1. Overview
JustYap is local-first, not offline-only. Saved journal entries, recordings, attached images, optional place labels, transcripts, summaries, moods, and categories are primarily kept in the app on your device. Your operating system may also include app-private data in a device backup or device-to-device transfer, as described below. When you use a feature that requires transcription or another AI result, the content needed for that request is securely sent to our backend and the relevant AI provider. If you enable JustYap's Google Drive backup, a separate copy is stored in your private Drive app-data folder.
This Privacy Policy explains how JustYap (“JustYap,” “we,” “us,” or “our”) handles personal information when you use the JustYap mobile application, website, support channels, and related services (together, the “Service”). It also explains your choices and privacy rights.
Using the Service means that you understand the practices described here. Where applicable law requires consent, we ask for it through the relevant device or feature flow.
2. Who we are
JustYap is developed and operated by Victor Lougon Sampaio Lopes, operating as JustYap. For purposes of applicable data-protection law, we are the controller of the account and service data described in this policy. Our privacy and data-protection contact for LGPD rights and other requests is justyap.app@gmail.com.
- Contact: justyap.app@gmail.com
- App identifier: com.justyap.app
3. Information we handle
3.1 Journal content saved on your device
Depending on how you use JustYap, the app may store voice recordings, typed entries, attached images, optional place labels, transcripts, summaries, dates, moods, categories, Weekly Recaps, Monthly Chapters, and journal settings in the app’s private storage on your device. A place label is a readable name such as a neighborhood or city. We do not store the underlying latitude or longitude with your Yap. The current app does not create a permanent central copy of your saved journal library in JustYap's database. An account that used an older cloud-sync version may still have legacy journal entries in the backend until the account is successfully deleted or you ask us to delete them. Depending on your device and operating-system settings, Apple or Google may separately include some app-private data in a system backup or device transfer.
3.2 Account and profile information
JustYap creates an anonymous account identifier so the Service can recognize your account and enforce plan access. Our Supabase-hosted profile may contain your random user ID, display name, plan, starter voice-Yap allowance, usage counters, and technical timestamps. If an email-based account option is offered and you choose it, Supabase Auth processes the email address and authentication credentials.
3.3 Subscription information
RevenueCat and the app store process purchase and subscription information, including product identifier, entitlement status, renewal state, transaction identifiers, and receipts. We do not receive your complete card or bank-account details.
3.4 Product analytics and technical data
We use PostHog to understand whether features work and how the app is used. Events may include screens viewed, buttons used, feature state, app version, platform, device characteristics, performance data, and error context. We filter fields associated with journal text, transcripts, recordings, images, place labels, file paths, and similar sensitive content before analytics events are sent.
We do not use journal content for advertising, and we do not sell journal content.
You can disable optional PostHog analytics at any time in Settings > App Preferences > Share App Usage Analytics. This choice remains in effect after logout. Some strictly necessary security, fraud-prevention, or service diagnostics outside PostHog may still be processed when permitted by law.
3.5 Device permissions
| Permission | Why it is used |
|---|---|
| Microphone | To record a voice Yap. The operating system asks for this permission. |
| Camera | Optional. To take a photo to attach to a Yap. |
| Photos | Optional. To choose images to attach using your device's photo picker. |
| Location | Optional. When you choose the current-location control, the app uses device location only to derive a readable place label for that Yap. Coordinates are not stored with the Yap. |
| Notifications | Optional. To schedule journaling and trial reminders on your device. Delivery is controlled by the operating system and is not guaranteed. |
| Biometrics | Optional. To unlock the app using the biometric system provided by your device. JustYap does not receive your fingerprint or face template. |
| Local files and storage | To save recordings and journal data, create exports, and prepare optional backups. |
| Google account and Drive app data | Optional. To create, restore, or delete a JustYap backup in the private app-data area of your Google Drive. |
4. How and why we use information
We use information to:
- provide voice and text journaling, image attachments, optional place labels, transcripts, summaries, recaps, chapters, moods, categories, exports, and backups;
- authenticate users, maintain plan access, enforce usage safeguards, and restore purchases;
- schedule notifications you choose;
- protect the Service, prevent abuse, diagnose errors, and improve performance and usability;
- respond to support, privacy, or legal requests; and
- meet legal, tax, accounting, and app-store obligations.
Depending on the context and applicable law, our legal bases may include performing our agreement with you, your consent for optional permissions or integrations, our legitimate interests in operating and securing the Service, and compliance with legal obligations.
5. AI processing
Transcription, summaries, Weekly Recaps, and Monthly Chapters require network processing. When you choose one of these features, JustYap sends only the content and context reasonably needed to produce the result.
Voice transcription
Selected audio is uploaded to Supabase Storage and passed through a Supabase Edge Function to Groq for speech-to-text processing. The upload is intended for transcription rather than as a central audio library. The standard creation and onboarding flows request deletion after processing, including after many error paths. If you later retry transcription from a saved Yap, the uploaded object may remain in Supabase Storage beyond that request and may require a successful storage cleanup or verified privacy request. Network or service failures can also delay deletion, so we do not promise instantaneous removal.
Summaries, recaps, and chapters
The relevant transcript or typed entry—and, for recap features, selected dates, moods, summaries, and journal context—is passed through Supabase Edge Functions to OpenAI to generate the requested output.
Attached images and place labels are not sent to Groq or OpenAI and are not analyzed by AI in the current version of the Service.
Important limits
- AI output may be incomplete, incorrect, or unexpected. You can review and edit it.
- JustYap is a reflection tool, not a medical, therapeutic, legal, financial, or crisis service.
- We use provider API services to deliver these features. Provider handling is also governed by their terms, privacy policies, and contractual settings.
- JustYap does not use submitted journal content for advertising or train a JustYap model with it, and we do not instruct our API providers to use it to train public models. Provider handling and any legally permitted retention remain governed by their business/API terms and privacy commitments.
6. Local storage, Google Drive backup, and exports
Local-first journal storage
Your saved journal library is stored in the app’s private area on your device. If you delete an entry, clear app data, uninstall the app, lose the device, or experience storage corruption, we generally cannot recover that local content.
Optional Google Drive backup
If you connect Google Drive, JustYap packages eligible journal data, audio, attached images, and optional place labels into a ZIP backup and uploads it from your device to Google’s restricted appDataFolder. The integration can access JustYap-created app data in that private folder; it cannot browse ordinary files in your Drive. The ZIP is not currently encrypted by JustYap before upload, so its access protection depends on your Google account and Google Drive. Backup reliability also depends on available storage, connectivity, and Google’s services.
Separate from JustYap's optional Drive ZIP, iOS or Android may include some app-private data in an operating-system backup or device-to-device transfer when that feature is enabled for your device. Those copies are controlled by your device, Apple or Google account, and platform backup settings; JustYap cannot confirm or delete every system-managed copy from inside the app.
Exports
When you create a PDF, image, or other export, the app lets you choose which elements to include. Depending on your choices, an export can include a transcript, summary, attached images, place label, mood, categories, and other Yap details. Once you share it outside JustYap, the destination you choose controls that copy.
7. Service providers and international processing
We use providers for specific functions. They may process information in countries other than yours, including the United States. International processing is subject to applicable transfer rules. Depending on the provider, destination, and law, safeguards may include provider contracts, standard contractual clauses, recognized adequacy decisions, or another legally permitted mechanism. Contact us for currently available information about the mechanism relevant to a particular recipient or transfer.
| Provider | Purpose | Policy |
|---|---|---|
| Supabase | Authentication, profile metadata, temporary audio storage, database functions, and Edge Functions | Privacy |
| Groq | Voice transcription | Privacy |
| OpenAI | Summaries, Weekly Recaps, and Monthly Chapters | Privacy |
| RevenueCat | Subscription entitlements and purchase validation | Privacy |
| PostHog | Sanitized product analytics and diagnostics | Privacy |
| Optional sign-in, private Drive app-data backup, and Android system backup or device transfer when enabled | Privacy | |
| Apple | App distribution and billing, and iCloud backup or device transfer when enabled | Privacy |
| Google Play | App distribution, billing, trials, refunds, and store-account records | Privacy |
We may also disclose information when reasonably necessary to comply with law, protect users or the Service, investigate fraud or abuse, or complete a business reorganization subject to appropriate safeguards.
8. Retention and deletion
- Local journal data: including attached images and optional place labels, remains in the app on your device until you delete it, clear app storage, or uninstall the app.
- Operating-system backups and transfers: may retain a separate system-managed copy according to your Apple or Google account, device, and platform settings, even after the app's on-device copy changes.
- Google Drive backups: remain in your Drive app-data folder until you delete them through JustYap, remove the app data through Google, or Google removes them under its policies.
- Transcription audio in Supabase Storage: is intended only for transcription. Most current flows request deletion after processing, but a retry-from-saved-Yap path or a technical failure can leave an object beyond the request until a later cleanup or verified deletion request succeeds.
- Account and usage metadata: is kept while needed to operate your account, provide entitlements, prevent abuse, resolve disputes, or meet legal obligations.
- Analytics: is retained according to our configured retention and PostHog’s applicable terms, then deleted or aggregated when no longer needed.
- Purchase records: may be retained by RevenueCat and your app store under their legal and accounting requirements.
You can delete your account and data through Advanced Options in Settings. The current deletion flow requests permanent deletion of the Supabase authentication account and associated profile/usage data, clears journal content, audio, attached images, and app settings stored locally on that device, and attempts to delete the connected JustYap Google Drive backup. Because remote steps depend on network and provider availability, a failed step may leave remote data in place until you retry or contact us.
You may also request deletion by email. After identity verification, we handle deletion requests without undue delay and, absent a legal reason or technical dependency requiring otherwise, within 30 days. Some limited records may be retained when required for legal, accounting, fraud-prevention, security, or dispute-resolution purposes.
9. Your choices and privacy rights
You can choose whether to record audio, take or attach images, save a place label, enable notifications or biometrics, connect Google Drive, purchase Premium, create exports, or use AI-dependent features. You can remove a place label by editing its Yap, and device permissions can be changed in your operating-system settings.
Depending on where you live—including Brazil’s LGPD, the EEA’s GDPR, and U.S. state privacy laws such as the CCPA/CPRA where applicable—you may request:
- confirmation that we process your personal data and access to that data;
- correction of incomplete or inaccurate account information;
- deletion, anonymization, restriction, or portability where applicable;
- information about recipients and international transfers;
- withdrawal of consent where processing relies on consent; and
- review or complaint rights provided by your local authority.
We do not discriminate against you for exercising an applicable privacy right.
These rights may also include objecting to certain processing, opting out of analytics where applicable, and complaining to a competent data-protection or consumer authority. Because journal content is primarily stored on your device, the most direct way to access, edit, export, or delete it is inside the app. For server-side account data or any privacy request, contact justyap.app@gmail.com. We may need to verify your identity before fulfilling a request.
We respond within the periods required by applicable law. For requests governed by Brazil’s LGPD, confirmation of processing or access may be provided immediately in a simplified form, or through a complete statement within the legally prescribed period, currently up to 15 days.
10. Security
We use measures designed to protect information, including HTTPS/TLS for network traffic, private app storage, access controls, sanitized analytics fields, an optional app PIN stored in the operating system's encrypted credential storage, and optional operating-system biometric locking. The previous app version stored the PIN preference in ordinary app-private storage; the current version migrates that record to encrypted credential storage and removes the legacy copy after a successful migration. Biometric templates remain with the operating system, and the PIN is not sent to JustYap's servers. The PIN and biometric lock control access to the app but do not separately encrypt the journal database, recordings, images, exports, Google Drive ZIP backup, or a system-managed device backup. No storage or transmission system is perfectly secure, so we cannot guarantee absolute security.
You can help by securing your device and Google account, installing operating-system updates, using the app lock if appropriate, and checking that important backups complete successfully.
11. Children’s privacy
JustYap is not directed to children under 13, or under 16 in the European Economic Area where that threshold applies, or a higher minimum age where local law requires it. We do not knowingly collect personal information from a child who is not legally able to use the Service. If you believe this has happened, contact us so we can investigate and delete applicable server-side information.
12. Changes and contact
We may update this policy as the Service, providers, or legal requirements change. We will post the revised policy here, change the “Last updated” date, may display a notice inside the app, and will provide additional notice when required.
Questions or privacy requests can be sent to:
JustYap
Attn: Victor Lougon Sampaio Lopes
justyap.app@gmail.com