The short version: your health record is yours. It lives on your device first. Cloud backup is optional, encrypted in transit and at rest, and held in the European Union. We do not sell your data and we show no adverts. Nobody sees your record except the people you choose to invite and the services we need to run the app, and every one of those services is listed below.
1. Who we are
Biojrnl is operated by Biojrnl Ltd, and we are the data controller for the personal data described in this policy. References to "we", "us" and "our" mean Biojrnl Ltd. Our company number and registered office are at the foot of this page.
For anything privacy related, write to gdpr@biojrnl.com.
Our representative in the European Union
We value your privacy and your rights as a data subject and have therefore appointed Prighter Group with its local partners as our privacy representative and your point of contact for the following regions:
European Union (EU)
Prighter gives you an easy way to exercise your privacy-related rights (e.g. requests to access or erase personal data). If you want to contact us via our representative, Prighter or make use of your data subject rights, please visit the following website: https://app.prighter.com/portal/17827418802
2. What Biojrnl is, and what it is not
Biojrnl is a personal health journal. It stores what you choose to enter: symptoms, medications, blood results, vaccinations, appointments and similar records. It is not a medical device, it is not a diagnostic tool, and it is not a substitute for medical advice.
3. The data we hold, why we hold it, and our lawful basis
Your health record
- Journal entries (symptoms, notes, dates, severity ratings)
- Medication names, dosages, schedules and dose logs
- Blood test results you record manually
- Vaccination records
- Appointment and trip records
- Documents and attachments you upload
- Care plans kept on a profile: the tasks in the plan, and who the plan is from, such as a clinician's name
- Handover notes left on a profile, and the replies carers leave under them
- The names of any custom categories you create
- Profile information: name, date of birth, blood type, emergency contacts, and any optional details you choose to add, such as gender, address, height and weight readings, allergies, ongoing conditions, GP, insurance and national health identifiers
This is special category data under UK GDPR Article 9. Our lawful basis for holding it is your explicit consent, under Article 9(2)(a) together with Article 6(1)(a). You give that consent when you create an account, and you can withdraw it at any time.
Account data
- Your email address, used to sign you in, to send you security emails such as password resets, and to contact you about your account
- A randomly generated user ID
- If you sign in with Apple or Google, the email address their sign-in service passes to us
Our lawful basis is performance of our contract with you, under Article 6(1)(b). Without this data we cannot give you an account.
Sign-in security log
Each time your account signs in, we record the time, the network (IP) address the sign-in came from, and the kind of device or app used. If an active session suddenly continues from a different network, we record that too. We keep this log for one purpose: spotting and investigating access to your account that should not be there. No other user can ever see it, including people you share profiles with. Each entry is deleted after 12 months, and the whole log is erased with your account if you delete it. Our lawful basis is our legitimate interest in keeping accounts secure, under Article 6(1)(f).
Activity log
Each profile keeps a log of the actions taken on it: who added or changed a record, what kind of record it was, and when. The log identifies the person by the name entered when they were invited, or failing that by their display name or the first part of their email address, and it holds none of the record's content. Everyone with access to that profile, the account holder, any co-manager and any guest, can see it, so that a shared record shows who did what. Our lawful basis is our legitimate interest in keeping a shared record accountable to the people in it, under Article 6(1)(f).
Subscription data
- Your tier (Free, Pro, Family or Care), updated by Apple or Google after a purchase
- Your subscription expiry date
Our lawful basis is performance of our contract, under Article 6(1)(b). We never receive your card details. Payments are handled entirely by Apple and Google, who are the merchants of record.
Crash and error reports
When the app runs into an error, a report is captured automatically and scrubbed, on your device, of the identifiers we can detect before anything is sent. Reports reach us only while "Help improve Biojrnl" is switched on in Settings. That switch is off unless you turn it on, and you can turn it off again whenever you like. Our lawful basis is your consent, under Article 6(1)(a).
Invitations
If you invite someone to share a profile, you give us their email address. We use it to send and manage that invitation and for nothing else. Our lawful basis is our legitimate interest in delivering the invitation you asked us to send, under Article 6(1)(f).
Website waiting list
If you left your email address on biojrnl.com before launch, we hold that address, the date you signed up, the date we last saw you, and the IP address the signup came from. We use it for one thing: telling you when the app is ready. Our lawful basis is your consent, under Article 6(1)(a).
Website visits
When you visit biojrnl.com, the site's own counting script records how it is used: the pages you open; what you click or tap, where on the page it landed and, for a link, where it points; how far down you scroll; which parts of a page were on your screen and for how long; how long you stay; and the time we received it. With that we keep the kind of device (phone, tablet or computer, judged by screen width), the country your connection comes from, and the name of the website that sent you, if one did. Each visit gets a random number, kept only for that browser tab, so the pages of one visit can be read together. Once a day has ended (midnight UTC), its records are turned into daily totals, such as how many visits a page had, how far down people scrolled, or how many visits went from the home page to the pricing page, and the records are deleted. The totals hold no visit number, and any country, device, referring website or path through the site seen on fewer than three visits that day is counted under "other". When you tap inside one of the pictures of the app, including the demo on the home page, we record the kind of tap and where it landed, not the name of any category, symptom or condition you pick. The script never records your IP address or anything you type. We use them to see which parts of the site help people and which do not. Our lawful basis is our legitimate interest in understanding and improving our website, under Article 6(1)(f). You can switch counting off, as section 14 explains.
Launch offer and giveaway
If you claim the launch offer or the giveaway on biojrnl.com, your browser keeps a random claim number for it, so that tapping again gives you the same code rather than a new one. We store that number with the code we gave you, the store it is for, and the time. We store no name, email address or IP address with it. The claim number is removed from your browser the next time you open the page you claimed on (our home page for the launch offer, the giveaway page for the giveaway) after that offer has ended, or sooner if you clear this site's data. When you tap to claim, Cloudflare Turnstile checks that a person, not a program, is claiming: to do that, Cloudflare looks at your browser and connection, including your IP address, which we pass to Cloudflare for that check only. Our lawful basis is our legitimate interest in giving the codes to people rather than to programs, under Article 6(1)(f).
We collect no location data from your device and use no location tracking; places you type in yourself, such as an appointment location or a trip destination, are simply part of your record. We do not collect contacts, browsing history or advertising identifiers. Beyond crash reports, the same "Help improve Biojrnl" switch also allows a handful of anonymous daily counters, for example how many entries were saved across all users that day. Each is a single number per day, with no account attached and nothing that could join it to one. With the switch off, we collect neither.
4. Where your record lives
- Your account, always. Biojrnl has no account-free mode. When you sign up we hold, on our servers, your email address, your date of birth (asked at sign-up, or on first use if you sign in with Apple or Google), the display name you choose, and a record of your agreement to these terms. Each sign-in is logged with an IP address and browser details so we can spot and investigate access to your account that should not be there. This happens whatever you do with the backup switch.
- Your record, on your device. The journal itself, entries, medications and results, is kept in an encrypted local database (SQLCipher), protected by a key held in your device's secure storage. Once you are signed in, the journal works without a connection.
- Your record, in the cloud, if you choose. If you turn on cloud backup, the journal is synchronised to Supabase, our backend provider, in the EU West region. It is encrypted in transit (TLS) and at rest. This is not end-to-end encryption: as with most cloud databases, the provider's infrastructure can decrypt data at rest. Sharing a profile with someone else requires backup to be on for that profile.
5. Sharing inside the app
Sharing is off unless you turn it on. If you invite someone to a profile, they see what your invitation allows: a guest sees the sections and time window you chose, and a co-manager sees the whole profile. Every guest also sees the profile's allergies, ongoing conditions and any handover note and carer replies, whichever sections you chose; the app tells you this before you send the invitation, and tells the guest before they accept. You can withdraw either's access at any time. One profile's data is never shown inside another profile's view.
If you manage a profile for someone else, you must have their consent first, or the legal authority to act for them. The app asks you to confirm this when the profile is created, and keeps a record of the confirmations given. And if someone keeps a Biojrnl profile about you and you want to know what it holds, have it corrected, or have it removed, write to gdpr@biojrnl.com: we will take it up with the account holder and handle it as the law of your country requires.
6. Who processes data for us
We do not sell your data and we do not share it with advertisers or data brokers. The following providers process limited data so the service can run:
- Supabase (EU West): cloud database, authentication and file storage. Receives the data you choose to sync. Privacy policy
- Resend (EU region): transactional email. Receives the addresses we email and the content of those emails: sign-in, security and waiting-list messages, and invitations carrying the sender's name and the invite code. No health data. Privacy policy
- RevenueCat (United States): subscription management. Receives your account's random identifier, your purchase receipts and the device and app details Apple and Google attach to them, so your subscription can be verified. Never receives health data or your email address. Privacy policy
- Apple App Store / Google Play: app distribution and payment processing, under their own privacy policies.
- Sentry (EU data region): crash and error reporting, as described in section 3. Never receives health data. Privacy policy
- Cloudflare: serves this website, stores the pre-launch waiting list and the website visit, launch offer and giveaway records described in section 3, and runs the Turnstile check on offer and giveaway claims. Receives standard request logs (IP address, country, browser). Privacy policy
- Microsoft 365 (UK tenancy): our business mailboxes. Receives only what you choose to email us. Privacy policy
- Prighter (Prighter EU Rep GmbH, Vienna; representative located in Ireland): our appointed representative in the European Union, described above. Processes the privacy requests you send through its portal, including anything you choose to write in them.
The current list, with regions, is always at biojrnl.com/subprocessors.
7. Where in the world your data goes
Your health record is stored in the European Union, wherever in the world you use Biojrnl. Some providers process limited, non-health data outside the UK. Where that happens, the transfer is protected by a recognised safeguard: for UK users, the UK International Data Transfer Addendum to the European Commission's Standard Contractual Clauses or a UK adequacy decision; for users in the European Economic Area, the Standard Contractual Clauses themselves or an EU adequacy decision.
- Supabase: your synced record stays in the EU West region. Supabase's corporate parent is a United States company; the data itself is hosted in the EU, our contract with Supabase incorporates EU Standard Contractual Clauses, and it may process your data only on our documented instructions. If any authority, in any country, demanded access to your data, we would disclose only what a law that actually binds us compels, and we would tell you unless that law forbids it.
- Sentry: our account is set to the European Union data region.
- Resend: EU region, with some processing in the United States.
- RevenueCat: United States. Hashed user ID and subscription state only.
- Cloudflare: a global network, so a request may be served from the location nearest to you.
- Prighter: privacy requests sent through the representative portal may be handled by its sub-processors, two of which (DigitalOcean and Microsoft 365) are in the United States under the EU-U.S. Data Privacy Framework; the others (Hetzner Online, Strato) are in the EEA. The current list is on our subprocessors page.
You can ask for a copy of the safeguards that apply by writing to gdpr@biojrnl.com.
8. How we protect your data
Your record is encrypted on your device and encrypted again in transit and at rest in the cloud. Access to cloud data is restricted by row-level security, so an account can only ever read its own records and the records explicitly shared with it, and that restriction is enforced by the database itself, not just by the app. Server functions check who is asking on every call, billing notifications are accepted only with a verified signature, and requests are rate-limited. Destructive actions, such as deleting your account, require you to re-enter your password or re-confirm with your sign-in provider first. Crash reports are stripped of personal data before they leave the device. If you use the app lock, your fingerprint or face never leaves your device.
No system is perfectly secure. If a breach ever puts your rights at risk, we will tell you and the Information Commissioner's Office, as the law requires. If you are in the United States, we will also notify you, and where the law requires it the Federal Trade Commission, under the Health Breach Notification Rule. Security researchers can reach us at security@biojrnl.com.
9. How long we keep your data
- Your record and account data, and everything tied to the account (subscription state, consent records, invitations you have sent): for as long as your account is active. If you delete your account, you have 30 days to change your mind: sign back in and choose Keep my account. When those 30 days end, your account and every record in it are erased from our live systems within a further 24 hours, and from our short-term disaster-recovery backups as those expire on their rolling cycle in the days that follow. Your record on the device is removed when you delete the app; on iPhone, the sign-in token in the system keychain can outlive the app until you sign out or delete the account.
- Crash and error reports: 90 days.
- Sign-in security log: 12 months for each entry, and erased with your account if you delete it.
- Activity log: for as long as the profile it belongs to exists. Entries about your own actions are erased with your account if you delete it.
- Waiting list entries: until we launch and have told you, or until you ask to be removed, whichever comes first. Write to gdpr@biojrnl.com at any time and we will delete your entry. Once the launch announcement has gone out, we will delete the whole list.
- Website visit records: added into the daily totals and deleted once their day has ended, by a clean-up that runs as people visit the site; a record that cannot be added is deleted anyway after 48 hours, by the first clean-up that has tried to add its day. The daily totals are kept.
- Launch offer claim numbers: deleted automatically by the same clean-up, from the day after the offer's codes expire on 9 October 2026. What remains is which codes were given out, for which store and when; the claim numbers are gone.
- Giveaway claim numbers: deleted the same way, from the day after the giveaway's last codes expire on 1 December 2026.
- Cloudflare keeps its own short-term recovery copy of the database that holds these website records; a deleted record drops out of it within 30 days.
10. Your rights
We apply one privacy standard to everyone, wherever you live: the UK GDPR and, if you are in the European Economic Area, the EU GDPR. If the law of your country or state gives you rights beyond these, those rights are unaffected. If you are in the United States, our consumer health data notice sets out the disclosures that Washington, Nevada and similar state laws require.
You have the right to:
- Access: ask for a copy of the data we hold about you
- Rectification: correct inaccurate data, which you can do directly in the app
- Erasure: delete your account and everything in it, in the app via Settings, then Danger zone, then Delete all my data, or via biojrnl.com/delete-account
- Portability: export your data at any time via Settings, then Export & backup
- Restriction: ask us to pause our use of your data while a question about it is resolved
- Objection: object to processing we base on a legitimate interest
- Withdraw consent: for cloud sync in Settings, then Backup & sync, then Cloud backup & sync, and for crash reports via the "Help improve Biojrnl" switch. Holding your health record at all rests on the consent you gave at sign-up, so to withdraw that consent entirely, delete your account. Withdrawing consent does not affect anything done lawfully before you withdrew it
To exercise any of these rights, write to gdpr@biojrnl.com. We will respond within one month. If your request is complex, or you have made several, the law lets us extend that by up to two further months, and we will tell you within the first month if we need to. There is no charge.
If we refuse a request, we will tell you why, and you can appeal by replying to our response. If your appeal fails and you are in the United States, you can raise the matter with your state Attorney General; elsewhere, section 11 explains how to complain to a data protection authority.
11. Complaints
If you are unhappy with how we have handled your data, you can complain to us directly at gdpr@biojrnl.com. We will acknowledge your complaint within 30 days and respond without undue delay.
You also have the right to complain to a data protection authority, whether or not you have complained to us first. In the UK that is the Information Commissioner's Office at ico.org.uk. If you live elsewhere, you can complain to the data protection authority of your own country.
12. Children
Biojrnl accounts are for people aged 16 and over, and we do not knowingly let anyone younger hold one. A parent or guardian may keep records about their child in a managed profile; the account holder gives that consent on the child's behalf and remains responsible for the record, as section 5 describes. If you believe someone under 16 is holding an account of their own, write to gdpr@biojrnl.com. We will look into it: we may contact the account holder and suspend the account while we check. If we confirm the holder is under 16, we will close the account and delete its data. We do not act on a third-party report without checking it first.
13. Automated decisions
We make no automated decisions about you and we build no profiles. Biojrnl does not score or grade your health and draws no conclusions from your record. It counts what you wrote, such as your most-logged areas, and shows it back to you.
14. Cookies and this website
biojrnl.com sets no advertising or analytics cookies and runs no third-party analytics or advertising scripts. It does run its own counting script, described in section 3 under Website visits. That script sets no cookies, and no other company receives what it records, apart from Cloudflare, which stores it for us.
The site keeps a few small things in your browser's own storage. For that browser tab only: the random visit number; the code of the advert or link you arrived through, if any; and whether the home-page demo tour is on. Until you clear this site's data: the colour theme you pick; a note that you switched counting off, if you did; and, if you claim the launch offer or the giveaway, its random claim number, which is removed the next time you open the page you claimed on after that offer has ended. Our host, Cloudflare, may set a short-lived security cookie to protect the site from automated abuse. Beyond this, the website collects only what section 3 describes and the standard request logs Cloudflare receives to serve the site.
Visit counting is on unless you switch it off. The switch applies to this browser, and clearing your browser's data for this site turns counting back on.
15. Changes to this policy
If we make material changes to this policy, we will tell you in the app and update the date at the top of this page.
16. Contact
- Privacy enquiries: gdpr@biojrnl.com
- General support: support@biojrnl.com
- Security disclosures: security@biojrnl.com
- Post: Biojrnl Ltd, 71-75 Shelton Street, London, WC2H 9JQ