Privacy & Terms
Last updated: 28 July 2026
This page covers both our Privacy Policy and our Terms of Use, in one place, in plain language. If anything here is unclear, contact us — we'd rather explain it than have you guess.
Privacy Policy
What we collect
When you register, we collect your email and password, and optionally your name, birth date, phone number, and a social media handle — all optional fields stay optional. If you write journal entries, we store what you write and any theme or personal topic you attach to it. If you take one of the self-assessment tests, we store your answers and score. We also record basic technical details: your chosen language, and, for visitors who haven't registered yet, an anonymous device token so a draft can survive a page reload. When you save an entry we also note whether it was written on a phone or on a computer, worked out from the description your browser sends of itself. It is stored with that entry so your own writing report can show it. We also record, against your account, which of our apps you have used — the iPhone app, the Android app, a phone browser or a computer browser — so that a problem you tell us about can be traced to the one you were using. That is a category and not a device: two different Android phones are the same single word here, and we keep no device identifier, no model and no operating-system version.
Your test answers are health data. The self-assessment questionnaires ask about mood, anxiety and, in one item, thoughts of self-harm — so your answers and scores count as health information under data-protection law, a category the law treats as needing your explicit consent. We rely on exactly that: we hold them because you chose to take the test, and for one purpose, which is to show you your own result and how it moves over time. They are never used for advertising, never sold, and seen by nobody else unless you have separately chosen to contribute your results. They are deleted when your account is.
How your writing is protected
You choose one privacy level for your journal in Preferences, and that single choice decides everything that happens to what you write. You can change it whenever you like; it applies to entries written from then on.
- Don't store at all — nothing is saved anywhere, not even encrypted. Write freely, and it's gone when you leave the page. These entries never appear in your journal history, because they never existed anywhere but on your screen.
- Zero-knowledge — only you hold the key — you set a separate passphrase, and your entry is encrypted on your own device before anything reaches our server. We store sealed text we cannot open. Nobody can read it — not our team, not someone who steals the database, not us under any request. If you forget that passphrase, those entries are unreadable for good, including by you; that is the price of the guarantee.
- Stored, encrypted (recommended) — encrypted before it reaches our database, with the key held only by our server and never inside the database itself. Our team does not read entries at this level. Because we hold the key, you can still get your writing back if you lose your device or reset your password — the same trade-off most banks make.
- Stored, encrypted, and shared to help the method — the same encryption as above, plus our team may read entries to understand what actually helps people and improve the method. Your name is always removed first.
- Open for research — not encrypted, and may be linked with your self-assessment test results for research. Never with your name, phone number, or address.
Beyond the level you pick, a few other protections are always available to you: you can blur your text while you type, so nobody beside you can read over your shoulder; opening your past writings asks for your password again — or your fingerprint or face — even on an already signed-in browser; and you can turn on two-factor authentication for the account itself. Our servers are our own, so your entries do not pass through a third-party cloud database vendor.
Prefer to watch? Two minutes on everything that protects your words:
Cookies
We use a small number of cookies: one that keeps you signed in, one that remembers your chosen language, one anonymous device token for visitors writing before they register, and one that remembers your cookie choice itself. None of these are used for advertising, and none are shared with ad networks.
Who else sees your data
Our servers are self-hosted — we don't route your data through a third-party cloud database vendor. If you use the optional AI writing analysis, the text you submit for that specific check is sent to an outside AI provider’s API to generate feedback; it isn't used to identify you. The request is made by a site-owned account and carries nothing about who wrote the text — no sender, no author, no details about the entry — only what is needed to produce your analysis. If email confirmation or notifications are enabled, an email provider handles delivery of those messages only.
The AI: what it sees, and what it never knows
Some parts of the app use an AI model — the writing check that reads an entry back to you, and the extras built on it. Today that model is not ours: it is run by an outside provider, on their machines, which is exactly why it is worth being exact about what "we send it to an AI" means. The phrase can describe almost anything; here it describes one narrow thing, and the points below are the whole of it.
We hide names and personal details before anything is sent. Before your writing leaves our server on its way to the AI provider's, we replace names, email addresses, phone numbers, links and anything else of that kind with neutral stand-ins. So instead of the model reading Sarah called me today, it reads P1 called me today. And when the answer reaches you, we put the original details back where they belong, so you never see those stand-ins at all.
The link between P1 and the real name exists only while your request is being handled; it is then thrown away, and it is never written into any log. Even so, this is not guaranteed to work every time — an unfamiliar name, or an unusual way of writing something down, can go unrecognised. So we use it as an extra layer protecting your privacy, and never as the only line of defence.
The model does not know who you are. When we send your writing to be analysed, we send the text itself and nothing more, with the personal details already hidden. We do not send your name, your email address, your account number, your device details or your location — not even an anonymous identifier that could be tied back to you. As far as the provider of the model is concerned, there is no profile behind the text: no way to know who is behind it or who wrote it. There is only the writing you sent, and the question we asked it to answer.
To the AI company, we are a single customer: the app, not each user separately. We reach the model through one account run by Weave, using a key kept on our own servers that never reaches your browser. So the company does not see which user wrote any given request, and it holds no separate accounts for our users and no direct way to tell one request from another. Yours arrives as one of the requests we process, with nothing in it to tell them that it is yours.
Your connection is encrypted. Every request we send uses an encrypted connection, the same kind banking sites rely on, and we never use anything less secure. And before the text reaches the point of being analysed it is already held by us encrypted, and is decrypted only when a check actually needs to run.
On the zero-knowledge level we go a step further: we do not hold the key that would let us read your data at all. There, a check can only happen from your own browser while you are on the page — and afterwards we keep neither the text that was checked nor the result that came out of it.
The AI features are entirely optional. You can use the app, write your journal, explore the theme library and take the self-assessment tests without an AI model reading a single word of your writing. Analysis only begins when you press Analyse this entry yourself, and that press is the moment the text is sent to be analysed.
If you would rather the analysis happened automatically after every save, you can switch that on in Preferences, but it stays off until you choose to turn it on. And even with a paid subscription, what you are getting is more of these optional AI features — the app's core functions do not depend on them and are not held behind the subscription.
We use AI to understand sentences, not to run the app. The AI model runs no part of the app itself. It cannot reach our database or search it, it does not remember what you sent in an earlier request, and it does not know your history, your streak, your test results, or anything you have written beyond the text we send it.
We give it one piece of text and one specific question about it — which of these sentences seem heavier? does another person appear in this day? what might be worth pausing on for longer? — and then it gives us its answer.
Everything to do with how the app works, what we choose to show you or to pass over, and your account details, stays under our control, handled by the app itself and on our own servers.
The same thing, end to end:
You write your day in your own words, and the writing stays with you.
There are three things we would rather tell you than have you discover for yourself. First, the masking is careful, but it is not infallible: it can miss a detail written in an unusual way, or a name that is uncommon in the language you are writing in. So we see it as one layer of protection among several, and not the whole of it.
Second, there is one feature that needs to read more than a single entry: when you ask the theme library to suggest themes for you, the engine reads what you have written in your flow, with the personal details hidden in the same way. The exception is entries on the zero-knowledge level, which we cannot reach at all. And in the end, all we keep from that analysis is the short report it produces — never the writing itself.
Third, we check the AI itself. On the two levels where you have already agreed that our team may read what you write — shared to help the method and open for research — we look at samples of the exchange: what was sent to the model, with names and contact details already masked, and what it answered back. We do that to catch the model being wrong, unkind or unsafe, and that is the only thing those samples are ever used for. We start with the exchanges our own checks flag, and take a small number at random besides. A sample is kept for at most ninety days, and it is not linked to your account. On the other three levels we do not do this at all: zero-knowledge entries we cannot open, don’t store at all leaves nothing to look at, and on the recommended stored, encrypted level our team still does not read your entries.
Research
We use a small set of anonymised numbers to study what writing does for wellbeing: the positivity score our AI gives an entry, how much you wrote, your language and streaks, and — if test sharing is on — your self-assessment scores. These numbers are separated from your identity before any research use: no name, no email, no account identifier, and findings are only ever published in aggregate. Your words themselves are never research data unless you explicitly chose the "Open for research" privacy level. Accounts created from July 2026 share test scores for research by default; you can switch this off any time in Preferences → Your data. Accounts created earlier keep their old setting (off) unless you turn it on. Some privacy levels have nothing to share by design: "Don't store at all" leaves no data anywhere, and zero-knowledge entries contribute only their length — never a positivity score, which for them does not exist on our servers.
This is one person's day: a name, a date, a positivity score, a word count.
Working with anonymised, aggregated data like this is ordinary and lawful — UK data-protection law does not restrict information that can no longer identify anyone. It is how Apple studies typing habits (differential privacy), how Google Maps shows traffic without knowing who is driving, and how the NHS and the ONS publish health statistics. The difference here is only how little we collect in the first place.
Your rights
You can review and change most of your data any time in Preferences. You can ask us to export or permanently delete your account and its writings by contacting us — we'll act on that request without asking you to justify it.
Data retention
We keep your data for as long as your account exists. If you delete your account, your writings and test results are deleted with it.
Changes to this policy
If we materially change how we handle your data, we'll update this page and its "last updated" date, and — for significant changes — let signed-in users know directly.
Terms of Use
Not medical advice
The self-assessment tests on this site (including CORE-OM and GAD-7) are screening tools, not a diagnosis. They're meant to help you notice patterns, not to replace a conversation with a qualified professional. If a result concerns you, please talk to one.
Your account
You're responsible for keeping your password private and for the accuracy of the information you provide. You must be old enough, under the law where you live, to agree to these terms on your own.
Payments & subscriptions
Writing, your journal, and every self-assessment test are free, and will stay free. A paid yearly subscription unlocks the AI-powered extras — more writing analysis and deeper insights. Founding members — people who joined while we were new — never pay anything.
The seller is Omar Meriwani, trading as Weave (sole trader, United Kingdom). The price and what it includes are always shown before you pay. Payments are handled by a dedicated payment provider; your card details never touch our servers. Prices include VAT where it applies. The subscription renews yearly; we email you before each renewal, and you can cancel anytime — cancelling stops the next renewal, and you keep the paid features until the period you already paid for ends.
Refunds: within 14 days of any payment you can ask for a full refund, no questions asked — this honours your cooling-off right under the UK Consumer Contracts Regulations, even though paid features start immediately. After those 14 days, if something isn't right, contact us and we will be reasonable. If a renewal payment fails, your account simply returns to the free tier — nothing is ever deleted over money.
If a price ever changes, we tell you well before your next renewal and the change applies only from that renewal. If you subscribe through an app store rather than our website, that store's own billing and refund process governs those purchases.
Acceptable use
Don't use the site to harass others, to post illegal content, or to attempt to access another person's account or data. We may suspend accounts that do.
Your content
What you write is yours. We don't claim ownership of your journal entries; we only use them the way the privacy level you chose above describes. The method itself, the site's design, and its published theme library are ours.
Availability & changes
We do our best to keep the site available and to give notice before major changes, but we can't guarantee uninterrupted service, and features may change as the method develops.
Limitation of liability
The site is provided as-is, without warranty. To the extent the law allows, we aren't liable for indirect or consequential damages arising from your use of it.
Contact
Questions about either policy? Reach out any time.
