Skip to content
PhostWriter app icon PhostWriter
Home Support Terms

Legal

Privacy Policy

Last updated: March 2026

Overview

PhostWriter is a personal journaling app that uses AI to help you write diary entries from your photos and daily activities. Your privacy is central to how the app is built.

Journal Entries

Your journal text is encrypted on your device before storage. The encryption key is generated on your device, stored in iOS Keychain, and never sent to our backend.

By default, encrypted journal entries are stored on PhostWriter servers so you can access them across sessions.

If you are a Pro user and enable Encrypted iCloud Backup in Settings > Privacy, encrypted entry copies are also written to your private CloudKit database.

Photos

Photos you select for journal generation are stored locally on your device.

If you are a Pro user and enable Encrypted iCloud Backup in Settings > Privacy, photo copies are encrypted on-device and stored in your private CloudKit database to support device restore.

Only the photos you explicitly select are sent, and only when you ask PhostWriter to generate a draft. Selected photos are sent to the PhostWriter backend and then forwarded to OpenAI's API for visual analysis. The backend processes these images only for generation and does not persist photo files as part of your account data.

Before sending, images are resized and compressed for generation. Requests to OpenAI are sent with request storage disabled (`store: false`). Additional retention behavior can still depend on OpenAI API policy and safety requirements.

Photo Labels

If you add optional notes to your photos, such as names or places, those labels are sent to the AI along with your selected photos to provide context for that draft. We do not persist photo labels in PhostWriter databases after generation.

AI Processing

Journal text is generated using OpenAI's GPT-5.6 Terra model.

The data sent to OpenAI can include:

  • selected photos
  • timestamps and location names from selected moments
  • photo labels or generation notes you provide
  • your chosen journal language

This AI generation flow is separate from encrypted journal storage. OpenAI requests are sent with request storage disabled (`store: false`).

What We Store on Our Server

  • your Apple ID identifier for authentication
  • your email address, if provided during sign-in
  • encrypted journal text for standard sync flows
  • entry metadata such as dates, photo counts, optional photo asset IDs, optional location, mood, and tags
  • subscription status
  • monthly usage counts and generation telemetry for abuse and cost monitoring
  • feedback messages you submit from the app

What We Do Not Have Access To

  • your unencrypted journal entries
  • your CloudKit private database contents
  • your long-term photo library contents

Data Deletion

You can delete individual entries, all entries, or your entire account at any time from Settings > Privacy. Account deletion permanently removes all your data from our servers.

Third-Party Services

  • Apple Sign-In for authentication
  • OpenAI API for journal text generation
  • Apple StoreKit for subscription management

Contact

If you have questions about this privacy policy, contact support@phostwriter.com.

PhostWriter app icon
PhostWriter™ Your photos remember. support@phostwriter.com
Home Support Terms