Jhourney App Privacy Policy
Applies to: the Jhourney mobile app for iOS and Android, and the Jhourney web app at
app.jhourney.io (together, the "App").
- Controller: Jhourney, Inc., 2261 Market Street, Suite 22161, San Francisco, CA 94114
- Contact: retreats@jhourney.io
- Effective date: August 3, 2026
- Last updated: August 3, 2026
This notice covers the App specifically. Our retreat programs are covered by the Jhourney Privacy Policy. Where both apply, the retreat policy governs retreat screening, retreat recordings, and safety processing, and this notice governs everything you do inside the App. Neither policy reduces the rights the other gives you.
1. The short version
| Topic | In short |
|---|---|
| What the App is | A meditation practice companion: a sit timer, written reflections, a gratitude and letter journal, audio and video lessons, and an AI facilitator you can talk to. |
| Who it's for | Adults (18+) who have attended or are attending a Jhourney retreat. |
| What we collect | Your account details, what you write in the App, your practice history, your conversations with the AI facilitator including an audio recording of each spoken session, optional voice recordings you make yourself, and basic device and usage data. |
| Who reads it | Jhourney facilitators and engineers read AI conversations as a normal part of supporting you and improving the facilitator. See Section 5.7. |
| AI | Several features send what you write or say to third-party AI providers to generate a response. See Section 5. |
| Training | We do not use your content to train AI models, and our AI providers are contractually prohibited from training on it. |
| Keeping excerpts | Keeping part of a conversation as a lasting test case or teaching example — beyond your own practice — needs your explicit permission. It is off by default and reversible in one tap. See Section 6. |
| Service providers | Named in full at jhourney.io/subprocessors. |
| Advertising | We do not sell your data, we do not share it for cross-context behavioral advertising, and the App contains no advertising or ad-tracking SDKs. |
| Deleting | Profile → Delete account removes your account and your data. No email required, no waiting period. |
2. Who this applies to, and age
The App is for adults 18 and over. We do not knowingly collect information from anyone under 18. If you believe a minor has created an account, email retreats@jhourney.io and we will delete it.
3. What we collect
3.1 Information you give us
| Category | Examples | Where it comes from |
|---|---|---|
| Account identity | Email address, password (stored by our authentication provider, never by us), first and last name, time zone | Sign-up; or your Apple ID / Google account if you use "Sign in with Apple" or "Continue with Google" |
| Practice reflections | Your intention before a sit, what you learned, your next intention, notes about your experience, jhana stage and time-to-jhana, session length | Entered by you on the sit screen |
| Onboarding answers | Your practice goal, the obstacles you expect, your coping strategies, your morning and evening anchors | Onboarding |
| Gratitude entries | The items you write in your morning and evening gratitude practice | Gratitude screen |
| Your letter | The letter you write to your future self, and highlights generated from it | Letter screen |
| AI facilitator conversations | An audio recording of the whole Jhourney Bot session (your voice and the AI's); the conversation as text; and what you type to the text-based facilitator | Jhourney Bot and facilitator chat |
| Voice recordings | Audio you record of yourself describing a meditation, plus any title and transcript for it | Record screen — only when you actively press record |
| Ratings and feedback | Your 1–5 ratings of an AI session and any notes you add; anything you send through the in-app feedback form | End-of-session sheet; feedback form |
3.2 Information generated by your use of the App
| Category | Examples |
|---|---|
| Practice history | Which sits you completed and when, streaks, minutes practised, curriculum progress, which lessons you marked done |
| Content activity | Audio tracks played and saved, videos watched and how far through, which weekly items you completed |
| AI session metadata | For each AI conversation: when it started and ended, how many turns, which model and prompt version ran, response latency, the conversational phase and technique the AI chose per turn, and whether a safety check was triggered |
| AI outputs about you | The practice suggestions generated for you, the summary distilled at the end of an AI session, and whether you used a suggestion |
| AI cost records | Per request: the feature, the model name, and token counts. This record contains none of your text. |
| Notification settings | Whether you enabled practice reminders and at what time |
3.3 Device and technical data
| Category | Examples | Purpose |
|---|---|---|
| Device identifiers | A random per-install identifier we generate, your device platform (iOS/Android), app version | Delivering push notifications to the right device; support |
| Push token | The push token our notification provider issues for your device, its notification permission status, and its time zone | Sending the reminders you asked for |
| Diagnostics | Crash reports, error messages, stack traces, the screen you were on, app version, OS version | Fixing crashes and bugs |
| Product analytics | Events like "sit completed", "letter saved", screen views, and your user ID and email as the identifier | Understanding which features are used |
| Connection data | IP address, request timestamps (recorded transiently by our hosting and infrastructure providers) | Running and securing the service |
We do not collect: your contacts, your photo library, your precise or coarse location, your health data from Apple Health or Google Fit, your advertising identifier (IDFA/AAID), or your browsing activity in other apps or websites.
3.4 Sensitive information
What you write and say in the App is often personal — how your practice is going, what is hard, how you feel. Some of it may qualify as sensitive personal information under laws such as GDPR Article 9 or the CPRA. We treat your written reflections, gratitude entries, letter, AI conversations, and voice recordings as sensitive by default:
- They are encrypted, both at rest and — for reflections, onboarding answers, gratitude entries, transcripts, debrief conversations, and AI-generated facilitator notes — at the individual database column level, so those fields are ciphertext even inside the database.
- They are never used for advertising, never sold, and never shared for cross-context behavioral advertising.
- They are never sold and never shared with anyone outside the providers listed in Section 8.
- Jhourney staff can read your AI conversations as part of running the service, and we describe exactly who and why in Section 5.7 rather than implying nobody looks.
4. Device permissions we ask for
| Permission | When we ask | What happens if you say no |
|---|---|---|
| Microphone | The first time you record on the Record screen, or start a Jhourney Bot session | Everything else in the App works normally. We access the microphone only while you are actively recording or in an AI session — never in the background, and never during a silent sit. The App shows you clearly when the microphone is live. |
| Notifications | When you turn on practice reminders | The App works normally; you just get no reminders. Reminders are off by default — you opt in. |
You can revoke either permission at any time in your operating system settings.
5. AI features in detail
This is the part most people want to read carefully, so we have written it plainly.
5.1 Which features use AI
| Feature | What it does |
|---|---|
| Jhourney Bot | A spoken, real-time conversation with an AI meditation facilitator. See 5.4. |
| AI facilitator chat / debrief | The same facilitator, in text, to debrief a sit. |
| Post-sit practice suggestion | Reads what you just wrote about a sit and suggests a concrete experiment for your next sit. |
| Letter highlights | Picks out a few lines of your own letter to resurface to you later. |
| Voice recording transcription | Converts a meditation recording you made into text, when you ask it to. |
None of these run unless you use the screen they live on. You are never opted into an AI feature silently.
5.2 Exactly what gets sent to an AI provider
| Feature | What leaves our servers |
|---|---|
| Post-sit suggestion | What you wrote about the sit you just finished (intention, what you learned, your notes, jhana stage, duration); a short summary of your last four completed sits, for continuity; and relevant excerpts from Jhourney's own teaching material |
| Letter highlights | The text of your letter |
| Transcription | The audio file you recorded |
| Jhourney Bot | Your live microphone audio; the running text transcript of the conversation; the session state; and relevant excerpts from Jhourney's teaching material |
| Facilitator chat | Your messages in that conversation, plus your recent practice context |
We do not send your email address, your name, your account identifier, or your payment or billing status to any AI provider. The provider receives your words without your identity attached.
5.3 Who the AI providers are
| Provider | What we use it for | Region |
|---|---|---|
| Anthropic | Language model that writes the suggestion / facilitator response | United States |
| OpenAI | Language model; audio transcription (whisper-1); speech-to-text for Jhourney Bot | United States |
| Language model (alternate / fallback) | United States | |
| Voyage AI | Turns text into a numerical representation ("embedding") so we can retrieve the right teaching material. Your text is sent for this step. | United States |
| LiveKit | Carries the real-time audio between you and the AI facilitator | United States |
| Deepgram, ElevenLabs | Speech-to-text — turning what you say into text, live | United States |
| Cartesia, ElevenLabs | Text-to-speech — the voice you hear | United States |
Which language-model provider handles a given request can change — we route between them for reliability and quality. All of them are bound by the same terms described in 5.5.
5.4 Jhourney Bot: the voice AI facilitator
Jhourney Bot is a live spoken conversation. It is the most personal thing in the App, so here is exactly how it works.
While you are talking
- Your microphone audio streams over an encrypted real-time connection carried by LiveKit.
- A voice-activity detector and a background-noise filter run inside our own facilitator process — they decide when you have finished speaking. These are local models; your audio does not leave our infrastructure for this step.
- Your speech is sent to a speech-to-text provider (Deepgram, ElevenLabs, or OpenAI) and comes back as text.
- That text, plus the conversation so far and relevant Jhourney teaching material, goes to a language model (Anthropic, OpenAI, or Google), which writes the next line.
- Before the AI speaks, a safety check runs on what you said. If it detects signals of crisis or acute distress, the response is redirected to safety-focused guidance and the event is recorded for a human to follow up on.
- The line is turned into speech by a text-to-speech provider (Cartesia or ElevenLabs) and played back to you.
What we keep afterwards
- An audio recording of the whole session — your voice and the AI's, mixed into a single file. It is written directly from LiveKit into our private recordings bucket, encrypted, and is played back only through a short-lived link issued to you (or to a member of staff acting under Section 5.7). Recording is on for every session; the App tells you before the session starts.
- The text transcript of the conversation — both your side and the AI's — turn by turn, encrypted at the database column level.
- How the AI made each decision: the phase of the conversation, the technique it chose, which prompt version and model ran, response latency, and any safety flag raised.
- A short distilled summary of the session, shown back to you.
- Your ratings and any notes you leave on the end-of-session sheet.
We keep the recording so you can revisit the sit you actually had, and so that when the AI gets something wrong we can hear what happened rather than guess. Deleting your account deletes your sessions and their recordings.
Why this is worth knowing
An audio recording is more revealing than a transcript: it carries your voice, your pauses, and your tone. If you would rather not be recorded, don't start a Jhourney Bot session — the text-based facilitator does the same work without audio.
5.5 Your content is not used to train AI models
- Jhourney does not train or fine-tune any model on your personal content.
- Every AI provider we use is engaged as a data processor under a data processing agreement that prohibits using your content for their own purposes, including training or improving their models.
- We use these providers' commercial API tiers, where the default is that inputs and outputs are not used for training.
- Providers may retain inputs for a short period (typically up to 30 days) for abuse monitoring, then delete them. They may not use that copy for anything else.
Separately, we would like to learn from real conversations in order to make our own AI better. We only do that with your explicit, separate permission — see Section 6. Even then, it never means handing your content to an AI provider for their training.
5.6 What we keep
The AI's output — the suggestion, the facilitator note, the transcript, the highlights, the session summary — is stored in your account so you can see it again later. You can delete it by deleting the entry or session it belongs to, or by deleting your account.
We also store a small usage record for each AI call: the feature, the model name, and the number of tokens in and out. It contains none of your text. It exists so we can enforce per-user usage limits and control cost.
5.7 Who at Jhourney can see your AI conversations
Being straight with you about this matters more than sounding reassuring, so here is the plain answer: your AI conversations are read by people at Jhourney. Not by outsiders, not by an ad network, not by an AI provider — but by our own facilitators and engineers, as a normal part of running the service.
| Who | When | Why |
|---|---|---|
| Jhourney facilitators | Ongoing, and always when a safety signal is raised | To support you better — knowing what you have actually been working on, and following up as a human when something in a conversation suggests you need one |
| Jhourney product engineers | Ongoing | To improve the AI facilitator: seeing where it misread someone, interrupted, or gave a weak response is how it gets better. Also to diagnose bugs and failures. |
| Anyone handling your support request | When you ask for help or report a bad AI response | To look at the specific session you are asking about |
This access is limited to staff who need it, and administrative access is logged. Nobody outside Jhourney sees these conversations, and they are never used for advertising.
We would rather tell you this clearly than bury it. If it is not something you want, the practical consequence is simple: don't put anything into an AI conversation that you would not be willing to have a Jhourney facilitator or engineer read.
This is separate from Section 6, which is about your conversations being kept and reused as durable material — test cases and worked examples that outlive the session. That requires your explicit permission; this does not.
5.8 AI is not a clinician, and you should not rely on it as one
- Jhourney is a wellness and education service, not medical care. We are not a HIPAA covered entity. Nothing the AI produces is medical, psychological, or crisis advice.
- You are talking to a machine. Jhourney Bot is an AI, not a human facilitator, and the App tells you so before and during every session.
- AI output can be wrong. Language models can produce confident, plausible, incorrect suggestions. Treat anything it says as an idea to consider, not an instruction to follow. Use your own judgement and your human facilitator.
- AI-generated content is labelled as such wherever it appears in the App.
- Safety routing is a safety net, not a safety guarantee. The automated check described in 5.4 is designed to make responses safer; it is not a substitute for emergency help. If you are in crisis, contact your local emergency services or a crisis line (in the US: call or text 988).
5.9 Automated decisions and human review
The App makes no solely automated decisions that produce legal or similarly significant effects about you. AI features generate suggestions, conversation, and text; they do not determine your access, your eligibility, your pricing, or any formal assessment of you.
If you want human review of anything the AI produced, or want to contest it, email retreats@jhourney.io.
5.10 How to avoid AI features
Every AI feature is optional and user-initiated:
- Don't start a Jhourney Bot session, and no audio recording or transcript is created. The text-based facilitator gives you the same practice without a microphone.
- Don't request a post-sit suggestion, and no reflection text is sent to any AI provider.
- Don't use letter highlights, and no letter text is sent.
- Don't request a transcript, and your recording audio is never sent for transcription.
Declining every AI feature does not restrict any other part of the App.
6. Helping us improve Jhourney — only with your explicit consent
We want the AI facilitator to get better, and the honest way to do that is to learn from real conversations. We are not willing to do that quietly. So:
6.1 The rules we hold ourselves to
- It is off by default. We do not use your conversations to improve Jhourney unless you deliberately turn it on.
- It is separate from using the App. Saying no costs you nothing. Every feature works identically either way, and we will never re-ask in a way that pressures you.
- It is granular. You choose each permission below independently. Turning on one does not turn on the others.
- It is reversible. You can withdraw at any time in Profile → Privacy, in one tap, with no explanation required.
- It is per-session too. Even with consent on, you can exclude any individual session.
- It stays inside Jhourney. Consenting never means your content is given to an AI provider to train their models. It never leaves the providers listed in Section 8.
6.2 What you can consent to
| Permission | What it allows | What it does not allow |
|---|---|---|
| Evaluation sets | A de-identified excerpt may be kept as part of a fixed test set. When we change a prompt or model, we re-run that set to check the new version is actually better and has not become unsafe. | Any model learning from it. An evaluation set is a ruler, not a lesson. |
| Teaching examples | A de-identified excerpt may be kept as a worked example that guides how the AI responds in other people's conversations, and used in training our human facilitators. | Fine-tuning or training model weights, at Jhourney or at any AI provider. |
The line these permissions draw is keeping and reusing, not reading. Staff reading your conversation as part of running the service is covered in Section 5.7 and happens either way. What needs your permission is an excerpt of your session being copied out, kept indefinitely, and applied to other people's experience.
None of these permissions cover model training. If we ever wanted to train or fine-tune a model on your content, that would be a new, separate, explicit request — not something these toggles quietly authorise.
6.3 What "de-identified" means here
Before any excerpt enters an evaluation set or example library:
- Your name, account, and email are stripped — the excerpt is never linked back to your account record.
- An automated redaction pass removes identifying references in the text itself: names, employers, specific places, distinctive personal events, and references to partners or family that would identify someone.
- A Jhourney facilitator reviews the redacted excerpt before it is approved for use.
De-identification is careful but not magic. If a conversation contains a detail that is distinctive enough, redaction can miss it. That is one honest reason to leave these permissions off if you would rather not take the chance.
6.4 What happens when you withdraw
- We stop using your content for the withdrawn purpose immediately.
- We remove your excerpts from evaluation sets and example libraries, so they are not used again.
- We cannot un-run tests that have already been run. Those produced aggregate scores — such as "version B scored 4% better across 200 cases" — that contain none of your content and cannot be traced back to you.
6.5 Legal basis
For users in the EU and UK, the legal basis for everything in this section is your explicit consent (GDPR Article 6(1)(a), and Article 9(2)(a) where the content is special-category data). Withdrawal does not affect processing already carried out lawfully. For California residents, these permissions go beyond what is needed to provide the service, and you may limit them at any time. The safety review described in Section 5.7 does not rely on this consent and continues regardless.
7. Why we use your information, and our legal bases
| Purpose | Legal basis (EU/UK) |
|---|---|
| Provide the App: your account, your journal, your practice history, the curriculum and library | Performance of a contract |
| Run AI features — suggestions, facilitator conversations, transcripts, highlights — when you request them | Performance of a contract; explicit consent where the content is special-category data |
| Send the practice reminders you turned on | Consent |
| Keep the service running, secure, and debugged (crash reports, error monitoring, abuse prevention) | Legitimate interests |
| Understand which features are used, in aggregate, to decide what to build | Legitimate interests |
| Respond to your support requests and feedback | Performance of a contract; legitimate interests |
| Detect and respond to safety signals in AI conversations | Vital interests; legitimate interests in participant safety |
| Facilitator and engineer review of AI conversations to support you and improve the facilitator (Section 5.7) | Performance of a contract; legitimate interests |
| Keeping excerpts as evaluation sets and teaching examples (Section 6) | Explicit consent only |
| Confirm what your account is entitled to (free vs. paid) | Performance of a contract |
| Comply with law and enforce our terms | Legal obligation; legitimate interests |
We do not use your information for advertising, profiling for marketing, or any automated decision-making with legal or significant effects.
8. Who we share it with
We share personal information only with service providers ("processors") who are under contract to process it on our instructions, protect it, and not use it for their own purposes.
8.1 The AI and voice providers, by name
These are the ones that receive what you write and say, so we name them rather than describe them: our claim that your content is not used for training is only something you can check if you know whose terms to check.
Anthropic, OpenAI, Google, Voyage AI, LiveKit, Deepgram, ElevenLabs, Cartesia.
What each of them does, and exactly what reaches it, is in 5.3 and 5.2. None of them receives your name, email address, or account identifier.
8.2 Everyone else, by category
| Category of provider | What they receive | Purpose |
|---|---|---|
| Authentication | Email, name, password credential, session and device metadata, Apple/Google sign-in identifiers | Signing you in and keeping you signed in |
| Managed database hosting (US) | All account data described in Section 3 | Storing your account and your journal |
| Encrypted cloud object storage (US) | Your meditation recordings and your Jhourney Bot session recordings, in a private, non-public bucket with server-side key-managed encryption | Audio storage |
| Application hosting | Requests to the App, including IP address and request metadata | Running and delivering the App |
| Push-notification delivery, including Apple's and Google's push services | Your push token and the notification content | Sending the reminders you asked for |
| Product analytics (US) | Product events, your account identifier and email | Understanding which features are used |
| Error and crash monitoring | Crash reports, app and OS version, the screen you were on | Diagnosing crashes |
| Customer relationship and billing records | Your email and subscription status | Determining whether your account is free or paid, and program communications |
| Content management | Nothing about you. We read our teaching content from it; no user data is sent to it. | Curriculum and daily content |
The full list, with every provider named, its location, and what it does, is at jhourney.io/subprocessors. It lives on its own page so that replacing one vendor with a comparable one doesn't require amending this policy — the protections described here don't change when that list does. A change that would materially affect how your information is handled still gets you notice in the App, per Section 13.
8.3 Other disclosures
We also disclose information where genuinely necessary: to on-call mental-health consultants or emergency services to protect life or safety, to legal and insurance advisers, to authorities where the law requires it, and to a successor entity in a merger or acquisition under confidentiality.
8.4 What we do not do
- We do not sell personal information.
- We do not share personal information for cross-context behavioral advertising.
- There are no advertising SDKs, ad networks, or cross-app tracking technologies in the App. We do not request App Tracking Transparency permission because we do not track you across apps or websites.
- We do not use your content to train AI models, and neither do our providers.
9. How long we keep it
| Data | Retention |
|---|---|
| Account and all journal content (sits, gratitude, letter, recordings, transcripts, AI suggestions) | Until you delete the entry or your account. Deleting your account removes it immediately. |
| AI facilitator sessions — session audio, transcripts, summaries, decision metadata, ratings | Until you delete your account |
| Stored audio (your meditation recordings; Jhourney Bot session recordings) | Removed with the recording or session it belongs to |
| AI provider copies of inputs | Held by the provider for abuse monitoring only, typically up to 30 days, then deleted |
| AI usage records (model, token counts — no text) | Retained for cost and abuse control |
| Safety event records | Retained for participant-safety and incident-response purposes, and may outlive account deletion in the minimal form needed for that purpose |
| Consented excerpts in evaluation sets and example libraries (Section 6) | Until you withdraw consent, or until the set is retired |
| Crash and error reports | Up to 90 days at our error-monitoring provider |
| Product analytics events | Per the retention period we configure with our analytics provider |
| Push tokens | Until you sign out, uninstall, or disable notifications |
| Records we must keep by law (tax, contracts, safety incidents) | For the period the relevant law requires |
| Administrative audit logs | Retained for accountability, and may survive account deletion in de-identified form |
10. Security
- In transit: everything moves over TLS, including the real-time audio connection for AI facilitator sessions. The App refuses non-HTTPS connections in production builds.
- At rest: the database is encrypted at rest, and we additionally apply column-level encryption to your free-text reflections, onboarding answers, gratitude entries, transcripts, debrief conversations, and AI facilitator notes — so those columns are ciphertext even inside the database.
- Audio: stored in a private cloud bucket with public access blocked and server-side key-managed encryption. The App never receives storage credentials; playback and upload use short-lived signed links issued only to you after an authorization check.
- On your device: your session token is stored in the iOS Keychain / Android Keystore via secure storage, not in plain application storage.
- Access control: every database read and write is scoped to your user ID at the service layer; administrative access is limited and logged.
- Diagnostics hygiene: our crash reporter is configured not to attach personal identifiers by default, and we strip credentials out of URLs before they reach it.
No system is perfectly secure, but if we become aware of a breach affecting your personal data we will notify the relevant authorities within 72 hours and notify you as required by law.
11. Your rights and choices
11.1 Delete your account from inside the App
Open Profile → Delete account. This permanently deletes your account, your sits, your journals, your gratitude entries, your letter, your recordings, your AI facilitator sessions, and your AI suggestions, and removes your sign-in identity so it cannot be used again. It cannot be undone, and it does not require you to email anyone.
11.2 Manage what you have consented to
Open Profile → Privacy to see and change the permissions in Section 6 at any time.
11.3 Other rights
- EU / UK (GDPR): access, correction, deletion, restriction, portability, objection, and withdrawal of consent at any time (withdrawal does not affect processing already carried out). You may lodge a complaint with your local supervisory authority; in the UK, the ICO.
- California (CCPA/CPRA): the right to know, delete, and correct; the right to limit the use of sensitive personal information; and the right to opt out of sale or sharing — we do neither, so there is nothing to opt out of. We honour Global Privacy Control signals on the web.
- Other US states with comprehensive privacy laws: equivalent rights, including the right to appeal a denial.
- We will never discriminate against you for exercising a right.
11.4 How to exercise them
Email retreats@jhourney.io. We may take reasonable steps to verify your identity. We respond within the timelines the law requires (EU/UK: one month; California: 45 days). To appeal a denial, reply with "Appeal" in the subject line.
12. International transfers
We process data in the United States. If you are in the EU, UK, or Switzerland, your data is transferred to the US. We rely on Standard Contractual Clauses (with the UK addendum where applicable) and other permitted safeguards for those transfers, and we require the same of our processors, including our AI providers.
Until our Article 27 representatives are published here, EU and UK users may contact us at retreats@jhourney.io for any privacy matter.
13. Changes to this notice
We may update this notice. We will change the effective date at the top and, for material changes — particularly any change to how AI features handle your content, or to what Section 6 covers — give you notice in the App before the change takes effect. We will never expand what a consent you already gave permits; a wider use requires asking you again.
14. Contact
Jhourney, Inc. 2261 Market Street, Suite 22161 San Francisco, CA 94114 retreats@jhourney.io