Last updated: January 2026
HeartLogs is built on a simple belief: your diary entries belong to you and only you. We do not share, sell, analyse, or monetise your personal journal entries. Period.
To provide the service, we collect only what is necessary:
Passwords are hashed using bcrypt with a cost factor of 12. All data is stored in a secure MySQL database. Authentication is handled by NextAuth with JWT-based sessions. Your diary is protected by your account credentials — we cannot read your entries without access to your account.
Your data is retained for as long as your account is active. You can delete any diary entry at any time. If you wish to delete your entire account and all associated data, please contact us. When you delete entries, they are permanently removed from our database.
HeartLogs uses Google OAuth as an optional sign-in method. If you choose Google sign-in, Google shares your name, email, and profile picture with us solely for account creation. We do not receive or store your Google password. The application is hosted on AWS EC2. Both providers operate under their own privacy and security standards.
If you have questions about this privacy policy or want to request account deletion, email us at privacy@heartlogs.com.