Version 1.0 · Effective August 6, 2026
This policy explains how InnerJourney handles information when you use innerjourney.space, the authenticated web application, or the Telegram bot. InnerJourney is an AI journaling and reflection service, not a medical or emergency service.
• Account and authentication data — name, email, password hash, locale, and identifiers returned by Google, Facebook, or Telegram when you choose those sign-in channels.
• Journal data — entries, chat messages, AI responses, summaries, profile and goals derived to provide context.
• Usage and billing records — timestamps, message/token counts, plan, subscription state and provider identifiers. InnerJourney does not receive or store full card details.
• Browser data — a random visitor ID, consent choice and campaign parameters in local storage. The service is not anonymous: account and technical data can be linked to your use.
We use this information to authenticate you, provide and secure the service, generate AI responses and summaries, enforce limits, manage billing, answer support requests and measure the public site when permitted. Journal content and related context are sent to the configured AI provider needed for a requested response. AI output may be inaccurate.
Depending on the feature you use, information is handled by: Anthropic and configured fallback AI providers (AI responses); Groq/OpenAI-compatible transcription and ElevenLabs (voice features); Creem (checkout and subscription management); Resend (service email); Google and Meta (optional sign-in); Telegram (bot delivery); Better Stack through the Sentry client (sanitised technical errors); and, only with the relevant public-site consent, Microsoft Clarity, Google Analytics and the Reddit advertising tag. Their own terms and retention practices also apply.
Optional Clarity, Google Analytics, Reddit advertising and InnerJourney audience events are limited to the public home routes (/ and /ru). They are off until the matching analytics or marketing choice is saved. Registration, login, legal and authenticated app routes do not load those optional marketing tools. Sanitised technical error reporting may run across routes as an operational service. You can change optional choices using “Privacy choices” on the public home page.
Account, journal, usage and subscription records remain in InnerJourney-controlled stores until account deletion or for as long as needed to operate the account. Consent and visitor values remain in your browser until you clear them. We do not promise a fixed deletion period for independent provider systems; provider retention is governed by their policies and our applicable service terms.
From the authenticated account page you can download a versioned JSON export of account, journal, session, usage and subscription data. You can also request permanent deletion of InnerJourney-controlled account data. If recurring billing is active, first open subscription management and set it to cancel. Deletion is reported as complete only after the application database and journal vector store confirm it. This does not promise deletion from provider systems outside our control.
Traffic is sent over HTTPS and email passwords are stored as hashes. No system is completely secure. We do not sell journal content to advertisers. We may disclose information when required by law, to protect the service or users, or to processors needed for the purposes above.
The service is not intended for children under 13. We may revise this policy and will publish a new version and effective date here. Privacy, export or deletion questions: support@innerjourney.space.