Privacy Policy
Effective date: October 6, 2026
Last updated: October 6, 2026
Neurojournal is a self-guided course in transformational drawing. You read lessons, draw on paper, and keep a private journal of what you drew and what you noticed. This policy explains what we store when you do that, who else touches it, and how you get it back or have it removed.
It applies to neurojournal.app and to the account you create there. It does not apply to anything you reach by leaving the site.
1. What we collect, and why
What you give us.
- Your email address — it is how you sign in and how we can reach you about your account.
- Your password — stored only as a hash by our authentication provider; we never see it.
- Your interface language, and whether you chose it — so the site opens in the language you read.
- Photos of your drawings and the notes you write — they are your practice journal; nobody else can open them.
- Which lessons you have marked as finished — so you can see where you stopped.
- Your access to the course and the dates it covers — it is what decides whether a lesson is open to you.
What arrives on its own.
- Technical data needed to serve a page: IP address, browser and device type, the address requested. Our hosting provider handles this as part of delivering the site.
- Product analytics, only if you agree to it. If you accept cookies in the banner, we record which pages are opened and which actions are completed, how quickly pages load and respond on your device, and we may record a session replay. If you decline, analytics runs in a cookieless mode: visits are counted without a persistent identifier, nothing is stored on your device, and you are not identified.
- Error reports. When something breaks on our side, we log what failed and where. Request headers and query strings are deliberately removed before anything leaves our servers, so a session cookie or a one-time sign-in code cannot travel with an error report.
If you choose "Continue with Google". Google tells us your email address, that Google has verified it, and an identifier for your Google account. That is all we ask Google for: not your name, your photo or your contacts, and no access to Gmail, Drive or anything else in your Google account. Google hands this to our server directly, and our server passes it to our authentication provider, which keeps it with your account. It is used only to sign you in, it is not shared with anybody else, and it is deleted together with your account.
What we do not collect. We do not ask for your name, date of birth, address or phone number. We do not buy data about you from anybody, and we do not attempt to identify you across other websites.
Your journal is treated as the most sensitive thing here. Photographs of your drawings and the notes beside them are stored in a private bucket, reachable only through short-lived signed links issued to you. Session replays are configured to blank the journal feed entirely and to mask the text of your reflections, so this content does not reach our analytics provider. Requests for your photographs are also left out of the replay's record of network activity, so the signed links do not reach it either; and a replay never keeps what a page sends or receives, only which addresses it asked for and how long they took.
2. When we share information
We do not sell personal information and we do not share it for cross-context behavioural advertising.
We use service providers who process data on our instructions and only to run the product:
- Supabase (United States) — accounts and sign-in, the database, your photos.
- Vercel (United States) — hosting, and the functions that answer requests.
- PostHog (European Union) — product analytics and error reports.
- Resend (European Union, Ireland) — sends account emails: confirming your address and resetting your password.
- Google (United States) — signs you in, only if you choose "Continue with Google".
There are no payments on the site today. Before there are, the payment provider will be added to this list.
We also disclose information where the law requires it, and we would transfer it as part of a merger or acquisition — in which case this policy continues to apply until it is replaced and you are told.
3. How to see, export and delete your information
- See it. Everything we hold about you is on your account pages: your address, your language, your access to the course, your journal.
- Export it. Your account page offers a copy of your data as a file: your profile, every practice with its text and a link to its photo, and the lessons you have finished.
- Delete it. Deleting your account removes the account, the journal entries, the photographs of your drawings and your lesson marks. This cannot be undone — the photos cannot be recovered afterwards, by you or by us.
- Change your language at any time from the site.
- Change your mind about analytics. The cookie settings page, linked from the footer of every page, shows what you chose and switches it; the change takes effect immediately.
How long we keep things. Your account and its contents stay until you delete them. Deleting the account removes them immediately from the live service. If backup copies of the database exist, they are kept for no more than 7 days before being overwritten. Server logs and error reports are retained for a short operational period and are not linked to a person.
If you are in California, you have the right to know what is collected, to obtain a copy, to ask for deletion, and not to be discriminated against for exercising those rights. The screens above are how you use them, and you will not be treated differently for doing so. If data protection law of the European Union applies to you, you also have the right to object to processing and to lodge a complaint with a supervisory authority.
4. How we protect your information
- Traffic to the site is encrypted in transit.
- Passwords are never stored by us in a readable form; our authentication provider stores a hash.
- The database enforces per-row access rules, so one reader cannot read another's journal even if a request asks for it.
- Photos live in a private bucket. They are not served from a public address; each view is a signed link that expires.
- Keys that could bypass those rules exist only on the server and never reach a browser.
No system is perfectly secure, and we do not promise that it is. What we do promise is that these measures exist and that we will tell you if something happens to your data that you ought to know about.
5. Cookies and similar technologies
- Necessary. A session cookie keeps you signed in; a language cookie remembers the language you chose; while you sign in with Google, a short-lived cookie (ten minutes) proves that the answer coming back from Google belongs to the sign-in you started. These are set without asking, because the site cannot work without them.
- Analytics. Set only after you accept them in the banner. Decline, and the analytics provider runs in the cookieless mode described above.
6. Children
Neurojournal is for adults: you must be 18 or older to create an account. We do not knowingly collect information from anyone under 18; if we learn that we have, we delete it.
7. Where your information is stored
Our database, sign-in, file storage and hosting run in the United States; product analytics and the sending of account emails run in the European Union. If you use the site from Ukraine or the European Union, your information is transferred to the United States to provide the service.
8. Changes to this policy
We may update this policy. If a change matters to you — what we collect, who we share it with, what rights you have — we will say so on the site before it takes effect, and the date at the top will change.
9. How to contact us
Write to hello@neurojournal.app — about your data, a request under this policy, or anything else in it.