inner day

Privacy Policy

Effective 22 July 2026 · Last updated 22 July 2026

Who we are

Inner Day (“Inner Day”, “we”, “us”, “our”) is a personal journaling service operated by Daniel Bulut, an individual based in Melbourne, Victoria, Australia. Inner Day is currently provided free of charge; it is run by an individual and is not a registered company.

We take the privacy of what you write extremely seriously. Journaling only works when you can be honest, and honesty requires trust. This policy explains, in plain terms, what information we collect, why, who can access it, how we protect it, and the choices and rights you have.

You can contact us about privacy at any time at danielbulut01@gmail.com.

The short version

  • We collect your email, the journal entries you write, a few onboarding answers, and basic technical and usage data.
  • To make the service work, Inner Day and our AI provider (Anthropic / Claude) read your entries — to generate your prompts, extract insights about what matters to you, and write your weekly reflections.
  • Your entries and the insights derived from them are encrypted in transit and at rest.
  • We do not sell your data, we do not use it for advertising, and we use no third-party analytics or trackers.
  • You can unsubscribe, pause, access, correct, or delete your information at any time.
  • Inner Day is not a medical, counselling, or crisis service.

1. Information we collect

Information you give us

  • Account information: your email address, used to create your account, sign you in, and deliver your prompts. Sign-in uses a one-time code sent to your email; we do not store a password.
  • Optionally, your name, if provided.
  • Your journal entries: the free-text reflections you write. These are the most sensitive information we hold and are treated accordingly (see sections 3 and 8).
  • Onboarding answers: the life areas you select and your free-text answer about what you hope to get from journaling.

Information we generate about you

To provide the service, we use AI (see section 2) to derive further information from your entries, including short insights distilled from your writing, a rolling context summary of what you have been exploring, your weekly summaries, and the prompts we generate for you. This derived information is also treated as sensitive and encrypted at rest.

Information we collect automatically

  • Approximate timezone, derived from your IP address (via our hosting provider) when you sign up, so we can deliver your prompt in your morning. We use this to infer your general timezone; we do not build a precise location profile.
  • Usage and delivery data: timestamps such as when you last replied and when you onboarded, and email delivery metadata.
  • Technical and log data: standard server logs generated by our infrastructure providers (such as IP address and request metadata) for security and reliable operation.
  • Essential cookies: a session cookie set by our authentication provider to keep you signed in. We do not use advertising, analytics, or third-party tracking cookies.

2. AI processing of your entries

Inner Day’s core feature — reflecting your writing back to you — requires a computer to read what you write. To do this, we send the text of your entries to our AI provider, Anthropic (the maker of Claude), via its API, to generate your personalised prompts, extract insights and update your context summary, and write your weekly summaries.

What this means for you:

  • Your entry text is decrypted and transmitted to Anthropic for processing, and the results are stored (encrypted) back in our database.
  • Under Anthropic’s commercial API terms, the content we send is not used to train Anthropic’s models.
  • We only send what is necessary to operate these features, and we do not send your entries to any AI provider for any other purpose.

If you are not comfortable with your writing being processed by an AI provider in this way, please do not use Inner Day, as this processing is essential to how the product works.

3. How your information is stored and protected

  • Encryption in transit. Every connection to Inner Day is secured with TLS (HTTPS) — the same standard that protects online banking. Your writing is encrypted whenever it moves between your device, our servers, and the providers we use to run the service (including our AI provider), so it cannot be read while in transit.
  • Encryption at rest. Your journal entries, the insights derived from them, your context summary, and the context we feed into prompt generation are encrypted at rest using strong, industry-standard encryption (AES-256-GCM), so that a database breach, backup leak, or exposed database credential does not reveal your writing in plain text.
  • This is not end-to-end encryption. To provide the service, Inner Day and our AI provider decrypt and read your entries as described in section 2. The operator of Inner Day therefore has the technical ability to access your content, and will do so only where necessary to operate, secure, debug, or improve the service, to provide support you request, or where required by law. We do not read your entries casually or out of curiosity.
  • No system is perfectly secure. While we take reasonable steps to protect your information, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.

4. Who we share your information with

We do not sell your personal information, and we do not share it for advertising. Inner Day is free and has no advertising or data-sale business model.

We share information with a small number of service providers who help us run the service, each only to the extent needed to perform their function and bound to handle it on our instructions:

  • Supabase — database and authentication hosting. Handles your account data and your (encrypted) entries and derived data.
  • Vercel — application hosting and delivery. Serves the app, processes requests and server logs, and derives your approximate timezone from your IP.
  • Anthropic (Claude) — AI processing. Receives the text of your entries and derived context for prompt, insight, and summary generation (see section 2).
  • Resend — email delivery. Handles your email address and the content of the emails we send you.
  • Trigger.dev — background job processing. Runs the pipeline that processes your entries after you submit them.

We may also disclose information:

  • to comply with the law, a legal process, or a lawful government request;
  • to protect the rights, safety, or property of Inner Day, our users, or others (for example, to address fraud, security, or a serious threat to someone’s life or health); and
  • in connection with a business transfer (for example, if Inner Day is ever acquired or its assets transferred), in which case we will require the recipient to honour this policy or notify you of any material change.

5. International data transfers

Inner Day is operated from Australia, and our service providers may store or process your information in the United States and other countries. This means your information, including your entries, may be transferred to and processed in countries whose data-protection laws differ from those in your own.

6. How we use your information

We use your information to:

  • provide the service — create your account, sign you in, generate and deliver your prompts, process your entries, and produce your weekly summaries;
  • personalise your prompts and summaries over time;
  • communicate with you — send your daily prompts, weekly summaries, re-engagement or pause notices, and respond to your requests;
  • maintain security and reliability, and prevent abuse; and
  • improve the service, consistent with this policy and applicable law.

7. How long we keep your information

We keep your account information and entries for as long as your account is active, so the service can keep learning from your writing and reflecting it back to you.

  • You can request deletion of your data at any time (see section 9). Currently, deletion is handled manually — email us and we will delete your account and associated data.
  • After deletion, residual copies may persist in encrypted backups for a limited period until those backups are cycled out, after which they are removed.
  • We may retain limited information where required to comply with legal obligations, resolve disputes, or enforce our agreements.

8. Sensitive information and your wellbeing

Your entries are sensitive.They may reveal information about your health (including mental health), emotions, relationships, beliefs, and other private matters. Under Australian privacy law this is “sensitive information”, and under some other laws (such as the EU/UK GDPR) it may be “special category” data, which receives heightened protection.

By writing and submitting entries, you consent to us collecting and processing this sensitive information for the purposes described in this policy (including AI processing under section 2). You can withdraw this consent at any time by unsubscribing, pausing, or deleting your account.

Inner Day is not a health, medical, psychological, counselling, or crisis service, and does not provide professional advice or treatment. It is a journaling tool. Nothing it generates should be relied on as professional advice.

If you are in distress or may be at risk of harming yourself, please seek help immediately. In an emergency, contact your local emergency number. You can also reach a crisis line: in Australia, Lifeline on 13 11 14 or Beyond Blue on 1300 22 4636; in the US and Canada, call or text 988; in the UK and Ireland, Samaritans on 116 123.

9. Your rights and choices

You can, at any time:

  • unsubscribe from prompts and summaries using the link in any email, or in the app;
  • pause your prompts and later resume them from your dashboard;
  • access the personal information we hold about you;
  • correct information that is inaccurate;
  • delete your account and associated data;
  • obtain a copy of your information in a portable form; and
  • withdraw consent to processing (noting this may mean you can no longer use the service).

To exercise any of these, email danielbulut01@gmail.com. We will respond within the timeframe required by applicable law.

Depending on where you live, you may have additional rights:

  • Australia: rights under the Privacy Act 1988 (Cth) and the Australian Privacy Principles, and the right to complain to the Office of the Australian Information Commissioner (OAIC).
  • EU / UK: rights under the GDPR / UK GDPR, including the right to lodge a complaint with your local data protection authority.
  • California: rights under the CCPA/CPRA, including the right to know, delete, and correct — noting we do not sell or share your personal information as those terms are defined.

10. Children's privacy

Inner Day is not intended for children or minors. You must be at least 18 years old to use it. We do not knowingly collect information from anyone under that age; if we learn that we have, we will delete it.

11. Data breaches

If a data breach occurs that is likely to result in serious harm, we will notify affected users and the relevant regulator as required by law (including the Notifiable Data Breaches scheme in Australia, and applicable breach-notification laws elsewhere).

12. Changes to this policy

We may update this policy from time to time. If we make material changes, we will notify you (for example, by email or an in-app notice) before they take effect where required. The “Last updated” date at the top reflects the latest version.

13. Contact us

For any privacy question, request, or complaint, contact us at danielbulut01@gmail.com. If you are not satisfied with our response, you may contact the OAIC (Australia) or your local data-protection authority.