T30 Journal — Privacy Policy

T30 Journal — Privacy Policy

Effective date: September 6, 2026

T30 Journal ("T30," "we," "us," or "our") is a journaling and emotional-wellness service that helps you track your day in 30-minute blocks. This policy applies to the T30 Journal apps on iPhone and Android, the optional web journal, and the public marketing website at t30journal.com, including its forms and assessments.

Platform-specific sections identify differences among iOS, Android, the web journal, and the public marketing website. Core Data, Keychain, Apple Health, and HealthKit refer to iOS; Room, Android Keystore, and Health Connect refer to Android.

At a glance

- Your journal syncs securely via Firebase (Google Cloud), protected by authentication rules and security policies. Premium subscribers may additionally encrypt selected journal fields on-device before upload. We do not read your data in the ordinary course of business.

- We do not sell or rent your journal data. We do not use journal content, partner content, health information, precise location, account identity, or assessment answers for advertising.

- Apple Health and Health Connect access are optional and read-only. T30 processes authorized health records into sleep and physical-activity summaries that users can view alongside the emotional states they record. Section 2.14 explains iOS handling, and §2.15 explains Android handling.

- Podcast subscriptions and listening progress sync to your private T30 account. Audio and artwork may load directly from a podcast publisher or hosting provider, which receives the ordinary network request.

- Optional Premium Daily Insights requires a separate click-through agreement. Selected data is readable by Google Cloud during AI processing, but T30 does not permit it to be used for model training or fine-tuning. The finished article is encrypted on your device before cloud storage.

- The optional web journal uses Google Analytics for coarse usage and product funnels, and provides an in-product control to turn it off. We do not send journal content, partner content, locations, emotions, needs, names, emails, or Firebase UIDs as analytics event parameters.

- The public marketing website is hosted by Squarespace and uses Squarespace Analytics, Google Analytics, Google Ads, and Meta Pixel. These technologies receive website and device information described in §2.11. They are not installed in the native apps or private web journal, and we do not configure them to receive journal content, partner content, health information, precise location, account identity, or assessment answers.

- You can delete your account and all in-app data at any time from within the app.


1. Who We Are

AppT30 Journal
PlatformsiOS (iPhone), App Store; Android, Google Play; optional web companion
Owner and data controllerBlocks and Circles LLC
Backend processorMultum Non Multa LLC operates backend engineering and infrastructure on behalf of Blocks and Circles LLC and may process data only to provide, secure, maintain, and support T30 Journal as directed by Blocks and Circles LLC.
Contactinfo@t30journal.com
Websitet30journal.com
Privacy Policyt30journal.com/privacy-policy
Terms of Uset30journal.com/terms-of-use
App Store license termsApple Standard EULA — also applies to the iOS licensed app and in-app purchases

2. Information We Process

2.1 Journal Content (User-Created)

  • Time-block entries and activity descriptions
  • Notes
  • Emotions (primary, secondary, tertiary selections and intensity)
  • Needs (primary and secondary selections)
  • Photos attached to entries (captured with camera or selected from photo library)
  • Location data associated with entries (GPS coordinates and/or saved custom locations)
  • Sleep tracking entries

On the iOS app, journal content is stored on your device using Core Data. On the Android app, it is stored using Room. On the web app, Firebase caches synced content locally in your browser (IndexedDB). When you are signed in, journal entries sync to Firebase Firestore and photos upload to Firebase Storage, both hosted on Google Cloud. Access is restricted by Firebase Authentication and Firestore security rules so that only you can read or write your own journal data.

On Android, optional voice check-ins use your device's speech-recognition service to turn your spoken answers into text. Depending on that service and your device settings, audio may be sent to the speech provider for recognition under its privacy practices. T30 uses the returned text to create the check-in you choose to save. You can enter answers with the keyboard instead. Journal voice memos you choose to record are encrypted in private app storage on that Android device; the current Android app does not upload these voice-memo files to Firebase.

2.2 Account Identity

If you use Sign in with Apple, the app processes:

  • Apple user identifier (opaque token)
  • Name (if you choose to share it during sign-in)
  • Email address (if you choose to share it during sign-in; Apple may provide a private relay address)
  • Firebase authentication identifier (UID), assigned when your Apple credential is linked to Firebase Auth

Apple credentials are stored locally in your device's Keychain. Firebase Auth maintains a server-side authentication record that includes your Firebase UID and the linked Apple identity. These are used for account state, sync eligibility, and partner connection features. Apple provides name and email only on the first sign-in; subsequent sign-ins use the locally cached values.

If you use Google Sign-In, the app processes the Google account identifier and profile metadata that Google returns to the app, linked to the same Firebase UID. Credentials are stored per Google's and Firebase's sign-in flows.

2.3 Partner Sharing Content

When you opt in to partner features, the app processes:

  • Invite code and connection state
  • Sharing preferences (which fields your partner can see)
  • Partner nudges
  • Partner messages, questions, and replies
  • Shared check-in data, including activity, notes, emotions, needs, and — when included — GPS coordinates and location names
  • Live location (optional): if you turn on live location sharing, your device sends periodic GPS updates to Firebase so your connected partner can see your position on a map until you turn sharing off. Updates use battery-efficient significant-location-change monitoring by default, with higher-frequency updates only while you have the app open or your partner is actively viewing the live map. Live location documents are retained in the cloud for up to seven days and include coarse device battery state and automated spoofing checks (e.g., simulated location flags).
  • Shared photos (stored in Firebase Storage; download URLs stored in Firestore)
  • Optional Location Drop photos or videos, including audio when you enable it, are uploaded to Firebase Storage and made available to the intended connected recipient through the Location Drop feature.
  • Shared daily summary reports (completion counts, top activities, emotion summary)
  • Both partners' Firebase UIDs and display names on partnership documents
  • Encrypted contact profile fields (optional): display name, email, phone number, and photo URL may be stored in encrypted form on the partnership record using keys exchanged between connected members

Partner content is user-generated. When sharing is active, a copy of shared data is stored in Firebase Firestore under a partnership document accessible to both connected partners. Shared photos are uploaded to Firebase Storage. Each partner controls what they share. Content you intentionally share with a partner (check-ins, reports, photos, messages, live location) remains readable by that partner; client-side encryption applies to your private journal sync and to encrypted contact-profile fields, not to shared partner content both of you are meant to access.

2.4 App Settings and Preferences

  • Display preferences (dark mode, emotion/need display toggles)
  • Notification settings (frequency, time window)
  • Daily start and end times
  • Custom emotion and need color assignments
  • Partner notification preferences

Settings are stored locally using UserDefaults on iOS or Android app storage such as SharedPreferences and Room. For Premium subscribers with multi-device sync enabled, eligible settings may also sync through Apple's iCloud Key-Value Store on iOS and Firebase Firestore.

2.5 Subscription and Purchase Data

If you subscribe to T30 Premium in the iOS app, Apple processes the transaction through StoreKit. If you subscribe in the Android app, Google processes the transaction through Google Play Billing. If you subscribe on the web, Stripe processes the checkout, 30-day trial eligibility, recurring billing, cancellations, and billing portal. Apple or Google may offer a trial to eligible subscribers. We receive confirmation of your subscription status, product, platform, trial state, and expiration date, but we do not receive or store your full payment card details. Apple's terms govern App Store purchases; see Apple's Privacy Policy and Apple's Standard User License Agreement (EULA). Google's terms govern Google Play purchases; see Google's Privacy Policy. Stripe's services are governed by Stripe's Privacy Policy.

2.6 Device Permissions

The app may request the following permissions, each of which you can grant or deny:

PermissionPurpose
CameraAttach photos to journal entries and capture optional photos or videos for Location Drops
Microphone (Android)Record journal voice memos, provide spoken answers for optional voice check-ins, or include audio in a video you choose to record
Photo LibrarySelect existing photos for entries; save exported images
Location (When In Use)Tag entries with your current location
Location (Always)Optional live location sharing with your connected partner while sharing is enabled (background updates with an in-app indicator)
Apple Health (read-only)Optionally read sleep analysis, workouts, step count, and walking/running distance to calculate Recovery Score and add wellness context to your insights
Health Connect (read-only, Android)Optionally read sleep sessions, step totals, distance, and exercise sessions so users can view physical-wellness summaries alongside the emotional states they record
Biometric authenticationSecure the app with Face ID, Touch ID, fingerprint, face authentication, or device credentials supported by your device (App Lock)
NotificationsSend journaling reminders and partner activity alerts

Biometric data (face or fingerprint) is processed by your device's operating system and supported secure hardware. T30 Journal never receives, stores, or transmits biometric templates. We receive only the authentication result.

2.7 Push Notifications

When partner notifications are enabled, the app registers for push notifications through Firebase Cloud Messaging (FCM). This involves:

  • A device token issued through Apple Push Notification service (APNs) on iOS or Firebase Cloud Messaging on Android and represented by an FCM registration token
  • The FCM token is stored in Firebase Firestore under your user record so that our server-side functions can deliver partner activity alerts to your device
  • Push notification payloads contain only routing identifiers (partnership ID and document ID) — not message text or journal content
  • You can disable partner push notifications in the app's settings at any time

2.8 Server-Side Processing

T30 Journal uses Firebase Cloud Functions (hosted on Google Cloud) to:

  • Route push notifications to the appropriate partner when a shared check-in, report, or message is created
  • Verify partnership membership for security checks
  • Aggregate report data on request

Cloud Functions operate with administrative access to Firestore for these specific purposes. They do not perform bulk data mining or profiling.

2.9 Diagnostics

Apple may provide aggregated crash and performance diagnostics to help us maintain app reliability. This data is governed by your device's Analytics & Improvements settings and Apple's privacy practices.

The Android release app uses Google Firebase Crashlytics to diagnose crashes and improve reliability. Crashlytics processes crash stack traces, app version, Android version, device model and technical state, crash timestamps, installation identifiers, and diagnostic breadcrumbs. T30 sanitizes its diagnostic breadcrumbs to remove sensitive identifiers and credentials and does not intentionally include journal text, partner messages, health records, or precise location in crash reporting. This information is used for reliability and troubleshooting, not advertising. Google retains crash traces and associated identifiers for 90 days before beginning removal from its live and backup systems. See Google's Firebase privacy information.

2.10 Support Communications

If you contact us by email, we process your email address and message content to respond to and resolve your request.

2.11 Websites and Browser Services

Public marketing website

The public website at t30journal.com is hosted by Squarespace. Squarespace and its infrastructure providers process ordinary website information such as IP address, browser and device type, operating system, referring page, requested URL, timestamps, security events, and cookie or similar identifiers needed to host, secure, and measure the site. Squarespace may provide us with aggregate traffic and form-submission reporting.

When you submit a contact, newsletter, directory, or assessment form, we process the information you choose to provide, such as your name, email address, professional information, selected answers, and message. We use it to respond to the request, deliver requested results, administer the directory or communication, and send marketing email only when the form and applicable law authorize it. Form information may be processed by Squarespace and the email or workflow provider connected to that form. We do not intentionally send form answers to advertising platforms.

The public website uses Squarespace Analytics, Google Analytics, Google Ads, and Meta Pixel to measure visits, understand advertising performance, and build or measure audiences. These services may receive a cookie or device identifier, IP address, approximate location derived from IP address, browser and device information, referring page, page URL and title, advertising click identifiers, visit time, and website interactions configured as analytics or advertising events. A visit to a page may reveal the page's subject through its URL or title. We do not intentionally configure these tags to receive journal content, partner content, health information, precise location, account identity, or the answers entered into an assessment or other form.

Meta and Google may use the information they receive according to their own terms and privacy policies. Depending on the visitor, configuration, and applicable law, these disclosures may be considered a "sale," "sharing," or targeted advertising even when no money changes hands. See Meta's Privacy Policy and Google's Privacy Policy. Browser settings and privacy extensions may allow you to block or clear cookies and similar technologies. California requests, including requests concerning sale or sharing where applicable, may be submitted as described in §12.

Web journal

When you use the private T30 Journal web app, the same categories of journal and account data may be processed as in the native apps. In addition:

  • Local browser storage: Firebase uses browser storage to maintain the authenticated session and cache data needed for the web experience.
  • Sign-in flows: Sign in with Apple and Google use each provider's web authentication through Firebase.
  • Web analytics: The web app uses Google Analytics for Firebase / Google Analytics 4 to understand coarse usage and product funnels, such as page views, sign-in method, checkout start/error, and feature save/delete events. Google Analytics may process a pseudonymous client identifier, approximate location derived from IP address, browser and device information, the sanitized page path, and event time. These events do not include journal text, prompt text, partner content, precise locations, emotion or need selections, names, emails, Firebase UIDs, invite secrets, or share tokens.
  • Web analytics control: You can turn analytics off in More / Privacy. Your choice is stored in your browser's local storage and may be reset if you clear site data.
  • Clearing site data: If you clear site data or storage in your browser settings, local cached data may be removed and you may need to sign in again.

We do not run Meta Pixel, Google Ads, or other third-party advertising trackers in the private web journal. The native iPhone and Android apps do not include Meta Pixel, and the iPhone app does not include the Firebase Analytics SDK.

2.12 Client-Side Firestore Encryption (Premium)

If you subscribe to T30 Premium and use Firebase sync, the app may encrypt selected sensitive fields on your device before they are written to Firebase Firestore, using AES-256-GCM. Encrypted categories include:

  • Journal blocks — activity, notes, location labels, emotions, needs, sleep data, and related synced metadata under users/{uid}/journalBlocks/
  • Significant events / deep journal entries — titles, reflections, journal text, custom answers, emotions, and related fields under users/{uid}/significantEvents/
  • Custom journal prompts — prompt text and category under users/{uid}/journalPrompts/
  • Derived Apple Health summaries and Recovery Score metrics — selected derived fields under users/{uid}/healthDailySummaries/ and users/{uid}/recoveryMetrics/; raw HealthKit samples are never uploaded

How keys work:

  • A per-account encryption key is generated on your device and stored in the Keychain (iOS) or browser-local storage (web, when enabled).
  • Signed-in account access can restore the encryption key used for synced entries. Firestore stores that key in an owner-only account-access record protected by Firebase Authentication. Legacy enrollments may also retain wrapped key material and recovery metadata during migration.
  • An existing legacy account must publish its current key from a device that can still open the encrypted entries before account-based restoration works. The migration preserves the current key so older encrypted entries remain readable.
  • Google Firebase still stores the encrypted payloads and provides transport and at-rest protection; Firebase/Google cannot read the plaintext of client-encrypted fields without your keys.

Photos attached to journal entries are stored in Firebase Storage as image files. Photo bytes are protected by Storage rules and Google Cloud encryption but are not individually re-encrypted by this client-side field encryption layer.

2.13 AI-Generated Daily Insights (Optional Premium Feature)

AI-generated Daily Insights is optional and requires a separate, versioned click-through agreement before the first generation request and again after a material disclosure change. T30 does not send data for this feature unless you affirmatively opt in. Turning it off stops future AI generation requests.

When enabled, the iPhone app creates a bounded source from selected recent T30 and Circle Check-Ins, Deep Journal, Empathy Journal, Emotion Journal, Safety Center entries, partner timeline notes, significant events, emotions, needs, commitments, completion patterns, and recorded wellness facts. Private reflection text is included and may contain sensitive information the user wrote about themselves or another person. Photos, precise locations, account identifiers, and encryption keys are excluded. The source is sent through TLS to a T30-controlled Cloud Function and then to Google Cloud's Vertex AI service. Although the connection is encrypted, the selected data must be available in readable form during AI processing.

T30 does not persist the selected source or the model's raw response as unencrypted journal content. After T30 validates the returned structure, the iPhone encrypts the finished Daily Insight article using the user's account key before creating the Firestore record. T30 stores operational metadata such as generation status, model and prompt version, input size, token counts, and timestamps; this metadata does not contain the selected journal text or the generated article body.

Under Google Cloud's service terms, Google may not use Customer Data to train or fine-tune AI/ML models without the customer's prior permission or instruction. T30 does not give that permission or instruction, does not use submitted data for tuning, and requires its generation service to fail closed unless training use is prohibited in its configuration. This no-training restriction is separate from retention: Google may temporarily process or retain prompts for security, abuse monitoring, caching, or service operation under its applicable terms and settings. T30 does not represent this feature as zero-retention.

The App records the consent version, provider-disclosure version, agreement version, faith-language preference, acceptance or revocation state, and server timestamps under the user's private Firebase account. These records allow the service to reject stale or revoked consent. Disabling the feature does not recall data already processed or delete an already encrypted Daily Insight article. Account deletion removes the user's consent and Daily Insight records through the account-deletion process described below.

2.14 Apple Health / HealthKit (Optional, iOS)

Connecting Apple Health is optional. T30 requests category-by-category permission through Apple's HealthKit authorization sheet, and you may grant or deny each category. The current app requests read-only access to:

  • Sleep analysis
  • Workouts
  • Step count
  • Walking and running distance

T30 uses this data only to provide app functionality, including Recovery Score, Health Insights, and wellness context alongside your journal activity. We do not use Apple Health data for advertising, marketing, data mining, or sale to data brokers, and we do not write data to Apple Health.

Raw HealthKit samples are processed on your device and are not persisted by T30 in Core Data, Firebase, analytics, or advertising systems. The app creates derived hourly and daily summaries such as sleep and in-bed minutes, step totals, walking/running distance, workout minutes, and workout count.

Derived summaries are cached locally in Core Data. If you are signed in, have eligible Premium sync, and owner-data sync is enabled, a bounded set of derived daily health summaries and Recovery Score metrics may sync to your private Firebase account so they are available across your devices. Current clients encrypt selected derived Health and Recovery fields with your account key before upload. Routing fields and timestamps remain readable to operate sync, and legacy records created before this encryption protocol may retain their earlier format. Firebase Authentication, Firestore security rules, TLS in transit, and Google Cloud encryption at rest also protect these records.

Partner Health context sharing is off until the journal owner separately enables it for that connection. Primary-partner status does not by itself authorize Health sharing. After the owner saves that choice, T30 may share encrypted derived health summaries with that partner. Raw HealthKit samples are never shared. Turning sharing off prevents new partner access and revokes the partner's membership on existing shared summaries where supported.

Revoking Apple Health permission stops future HealthKit reads. It does not automatically erase summaries T30 already derived; you can remove those summaries by deleting your T30 account and local app data as described in §§7–8.

2.15 Health Connect (Optional, Android)

Connecting Health Connect is optional and available to eligible Premium members. T30's Health Connect feature lets users view sleep and physical-activity summaries alongside the emotional states they record in journal entries and check-ins so they can recognize personal patterns. T30 does not diagnose a cause, condition, or treatment from this information. Before Android shows the Health Connect permission sheet, T30 explains this use. The Android app requests read-only access to:

  • Sleep sessions (READ_SLEEP) — T30 reads session times and sleep stages to calculate time asleep, show it alongside recorded emotional states, and contribute to Health Insights, Recovery Score, and reports.
  • Steps (READ_STEPS) — T30 reads step-count totals for hourly and daily movement summaries shown alongside emotional-state and check-in patterns in Health Insights, event lookbacks, and reports.
  • Distance (READ_DISTANCE) — T30 reads distance totals for movement summaries shown alongside emotional-state patterns in Health Insights, event lookbacks, and reports.
  • Exercise sessions (READ_EXERCISE) — T30 reads exercise-session start and end times to calculate workout duration and count, show them alongside recorded emotional states, and contribute to Recovery Score, Health Insights, event lookbacks, and reports.

Android groups StepsCadenceRecord with Steps under READ_STEPS, and groups CyclingPedalingCadenceRecord with exercise sessions under READ_EXERCISE. T30 does not query, use, store, or display step-cadence or cycling-cadence samples. T30 also does not request exercise routes, heart rate, calories, or permission to write any data to Health Connect.

The Android app queries only the time range needed for the visible feature: 24-, 48-, or 72-hour Health Insights and event lookbacks; a seven-day Recovery Score; or the selected report period, capped at 365 days. It converts authorized records into hourly or daily totals for display. Raw Health Connect records, source-app or device metadata, record identifiers, and routes are not saved by T30 in Room, Firebase, analytics, or advertising systems.

Android Health Connect summaries remain in app memory while the applicable screen or report is open. A user may include derived totals in a PDF and send that file using Android's share sheet. T30 does not automatically send Health Connect records or derived Android Health Connect summaries to a partner or third party, and does not use them for advertising, marketing, data mining, credit decisions, or sale to data brokers.

You may grant all, some, or none of the requested categories. You can review or revoke access through T30's Health Context screen or Android's Health Connect settings. Revoking access stops future reads. Because the Android implementation does not persist Health Connect records or derived summaries, there is no separate stored Health Connect dataset to delete from T30 after revocation; user-created PDFs remain under the user's control.

2.16 Podcasts

The Podcasts feature uses a T30-managed catalog of approved public RSS feeds. T30's Firebase services provide catalog metadata to the app. When you are signed in, show and episode identifiers, subscriptions, episode playback position and duration, completion state, last-played and completion times, Up Next queue, playlist names and contents, playback speed, and automatic-download preferences sync to your private Firebase account. This listening state is linked to your account so playback and library features work across your devices. It is not shared with a connected partner and is not used to analyze listening behavior, advertising, or marketing.

Podcast artwork and episode audio may load directly from the publisher or its hosting provider; T30 does not proxy or rehost the audio. When artwork loads or you stream or download an episode, that provider receives the ordinary network request, which may include your IP address, device or browser information, request time, and the requested image or audio file. The app shows an audio-host disclosure before first playback. A publisher's handling of its server logs is governed by its own privacy practices.

If you request a podcast, T30 stores your Firebase UID, the show name, optional official website or RSS URL, optional note, source platform, request status, and created/updated timestamps. A per-account daily count is stored to enforce the request limit. These records are used to review and manage the catalog, not for advertising or marketing.

On iOS and Android, downloaded episodes are stored only on that device. Automatic downloads follow the selected network, retention, and episode-count settings; manually downloaded episodes remain until you delete them. The web client is streaming-only. Unsubscribing stops future automatic downloads but does not remove manual downloads or playlist entries. Deleting your T30 account removes synced podcast state and podcast requests associated with your UID; uninstalling the mobile app or deleting its local data removes device-local downloads.


3. How We Use Information

We use the information described above to:

  • Provide journaling, emotion tracking, needs tracking, and time-block features
  • Offer access to T30 Journal through our website (browser), consistent with native app functionality where supported
  • Store and sync your data across your devices via Firebase
  • Enable partner sharing workflows (invites, shared check-ins, reports, photos, and messages)
  • Authenticate your account and manage subscription entitlements
  • Deliver push notifications for partner activity
  • Secure the app via biometric or passcode lock
  • Deliver reminder notifications you have configured
  • Generate reports, statistics, and analytics within the app
  • Let you view optional Apple Health or Health Connect sleep and physical-activity summaries alongside the emotional states you record in Health Insights, Recovery Score, event lookbacks, and reports
  • Provide the podcast catalog, sync your private podcast library and playback state, download episodes you select or configure, and review podcast requests you submit
  • Create an AI-generated Daily Insight only after separate consent, using the limited data described in §2.13
  • Measure coarse web-app usage and funnels with Google Analytics, without journal or partner content
  • Host, secure, and operate the public marketing website; respond to forms and deliver communications you request
  • Remember and apply website cookie preferences
  • Export your journal data as PDF or images
  • Maintain reliability and resolve support requests

4. Where Your Data Lives

DataStorage Location
Journal entries, emotions, needs, sleep dataiPhone: Core Data; Android: Room and private app storage; eligible synced data: Firebase Firestore. Web app: IndexedDB (Firebase local cache) and Firebase Firestore.
Raw Apple Health / HealthKit samplesApple Health on your device only; processed temporarily and not persisted by T30
Derived Apple Health summaries and Recovery Score metricsOn-device Core Data; for eligible Premium sync, selected fields are encrypted by current clients before private Firebase Firestore storage under your account; after separate Health-sharing consent, encrypted derived summaries may be stored under the partnership
Raw Health Connect records (Android)Health Connect on your Android device; processed temporarily for the selected feature and not persisted by T30
Derived Android Health Connect summariesHeld in app memory for the visible feature; included in a PDF only when the user creates that export
Selected Daily Insights sourceReadable temporarily by T30-controlled Cloud Functions and Google Cloud Vertex AI during an opted-in generation request; not stored by T30 as unencrypted journal content
Finished Daily Insight articleEncrypted on the iPhone with the user's account key before storage in private Firebase Firestore
Daily Insights consent and operational metadataPrivate Firebase Firestore records under the user's account; no selected journal text or generated article body in operational metadata
Photos attached to entriesNative app: on-device file storage and Firebase Storage (Google Cloud). Web app: browser cache and Firebase Storage (Google Cloud)
Account credentials (Apple)Native app: Keychain. Web: managed by Firebase Auth and your browser session per Firebase defaults
Account identity (Firebase)Firebase Auth (Google Cloud)
App settingsOn-device UserDefaults, SharedPreferences or Room, iCloud Key-Value Store where applicable, and Firebase Firestore
Partner shared data (check-ins, photos, reports, messages)Firebase Firestore and Firebase Storage (Google Cloud)
Podcast subscriptions, playback state, queue, playlists, and settingsPrivate Firebase Firestore account documents; downloaded audio remains only on the iOS or Android device
Podcast catalog requestsServer-owned Firebase Firestore records containing the request, source platform, status, timestamps, and requesting Firebase UID; per-account request-limit state is stored separately
Push notification tokenFirebase Firestore (Google Cloud)
Encryption keys and recovery metadata (Premium)On-device Keychain (iOS), Android Keystore, or browser session storage (web); owner-only account-access key material and legacy wrapped recovery metadata in Firebase Firestore users/{uid}/crypto/
Partnership encryption key metadataFirebase Firestore partnerships/{id}/cryptoKeys/ (partnership members only)
Web usage analytics eventsGoogle Analytics for Firebase / Google Analytics 4 (web only; no journal or partner content in event parameters)
Public website technical data and cookie choicesSquarespace and its hosting, security, and analytics infrastructure
Public website forms and assessmentsSquarespace and the email or workflow provider connected to the form
Subscription statusOn-device and Firebase entitlement records; managed by Apple StoreKit, Google Play Billing, or Stripe for purchases on the applicable platform

Firebase services are hosted on Google Cloud Platform. Our Firebase project is configured in the United States region. Google encrypts data in transit (TLS) and at rest. For details, see Google Cloud's security practices.


5. Sharing and Disclosure

  • We do not sell or rent your journal data.
  • We do not disclose journal content, partner content, health information, precise location, account identity, or assessment answers for advertising or cross-context behavioral profiling.
  • Blocks and Circles LLC determines why and how T30 Journal processes personal information and is responsible for the service and this policy.
  • Multum Non Multa LLC provides backend engineering, infrastructure operation, maintenance, and support as a processor/service provider acting on documented instructions from Blocks and Circles LLC. Multum Non Multa LLC is not authorized to use T30 data for its own advertising, marketing, or unrelated purposes.
  • Squarespace hosts the public marketing website and processes website requests, security data, cookie preferences, analytics data, and form submissions as described in §2.11.
  • Google Firebase / Google Cloud Platform processes data necessary for sync, storage, authentication, push notifications, Cloud Functions, optional opted-in Vertex AI generation, and web-journal analytics, subject to the Google Cloud Data Processing Addendum, Google Cloud Service Specific Terms, and Google's Privacy Policy.
  • Google Analytics and Google Ads process public-website technical, usage, and advertising data described in §2.11 for measurement and advertising services.
  • Meta Pixel processes public-website technical, usage, and advertising data described in §2.11 for advertising measurement and audience services.
  • Apple services (HealthKit, Sign in with Apple, StoreKit, APNs, iCloud Key-Value Store) process data necessary for app functionality, subject to Apple's Privacy Policy.
  • Stripe processes web Premium checkout, trial, billing portal, renewal, cancellation, and payment-method handling, subject to Stripe's Privacy Policy.
  • Partner sharing: When active, your connected partner can access shared check-in data, photos, reports, messages, and—when you enable Health context—encrypted derived health summaries stored in Firebase Firestore. Raw HealthKit samples are never shared. You control what is shared and can disconnect at any time.
  • Podcast publishers and hosting providers: When podcast artwork or audio loads directly from an external host, that host receives the ordinary network request described in §2.16. T30 does not send your Firebase UID, journal content, or partner content with that request.
  • Email providers process support emails you send to us.
  • Legal obligations: We may disclose information if required by law or to protect rights, safety, or security.

6. Partner Content Safety

Partner messages, nudges, and shared check-ins are user-generated content. The app provides:

  • In-app reporting for inappropriate partner content
  • Block and unblock controls for partner connections
  • Disconnect to stop all future sharing
  • Support contact (info@t30journal.com) for moderation and safety follow-up

When you disconnect from a partner, no new data is shared. Previously shared copies stored in Firebase Firestore may persist until the other person deletes them or deletes their account. Data already downloaded to the other person's device is subject to their own device management.


7. Your Choices and Controls

ActionHow
Grant or revoke Camera, Photos, Location, Face ID, or Notification permissionsiOS Settings > T30 Journal
Grant or revoke Android Camera, Microphone, Location, or Notification permissionsAndroid Settings > Apps > T30 Journal > Permissions or Notifications, depending on the permission and device
Grant or revoke Health Connect categories on AndroidT30's Health Context screen or Android Health Connect settings
Grant or revoke Apple Health categoriesApple Health app or iOS Settings > Health > Data Access & Devices > T30 Journal
Enable or disable partner push notificationsIn-app Settings
Choose your role and sharing preferencesIn-app Settings
Enable or disable derived Health context sharing with a partnerIn-app partner sharing settings
Manage podcast subscriptions, queue, playlists, downloads, playback speed, and automatic-download settingsIn-app Podcasts library and download settings
Accept or revoke AI Daily Insights processingIn-app Daily Insights agreement and AI data-use controls
Enable or disable pseudonymous Google Analytics in the web journalWeb app > More > Privacy
Limit public website analytics or advertising technologiesUse browser cookie controls, tracking protection, or a privacy extension; submit an applicable California request using the method in §12
Disconnect from a partnerIn-app partner settings
Delete your account and all in-app dataIn-app Settings > Data & Privacy

Note on account deletion: When you delete your account in the app, we run an automated server process (Firebase Cloud Functions with administrative access) that, for your Firebase user: deletes your private Firestore data (including journal blocks, events, prompts, derived Apple Health summaries, Recovery Score metrics, podcast subscriptions, listening progress, queue, playlists, podcast settings, entitlements, and settings documents), deletes podcast requests associated with your UID, deletes Firebase Storage objects under your user photo path, removes partnership documents you belonged to (including their shared subcollections such as messages, shared check-ins, and encrypted derived health summaries), removes invite records associated with you, removes purchase-token mapping documents used for subscription reconciliation, and deletes your Firebase Authentication account. The app then clears your local app database and private app files (Core Data on iPhone; Room and private app storage on Android), locally cached derived health summaries, podcast downloads, and key material on the device. You do not need to email us to complete this removal for the categories above. If a prior partner still has a copy of data on their own device, that copy is governed by their own device controls.


8. Data Retention

  • Journal data is retained on-device and in Firebase Firestore until you delete individual entries or delete your account.
  • Raw Apple Health samples are processed temporarily on your device and are not retained by T30.
  • Derived Apple Health summaries and Recovery Score metrics are retained locally and, when eligible sync is enabled, in Firebase Firestore until you delete your T30 account. Revoking HealthKit permission stops future reads but does not by itself erase summaries already derived.
  • Podcast library and listening state is retained in your private Firebase account until you delete the applicable records where the app provides that control or delete your account. Device downloads remain until automatic retention removes them, you delete them, you clear local app data, or you uninstall the app.
  • Podcast requests and request-limit records are retained while needed to review requests, prevent duplicate submissions, enforce limits, and operate the catalog. Account deletion removes requests associated with your Firebase UID and your per-account request-limit record.
  • Partner shared data (check-ins, photos, reports, messages) in Firebase Firestore under a partnership is removed when either partner deletes their account (the partnership document and its subcollections are deleted server-side as part of that user's account deletion). It is also removed if you disconnect or delete content through in-app partner controls where applicable.
  • Account credentials (Sign in with Apple) are retained in Keychain until you sign out or delete your account. Firebase Auth records are deleted when your account is deleted.
  • Push notification tokens are retained in Firestore while your account is active and are removed when the Firebase Auth account is deleted.
  • App settings are retained until you uninstall the app or reset them.
  • Support emails are retained only as long as necessary for support, legal, and operational purposes.
  • Public website technical and security logs are retained according to Squarespace's applicable settings and service terms and only as long as needed for security, troubleshooting, aggregate reporting, and legal obligations.
  • Public website forms and assessment submissions are retained while needed to provide the requested response or service, maintain consent and suppression records, resolve disputes, and meet legal obligations. You may request deletion unless retention is required by law.
  • Website cookie choices remain until they expire, you change them, or you clear browser data.
  • Encryption keys and recovery metadata are retained in Keychain or browser session storage and in owner-only Firestore records until you delete your account or rotate keys where supported. Legacy encrypted history may remain unreadable until a previously enrolled device publishes its current key to account access.
  • Daily Insights consent records and encrypted articles are retained in Firebase until you delete your account or delete the applicable content where supported. Operational generation metadata is retained as needed for security, rate limiting, reliability, and legal compliance. Google may temporarily retain AI inputs for security, abuse monitoring, caching, or service operation under its terms and settings.

9. Security

Your journal data is protected by:

  • On-device encryption provided by iOS
  • Firebase Authentication (only you can access your own data)
  • Firestore security rules that enforce per-user and per-partnership access control
  • Google Cloud encryption in transit (TLS) and at rest for all Firebase-hosted data
  • Client-side AES-256-GCM encryption of selected Firestore fields for Premium sync, with the account key available through an owner-only Firebase-authenticated Firestore record
  • Client-side encryption of derived health summaries shared with an eligible connected partner
  • Keychain encryption for account credentials and encryption keys
  • Optional App Lock (Face ID, Touch ID, or device passcode)

Cloud Functions operate with administrative privileges scoped to specific operations (push routing, partnership verification, report aggregation, and opted-in Daily Insights generation). Daily Insights uses App Check, server-verified direct Premium eligibility, versioned consent, bounded inputs, no request-response application logging, and encrypted article storage. We follow the principle of least privilege in function design.

We recommend keeping your device passcode enabled and your iOS version up to date.


10. Children's Privacy

T30 Journal is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us at info@t30journal.com and we will delete it.


11. International Users

T30 Journal stores data on your device, optionally in your iCloud Key-Value Store (for settings), and in Firebase (Google Cloud). Our Firebase project is hosted in the United States. If you are located outside the United States, your data will be transferred to and processed in the United States.

Google Cloud provides data transfer mechanisms including Standard Contractual Clauses (SCCs) for transfers from the European Economic Area, the United Kingdom, and Switzerland. See the Google Cloud Data Processing Addendum for details.

If you contact support or submit a website form, your information may also be processed in the United States.


12. Your Privacy Rights

Depending on where you live, you may have rights including access, correction, deletion, data portability, and the right to object to or restrict processing.

  • For data stored in the app: Use the in-app controls described in Section 7, including account and data deletion.
  • For complete server-side data removal, website-form requests, or other inquiries: Contact info@t30journal.com.

California Residents (CCPA/CPRA)

Depending on whether the law applies to Blocks and Circles LLC and the circumstances of your request, California residents may have rights to know and access categories and specific pieces of personal information; delete personal information; correct inaccurate personal information; obtain information about sources, purposes, and recipients; opt out of sale or sharing; limit certain uses of sensitive personal information; and receive equal service without discrimination for exercising privacy rights.

We do not sell personal information for money. We do not sell or share journal content, partner content, health information, precise location, account identity, or assessment answers for cross-context behavioral advertising. The public marketing website uses Meta Pixel and Google advertising and analytics technologies as described in §2.11. California law may treat those website disclosures as "sharing" for cross-context behavioral advertising even when no money is paid. Where the CCPA/CPRA applies, you may request to opt out of that sale or sharing by emailing info@t30journal.com with "Do Not Sell or Share" in the subject.

To submit a request, use the in-app deletion controls where available or email info@t30journal.com with "California Privacy Request" in the subject. We may ask for information reasonably necessary to verify the request and match it to our records. An authorized agent may submit a request on your behalf; we may require proof of authorization and may verify your identity directly. Information submitted for verification will be used only to process the request, prevent fraud, and keep required records. We will not discriminate against you for exercising an applicable privacy right.

California Online Privacy Protection Act and Browser Signals

The categories collected through the public website and web journal, the categories of recipients, and the review and deletion methods are described in §§2, 5, 7, and 12. Squarespace, Google, Meta, and other providers described in this policy may collect technical information over time as needed to host, secure, measure, and advertise the public website. Meta Pixel and Google advertising tags are limited to the public marketing website; we do not run those advertising trackers in the private web journal or native apps.

Browser "Do Not Track" signals do not have one uniform industry meaning, so our services do not separately respond to that signal. The current Squarespace configuration does not automatically translate a Global Privacy Control signal into suppression of the site-wide advertising tags. You may use browser tracking protection or submit a "Do Not Sell or Share" request by email. If the CCPA/CPRA applies to Blocks and Circles LLC, a technical mechanism that honors qualifying opt-out preference signals is required in addition to the disclosures in this policy.

European Economic Area and United Kingdom (GDPR/UK GDPR)

Legal bases for processing:

BasisApplies to
Performance of a contractProviding app functionality (journaling, sync, partner sharing, subscriptions)
Legitimate interestsApp reliability, abuse prevention, support, push notification delivery
ConsentOptional permissions (Apple Health, Health Connect, Location, Camera, Photos, Notifications, and biometric authentication) and optional AI Daily Insights processing

Processors and sub-processors: Blocks and Circles LLC is the controller. Multum Non Multa LLC processes backend data on behalf of Blocks and Circles LLC. Google Cloud Platform (Firebase Auth, Firestore, Storage, Cloud Messaging, Cloud Functions, and Vertex AI when separately enabled), Squarespace for the public website, and other providers identified in this policy process information for the applicable service. Google processes covered cloud data under the Google Cloud Data Processing Addendum, which includes Standard Contractual Clauses for international transfers.

You may withdraw consent for optional permissions at any time through iOS or Android settings, the Apple Health app for HealthKit categories, Health Connect settings on Android, or the web journal's analytics control. You can limit public-website trackers through browser cookie controls, tracking protection, or a privacy extension. You have the right to lodge a complaint with your local data protection authority. We encourage you to contact us first at info@t30journal.com so we can address your concern.


13. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the "Effective date" at the top and post the updated policy at the same URL. If a change materially affects how we use sensitive information or introduces a new advertising use, we will provide additional notice or request consent when required by law.


14. Contact Us

If you have questions or concerns about this Privacy Policy or your data: