[PLACEHOLDER] and have it checked against the law of
your jurisdiction before publishing.
Privacy Policy
The short version
You write; we store it; we don’t read it; we don’t sell it; when you ask for a reflection the relevant entries go to an AI provider to be turned into one, and come straight back; you can download everything at any time, and you can ask us to delete all of it.
1. What we collect
Because you gave it to us when you signed up
- Your email address (this is your login, and how we’d reach you)
- Your password, stored only as a bcrypt hash. We never store, and cannot recover, the password itself
- Optionally, a display name
- Optionally, your birth year (used to turn “I was about nine” into an approximate year on your timeline)
Because it’s your journal
- The entries you write: titles and body text
- The date information you attach: exact dates, months, years, approximate ages, decades, year ranges, “I don’t know”, any free-text notes about the date, and any “this happened before/after that” ordering you set
- Everything else you optionally add to an entry: mood, people, places, tags, songs, follow-up links, and whether you marked it formative or difficult
- Photographs and images you upload, stored as files on our server
- Journeys, journey notes, life phases, and connections between entries
- Previous versions of an entry, kept automatically when you change its title or body, so an edit can be undone
- Reflections generated by the AI features, saved to your account so you can read them again
Because the software has to run
- A session cookie so you stay signed in (see §7)
- For each AI action: the date, which feature it was, which model was used, a token count and a cost figure. This is metadata only, never the content of the entries or the reflection
- Ordinary server logs, which may include IP addresses and error traces
[PLACEHOLDER: confirm your web-server log retention period and state it here]
Optionally, if you link Telegram
- A short-lived link code, and your Telegram chat ID, so a message from you can be matched to your account
We do not collect: card or bank details (payments for Pro are taken by Paddle, our
merchant of record, and we store only a customer reference and a subscription reference), location data,
contacts, advertising identifiers, or any third-party analytics or tracking data.
[PLACEHOLDER: if any analytics is ever added, this line must be updated first]
2. Why we hold it
To give you the service you signed up for, and for nothing else. Specifically: to let you sign in; to store and show you your journal; to generate a reflection when you ask for one; to count your usage against your plan’s limits; and to keep the service running and secure.
We do not build profiles, we do not do behavioural advertising, and we have no advertising business of any kind.
[PLACEHOLDER: if GDPR/UK GDPR applies, state your lawful bases, likely performance of a
contract for the core service, and legitimate interests for security and abuse prevention.
Note that special-category data may be present in journal entries by their nature, and take
advice on the consent position before launch.]
3. Where it’s stored
Your account and your journal live in a MySQL database, and your uploaded images live as
files, on a server operated by us at [PLACEHOLDER: hosting provider] in
[PLACEHOLDER: region/country]. Access to that server is restricted to
[PLACEHOLDER: who has production access].
Passwords are hashed with bcrypt, at a work factor of 12, and are never stored in a form that could be turned back into your password.
We want to be exact about this: your entries are stored in the database as ordinary text, and your images as ordinary files. They are not end-to-end encrypted, and we do not currently apply application-level encryption to them. That means someone with direct access to the server could in principle read them, which is why that access is limited and why we say it here rather than letting you assume otherwise. See our Security & your data page for the full picture.
4. When your writing leaves our server
There are exactly two situations in which the content of your journal is sent anywhere else: when you press a button that asks for an AI reflection, and when you send the Telegram bot a voice note to capture as an entry.
When you do, Lapriland assembles the relevant entries (for some features that’s a specific entry, for others it’s a summarised sweep of your journal) and sends them over an encrypted HTTPS connection to a third-party AI provider, reached via a model-routing service, which generates the text and returns it. The reflection is then saved to your account.
Things worth knowing about that path:
- It never happens on its own. There is no background analysis, no scheduled job that reads your journal, and nothing that runs while you’re not looking. Every single AI request is one you initiated.
- If you never use the AI features, your entries never leave our server. The journal, the timeline, journeys, the soundtrack, echoes and export all work without any AI at all.
- If an entry has an image and you use a feature that reads images, that image is sent too, as part of the same request.
- Voice notes work the same way, with audio. If you link Telegram and send the bot a voice note, the audio recording is sent to the AI provider to be transcribed into an entry, then the recording is deleted from our server, and we keep only the text. The original message also lives in your Telegram chat history, which is governed by Telegram’s own privacy policy, not ours. Chats with a Telegram bot are not end-to-end encrypted, so Telegram’s own servers can read them; if that matters to you, record in the web app instead.
- Only providers that promise not to keep it. Every request goes only to providers that neither store nor train on what we send, on zero-data-retention terms. If that ever has to change, this page changes first.
- You can keep any memory away from the AI. Switch it on in the memory’s details and that memory is never included in a reflection, a question to your journal or a portrait, and its own AI buttons stay off.
- The provider processes what we send under its own terms and privacy policy. We do not
control its internal handling and we will not make promises on its behalf.
[PLACEHOLDER: name the current provider and link its privacy policy and data-retention terms here, and update this section whenever the provider changes] - We do not use your entries to train any model, and we do not license, sell, or share them with anyone for that purpose or any other.
5. Who else we share it with
Nobody, other than:
- The AI provider described in §4, only for reflections you request
[PLACEHOLDER: hosting provider], which operates the server your data sits on- If you link Telegram, Telegram itself, which necessarily processes any message you send its bot
- If you subscribe to Pro, Paddle (Paddle.com Market Ltd), our merchant of record, which takes the payment, issues the receipt and handles tax. It receives your email address and billing details; we receive back a customer reference, a subscription reference and its status. See our refunds and cancellation page.
- Where we are legally required to, such as by a valid court order or equivalent legal process. If we are permitted to tell you, we will.
We do not sell your personal data, and we do not share it for advertising or marketing. There is no advertising in Lapriland and no plan to add any.
If Lapriland were ever sold or transferred, your data could transfer with it, and we would tell you before that happened, and this policy would continue to apply until you were given notice of a new one.
6. Your rights over it
Export is available now, on every plan, with no request needed. From Settings you can download your whole journal at any time: a JSON file of your entries, journeys, phases and connections, or a zip containing that JSON, a readable plain-text book of your entire journal, and every image you’ve uploaded.
Deletion. Email [PLACEHOLDER: contact email] from the address on your account and we
will delete it, meaning your entries, images, journeys, reflections, tags and account record,
permanently, within [PLACEHOLDER: e.g. 30] days. We may retain a minimal record that the
account existed and was deleted, and anything a law requires us to keep. Please export first
if you want a copy; we can’t restore it afterwards.
Correction and access. You can edit or delete any entry yourself at any time, and change your display name, email and birth year in Settings. Everything we hold about you is in the export.
[PLACEHOLDER: if GDPR/UK GDPR or CCPA applies, add the remaining statutory rights,
restriction, objection, portability, the right to complain to a supervisory authority, and
your DPO or representative if you need one.]
7. Cookies
Lapriland sets one cookie, journal.sid. It holds a session identifier and nothing else:
no tracking, no advertising, no third-party cookies, no analytics. It’s marked HttpOnly so
scripts can’t read it, SameSite=Lax, and served as Secure over HTTPS. Clearing it, or
signing out, ends the session.
We use no third-party analytics, tags, pixels or trackers of any kind.
8. Children
Lapriland is not intended for children, and you must be at least
[PLACEHOLDER: minimum age, commonly 16, or 13 with local variation] to create an account.
If we learn that an account belongs to a child below that age, we’ll delete it.
9. Changes to this policy
If we change it in a way that matters, we’ll update the effective date at the top and let account holders know by email before it takes effect. In particular, if the AI data path in §4 ever changes, we’ll tell you.
10. Contact
[PLACEHOLDER: contact email] for privacy questions, export help, or deletion requests.