Privacy Policy
Effective Date: 8/25/2026 · Last Updated: 8/25/2026
Developer: Jerry Sha
App Name: Custom Journal App
Website: https://www.customjournalapp.com
Contact: jerry@customjournalapp.com
Introduction
Your privacy is important to us. This Privacy Policy explains how Custom Journal App collects, uses, and protects your information when you use our app. By using the app, you agree to the practices described in this policy.
Custom Journal App is designed to work entirely offline. You do not need an account to use the app, and if you never sign in, your journal content never leaves your device. Cloud sync and backup are optional features that you turn on yourself.
We publish separate iOS and Android versions of the app. They share most of this policy, but they store your journal in different places. Sections marked iOS only or Android only apply solely to that version; everything else applies to both.
Where Your Journal Is Stored
On both platforms, all journal entries, books, templates, checklists, photos and settings are stored only on your device unless you turn on an optional cloud feature. If you never enable one, no journal content is transmitted anywhere.
iOS only — Firebase sync
- If you enable Sync, a copy of your journal is stored in our Google Firebase project: Cloud Firestore holds entries, books, templates, checklists, schedules and statistics, and Cloud Storage holds journal photos.
- Your data is kept in a private area tied to your account. Firebase security rules prevent any other user from reading or writing it.
- Because this data lives in our project, we are technically able to access it. See Security below.
- Separately, Apple iCloud device backup may include the app's local data. That backup is controlled by your iOS settings and by Apple, not by us.
Android only — your own Google Drive
- If you enable backup or sync, your journal is written to your own Google Drive account, in the hidden application data folder that only this app can see.
- We do not host, receive, or have access to Android backups. They sit in your Drive, under your control, and you can delete them at any time from your Google account.
- The app requests only the
drive.fileanddrive.appdatapermissions, which limit it to files it created itself. It cannot see or open any other file in your Drive.
Account Information
An account is required only to enable cloud sync and to manage premium subscriptions. You can use every journaling feature without one.
iOS only
Sign-in uses Sign in with Apple through Firebase Authentication. We receive and store a unique account identifier (Firebase UID and Apple user identifier); your email address, or the private relay address Apple generates if you choose to hide your email; your name, if you choose to share it; and sign-in timestamps and technical metadata generated by Firebase Authentication, which may include IP address.
Android only
Sign-in uses your Google account, which both authorizes Google Drive backup and creates a Firebase Authentication record. We receive and store a unique account identifier (Firebase UID), the email address of the Google account you select, and sign-in metadata generated by Firebase Authentication.
On both platforms this information is used solely to authenticate you, to associate synced data or subscription status with your account, and to provide support. We do not use it for advertising or marketing.
Diagnostic and Usage Information
Both versions of the app use Google Firebase services to stay stable and to help us understand how features are used:
- Firebase Crashlytics — crash reports and related device state (device model, OS version, app version).
- Firebase Analytics — aggregate, event-level usage data such as which screens and features are opened. Analytics uses a randomly generated app-instance identifier and may derive approximate (country/region-level) location from your IP address. It is not linked to your journal content.
- Firebase Remote Config — to deliver configuration and promotional settings.
- Firebase App Check — to verify that requests come from a genuine copy of the app. This uses Apple's App Attest on iOS and Google Play Integrity on Android.
- Firebase Cloud Functions — to run server-side operations such as subscription receipt validation and account email confirmation.
- Firebase Cloud Messaging — to deliver push notifications. This involves a device messaging token.
We do not use advertising identifiers, we do not track you across other companies' apps or websites, and we do not display third-party advertising.
Information You Send Us Directly
Feedback and support
If you submit feedback from inside the app, we store your message together with the email address you optionally provide, your app version, device model and OS version, your install date, and your subscription tier. We use this only to read and respond to your feedback.
Android only — app lock password reset
The Android app offers an optional app lock. If you set a recovery email address and then use the password reset option, the app transmits your recovery email address and your app lock code to our backend so the code can be emailed back to you. This app lock protects access to the app on your device; it is not an encryption key and does not protect your journal against someone with access to the device's file system. Do not reuse a password you use anywhere else.
Subscriptions
Custom Journal Premium is purchased through the Apple App Store on iOS and Google Play Billing on Android. We never receive or store your payment card or billing details — those are handled entirely by Apple or Google. We receive only the purchase receipt and subscription status needed to unlock premium features on your account.
How We Use Your Information
- To store and synchronize your journal, when you enable sync or backup.
- To authenticate you and secure access to your own data.
- To diagnose crashes and technical issues, and to improve app performance.
- To respond to feedback and provide customer support.
- To verify and maintain premium subscription status.
We do not sell or share your personal information, as those terms are defined under the California Consumer Privacy Act, and we do not disclose your journal content to third parties for their own purposes. We share data only with the service providers listed below, who process it on our behalf, and only where required by law.
Third-Party Services
Both platforms:
- Google LLC (Firebase) — Authentication, Cloud Functions, Crashlytics, Analytics, Remote Config, Cloud Messaging, App Check and Realtime Database, acting as our service provider. See Firebase Privacy and Security and the Google Privacy Policy.
iOS only:
- Google LLC (Firebase) — Cloud Firestore and Cloud Storage, which hold your synced journal content and photos.
- Apple Inc. — Sign in with Apple, iCloud device backup, and App Store subscription processing. See the Apple Privacy Policy.
Android only:
- Google Drive — optional backup and restore, stored in your own Google account rather than ours.
- Google Play Billing — subscription processing.
Security
Data in transit is protected with TLS, and data at rest on Google's servers is encrypted with AES-256. Firebase security rules restrict every synced document and file so that it can be read or written only by the signed-in account that created it.
Please note (iOS sync): synced data is not end-to-end encrypted. Because your entries are stored under our Firebase project, we are technically able to access them. We access them only where necessary to provide support you have requested, to investigate abuse, or where required by law. If you prefer that your journal never leave your device, simply do not enable sync.
Android backups are held in your own Google Drive rather than by us, and are protected by your Google account's own security.
You are responsible for maintaining the security of your devices, your Apple or Google account, and your own backups.
Data Retention and Deletion
- Journal content stored on your device remains until you delete it or uninstall the app.
- iOS: synced content remains in our Firebase project until you delete it or delete your account. You can delete your account in the app under Settings → Sync. This removes your Firebase Authentication record, all synced documents under your account, and all photos you have synced to Cloud Storage. Journal content already on your device is not affected.
- Android: backups remain in your Google Drive until you delete them, either from within the app or from your Google account's storage settings. Because we never hold them, deleting them is entirely within your control.
- Residual copies may persist in routine encrypted backups for a limited period before being overwritten.
- Crash and analytics data is retained according to Firebase's default retention periods and is not tied to your journal content.
- Feedback messages are retained until we have resolved your request and are periodically purged.
Your Privacy Rights
Depending on where you live, you may have the right to access, correct, export, or delete the personal information we hold about you, to object to or restrict certain processing, and to withdraw consent. You can exercise most of these directly in the app — your entries are visible and editable at any time, the export feature produces a copy of your data, and account and backup deletion are available in Settings. For anything else, contact us at jerry@customjournalapp.com and we will respond within the timeframe required by applicable law. You will not be discriminated against for exercising these rights.
Where the GDPR applies, our legal bases for processing are: performance of a contract (providing sync and subscriptions), consent (which you give by enabling sync or backup, and can withdraw by disabling it), and legitimate interests (keeping the app stable and secure).
International Data Transfers
Our Firebase project stores data on Google servers, which may be located in the United States or other countries. If you use the app from outside those countries, your information will be transferred and processed there. Google provides appropriate safeguards for such transfers, including the European Commission's Standard Contractual Clauses.
Children's Privacy
Custom Journal App is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, contact us at jerry@customjournalapp.com and we will delete it.
Changes to This Policy
We may update this Privacy Policy from time to time. The "Last Updated" date above reflects the most recent revision, and any changes will be posted on our official website: https://www.customjournalapp.com/privacy. Material changes will also be announced in the app.
Contact Us
Questions about this policy, or requests concerning your data: jerry@customjournalapp.com
For app support, you can also reach us at jerry@customjournalapp.com (Android) or ios.help@customjournalapp.com (iOS).