Privacy Policy
Effective 9 September 2026. This policy covers the Listening iOS app and journal.algernonlabs.com, both operated by Algernon Labs ("we", "us").
It is written to be read. Where a plain sentence and a precise one differ, we have used the precise one.
Summary
- Your journal entries are stored on our servers so they can be read, extracted, and analysed.
- On iPhone, voice recordings never leave your device — transcription happens there. In the browser they are uploaded to be transcribed, then deleted on your schedule.
- Entry text is sent to Anthropic to extract structured values, and a photo you attach to an entry is sent there to be described so the app can talk about it. Neither is used to train models.
- A photo you attach has any legible writing in it read out and kept — a menu, a receipt, a page of notes, or anything else readable that happens to be in shot. It is how photographing a receipt logs it. Don't attach a photo of something you'd rather we didn't keep.
- Your photo library is never read for image content. If you turn on the map, the only things read from it are the date and the coordinate your camera saved — never a picture.
- If you turn on live health, the app receives your heart rate, heart-rate variability, resting heart rate and workouts from HealthKit as they are recorded, and will say something in your thread and on your lock screen when it notices a finished workout or an unusual day. Off by default until you connect Health.
- Friends you add by code can see the categories of your data you choose — workouts, heart rate, HRV, sleep, mood, city, streak — and are told when the app notices a health event. Never your entries.
- We do not sell your data, show ads, or run third-party analytics or tracking SDKs.
- You can export everything, and delete any value, any entry, or your whole account, from inside the app.
What we collect
Account
Your email address, and — if you sign in with Google or Apple — the fact that they confirmed it. We do not receive your Google or Apple password. If you use Apple's Hide My Email, the private relay address Apple gives us is your account's email here — we never learn the real one. We also store your time zone, your chosen day-boundary hour, and your interface language, and whether you prefer the light or dark theme, because day-grouping, check-in timing and how the app looks depend on them. When you change these settings — or the city you set — we keep a dated record of the change, and the app notes the time zone your device reports when you open it: knowing when you moved is what keeps the entries around a trip interpretable later. This history is settings only, never journal content, and it is deleted with your account. While you are writing a message, the app also stores a single timestamp of your most recent typing — never the unsent text itself — so it can wait until you have finished before it replies.
What you tell us when you sign up
A name to call you by, if you give one. We ask rather than take it from Google or Apple, and it is used to address you in the app — nothing else reads it. Skip the question and the app simply never uses your name; clear it later in Settings and it is gone.
Then a short profile from the questions asked once, at the start: your age range and how you identify, why you came to Listening, anything you asked us to keep an eye on (sleep, mood, energy and similar), practices you already keep, roughly when you sleep and wake, whether you want the daily check-ins, and optionally the city you live in. Every one of those questions can be skipped, and skipping is stored as "skipped" rather than guessed at.
These answers do three things and nothing else. Two are on your own screen: they decide which of your metrics we show you first, and which rows your factors board starts with.
The third is that a short summary of them is included in the context sent to Anthropic when the app writes you a reply — your first name if you gave one, your age range and how you identify, why you came, what you asked us to watch, your practices, your usual sleep hours, and your city. This is so the app writes like something that knows who it is talking to; a reply pitched at a 22-year-old can land badly on someone twice that. It is context, not instruction: nothing tells the model to treat you a particular way because of your age or your gender. Anything you skipped is simply absent — we never send a guess or a placeholder. As with your entries, this is not used to train models.
Your age range and how you identify are read by that summary and by nothing else. No statistic is calculated per age group or per gender, no insight is conditioned on either, and they are never used to advertise to you or shared with anyone. You can change any answer at any time under Settings, and you can erase the whole profile — on its own, without deleting your account, your entries, or anything derived from them — with Forget what I told you in the same place. Erase it and the summary goes with it, starting from your next reply.
We deliberately do not ask for your relationship status, your faith, or any mental-health or therapy history. Some journalling apps do. We do not, because nothing in Listening would behave differently if we knew, and collecting sensitive information that changes nothing is not a trade we are willing to make on your behalf.
What you write
The text of your entries, exactly as you wrote it, with the time you wrote it and the time zone you were in. Entries are never edited or rewritten by us — when you edit one, the previous wording is kept alongside it. Photos you choose to attach are stored with their entry and deleted with it, and a photo you attach is looked at: it is sent to Anthropic, which writes a description of what is in it so the app can talk with you about the picture you sent rather than ignore it. That description is kept alongside the entry, you can read it, and it is deleted with the entry. It is written once, when you send the photo, and the picture itself is never looked at again — so that description is all the app will ever know about it.
The description includes any writing that is legible in the picture, read out as text. A street sign, a menu and its prices, a book's title, a receipt's line items, a page of handwriting, a whiteboard, or a screen — if it is legible, it is transcribed into the description and kept there. This is deliberate: it is what makes photographing a receipt or a page of notes a way of logging them. It also means anything readable that happens to be in shot is captured too, including writing you were not thinking about when you took the picture. If a photo has something on it you would rather the app did not keep, do not attach it — and if you have already sent one, deleting the entry deletes the photo and the description with it. Nothing in this paragraph applies to your photo library, which is covered further down and is never read for image content at all.
What the description is used for: talking with you about the picture, and the written summary of that day. It is never turned into a stored value about your day — not a meal, not a mood, not a number — because the app records what you tell it, not what a model thinks it saw. A day's summary may mention what you photographed, and it is marked in the app's own notes as coming from a picture rather than from you. If you mark one of the app's own messages “That landed” or “Didn't make sense”, we store that one word against that message: it is how the app learns to speak up less when it has been getting you wrong. You can change it or take it back at any time.
What we derive from it
Structured values extracted from your entries — sleep, mood, exercise, factors — each stored with the verbatim snippet it came from. Names of people you mention become private entries in your own entity list, visible only to you. Everything in this category is derived and can be rebuilt from your entries.
What the app remembers
The app writes and keeps a short page about each person, place and recurring subject in your journal — a title, a line describing them, and a handful of details. It is how the app can talk about your life without asking you who someone is every time. These pages include people you write about, and they are built only from your own entries: every detail must point at the entries it came from, and one that cannot is discarded rather than kept.
You can read every page in the app, correct any of them in your own words, and delete any of them. Deleting a page does not delete your entries — the app stops holding that description; your journal is untouched. A deleted page is not rebuilt later. Corrections you make are kept and honoured even when the app rebuilds everything else it has derived.
You can turn off memory entirely, and you can mark any individual person as one the app should leave alone. Writing these pages uses the same model provider already named above for extraction; it adds no new company to the list.
Diagnostics
Ordinary server logs: request times, error codes, account identifiers. Entry text is never written to logs or error reports — this is enforced in code by a logging filter, not by convention. If the app crashes, the report contains no journal content.
If the app itself crashes, it sends us a report on the next launch: the error message, the stack trace, which screen you were on, and a short list of recent actions such as "opened settings". If you were signed in, your account id is recorded with it, because the first question about any crash is which account hit it. It never contains anything you wrote — not entry text, not a transcript, not a check-in answer. These reports go only to our own servers, live in the ordinary server logs, and are deleted with them after 30 days.
No crash-reporting or analytics service receives any of it. We run no third-party error-tracking tool and no analytics SDK: diagnostics reach our servers and stop there. The companies that do touch your data are listed below, and that is the whole list.
Location
To put the weather beside your day, and to draw the map of where you have been. Both are optional. You can type a city instead — that is the default, and nothing asks for your position unless you tap "Use my location".
If you do turn it on, the app reads a coarse position (roughly city-level, not a precise one) and we store it rounded to about a kilometre. Once it is on, the app refreshes it at most once every twelve hours while you have it open, so the weather follows you when you travel. It is never read in the background, never sold, and never used to advertise to you. The only sharing is the one you choose: a friend with your place category on sees the city of the day as a name (Friends and sharing). Turning off location permission for Listening in iOS Settings stops all of it immediately; the city you typed keeps working.
We keep one place per day — the first coarse position or city we have for that day, and nothing more. Not where you went during it, not how long you stayed, not a route: a day is the smallest thing we record and movement within a day is not stored at all. This is what will eventually let the app show you where you have been and notice things like how you sleep away from home.
Settings → Places shows exactly how many days are held and over what dates, and deletes all of them on request. That is a real deletion, not a hidden flag, and it leaves your entries untouched.
Filling in the map from your photos
The map above can only show days you had the app open, so it starts out short. If you want, you can fill it in from photos you have already taken — this is optional, it never happens on its own, and it only runs when you tap the button that offers it.
We want to be direct about what this is, because it is easy to describe vaguely: giving an app access to your photo library is a way of giving it your location history. That is exactly what this feature uses it for, and we would rather say so than let you find out later.
It is also worth being clear that this is ongoing, not a single import. Once you turn it on, every time you open the app it looks for photos taken since the last check and fills in days it is missing. That is what keeps the map from going stale on the days you did not open Listening — and it is the reason we do not ask for background location, which would be a far larger thing to grant.
Here is precisely what happens when you tap it:
- We never look at your photos. Not the image, not a thumbnail, not a copy. Your camera writes a coordinate and a date alongside each photo, and those two things are all we read.
- We keep one coarse point per day, rounded to about a kilometre before it is saved — the same as everywhere else here. Forty photos from one day become one row.
- We only fill days we do not already have. A day the app recorded itself is left exactly as it was.
- Which photo a day came from is never recorded. Once it is saved, the row is indistinguishable from any other, and nothing links it back to a photo.
- It keeps your map current, and only while the app is open. The first tap reads what is already there. After that, whenever you open Listening, it checks for photos taken since the last look and fills in any day it does not have. Nothing runs in the background, nothing watches your library while the app is closed, and you can stop it at any time by removing photo access in iOS Settings — everything already saved stays, and nothing new is added.
iOS lets you grant access to your whole library or only to photos you pick, and either is fine — we use what you gave and tell you how many days it produced. You can decline entirely and the rest of the app is unaffected. Deleting your location history in Settings deletes these days along with the rest.
One thing worth knowing: this makes the map denser where life was more interesting, because that is when people take photos. It is a record of where you pointed a camera, not of where you were.
Working out your time zone
To read your health data on the right days, the app works out which time zone you were living in on each day. It uses only what it already has: the time zone your phone reports when you open the app, the time zone each entry was written in, and the one place per day described above — from your phone or your photos. Turning a place into a time zone happens on our server, from a map of time zones built into it; your locations are not sent anywhere to do it. What is kept is one time zone per day, never a place, and deleting your location history deletes the time zones worked out from it.
What we do not collect
No advertising identifiers, no third-party analytics or tracking SDKs, no precise or background location, and no contacts.
Two things we can read only because you explicitly turned them on, and nothing happens with either unless you do: health data from HealthKit, and the date-and-coordinate pair your camera stored alongside your photos. We never read the photos themselves.
If you connect Health, what we read is what your phone and watch measure: steps, distance, flights climbed, active energy, workouts and exercise minutes, sleep, heart rate, resting heart rate, heart-rate variability, breathing rate, blood oxygen, wrist temperature during sleep, VO2 max, body weight, time in daylight, and the mood you log in Health. Apple's Health app lists every one and lets you turn any of them off individually. We deliberately do not read what you type into other apps — food, caffeine, alcohol, water, medications, mindfulness sessions — because those are your words about your life, and this app already has a place for those: your journal.
Those readings are also what the app's health monitor is computed from. It compares one day's heart-rate variability, resting heart rate, breathing rate, blood oxygen, wrist temperature, sleep and activity with your own readings over the previous sixty days, and shows the comparison as a stress and a readiness figure. Nothing about it is stored: the figures are worked out on our server each time you open the screen, from the readings already described, and are never sent anywhere, shown to anyone else, or used to decide anything about you. It describes what your own measurements did. It is not a diagnosis, it is not medical advice, and it is not a medical device.
Voice and audio
This works differently on the iPhone app and in the browser, so the two are set out separately. The difference is real and we are not going to blur it.
On the iPhone app, audio never leaves your device. When you create an account the app downloads a speech model, and every voice entry is transcribed locally by that model. Recordings are not uploaded, not streamed, and not sent to any transcription service. If the model is not ready yet, or a recording is too long to transcribe in one pass, the entry waits on your device until it can be — it is never sent to a server instead.
Deleting the recordings kept on your phone, and deleting your account, both ask Face ID, Touch ID or your passcode first. That check happens entirely on your device: iOS answers yes or no, and the app never receives your face, your fingerprint or your passcode. If your device has none of these set up, the action proceeds on the on-screen confirmation alone — we will not stand between you and deleting your own data.
In the browser, audio is uploaded. A web page cannot run the speech model, so a voice entry made at journal.algernonlabs.com is uploaded to our storage, transcribed by OpenAI's Whisper API, and then deleted on your retention schedule — 30 days by default, adjustable from 0 to 90, where 0 means it is discarded as soon as it has been transcribed.
If you would rather no recording of your voice ever left your device, use the iPhone app, or type instead of speaking in the browser.
On both, the transcript — the words, as text — is sent to our server and treated exactly like an entry you typed, including being sent to Anthropic for extraction. We say this plainly because a privacy claim that overstates is worse than none.
How it's used
Your data is used to operate the product you are paying for, and for nothing else:
- To store and show you your journal.
- To extract structured values from your entries, and to ask you a clarifying question when an entry is ambiguous.
- To compute statistics, findings, and experiment results across your own history.
- To send you service email you asked for — check-in reminders, account notices.
- To keep the service running and secure, and to debug faults.
We do not use your journal to train machine-learning models, ours or anyone else's. We do not profile you for advertising. We do not sell or rent personal data, and we do not share it for cross-context behavioural advertising.
Health and sensitive data
Sleep, mood, energy, symptoms, exercise, alcohol, medication — the things this app exists to track — are health data in the eyes of European, UK and Californian law, and are treated as a special category deserving stronger protection. Entries can also reveal other sensitive things about you: who you spend time with, what you believe, how you feel about your job. We treat everything you write as sensitive, because a journal does not separate neatly.
What that means in practice:
- Consent is the only basis on which we process it. The sign-in screen states, before you create an account, that Listening stores and analyses health information you write, and names what that means; creating the account is how you consent to it. We do not rely on any other justification, and we do not process health data for anything you have not asked for.
- You can withdraw it at any time, by deleting your account in Settings → Account. Withdrawing does not undo processing that already happened, but it stops all of it and removes the data.
- We do not use sensitive data for anything beyond the features you are using it for. We never use it to advertise, profile you commercially, or infer anything for a third party.
- We do not sell it, share it for cross-context behavioural advertising, or disclose it except to the processors named below who are needed to run the product — and, only for the categories you switch on and only to the friends you accept, as described under Friends and sharing.
If you would rather not give us health data at all, do not create an account — there is no reduced mode in which this product is useful without it, and we would rather say so than pretend otherwise.
Live health data
Connecting Health used to mean one number per metric per day. If you also turn on Live health (Settings → Health), the app receives individual readings from HealthKit as your iPhone records them, including while the app is closed: each heart-rate reading, each heart-rate-variability reading, the day's resting heart rate, and each workout with its type, duration, distance and energy. Nothing else — no location from a workout route, no ECG, no blood oxygen, no cycle data.
Here is what happens with it:
- A live view. Your latest heart rate, today's HRV and resting heart rate against your own two-week baseline, and this week's workouts, shown in the app.
- The app notices three things, by fixed rules, not by a model: a workout has finished; today's HRV is well below your usual; today's resting heart rate is well above it. "Your usual" is the median of the previous fourteen days and needs at least seven of them — with fewer, nothing is compared and nothing is said.
- It says so. Each of those becomes one message in your thread, written by Anthropic's model from the numbers and the last few things you wrote, and a notification on your phone carrying the same words. It describes and asks; it never diagnoses, never tells you what to do, and never uses medical language. See Automated processing.
- Friends you share with see it too — the categories you choose, for each friend separately. See Friends and sharing.
How long. Individual heart-rate readings are deleted after thirty days; nothing reads one older than that. HRV, resting heart rate and workouts are kept while your account exists, because the baselines and the weekly view need them. Settings → Health → Delete live data deletes all of them, and every event and message the app made from them, immediately. Turning Live health off stops new readings arriving and leaves what is stored until you delete it — the same rule as disconnecting Health.
Live health is off until you connect Health and only exists on iPhone. Everything else in the app works without it.
Push notifications
Check-in reminders are still scheduled on your phone and never travel through anyone's servers. Two newer things do: the app's reaction to a live health event, and anything a friend sends you or does that concerns you. Those are sent from our servers to Apple's push service, which displays them on your phone, and the notification carries the words — the message the app wrote about your workout or your day, a friend's message, the fact that a friend finished a run. Nobody but Apple sits between our server and your lock screen; we chose to send directly rather than through a relay precisely so that no additional company reads them.
We never ask for notification permission when the app opens. It is asked when you turn on Live health or accept a friend, and declining leaves everything else working — the message is still in your thread, the friend's message is still on their screen. Nothing is sent inside the sleep window you told us about. Signing out removes your phone from our list.
Why we're allowed to
If you are in the European Economic Area or the United Kingdom, the law requires us to name the legal basis for each thing we do. Ours are:
- Performance of a contract
- Storing your entries, extracting values, computing your statistics, running your account and your subscription. This is the service you signed up for; without processing there is no product.
- Explicit consent
- Everything in the section above — health and other special-category data. Consent is also the basis for any integration you connect yourself, such as HealthKit, and for optional service email. Withdrawable at any time.
- Legitimate interests
- Keeping the service secure, debugging faults, and preventing abuse — using logs that contain no entry text. We have weighed this against your interests; the data involved is operational, not personal content.
- Legal obligation
- Retaining or disclosing data where the law compels it, and notifying you and regulators of a breach.
We do not rely on legitimate interests for anything involving the content of your journal. The law does not permit it for health data, and we would not want to.
Automated processing
Two parts of this product are automated, and you should know exactly what they do.
Extraction. A language model reads your entries and pulls out structured values. It is imperfect. Every value it produces is stored with the verbatim words it came from, shown to you, and correctable in one tap. When an entry is ambiguous it asks you rather than guessing.
Analysis. Statistical tests run across your own history to surface patterns, and experiments you set up test them. These describe your data back to you.
Neither makes a decision that produces a legal effect or similarly significantly affects you. We do not score you, rank you, share any assessment with anyone, or use any of it to decide anything about you — pricing, access, or otherwise. Nothing the app concludes leaves your account. You can turn analysis off, correct any input to it, and delete the output.
Who else touches it
We use a small number of service providers. Each is contractually limited to processing data on our instructions.
- Anthropic
- Receives your entry text to extract structured values and to write clarifying questions, and receives any photo you attach to an entry in order to describe what is in it. If Live health is on, it also receives the numbers behind a health event and your most recent entries, to write the message the app says about it. It never receives anything from your photo library. Under Anthropic's commercial terms, inputs are not used to train their models.
- OpenAI
- Receives voice recordings made in the browser, to transcribe them. Never receives audio from the iPhone app, which transcribes on the device. Under OpenAI's API terms, inputs are not used to train their models.
- Only if you choose Google sign-in, and only to verify your identity. Google does not receive your journal.
- Neon
- Hosts the database your entries live in.
- Fly.io
- Runs our application servers.
- Cloudflare
- Serves this website, stores browser-uploaded audio until it is deleted, and provides DNS and TLS.
- Apple
- Handles all payment for subscriptions. We never see your card details. Apple shares only whether a subscription is active. Also receives and displays the push notifications described under Push notifications, which carry the notification text.
We will also disclose data if legally compelled, and will tell you unless we are prohibited from doing so. If the business is ever sold or transferred, your data moves under this policy and you will be told before anything changes.
These providers operate in the United States and the European Union, so your data may be processed outside your country. Transfers rely on the providers' standard contractual clauses.
Stored on your device
This website sets no cookies and runs no scripts. The marketing and legal pages are static files. There is no analytics tag, no pixel, no consent banner to dismiss, because there is nothing to consent to.
The app itself stores a few things locally, all of them necessary and none of them for tracking:
- Your session
- A sign-in token, so you are not asked to sign in on every visit. Signing out removes it.
- Your offline queue
- Entries you write without a connection, held on the device until they can be sent. This is why you can write on a plane.
- Your preferences
- Interface language and similar local settings.
All of it lives in your browser's own storage, or on your phone, and is cleared when you sign out or clear site data. None of it is readable by another site, and we do not use it to recognise you across services. We do not respond differently to a Do Not Track or Global Privacy Control signal because there is no tracking here to turn off.
How long we keep it
- Entries
- Until you delete them or your account. Entries are the one thing in this system we treat as irreplaceable.
- Derived values
- Same as the entry they came from; deleting an entry deletes everything derived from it.
- Voice recordings — iPhone
- On your device only, on your retention setting: 30 days by default, 0 to 90 by choice.
- Voice recordings — browser
- In our storage, on the same retention setting, then hard-deleted.
- Account record
- Until you delete the account.
- Server logs
- 30 days. They contain no entry text.
- Backups
- Deleted data disappears from rolling backups within 30 days of deletion.
Your rights
All of these work from inside the app, without emailing anyone and without a paid subscription:
- Export. Settings → Account → Export. JSON with your raw entries and every extracted value alongside the snippet it came from, plus markdown for reading.
- Correct. Tap any extracted value to edit or remove it. Your original text is never altered — corrections are recorded next to it.
- Delete. One value, one entry, or the entire account. Account deletion removes every row and every stored object, and cannot be undone.
Depending on where you live you may also have the right to object to or restrict processing, to request a copy in a portable format (the export is one), and to complain to your data protection authority. To exercise anything not available in the app, email us; we reply within two business days and will not charge you for it.
Where you live
The rights above are given to everyone, wherever you are. Some places add specifics.
- European Economic Area and the United Kingdom
- You have the rights of access, rectification, erasure, restriction, portability, and objection, and the right to withdraw consent at any time without affecting processing already carried out. You may complain to your national data protection authority — in Ireland the Data Protection Commission, in the UK the Information Commissioner's Office — and you may do so without contacting us first, though we would rather you gave us the chance to fix it.
- California
- You have the right to know what we collect and why, to delete it, to correct it, to a portable copy, and not to be discriminated against for exercising any of them. We do not sell personal information and we do not share it for cross-context behavioural advertising — not in the ordinary sense and not in the broad statutory sense — so there is no "Do Not Sell or Share" link to click, because there is nothing for it to switch off. We use sensitive personal information only to provide the service you asked for, which is the limited purpose the right to limit its use is designed to secure; we have nothing further to restrict. Every one of these rights is exercisable from inside the app, immediately, without asking us.
- Canada
- You may ask what we hold about you, ask us to correct it, and challenge our handling of it. If our answer does not satisfy you, you can complain to the Office of the Privacy Commissioner of Canada at priv.gc.ca.
Whoever you are: we do not charge for any of this, we do not require you to create an account to ask, and we will not ask you for more identifying information than we need to be sure it is you.
Security
Data is encrypted in transit with TLS and at rest by our database and storage providers. Access to production systems is limited to people who need it and protected by multi-factor authentication. Entry text is excluded from logs and error reports by design.
No service is perfectly secure. If a breach affects your data we will tell you and the relevant regulator without undue delay, and within 72 hours where the law requires it.
Children
Listening is not directed to children under 13, and we do not knowingly collect their data. If you believe a child has created an account, email us and we will delete it.
Changes
If we change this policy we will update the date at the top. If a change materially affects how your data is handled, we will tell you in the app or by email before it takes effect, so you can export or delete first.
Contact
Algernon Labs — [email protected]
One person is accountable for privacy here, and that address reaches them. Write for any of it: access, correction, deletion, a copy of your data, withdrawing consent, a complaint, or a question about a sentence on this page. We reply within two business days, and resolve requests within 30 days at the outside — sooner in almost every case, because most of these are buttons in the app that you do not need us for.