Privacy policy
AI Voice Journal is an invited TestFlight pilot operated by Runpoint. This policy describes the current pilot build; if the product or its providers change, this page will change before the new behavior is released.
What the app stores
Journal entries, finalized transcripts, explicit mental/physical/energy ratings, editable structured fields, Life Story items, pattern evidence, consent records, settings, and normalized context are stored in an encrypted local database on your iPhone. The encryption key is stored separately in the iOS Keychain. The app does not persist raw microphone audio.
OpenAI processing
During a live session, microphone audio, transcript events, and only the context listed in the session receipt are sent to OpenAI over encrypted transport. After a session, the finalized transcript, explicit ratings, and the same selected context may be sent through the app backend to OpenAI for structured extraction. The backend does not durably store those request or response bodies.
OpenAI states that API data is not used to train its models unless the API customer opts in. This pilot assumes OpenAI’s default abuse-monitoring controls, under which customer content may be retained for up to 30 days unless longer retention is required by law or reasonably necessary for safety. The pilot is not represented as having Zero Data Retention. See OpenAI data controls.
Calendar and Oura
Calendar access is optional. iOS grants full Calendar access, but the app behaves read-only and contains no feature to create, edit, or delete events. Raw EventKit objects remain on-device. Event titles are removed before aggregation unless you separately enable title use.
Oura is optional and never blocks journaling. Oura data and deterministic derivatives are not sent to OpenAI. Oura connection is not enabled in the pilot until the required provider authorization and compliant data boundary are complete.
Operational records
The app backend stores pseudonymous, installation-scoped security and content-free operational records needed for App Attest, abuse prevention, rate limits, and reliability. These records do not contain journal prose, event titles, people, Life Story text, raw health readings, screenshots, or screen recordings. Operational records expire within 30 days; inactive installation security records expire on the documented cleanup schedule.
Apple may separately process TestFlight crash reports and beta feedback under Apple’s settings and policies. The app does not add journal content to diagnostics.
Export and deletion
After unlocking the app, you can export a ZIP with user-owned records, readable Markdown entries, transcripts, ratings, Life Story, patterns and evidence, context receipts, consents, and settings.
Permanent deletion removes the app-controlled backend identity and operational records before destroying the local journal key and app-owned files. It cannot delete OpenAI records still within the provider’s disclosed retention window, Apple-managed diagnostics, source Calendar or Oura records, or copies you moved to Files or another app.
Your choices
You can journal without Calendar or Oura. You can disable individual context uses, disable Life Story retrieval and suggestions, edit or delete journal-derived data, export your data, or permanently delete app-controlled data.
Contact and changes
For privacy questions during the pilot, use Runpoint’s contact page or TestFlight’s Send Beta Feedback action. Material changes will be posted here before they reach the pilot build.