Privacy Policy Beta
How we care for your most sacred words
Last updated: 17 February 2026

This privacy policy is current as of the date above and applies to the beta version of The Living Journal. It will be reviewed by qualified legal counsel before any paid subscription launch.

Our Data Sovereignty Promise

Your prayers never leave our infrastructure. All AI processing happens on local hardware we own and control. No OpenAI, Anthropic, or Google AI APIs are used to process your journal entries. Your most intimate spiritual reflections are never sent to any cloud AI service.

We believe this is not just a privacy feature -- it is a matter of spiritual trust. When you confide in your journal, those words remain within the walls of our digital monastery.

1. Who We Are

The Living Journal is a product of The Digital Monastery, operated by Dave in Perth, Western Australia. The Living Journal is an AI-powered spiritual journaling application designed to support your personal relationship with God through guided reflection, prayer, and contemplation.

The Living Journal is not a counselling service, therapy provider, pastoral care service, or crisis intervention tool. It is a journaling tool that uses artificial intelligence to provide reflective responses to your written entries.

This Privacy Policy explains how we collect, use, store, and protect your personal information in accordance with the Australian Privacy Act 1988 (Cth), as amended by the Privacy and Other Legislation Amendment Act 2024.

2. What Data We Collect

We are transparent about every category of data we collect. The table below lists all data types, their purpose, and their sensitivity classification under Australian privacy law.

Data Type Purpose Sensitivity
Email address Account creation, authentication (sign-in link login), and optional notifications Personal
Name Personalising prompts and AI responses (e.g., addressing you by name) Personal
Journal entries (prayers, reflections, confessions) Core service: storing your journal for your own review, and generating AI responses Highly Sensitive -- religious beliefs
Photos of handwritten journal pages Allowing you to photograph and store handwritten entries Sensitive
OCR-extracted text from handwritten entries Converting handwritten text to digital form for AI processing Sensitive
AI-generated responses Storing the "Friend voice" reflections so you can revisit them Sensitive
Sentiment analysis data Understanding the emotional tone of your entries to provide appropriate responses Sensitive
Crisis/sensitive content flags Identifying entries that may indicate distress so the system can display crisis resources Extremely Sensitive
Flagged AI responses and user notes When you report an AI response as inappropriate, your feedback is stored for review Sensitive
Detected spiritual/psychological patterns Tracking themes across your entries (e.g., recurring topics of gratitude, grief, growth) Highly Sensitive
Weekly reflections AI-generated summaries analysing your week of journal entries Highly Sensitive
Onboarding assessment answers Understanding your spiritual background to personalise prompts and tone Sensitive
Login timestamps and session tokens Authentication, session management, and security Personal
Notification preferences (method, time, days, timezone) Sending reminders at times you choose Personal
Journey progress (current week, current day) Tracking where you are in the 14-week guided series Personal
Soaking session history Recording when you choose to listen to worship music rather than journal Personal
Nominated support person name and contact email Optionally provided during onboarding — stored for a future feature that would notify a trusted person if crisis content is detected. This feature is not yet active. Your consent is required before it is used. Sensitive — third-party personal information

3. Sensitive Information and Religious Beliefs

We recognise that your journal entries contain some of the most sensitive categories of personal information that exist under law. We treat this responsibility with the gravity it deserves.

Under the Australian Privacy Act 1988, religious beliefs are explicitly classified as "sensitive information" (Section 6). This classification applies to the majority of data The Living Journal collects, including your journal entries, prayers, confessions, onboarding answers about your spiritual life, and any AI-generated responses that reflect your beliefs.

What "sensitive information" means for you

Consent

By creating an account and submitting journal entries, you provide explicit consent to the collection and processing of sensitive information (including religious beliefs) as described in this policy. You may withdraw this consent at any time by deleting your account (see Section 9: Your Rights).

4. How We Store Your Data

All of your personal data is stored on infrastructure we physically own and control in Perth, Western Australia. Your data is not stored in any cloud service, third-party data centre, or overseas facility.

Our infrastructure

No cloud storage. No overseas servers. No exceptions.

Your data resides on physical hardware in Perth, Western Australia. We do not use Amazon Web Services, Google Cloud, Microsoft Azure, or any other cloud hosting provider for data storage or AI processing.

5. How We Use Your Data

We collect and use your data solely for the following purposes:

  1. Providing the journaling service -- storing your entries, displaying your history, tracking your progress through the guided series.
  2. Generating AI responses -- your journal entry text is sent to our local AI model (running on our Mac Studio) to produce a reflective "Friend voice" response. This processing happens entirely within our local network.
  3. Personalising your experience -- using your name, onboarding answers, and detected patterns to tailor prompts and responses to your spiritual journey.
  4. Sentiment analysis -- understanding the emotional tone of your entries to ensure AI responses are appropriately compassionate and relevant.
  5. Weekly reflections -- analysing your week of entries to generate a summary that identifies themes and encourages growth.
  6. Crisis resource display -- if the system detects content that may indicate distress, it ensures crisis support resources are prominently displayed.
  7. Service improvement -- the developer may access aggregated, de-identified usage patterns (e.g., how many entries per week on average) to improve the service. Individual journal content is not read for this purpose except where you have flagged a response for review, or during active debugging of a technical issue with your explicit knowledge.
  8. Notifications -- if you opt in, sending daily reminders and milestone celebrations at your chosen time and via your chosen method.

We will never use your data for purposes beyond those listed above without obtaining your explicit consent first.

6. AI Processing and Local Inference

The Living Journal uses artificial intelligence to generate reflective responses to your journal entries. Here is exactly how this works:

How AI processing works

  1. You write a journal entry in the app.
  2. Your entry text is sent from our application server to our AI inference server (Apple Mac Studio M4 Max, located in our premises in Perth, WA).
  3. The AI model (an open-source language model running via Ollama) generates a response.
  4. The response is sent back to the application server and stored alongside your entry.
  5. At no point does your entry text leave our local network.

What we do NOT do

Important: AI-generated responses are produced by a machine learning model and may contain errors, inaccuracies, or theologically unsound content. These responses do not constitute pastoral counselling, therapy, or professional advice of any kind. Please exercise your own judgment and consult qualified professionals where appropriate.

7. External Services and Third Parties

While your journal data remains on our local infrastructure, The Living Journal does interact with a small number of external services. We disclose all of them here in full transparency.

Service What It Does What Data Is Shared
Cloudflare Tunnel Routes public traffic from the-living-journal.com to our server. Cloudflare terminates the HTTPS connection before passing traffic to our infrastructure. Cloudflare sees encrypted web traffic metadata (IP addresses, request paths, timestamps). Journal entry content is transmitted over HTTPS and is not stored by Cloudflare. Cloudflare's privacy policy applies: cloudflare.com/privacypolicy
ntfy.sh A push notification relay service used to send the developer (Dave) a private alert when crisis content is detected in a journal entry. Only your first name and the alert text ("may need support") is transmitted. No journal content is sent. ntfy.sh privacy policy applies: ntfy.sh/privacy
Tailscale VPN Provides secure, encrypted administrative access to the server infrastructure. Not used for user access since the public domain launched. Connection metadata only (IP addresses, connection timestamps). Tailscale cannot see the content of your traffic — it is end-to-end encrypted. No journal data is accessible to Tailscale.
YouTube (via youtube-nocookie.com) The "Soaking" music library page embeds YouTube worship music playlists using YouTube's privacy-enhanced mode (youtube-nocookie.com). When you visit the Soaking page, your browser loads content from Google/YouTube servers. This may transmit your IP address and viewing behaviour to Google. We use the "nocookie" embed mode to reduce tracking, but cannot fully prevent Google from collecting some data. No journal data is shared with YouTube.
Gmail SMTP (if email notifications enabled) If you opt in to email notifications, reminder emails are sent via Gmail's SMTP servers. Email address, email subject line, and notification message content transit Google's mail servers. Journal entry content is never included in notification emails. Notification messages contain only gentle reminders (e.g., "Your journal is ready whenever you are").

Services we do NOT use

8. Crisis Content Handling

The Living Journal is not a crisis service. If you or someone you know is in immediate danger, please contact emergency services (000) or Lifeline (13 11 14) immediately.

The Living Journal includes a sensitive content detection system that may flag journal entries containing language associated with crisis situations, including references to self-harm, suicidal ideation, severe distress, or abuse.

What happens when content is flagged

What does NOT happen

What DOES happen

This system is imperfect. It may fail to detect genuine crisis content, or may incorrectly flag content that is not a cause for concern. You should never rely on The Living Journal as a safety mechanism or crisis monitoring tool.

9. Your Rights

Under the Australian Privacy Act 1988 (Australian Privacy Principles 12 and 13), you have the following rights regarding your personal information:

Right of access

You may request a copy of all personal information we hold about you. Your journal entries and history are already accessible within the application. For a complete data export, contact us at oddydavid@hotmail.com.

Right of correction

If any personal information we hold about you is inaccurate, incomplete, or out of date, you may request that we correct it. You can update your name, notification preferences, and timezone directly in the Settings page. For other corrections, contact us.

Right of deletion

You may delete your account and all associated data at any time via the Settings page (the "Delete My Account" option). This will permanently and irreversibly delete:

This deletion is performed as a cascading database delete and cannot be undone. We do not retain backup copies of deleted accounts.

Right to withdraw consent

You may withdraw your consent to the collection and processing of sensitive information at any time by deleting your account or by contacting us. Withdrawal of consent means we can no longer provide the service, as the core function requires processing your journal entries.

Right to complain

If you believe we have breached the Australian Privacy Principles, you may:

  1. Contact us directly at oddydavid@hotmail.com and we will investigate and respond within 30 days.
  2. If unsatisfied with our response, lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au or by calling 1300 363 992.

10. Data Retention

We retain your personal data for as long as your account is active. Specifically:

11. Data Security

We implement the following security measures to protect your data:

Honest limitation: During this beta phase, journal entries are stored in plaintext in the SQLite database. Encryption at rest is planned for a future release before paid launch. We believe in being honest about our current limitations rather than making claims we cannot support.

12. Data Breach Notification

In the unlikely event of a data breach that could result in serious harm to you, we will:

  1. Notify all affected users via email within 72 hours of becoming aware of the breach.
  2. Provide a clear description of what data was affected.
  3. Describe what steps we are taking to address the breach and prevent recurrence.
  4. Provide recommendations for steps you can take to protect yourself.
  5. Notify the Office of the Australian Information Commissioner (OAIC) if required under the Notifiable Data Breaches scheme.

Given the highly sensitive nature of the data we hold (religious beliefs, prayers, personal confessions), we consider any unauthorised access to journal entry data to be a serious breach warranting notification, regardless of the technical threshold.

13. Children

The Living Journal is not intended for use by children under the age of 16. We do not knowingly collect personal information from children under 16. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at oddydavid@hotmail.com and we will delete the account and all associated data.

14. International Users

The Living Journal is operated from Perth, Western Australia and all data is stored and processed in Australia.

European Union / United Kingdom users

If you are located in the EU or UK, please be aware that:

15. Australian Small Business Exemption

Under the Privacy Act 1988, organisations with annual turnover of less than $3 million are generally exempt from the Australian Privacy Principles. The Digital Monastery currently falls below this threshold.

However, given that we collect and process sensitive information (religious beliefs), and given the presence of crisis content detection features, we have made a deliberate decision to comply with the Privacy Act as if we were a covered entity. We believe this is the right thing to do when people trust us with their prayers, confessions, and spiritual struggles.

We do not rely on the small business exemption. We hold ourselves to the full standard of the Australian Privacy Principles because the nature of your data demands it.

16. Changes to This Policy

We may update this Privacy Policy from time to time as the service develops. When we make changes:

We encourage you to review this policy periodically.

17. Contact Us

If you have any questions about this Privacy Policy, wish to exercise your rights, or have a privacy concern, please contact us:

For complaints about our handling of your personal information, please see the complaint process described in Section 9: Your Rights.