice journal entries (Yaps). |
| Notifications | Optional. Used to deliver daily journaling reminders at your configured times. |
| Face ID / Touch ID / Biometrics | Optional. Used to lock the App. Authentication is handled locally by the OS (iOS Secure Enclave / Android Keystore). We never access or store your biometric data. |
| Local File System | Required to save temporary audio clips locally during recording and prepare database backups. |
2.4 Explicit AI Processing Permission
Before your first use of any AI feature, the App asks for your permission to send the content needed for that feature to trusted AI providers.
When you use AI features, the following data may be processed:
- Transcription: your selected audio recording is sent through JustYap's Supabase Edge Functions to Groq to create a transcript.
- Daily Summaries, Weekly Recaps, and Monthly Chapters: your transcript, typed journal text, summaries, dates, moods, and selected journal context needed for the requested feature are sent through JustYap's Supabase Edge Functions to OpenAI.
This processing happens only when you intentionally request an AI feature. The content is transmitted over HTTPS/TLS and is used only to provide the feature you requested. It is not used for advertising and is not used to train public AI models.
3. How We Use Your Information
We use the collected information for the following legal and operational purposes:
* Core Service Delivery: Allowing you to record, log, read, and manage your journal locally.
* AI Feature Processing: Providing automated speech-to-text transcriptions, summaries, weekly recaps, and monthly chapters through Groq and OpenAI.
* Subscription Verification: Verifying purchase history and enabling entitlements via RevenueCat.
* Analytics and App Improvement: Identifying application crashes, performance bottlenecks, and aggregate usage patterns via PostHog.
* Communication and Reminders: Delivering local or push notification reminders.
* Account Administration: Maintaining your basic profile settings and usage limits on Supabase.
* Local Export: Enabling you to export your data into images or PDFs directly on your device (we do not upload or store these exported documents).
4. Data Storage, Retention, and Deletion
4.1 Local Device Ownership
Because all your journal entries (Yaps), transcripts, summaries, and categories reside exclusively in your device’s local filesystem, we cannot retrieve, restore, export, or access your journal data. If you delete the App, lose your device, or experience physical hardware corruption, your data is gone permanently unless you have an existing backup.
4.2 Personal Google Drive Backups
If you configure the optional Google Drive Backup feature:
* All database files and voice recording files are zipped and uploaded directly from your device to your personal Google Drive storage space.
* We do not host, store, or monitor these backups. The files are hosted privately within your Google account, and your credentials do not pass through our servers.
4.3 Data Retention
- Profile Metadata: We retain your account identifier, display name, subscription tier, and usage counters as long as your account remains active.
- Account Deletion: You can delete your account at any time via the settings menu in the App or by contacting us at justyap.app@gmail.com. Upon receipt of a deletion request, we permanently delete your profile metadata and usage records from our Supabase servers within 30 days. Deleting your account from our servers will not automatically clear local data on your device; you must uninstall the App to erase local files.
- Analytics Retention: PostHog usage statistics are anonymized and retained for a maximum of 12 months before automatic deletion.
5. Third-Party Service Providers and Data Transfers
We partner with third-party processors to handle specific tasks. Each partner is bound by confidentiality and data protection laws:
- Supabase (Authentication, Backend Database, Edge Functions): Stores account profile metadata and handles routing of backend requests. Data is hosted securely on AWS in the United States.
- Privacy Policy: https://supabase.com/privacy
- OpenAI (AI Summarization & Recaps): Processes text transcripts to generate summaries and weekly/monthly recaps. OpenAI is contractually obligated not to use our API requests to train their language models.
- Privacy Policy: https://openai.com/policies/privacy-policy
- Groq (Audio Transcription): Whisper transcription API. Processes voice recordings to output text. Groq processes audio files in-memory and does not permanently store audio recordings.
- Privacy Policy: https://groq.com/privacy-policy/
- RevenueCat (Subscription Operations): Validates and stores app purchase history, plan statuses, and receipts.
- Privacy Policy: https://www.revenuecat.com/privacy
- PostHog (Product Analytics): Collects anonymous usage trends (e.g. screen transitions). Does not receive journal content.
- Privacy Policy: https://posthog.com/privacy
- Expo (Push Notification Delivery): Manages push tokens for reminders.
- Privacy Policy: https://expo.dev/privacy
- Google Drive API (Backup Feature): We request the highly secure and restricted
appDataFolderscope. We can only access, create, read, or write the specific backup files created by JustYap. We cannot view, access, or modify any other files in your Google Drive.- Google Privacy Policy: https://policies.google.com/privacy
6. Global Privacy Rights (GDPR, CCPA, and LGPD Compliance)
We comply with global privacy standards, including the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and the Brazilian General Data Protection Law (LGPD).
Depending on your jurisdiction, you have the following rights:
* Right to Access / Portability: You can request details of the metadata we store on our servers or export your journal data directly from the App.
* Right to Deletion (Erasure): You can request the deletion of your account and metadata from our servers.
* Right to Correction: You can correct your display name or account credentials.
* Opt-Out of Analytics: You can contact us to request exclusion from PostHog telemetry monitoring.
To exercise these rights, please email us at justyap.app@gmail.com. We will verify your identity before processing the request.
7. Security
We take data security seriously:
* All network communications between the App, our Supabase functions, and third-party APIs are encrypted using TLS/HTTPS protocols.
* Because your journal is stored locally, the physical security of your entries is dependent on your device’s operating system security and your use of our local passcode feature.
8. Children’s Privacy
The App is not intended for or directed to children under 13 years of age (or 16 in the European Economic Area). We do not knowingly collect personal data from children. If we discover that a child has provided us with personal information on our database, we will delete it immediately.
9. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. When updates occur, we will adjust the “Last Updated” date at the top of the policy and display a notification inside the App. Your continued use of the App after updates become effective constitutes acceptance of the new policy.