Security & Privacy
Your privacy and security are at the heart of everything we build. Here's exactly how we protect your data and respect your trust.
Our Privacy Promise
All data encrypted locally
Your journal entries are encrypted on your device using industry-standard AES encryption
No cloud storage by default
Your data stays on your device unless you choose to back it up
AI processing happens securely
When you request insights, data is processed securely and never stored
We never sell your data
Your personal information is never shared with advertisers or third parties
Open source encryption
We use proven, auditable encryption standards
Optional cloud backup
If you choose cloud backup, it's fully encrypted end-to-end
Technical Safeguards
Device-Level Security
- •AES encryption: All journal entries encrypted with 256-bit AES
- •Expo SecureStore: Sensitive data stored using platform-native secure storage
- •Biometric protection: Face ID, Touch ID, or PIN required for access
- •No cloud databases: No vulnerable cloud storage by default
Network Security
- •HTTPS encryption: All network communications use TLS 1.3
- •Certificate pinning: Protection against man-in-the-middle attacks
- •Minimal data transmission: Only necessary data sent for AI processing
AI Processing Security
- •Temporary processing: Data processed and immediately discarded
- •No training data: Your content never used to train AI models
- •Secure API calls: Encrypted transmission to OpenAI's secure servers
- •No human review: AI processing is fully automated
Who Has Access to Your Data
✓ You Have Access
- • Your journal entries on your device
- • AI-generated insights you request
- • Export capabilities for your data
- • Full control over backup settings
✗ No One Else Has Access
- • Seen Place team cannot read your entries
- • No remote access capabilities built in
- • No backdoors or admin overrides
- • No data mining or behavioral tracking
Third-Party Services
OpenAI API
Purpose: Generate AI insights and reflections from your journal entries
- • Data sent: Only journal content you choose to analyze
- • Data retention: Not retained by OpenAI per their API terms
- • Usage: Not used to train their models
- • Privacy policy: OpenAI's Privacy Policy
What We DON'T Use
- • No Google Analytics or tracking pixels
- • No Facebook or social media integrations
- • No advertising networks or data brokers
- • No marketing automation platforms
- • No behavioral analytics services
Compliance & Standards
Privacy by Design
Built with privacy as a core principle, not an afterthought
Industry Standards
Following OWASP guidelines and security best practices
Transparent Practices
Clear documentation of all data handling practices