Privacy Policy

Effective 28 July 2026. This policy covers the Listening iOS app and journal.algernonlabs.com, both operated by Algernon Labs ("we", "us").

It is written to be read. Where a plain sentence and a precise one differ, we have used the precise one.

Summary

  • Your journal entries are stored on our servers so they can be read, extracted, and analysed.
  • On iPhone, voice recordings never leave your device — transcription happens there. In the browser they are uploaded to be transcribed, then deleted on your schedule.
  • Entry text is sent to Anthropic to extract structured values. It is not used to train models.
  • We do not sell your data, show ads, or run third-party analytics or tracking SDKs.
  • You can export everything, and delete any value, any entry, or your whole account, from inside the app.

What we collect

Account

Your email address, and — if you sign in with Google — the fact that Google confirmed it. We do not receive your Google password. We also store your time zone, your chosen day-boundary hour, and your interface language, because day-grouping and check-in timing depend on them.

What you write

The text of your entries, exactly as you wrote it, with the time you wrote it and the time zone you were in. Entries are never edited or rewritten by us.

What we derive from it

Structured values extracted from your entries — sleep, mood, exercise, factors — each stored with the verbatim snippet it came from. Names of people you mention become private entries in your own entity list, visible only to you. Everything in this category is derived and can be rebuilt from your entries.

Diagnostics

Ordinary server logs: request times, error codes, account identifiers. Entry text is never written to logs or error reports — this is enforced in code by a logging filter, not by convention. If the app crashes, the report contains no journal content.

What we do not collect

No advertising identifiers, no third-party analytics or tracking SDKs, no location beyond a city you set yourself, no contacts, no health data from HealthKit unless you explicitly connect it, and no data from any other app.

Voice and audio

This works differently on the iPhone app and in the browser, so the two are set out separately. The difference is real and we are not going to blur it.

On the iPhone app, audio never leaves your device. When you create an account the app downloads a speech model, and every voice entry is transcribed locally by that model. Recordings are not uploaded, not streamed, and not sent to any transcription service. If the model is not ready yet, or a recording is too long to transcribe in one pass, the entry waits on your device until it can be — it is never sent to a server instead.

In the browser, audio is uploaded. A web page cannot run the speech model, so a voice entry made at journal.algernonlabs.com is uploaded to our storage, transcribed by OpenAI's Whisper API, and then deleted on your retention schedule — 30 days by default, adjustable from 0 to 90, where 0 means it is discarded as soon as it has been transcribed.

If you would rather no recording of your voice ever left your device, use the iPhone app, or type instead of speaking in the browser.

On both, the transcript — the words, as text — is sent to our server and treated exactly like an entry you typed, including being sent to Anthropic for extraction. We say this plainly because a privacy claim that overstates is worse than none.

How it's used

Your data is used to operate the product you are paying for, and for nothing else:

  • To store and show you your journal.
  • To extract structured values from your entries, and to ask you a clarifying question when an entry is ambiguous.
  • To compute statistics, findings, and experiment results across your own history.
  • To send you service email you asked for — check-in reminders, account notices.
  • To keep the service running and secure, and to debug faults.

We do not use your journal to train machine-learning models, ours or anyone else's. We do not profile you for advertising. We do not sell or rent personal data, and we do not share it for cross-context behavioural advertising.

Health and sensitive data

Sleep, mood, energy, symptoms, exercise, alcohol, medication — the things this app exists to track — are health data in the eyes of European, UK and Californian law, and are treated as a special category deserving stronger protection. Entries can also reveal other sensitive things about you: who you spend time with, what you believe, how you feel about your job. We treat everything you write as sensitive, because a journal does not separate neatly.

What that means in practice:

  • Consent is the only basis on which we process it. The sign-in screen states, before you create an account, that Listening stores and analyses health information you write, and names what that means; creating the account is how you consent to it. We do not rely on any other justification, and we do not process health data for anything you have not asked for.
  • You can withdraw it at any time, by deleting your account in Settings → Account. Withdrawing does not undo processing that already happened, but it stops all of it and removes the data.
  • We do not use sensitive data for anything beyond the features you are using it for. We never use it to advertise, profile you commercially, or infer anything for a third party.
  • We do not sell it, share it for cross-context behavioural advertising, or disclose it except to the processors named below who are needed to run the product.

If you would rather not give us health data at all, do not create an account — there is no reduced mode in which this product is useful without it, and we would rather say so than pretend otherwise.

Why we're allowed to

If you are in the European Economic Area or the United Kingdom, the law requires us to name the legal basis for each thing we do. Ours are:

Performance of a contract
Storing your entries, extracting values, computing your statistics, running your account and your subscription. This is the service you signed up for; without processing there is no product.
Explicit consent
Everything in the section above — health and other special-category data. Consent is also the basis for any integration you connect yourself, such as HealthKit, and for optional service email. Withdrawable at any time.
Legitimate interests
Keeping the service secure, debugging faults, and preventing abuse — using logs that contain no entry text. We have weighed this against your interests; the data involved is operational, not personal content.
Legal obligation
Retaining or disclosing data where the law compels it, and notifying you and regulators of a breach.

We do not rely on legitimate interests for anything involving the content of your journal. The law does not permit it for health data, and we would not want to.

Automated processing

Two parts of this product are automated, and you should know exactly what they do.

Extraction. A language model reads your entries and pulls out structured values. It is imperfect. Every value it produces is stored with the verbatim words it came from, shown to you, and correctable in one tap. When an entry is ambiguous it asks you rather than guessing.

Analysis. Statistical tests run across your own history to surface patterns, and experiments you set up test them. These describe your data back to you.

Neither makes a decision that produces a legal effect or similarly significantly affects you. We do not score you, rank you, share any assessment with anyone, or use any of it to decide anything about you — pricing, access, or otherwise. Nothing the app concludes leaves your account. You can turn analysis off, correct any input to it, and delete the output.

Who else touches it

We use a small number of service providers. Each is contractually limited to processing data on our instructions.

Anthropic
Receives your entry text to extract structured values and to write clarifying questions. Under Anthropic's commercial terms, inputs are not used to train their models.
OpenAI
Receives voice recordings made in the browser, to transcribe them. Never receives audio from the iPhone app, which transcribes on the device. Under OpenAI's API terms, inputs are not used to train their models.
Google
Only if you choose Google sign-in, and only to verify your identity. Google does not receive your journal.
Neon
Hosts the database your entries live in.
Fly.io
Runs our application servers.
Cloudflare
Serves this website, stores browser-uploaded audio until it is deleted, and provides DNS and TLS.
Apple
Handles all payment for subscriptions. We never see your card details. Apple shares only whether a subscription is active.

We will also disclose data if legally compelled, and will tell you unless we are prohibited from doing so. If the business is ever sold or transferred, your data moves under this policy and you will be told before anything changes.

These providers operate in the United States and the European Union, so your data may be processed outside your country. Transfers rely on the providers' standard contractual clauses.

Stored on your device

This website sets no cookies and runs no scripts. The marketing and legal pages are static files. There is no analytics tag, no pixel, no consent banner to dismiss, because there is nothing to consent to.

The app itself stores a few things locally, all of them necessary and none of them for tracking:

Your session
A sign-in token, so you are not asked to sign in on every visit. Signing out removes it.
Your offline queue
Entries you write without a connection, held on the device until they can be sent. This is why you can write on a plane.
Your preferences
Interface language and similar local settings.

All of it lives in your browser's own storage, or on your phone, and is cleared when you sign out or clear site data. None of it is readable by another site, and we do not use it to recognise you across services. We do not respond differently to a Do Not Track or Global Privacy Control signal because there is no tracking here to turn off.

How long we keep it

Entries
Until you delete them or your account. Entries are the one thing in this system we treat as irreplaceable.
Derived values
Same as the entry they came from; deleting an entry deletes everything derived from it.
Voice recordings — iPhone
On your device only, on your retention setting: 30 days by default, 0 to 90 by choice.
Voice recordings — browser
In our storage, on the same retention setting, then hard-deleted.
Account record
Until you delete the account.
Server logs
30 days. They contain no entry text.
Backups
Deleted data disappears from rolling backups within 30 days of deletion.

Your rights

All of these work from inside the app, without emailing anyone and without a paid subscription:

  • Export. Settings → Account → Export. JSON with your raw entries and every extracted value alongside the snippet it came from, plus markdown for reading.
  • Correct. Tap any extracted value to edit or remove it. Your original text is never altered — corrections are recorded next to it.
  • Delete. One value, one entry, or the entire account. Account deletion removes every row and every stored object, and cannot be undone.

Depending on where you live you may also have the right to object to or restrict processing, to request a copy in a portable format (the export is one), and to complain to your data protection authority. To exercise anything not available in the app, email us; we reply within two business days and will not charge you for it.

Where you live

The rights above are given to everyone, wherever you are. Some places add specifics.

European Economic Area and the United Kingdom
You have the rights of access, rectification, erasure, restriction, portability, and objection, and the right to withdraw consent at any time without affecting processing already carried out. You may complain to your national data protection authority — in Ireland the Data Protection Commission, in the UK the Information Commissioner's Office — and you may do so without contacting us first, though we would rather you gave us the chance to fix it.
California
You have the right to know what we collect and why, to delete it, to correct it, to a portable copy, and not to be discriminated against for exercising any of them. We do not sell personal information and we do not share it for cross-context behavioural advertising — not in the ordinary sense and not in the broad statutory sense — so there is no "Do Not Sell or Share" link to click, because there is nothing for it to switch off. We use sensitive personal information only to provide the service you asked for, which is the limited purpose the right to limit its use is designed to secure; we have nothing further to restrict. Every one of these rights is exercisable from inside the app, immediately, without asking us.
Canada
You may ask what we hold about you, ask us to correct it, and challenge our handling of it. If our answer does not satisfy you, you can complain to the Office of the Privacy Commissioner of Canada at priv.gc.ca.

Whoever you are: we do not charge for any of this, we do not require you to create an account to ask, and we will not ask you for more identifying information than we need to be sure it is you.

Security

Data is encrypted in transit with TLS and at rest by our database and storage providers. Access to production systems is limited to people who need it and protected by multi-factor authentication. Entry text is excluded from logs and error reports by design.

No service is perfectly secure. If a breach affects your data we will tell you and the relevant regulator without undue delay, and within 72 hours where the law requires it.

Children

Listening is not directed to children under 13, and we do not knowingly collect their data. If you believe a child has created an account, email us and we will delete it.

Changes

If we change this policy we will update the date at the top. If a change materially affects how your data is handled, we will tell you in the app or by email before it takes effect, so you can export or delete first.

Contact

Algernon Labs — alexhu@me.com

One person is accountable for privacy here, and that address reaches them. Write for any of it: access, correction, deletion, a copy of your data, withdrawing consent, a complaint, or a question about a sentence on this page. We reply within two business days, and resolve requests within 30 days at the outside — sooner in almost every case, because most of these are buttons in the app that you do not need us for.