Privacy Policy

Last updated: January 2026

Our promise to you

HeartLogs is built on a simple belief: your diary entries belong to you and only you. We do not share, sell, analyse, or monetise your personal journal entries. Period.

What data we collect

To provide the service, we collect only what is necessary:

  • Account information — your name, email address, and a hashed password (or Google account identifier if you sign in with Google).
  • Diary entries — the content, title, mood, tags, and timestamps you provide when writing.
  • Session data — standard authentication cookies to keep you logged in. We do not use tracking cookies, analytics cookies, or advertising cookies.

What we do NOT collect

  • No analytics or tracking scripts
  • No advertising identifiers
  • No location data
  • No browsing history outside HeartLogs
  • No IP logging beyond standard server operations
  • No third-party data sharing

How we protect your data

Passwords are hashed using bcrypt with a cost factor of 12. All data is stored in a secure MySQL database. Authentication is handled by NextAuth with JWT-based sessions. Your diary is protected by your account credentials — we cannot read your entries without access to your account.

Data retention & deletion

Your data is retained for as long as your account is active. You can delete any diary entry at any time. If you wish to delete your entire account and all associated data, please contact us. When you delete entries, they are permanently removed from our database.

Third-party services

HeartLogs uses Google OAuth as an optional sign-in method. If you choose Google sign-in, Google shares your name, email, and profile picture with us solely for account creation. We do not receive or store your Google password. The application is hosted on AWS EC2. Both providers operate under their own privacy and security standards.

Contact

If you have questions about this privacy policy or want to request account deletion, email us at privacy@heartlogs.com.