On the device first
Biojrnl works offline. Your record is written to your phone and read from your phone, whether or not anything is switched on beyond that.
Privacy
A journal is only honest if it is private. This page is the plain explanation of how that is built. The binding version is the privacy policy, and the two do not disagree.
Biojrnl works offline. Your record is written to your phone and read from your phone, whether or not anything is switched on beyond that.
Each account's journal is a separate encrypted database file, unlocked by a key held in the phone's own secure storage.
Cloud backup is a switch you decide to turn on. It is not on when you install the app, and nothing syncs until you say so.
When you sign in, Biojrnl opens one database file that belongs to your account alone. It is encrypted with SQLCipher, and the passphrase is generated once on first run and stored in the iOS Keychain or the Android Keystore. It is never written into the database, never put in ordinary app preferences and never written to a log.
One key per account matters on a shared phone: another account's key cannot open your file. Signing out closes your file and leaves it where it is. Deleting an account removes that account's file and nothing else.
This sits on top of the phone's own full-disk encryption rather than replacing it. The point is the case where the raw file is pulled off a lost handset.
Cloud backup is optional. With it on, your record is copied to Biojrnl's managed database so it survives a lost phone and can reach a second device. It is encrypted in transit and at rest, and it is held in the European Union.
With it off, your health record stays on the handset. Your account does not: Biojrnl has no account-free mode, so your email address, your date of birth and a record of your agreement to the terms are held on our servers from the moment you sign up, and each sign-in is logged with an IP address and browser details for security. The backup switch governs the record you write, not the account you write it in.
Sharing works the other way round from what you might expect. Sharing a profile with a co-manager or a guest requires backup to be on for that profile, because the other person's phone has to read it from somewhere. Turning sharing on turns backup on. Turning backup off afterwards does not retract what sharing has already uploaded.
Only the people you have put there.
Profiles do not leak into each other. One profile's entries never appear in another profile's screens, which is the first rule the app is built to and the one most heavily tested.
The setting called "Help improve Biojrnl" is off unless you switch it on. With it on, technical crash reports go to our error-reporting provider, configured to scrub personal information and to carry no health data. With it off, none are sent.
You can export at any time, on any plan, including free. An app that holds your history hostage is not a record. Deleting your account removes everything, with a thirty day window to change your mind first. The steps are on the delete your account page.
Biojrnl is run by Biojrnl Ltd, a company registered in England and Wales. The infrastructure providers we rely on are listed one by one, with what each of them receives, on the subprocessors page.
For anything privacy related, write to gdpr@biojrnl.com. To report a security problem, write to security@biojrnl.com.
The documents themselves. Privacy policy · Terms of service · Subprocessors · Consumer health data notice · Delete your account Copyright
Biojrnl is on iPhone and Android. Free to start, no adverts, and your story stays yours.
Free to start. Made in the United Kingdom.