Effective date
Effective: 15 September 2026 · Last updated: 15 September 2026
Who we are
sarn is operated by an individual developer and is not yet a registered business. For anything about this policy or your data: support@sarn.app.
The short version
- Your writing is encrypted before it is stored, with a key that is not held in the database. Someone who obtained a copy of the database alone could not read your entries.
- We do not train any AI model on your writing, and we do not sell or share your data with anyone for advertising.
- You bring your own AI provider key. When your entries are polished, they are sent to the provider you chose, using your key. That provider’s privacy policy governs what they do with it — we cannot control that, and you should read it.
What we collect
What you give us
- Email address
- To create your account and sign you in.
- Password or Google sign-in
- Authentication. Passwords are hashed and never stored in readable form.
- Display name and timezone
- Your timezone decides what “today” means for your journal.
- Entries, goals, tasks, plans, reminders
- This is the product.
- Your AI provider’s base URL, model id and API key
- To send your entries to the model you chose.
What is generated for you
Polished versions of your entries, per-goal progress notes, and the running “themes” summary — all produced by the AI model you configured, and stored the same way as everything else you write.
What is collected automatically
Standard server logs (IP address, user agent, request path, timestamp) kept by our host for operational and security purposes for 30 days.
What we do not collect
- No advertising or tracking cookies. The only cookies sarn sets are the ones that keep you signed in.
- We do not buy data about you, and we do not build a profile of you from anything other than what you type into the app.
- We do not use your writing to train any model, ours or anyone else’s.
How your writing is protected
Journal entries, goal titles and descriptions, task text, plan items, AI-derived progress notes and themes, and your stored AI key are encrypted at the application layer with AES-256-GCM before being written to the database. The key lives in the server’s environment, not in the database, so a database dump on its own is unreadable. This is in addition to the database provider’s own encryption at rest and TLS in transit.
What this protects against and what it does not. It defends against a stolen backup or a compromised database. It does not make sarn zero-knowledge: the server necessarily decrypts your entries in order to display them and to send them to your chosen AI provider, so an attacker with control of the running server, or someone with legal authority over us, could reach your content. We would rather say that plainly than imply a guarantee we cannot make.
Every table enforces row-level security in the database: your rows are readable only by your own authenticated session. This is verified by an automated test on every change.
The AI part, specifically
You supply an API key for an OpenAI-compatible provider — OpenRouter, OpenAI, or another of your choosing. When you save an entry:
- The entry text is sent from our server to your provider, using your key. It is never sent from your browser, and your key is never exposed to the browser — only the last four characters are ever shown back to you.
- Roughly once a day, recent entries are sent again to refresh your running themes.
- What your provider does with that text is governed by their policy, not ours. Some providers retain prompts; some train on them by default unless you opt out. This is worth ten minutes of your time before you paste a key in.
If you have not configured a key, no part of your writing is sent anywhere. The app works; it simply does not polish.
Automated content handling
sarn checks your entries against a fixed list of phrases describing self-harm or suicidality, so that it can show crisis resources instead of AI-generated “suggestions”. This check runs locally in your browser or on our server, is not an AI model, produces no score or label, is not stored, logged, or transmitted anywhere, and is discarded immediately after it decides what to display. It is not a safety or monitoring system, and nobody is notified.
Who else touches your data
- Supabase
- Database, authentication, transactional email delivery.
- Oracle Cloud
- The server sarn runs on.
- Resend
- Sends account emails (confirmation, password reset).
- Your chosen AI provider
- Receives entry text you ask to be polished.
sarn does not currently connect any error-tracking or analytics service. If that changes, this page will be updated to name the tool and describe what it records.
Your rights, and how to actually use them
Whatever jurisdiction you are in, these two work today, from inside the app, with no email required:
- Export everything. Settings → Your data → Download my data. One JSON file, decrypted and readable, containing everything you have written. Your AI key is deliberately excluded — it is a live credential, not your data.
- Delete everything. Settings → Your data → Delete my account. Immediate and permanent. There is no grace period and no backup we will restore from on request. Export first if you want a copy.
Under GDPR, UK GDPR, CCPA/CPRA and similar laws you may also have rights to access, correct, restrict or object to processing, and to complain to your data protection authority. Write to support@sarn.app.
Retention
Your content is kept until you delete it, or until you delete your account, at which point it is removed from the live database immediately.
Backups. We take nightly database backups and keep them for 14 days. A deleted account’s data may persist in a backup for up to that long before it ages out. Backups are not searched or restored on request.
Children
sarn is not intended for anyone under 16, and we do not knowingly collect their data.
Security incidents
If we become aware of a breach affecting your data, we will notify affected users and any required regulator within the timeframes the law requires.
Changes
We will post any change here and update the date at the top. For a change that materially affects how your data is handled — for example, if sarn ever supplies the AI model rather than you — we will tell you by email before it takes effect.
Contact
support@sarn.app. sarn is operated by an individual developer and is not yet a registered business, so there is no postal address to list here.