Privacy

Your story stays yours.

A journal is only honest if it is private. This page is the plain explanation of how that is built. The binding version is the privacy policy, and the two do not disagree.

On the device first

Biojrnl works offline. Your record is written to your phone and read from your phone, whether or not anything is switched on beyond that.

Encrypted where it sits

Each account's journal is a separate encrypted database file, unlocked by a key held in the phone's own secure storage.

Off by default

Cloud backup is a switch you decide to turn on. It is not on when you install the app, and nothing syncs until you say so.

What lives on the phone

When you sign in, Biojrnl opens one database file that belongs to your account alone. It is encrypted with SQLCipher, and the passphrase is generated once on first run and stored in the iOS Keychain or the Android Keystore. It is never written into the database, never put in ordinary app preferences and never written to a log.

One key per account matters on a shared phone: another account's key cannot open your file. Signing out closes your file and leaves it where it is. Deleting an account removes that account's file and nothing else.

This sits on top of the phone's own full-disk encryption rather than replacing it. The point is the case where the raw file is pulled off a lost handset.

What happens when you turn on backup

Cloud backup is optional. With it on, your record is copied to Biojrnl's managed database so it survives a lost phone and can reach a second device. It is encrypted in transit and at rest, and it is held in the European Union.

With it off, your health record stays on the handset. Your account does not: Biojrnl has no account-free mode, so your email address, your date of birth and a record of your agreement to the terms are held on our servers from the moment you sign up, and each sign-in is logged with an IP address and browser details for security. The backup switch governs the record you write, not the account you write it in.

Sharing works the other way round from what you might expect. Sharing a profile with a co-manager or a guest requires backup to be on for that profile, because the other person's phone has to read it from somewhere. Turning sharing on turns backup on. Turning backup off afterwards does not retract what sharing has already uploaded.

Who can see a profile

Only the people you have put there.

  • You see everything in your own account.
  • Co-managers see and help keep the whole of a profile you have invited them to. Their access is all-or-nothing, and you can withdraw it at any time.
  • Guests see the sections you choose, for the time you choose, including until you remove them. Every guest also sees the profile's allergies, ongoing conditions and any handover note and carer replies, whatever else you share; the app tells you this before you send the invitation. Home address, insurer details and national identifiers stay hidden from a guest unless you switch them on for that invitation.

Profiles do not leak into each other. One profile's entries never appear in another profile's screens, which is the first rule the app is built to and the one most heavily tested.

What Biojrnl does not do

  • It does not sell your health data. There is no version of this where it does.
  • It shows no adverts and builds no advertising profile.
  • It collects no location, no biometrics, no browsing history and no advertising identifiers.
  • It does not infer anything about your health. It stores what you write and shows it back.
  • It has no AI. Nothing writes your entries, nothing summarises you, nothing learns from your record.
  • It connects to nothing. No smartwatch feeds, no imported vitals. The record is what you chose to write, which is why it is worth reading.
  • It does not diagnose, grade or interpret. Its only notifications are reminders you choose to set and activity messages about profiles you share. It is not a medical device.

Crash reports are opt in

The setting called "Help improve Biojrnl" is off unless you switch it on. With it on, technical crash reports go to our error-reporting provider, configured to scrub personal information and to carry no health data. With it off, none are sent.

Your record, and getting it back out

You can export at any time, on any plan, including free. An app that holds your history hostage is not a record. Deleting your account removes everything, with a thirty day window to change your mind first. The steps are on the delete your account page.

Who we are, and who we use

Biojrnl is run by Biojrnl Ltd, a company registered in England and Wales. The infrastructure providers we rely on are listed one by one, with what each of them receives, on the subprocessors page.

For anything privacy related, write to gdpr@biojrnl.com. To report a security problem, write to security@biojrnl.com.

Yours to keep,
in your pocket.

Biojrnl is on iPhone and Android. Free to start, no adverts, and your story stays yours.

Free to start. Made in the United Kingdom.