Jou app
Jou Privacy Policy
Last updated: 31 July 2026. Jou is operated by Whale Boy Ltd ("we", "us", "our"). This policy explains how Jou handles personal data.
What Jou Is
Jou is a journaling and sticker app. You can create journal entries, add titles, body text, moods, stickers, rich-text blocks and todo-style items, create custom photo stickers, manage sticker credits, unlock stickers, export or import journal data, use reminders, and optionally sign in for account-backed features.
Data We Collect
- Account data: your email address, Supabase user ID, authentication provider details, account creation date, and password reset or sign-in information. Passwords are handled by Supabase Auth.
- Apple or Google sign-in data: identity tokens needed to sign you in. Apple may provide your name and email or private relay email. Google may provide sign-in identity information.
- Journal content: entry titles, body text, mood identifiers, dates, sticker placements, remote sticker URLs, rich-text blocks, and todo items. Entries remain stored locally on your device by default. They are sent to and synced through Supabase only while Jou Plus cloud sync is active; signing in alone does not sync journal content.
- Custom photo sticker data: the generated PNG sticker, its storage path, style, dimensions, display name, pack information, generated file size, upload and completion timestamps, upload status, access tier, and creation or archive status. We do not upload the original photo you select or take.
- Custom-sticker usage data: account-linked sticker ID, byte size, subscription tier, and upload completion time. We use this to operate the service, prevent abuse, and enforce reasonable technical limits.
- Journal-entry-to-sticker reference data: a private index linking a synced journal entry to any custom sticker it uses. We use this only to avoid deleting an image still required by a journal entry.
- Commerce data: credit balance, credit ledger entries, owned stickers or collections, StoreKit product IDs, transaction IDs, subscription product, subscription status, and expiry date. Apple handles payment processing; Jou does not receive card details.
- Voluntary feedback: if you use the Home Screen feedback action, we collect the reason you select and any feedback message you choose to provide. You may separately choose to provide a contact email and, when signed in, to include your Jou account ID. We do not attach your journal entries, photos, or other journal content to feedback.
- Feedback-throttling data: a random per-installation identifier and the IP address for a feedback request are used to create separate secret-keyed hashes. Only the hashes are retained for approximately 24 hours to prevent feedback abuse; raw identifiers are not stored in the rate-limit records or on the feedback record.
- Rewarded-ad data: for Watch & Earn, AdMob server-side verification may provide user ID, transaction ID, ad unit, ad network, reward item or amount, sticker or pack IDs, verification time, claim time, and the signed callback query.
- Optional analytics data: only if you choose Share Analytics, PostHog receives an internal account ID for signed-in users, a generated device identifier, lifecycle and product-interaction events, counts and boolean states, feature-flag data, and fixed diagnostic categories. It does not receive your email address or free-form error messages.
- Device and technical data: app/platform identifiers, diagnostics, performance or error data, and feature-flag data. Google Mobile Ads/UMP may process approximate location, advertising data, device identifiers, product interaction, performance, and diagnostics according to their SDK behaviour.
- Local settings: reminder settings, default mood, theme settings, tutorial state, sync retry state, rewarded-ad claim counters, and passcode-lock settings.
- Security data stored on-device: passcode salt/hash, Face ID setting, and recovery user ID/email in Keychain. Jou does not receive your biometric data; Face ID is handled by iOS.
Custom Photo Stickers
You can choose a photo from your library or take a photo with your camera to create a custom sticker. Photo-library and camera access are optional and are only requested when you choose to use this feature.
Jou processes the selected or captured photo on your device to create the sticker. Depending on the style you choose, this may include iOS subject cut-out, framing, and cropping. We do not send your original photo to our servers or to an AI or third-party image-processing service.
Only the generated PNG sticker is uploaded to private, account-scoped Supabase storage so it can be used and synced in Jou. Custom stickers may also be cached locally on your device for display. They are not public and are accessible only to the account that created them.
We record account-linked upload usage, including the sticker ID, byte size, subscription tier, and completion time, to operate the service, prevent abuse, and enforce reasonable technical limits. We also maintain a private journal-entry-to-sticker reference index so that we can avoid deleting an image still required by a synced journal entry.
Feedback
The feedback action is optional. We use feedback to understand issues, plan improvements, and, only if you ask us to contact you, respond to you. Feedback is not sent to PostHog and we do not use it for advertising, marketing, or tracking. Selecting the optional account-ID switch helps us investigate the feedback, but it is not required to send it.
To prevent abuse of the feedback service, we use a random per-installation identifier and the IP address for a feedback request to create separate secret-keyed hashes. We retain only those hashes for approximately 24 hours to limit repeated submissions. We do not store the raw installation identifier or IP address in the rate-limit records, and the hashes are not stored on the feedback record.
Optional Analytics And Consent
PostHog analytics is off by default. Jou does not configure PostHog, identify you, collect analytics events, or request PostHog feature flags until you explicitly choose Share Analytics. Declining analytics does not restrict any paid or core app feature.
You can change your choice at any time using the Share Analytics switch in Settings. Turning it off opts the app out of PostHog collection, resets the local PostHog identity, and blocks subsequent analytics and feature-flag calls. Analytics collected while consent was active may remain for the retention period below, unless applicable law requires earlier deletion.
What We Do Not Send To Analytics
PostHog does not receive journal body text, journal titles, mood names, sticker images or image URLs, email addresses, feedback messages, authentication tokens, or URLs with secret query values. Screen autocapture, element autocapture, session replay, and automatic error capture are disabled. Manual diagnostics contain only a fixed, allow-listed error-category value and cannot accept error messages or caller-supplied properties.
How We Use Data
We use data to provide accounts, sync, journal and custom-sticker storage, exports/imports, purchases, credits, subscriptions, sticker unlocks, rewarded ads, reminders, security, fraud prevention, support, product improvement, analytics, feature flags and legal compliance.
Third Parties
- Supabase for backend, authentication, database, storage and Edge Functions.
- PostHog for optional, consent-based product analytics, feature flags and fixed diagnostic categories.
- Apple for Sign in with Apple, StoreKit, App Store purchases, subscriptions and refunds.
- Google for Google Sign-In, Google Mobile Ads/AdMob and related consent/ad SDK tooling.
These providers process data under their own terms and privacy policies. We do not sell journal content, and we do not use journal content for advertising analytics.
Export, Deletion And Retention
You can export journal data from Settings as a JSON file. This export includes your journal entries and should be kept private.
You can delete your account in Settings. Jou calls a Supabase delete-account function, removes custom photo-sticker files from private storage, deletes the authentication user and associated Supabase records, removes that account's local journal entries, streak records, sticker ownership and reward history, clears related sticker and commerce cache state, and signs you out.
Guest data means local content and rewards created while you are signed out. When you next sign in, Jou deliberately assigns that guest data to the account you sign in to. Deleting an account removes data assigned to that account. Any guest data that has not been assigned to an account, and local records belonging to another account on the same device, are kept.
We keep account data for as long as your account is active. If you delete your account, we delete the personal data held in Supabase for that account. Deleted data may remain temporarily in encrypted database backups until those backups expire under Supabase's backup schedule. We do not restore deleted accounts from backups except where needed for disaster recovery.
Active custom stickers are retained while needed for your account. A custom sticker referenced by a synced journal entry is retained while that reference and your account continue to exist. Replaced or archived custom stickers that are not referenced by a synced journal entry normally become eligible for deletion after 90 days. Failed, cancelled, or abandoned uploads normally become eligible after a short recovery period of about 24 hours. An unreferenced Plus custom sticker normally becomes eligible for deletion 180 days after Plus expires. A safety period and daily processing mean that deletion may occur later than the earliest eligibility date. If you resubscribe before deletion, subscription-lapse cleanup is cancelled. Account deletion requests immediate removal of custom-sticker files and associated records, subject to the backup retention described above.
We retain voluntary feedback for up to 24 months to understand recurring issues and improve Jou. When you delete an account, any optional Jou account ID on feedback is disassociated. If you supplied a contact email, you can ask us to delete that feedback by contacting hello@whaleboy.co.uk.
We keep analytics data collected with your consent in PostHog for up to 12 months, or for the shorter retention period configured on our PostHog account if that changes. Withdrawing consent stops future collection but does not automatically delete analytics already collected.
We retain operational cron execution history for no more than 30 days.
We keep operational and security logs for up to 90 days, unless we need to keep specific logs longer to investigate abuse, security incidents, payment issues, or legal obligations. Apple may retain purchase, subscription, refund, and transaction records under Apple's own policies. Google, Supabase, and PostHog may retain certain operational logs and backup data according to their own retention schedules and policies.
Your Choices
You can decline analytics when asked or switch off Share Analytics in Settings at any time. You can also sign out, delete your account, export your data, cancel reminders, disable passcode lock, manage Face ID in device settings, manage tracking permissions in iOS if enabled, and cancel subscriptions through Apple. You may contact us to request access, correction, deletion, restriction or portability of personal data.
Security
Jou uses iOS file protection for local journal storage where available, Keychain for passcode-lock material, HTTPS-based services, Supabase row-level security, and server-side purchase or reward verification. No system is perfectly secure.
Controller Details
Whale Boy Ltd is the data controller responsible for the processing of personal data described in this Privacy Policy.
Whale Boy Ltd
Company Number: 17202630
Contact: hello@whaleboy.co.uk
International Transfers
We are based in the United Kingdom. Some of the service providers we use are based outside the United Kingdom and European Economic Area (EEA), or may process personal data in countries outside the United Kingdom and EEA, including the United States and other countries where they or their sub-processors operate.
Where personal data is transferred internationally, we rely on appropriate safeguards where required by applicable data protection laws. These safeguards may include adequacy regulations, the UK International Data Transfer Addendum, the EU Standard Contractual Clauses, and equivalent contractual safeguards implemented by our service providers.
Supabase
Purpose: Backend hosting, authentication, database, file storage, Edge Functions, and operational logs.
Where processing may take place: The Supabase project region selected by us, plus other countries where Supabase and its sub-processors provide support, hosting, security, or operational services.
Safeguards: Supabase Data Processing Addendum, EU Standard Contractual Clauses, UK International Data Transfer Addendum, and Supabase sub-processor terms.
PostHog
Purpose: Optional product analytics, feature flags, and fixed diagnostic categories after consent.
Where processing may take place: PostHog US Cloud or EU Cloud, depending on our configured region, plus countries where PostHog sub-processors operate, including the US, Germany, France, and global edge locations.
Safeguards: PostHog Data Processing Agreement, EU Standard Contractual Clauses, UK International Data Transfer Addendum, and the EU-US Data Privacy Framework where applicable.
Purpose: Google Sign-In, AdMob advertising, and rewarded-ad verification.
Where processing may take place: The US, EEA, and other countries where Google and its sub-processors operate.
Safeguards: Google data protection terms, EU Standard Contractual Clauses, and applicable data transfer frameworks.
Apple
Purpose: App Store distribution, StoreKit purchases, subscriptions, refunds, and Sign in with Apple if enabled.
Where processing may take place: Apple entities and service providers globally, including the US and Ireland.
Safeguards: Apple privacy terms, Apple security safeguards, and Standard Contractual Clauses where applicable.
Children
Jou is not specifically directed at children. We do not knowingly collect personal data from children in violation of applicable law. If you believe a child has provided personal data without the necessary consent, please contact us so we can investigate and take appropriate action.
Changes
We may update this policy. Material changes will be reflected by changing the "Last updated" date and, where appropriate, notifying users in the app.
Contact
Privacy-related questions about Jou can be sent to hello@whaleboy.co.uk.
This page applies to the Jou app. Related policies: