Privacy Policy

Last updated: 2026-09-12

One Simple Life (“we”, “us”) built Hourly Journal, a journaling app for iOS, Android and the web at app.hourlyjournal.com. This policy explains what we collect, why we collect it, who we share it with, how long we keep it, and the rights you have over it. We are the data controller for the information described here.

We do not sell your personal information, and we do not show you ads or share your data with advertisers.

What we collect

  • Account information– your name, email address, timezone, and how you signed in (email and password, or Google or Apple sign-in). Passwords are stored only as a hash; we never see your password itself.
  • Journal content– the entries, tags, moods, energy levels, and workspace names and settings you create, plus any passcode you set on a workspace (see “Workspace passcode” below). Some of what you choose to record can be health-adjacent – a mood, an energy level, or wake and sleep times you tag yourself. We treat it with the same care as the rest of your journal. We do not connect to Apple Health, Health Connect, Google Fit, or any fitness tracker or sensor, and we do not collect health data from any source other than what you type.
  • Device and notification data– a push notification token for each device you sign in on, so we can send you the occasional service or product notification, and basic device details (model, operating system version, app version) that come attached to crash reports and support emails.
  • Usage and diagnostic data– crash reports and basic product-analytics events, such as which screen you were on or which feature you tapped, so we can find bugs and see which parts of the app are actually used. These record actions, not the words you write.
  • Payment information– if you subscribe, our payment processor (see “Who processes your data” below) collects your card or payment details directly. We never see or store your full card number. We do receive a record that a payment succeeded, which plan it was for, and when it renews or expires.

Your hourly reminders are scheduled by your own device, not by our servers. We are not told when a reminder fires, whether you acted on it, or where you are.

Why we collect it, and our legal basis

Where data-protection law such as the UK or EU GDPR applies to you, the legal basis for each use is given in brackets.

  • To provide the service – sync your entries across devices, show your streaks and insights, and keep your account working [performance of our contract with you].
  • To keep your account secure, let you sign in, and prevent abuse and fraud [legitimate interests, and our legal obligations].
  • To send account and service emails, such as verification codes and password resets [performance of our contract].
  • To send engagement emails you can switch off, such as the weekly digest and streak reminders [legitimate interests, or your consent where required – you can opt out at any time].
  • To fix bugs and understand which features are used, so we can improve the app [legitimate interests].
  • To process payments, manage subscriptions, and meet tax and accounting obligations [performance of our contract, and our legal obligations].

Where your data is stored

Your account and journal data are stored in our database, hosted with our cloud hosting provider, and synced to your devices so you can keep using the app offline. A copy of your entries therefore also lives on each device you sign in on, and stays there until you sign out or delete the app.

We and the providers listed below operate in more than one country, so your information may be stored or processed outside the country you live in, including in countries whose data-protection laws differ from your own. Where such a transfer is subject to the UK or EU GDPR, we rely on the safeguards our providers offer for international transfers, such as standard contractual clauses.

Who processes your data

We rely on a small number of outside companies to run the service, each limited to the job named here:

  • Paddle– our merchant of record for card and digital-wallet payments outside India. Paddle handles your payment details, calculates and remits sales tax and VAT, and appears on your bank or card statement. We never see your full card details.
  • Razorpay– handles payments made in India (INR).
  • Apple (App Store) and Google (Play)– handle payment for in-app purchases made on those platforms, and provide sign-in if you choose “Sign in with Apple” or “Sign in with Google”.
  • ZeptoMail (Zoho)– sends our transactional and account emails: verification codes, password resets, streak reminders, the weekly digest, and data-export emails. Your weekly digest contains a summary of your own entries, so that summary passes through our email provider on its way to you.
  • Firebase (Google)– delivers occasional push notifications and reports crashes (Crashlytics) and basic app analytics.
  • PostHog– product analytics, so we can see which features are used.
  • Our cloud hosting provider– hosts the database and servers that store your account and journal data.

Each of these providers only receives the information it needs to do its job – for example, an export email needs your email address, but not your payment details. We may also disclose information if we are legally required to, or to establish or defend a legal claim.

This website

hourlyjournal.com, the marketing site you are reading now, sets no advertising or tracking cookies and runs no third-party analytics. Your browser may store a small preference locally, such as whether you chose the light or dark theme; that stays on your device and is never sent to us. The app itself, at app.hourlyjournal.com, stores your sign-in session and an offline copy of your journal in your browser so it keeps working without a connection.

Security

Traffic between your devices and our servers is encrypted in transit. Passwords and workspace passcodes are stored only as hashes, and access to production systems is limited to the people who need it. No service can promise perfect security, and we do not claim journal entries are end-to-end encrypted – see the next two sections for exactly what that means in practice.

Workspace passcode

A workspace can be locked with a 4-digit passcode. This is a privacy screen intended to stop someone glancing at your phone from opening that workspace – it is not encryption, and it does not prevent us, as the service operator, from accessing the underlying data if we ever needed to for support or legal reasons. The passcode’s hash is synced across your devices so the lock still works offline. If you forget your passcode, you can reset it by email.

Staff access to your journal

Access to journal content by our team is restricted to what is needed to operate the service and respond to support requests, such as investigating a bug you reported. We do not read journal entries for any other purpose, and we do not use them to train machine learning models.

Your rights

You can exercise the first three of these yourself, in the app, right now:

  • Export– request a full copy of your data at any time from Manage Profile; it is free and sent by email. A filtered export, by date range, tag or other criteria, is available as a paid feature.
  • Delete– delete your account and data from Manage Profile in the app, or from Settings on the web. Our Account Deletion page has the step-by-step, including how to ask us if you have already uninstalled the app.
  • Unsubscribe– turn off engagement emails (the weekly digest, streak reminders) in Notification Settings, or use the one-click unsubscribe link in the email. Account emails, such as verification and password reset, are not optional, since they are needed to run your account securely.

Depending on where you live, you may also have the right to ask us to correct information that is wrong, to restrict or object to how we use it, to receive it in a portable format, and to withdraw any consent you have given. Email us and we will action it. If you are in the UK, the EU, or another region with a data-protection authority, you also have the right to complain to that authority, though we would appreciate the chance to put things right first.

How long we keep data

We keep your account and journal data for as long as your account is active. When you delete your account, we remove it from active use immediately and erase it within 30 days. During that window we keep a limited record of the deletion, for fraud prevention, dispute handling and legal compliance. Records of payments are kept for as long as tax and accounting law requires, separately from your journal content. The Account Deletion page sets out exactly what is removed and what is kept.

Children’s privacy

Hourly Journal is not directed at children under the age of 13, and we do not knowingly collect personal information from anyone under that age. Where local law sets a higher age of consent for online services, that higher age applies. If you believe a child has provided us with personal information, please contact us and we will delete it.

Changes to this policy

We may update this Privacy Policy as the product changes. We will post the new version on this page and update the date at the top. If a change materially affects how we use your information, we will tell you in the app or by email rather than relying on you to notice.

Contact us

If you have any questions about this Privacy Policy, or want to exercise any of the rights above, contact us at [email protected].