Privacy Policy
Last Updated: February 15, 2026
Website Notice
This privacy policy covers the GrateMoment mobile app and this website. The website is informational only and does not use cookies or trackers. We only receive personal information when you intentionally submit a support request.
Introduction
This Privacy Policy describes how our journal application (“we,” “our,” or “the app”) collects, uses, and protects your personal information when you use our services. We are committed to protecting your privacy and ensuring the security of your personal data.
By using our app, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with our policies and practices, please do not use our services.
What we collect on this website
gratemoment.com does not use analytics scripts, advertising pixels, or cookies. The only time we receive personal data on the website is when you submit a support request.
- Support form: Name, email, issue type, and details you provide (including optional attachments) so we can respond.
- Server logs: Basic, non-identifying request logs retained briefly for security and uptime monitoring.
- Retention: Support submissions are kept only as long as needed to resolve your request and to meet legal obligations.
No hidden collection:
If you never submit a form, we do not collect your personal information on this site.
Data Collection
We collect the following types of information:
Personal Journal Entries
- Text content of your journal entries
- Timestamps of when entries were created or modified
- Entry metadata such as mood ratings, tags, and categories
Photos and Media
- Images you attach to your journal entries
- Photo metadata including timestamps and basic file information
- Images are stored securely in encrypted cloud storage
Voice Recordings
- Audio recordings you create for voice journal entries
- Transcriptions of voice recordings (processed securely)
- Audio file metadata and timestamps
Authentication Data
- Email address (when using email authentication)
- Profile information from third-party providers (when using social sign-in)
- Unique user identifiers generated by our authentication system
Usage Analytics
- App usage patterns and feature engagement
- Device information (type, operating system, app version)
- Performance data and crash reports
- General location data (country/region level only, not precise location)
Technical Data
- IP addresses (temporarily, for security purposes)
- Device identifiers and characteristics
- Network connection information
- App settings and preferences
We do not collect:
- • Precise location data
- • Contacts or address book information
- • Other apps installed on your device
- • Sensitive personal information beyond what you choose to share in your journal
Data Usage
We use your data for the following purposes:
Core App Functionality
- Storing and displaying your journal entries across devices
- Syncing your data securely across multiple devices
- Providing search functionality within your entries
- Organizing entries by date, tags, and categories
AI-Powered Features
- Analyzing journal entries to provide personalized insights
- Generating mood patterns and emotional trends
- Providing writing suggestions and prompts
- Creating summaries of your journaling patterns
- Transcribing voice recordings to text
Personalization
- Customizing the app experience based on your preferences
- Providing relevant writing prompts and suggestions
- Tailoring insights and analytics to your journaling style
- Remembering your app settings and preferences
We do not:
- • Sell your personal data to third parties
- • Use your journal content for advertising purposes
- • Share your entries with other users
- • Use your data for purposes unrelated to the app's functionality
Data Storage
Cloud Infrastructure
Your data is stored using secure cloud services that provide enterprise-grade security:
- Database Services: Stores your journal entries, metadata, and app settings
- File Storage: Securely stores photos and audio files with encryption
- Authentication Services: Manages user accounts and authentication tokens
- Processing Services: Processes data securely in controlled environments
Encryption and Security Measures
- All data is encrypted in transit using industry-standard protocols
- Data at rest is encrypted using enterprise-grade encryption
- Our cloud providers implement automatic encryption for all stored data
- Regular security audits and compliance with industry standards
Third-Party Services
We integrate with carefully selected third-party services. We do not publish vendor names publicly but share a current list on request.
Cloud Infrastructure Providers
- Secure authentication services for user sign-in
- Encrypted database services for data storage
- Secure file storage for media files
- Performance monitoring and analytics services
- Backup and disaster recovery services
Platform Integration Services
- Third-party authentication providers for social sign-in
- Push notification services for app communications
- App distribution platform services
- Payment processing services (where applicable)
AI and Processing Services
- Machine learning services for AI-powered insights
- Natural language processing for journal entry analysis
- Speech-to-text services for voice transcription
- Content analysis services for personalized recommendations
User Rights
You have the following rights regarding your personal data:
Data Access & Export
- View all personal data we have collected
- Export journal entries in multiple formats (JSON, PDF, CSV, HTML)
- Download all photos and audio files in their original formats
- Portable format suitable for migration to other services
Account Deletion
You can permanently delete your account and all data from within the app: Settings → Account → Delete Account.
Important:
- • Account deletion is permanent and cannot be undone
- • We recommend exporting your data first using the backup feature
- • All personal information is removed from our systems within 24 hours
Data Retention
Active Accounts
- Journal entries: Retained indefinitely while your account is active
- Photos and audio files: Stored as long as associated entries exist
- Usage analytics: Aggregated data retained for up to 2 years
Inactive Accounts
- Accounts inactive for 3 years receive reactivation notice
- After 4 years, account is scheduled for deletion with 90-day notice
- Option to reactivate during notice period
International Data Transfer
Your data may be processed across our providers' global network for optimal performance and security.
For EU Users:
- EU-US Data Privacy Framework compliance
- Standard Contractual Clauses (SCCs) for data transfers
- GDPR Article 46 safeguards implemented
Security Measures:
- End-to-end encryption during all data transfers
- TLS 1.3 encryption for data in transit
- Certificate pinning and validation
Contact Information
Privacy Team
- Email: privacy@gratemoment.com
- Response time: Within 48 hours
Data Protection Officer
- Email: dpo@gratemoment.com
- Available for: Complex privacy questions
Policy Updates
- Users notified of material changes via email
- In-app notifications for significant updates
- 30-day notice period for major changes affecting user rights
- Historical policy versions are maintained and accessible