Privacy Policy
Last updated: June 16, 2026
This Privacy Policy describes how Gryphon Collaborative LLC ("Company," "we," "us," or "our") collects, uses, stores, and shares your personal information when you use Gryphon Journal ("the Service"). By using the Service, you agree to the collection and use of information as described in this Policy.
1. Who We Are
Gryphon Journal is operated by Gryphon Collaborative LLC, a Wyoming limited liability company. For questions about this Privacy Policy or your personal data, contact us at:
Email: GryphonJournal@gmail.com
Website: gryphonjournal.com
2. Information We Collect
Information You Provide
- Account information from Google Sign-In (name, email address, and profile photo provided by Google)
- Journal entries and reflections you create within the Service
- Subscription and billing information processed by Stripe (we do not receive or store your full payment card number)
- Communications you send us, such as support requests
Information Collected Automatically
- Log data: IP address, browser type, pages visited within the Service, timestamps, and error logs
- Device information: browser version, operating system, and screen resolution
- Usage data: features used, session duration, and interaction patterns
Information We Do Not Collect
We do not knowingly collect: health or medical records, financial account data, government ID numbers, or personal information from children under 13.
3. How We Use Your Information
We use the information we collect to:
- Provide, operate, and maintain the Service
- Deliver your journal entries to your email address via Resend
- Process subscription payments via Stripe
- Respond to your support inquiries
- Monitor and improve Service performance and reliability
- Detect and prevent fraud, abuse, or security incidents
- Comply with legal obligations
We do not use your journal entries for advertising purposes, do not sell your personal data to third parties, and do not use your entries to train AI or machine learning models.
4. Legal Basis for Processing (EU/UK Users)
If you are located in the European Union or United Kingdom, we process your personal data under the following legal bases:
- Contract performance: Processing necessary to provide the Service you have requested (e.g., storing your journal entries, sending email copies)
- Legitimate interests: Processing for security monitoring, fraud prevention, and Service improvement, where these interests are not overridden by your rights
- Legal obligation: Processing required to comply with applicable laws
- Consent: Where we rely on consent (e.g., optional communications), you may withdraw consent at any time without affecting prior processing
5. Third-Party Service Providers
We share your data with the following third-party providers solely to operate the Service:
- Supabase (data storage and database infrastructure) — supabase.com/privacy
- Resend (transactional email delivery) — resend.com/legal/privacy-policy
- Stripe (payment processing) — stripe.com/privacy
- Google (authentication via Google Sign-In) — policies.google.com/privacy
Each provider is bound by their own privacy policy and, where applicable, a data processing agreement with us. We do not permit these providers to use your data for their own marketing or other purposes beyond providing their services to us.
We do not currently use third-party analytics providers or advertising networks. If this changes, we will update this Policy.
6. Cookies and Tracking
The Service may use session cookies or similar technologies to maintain your authenticated session. We do not use advertising cookies, cross-site tracking cookies, or third-party analytics cookies.
You can configure your browser to refuse cookies, but doing so may affect your ability to use the Service (for example, you may be required to sign in each time).
7. Data Retention
We retain your personal data for as long as your account is active or as needed to provide the Service. Specifically:
- Journal entries: Retained until you request deletion or close your account
- Account information: Retained until your account is deleted
- Log and usage data: Retained for up to 90 days for security and debugging purposes
- Billing records: Retained as required by law (typically 7 years for financial records)
After the applicable retention period, data is securely deleted or anonymized.
8. Your Rights and Choices
Depending on your location, you may have the following rights regarding your personal data:
All Users
- Access: Request a copy of the personal data we hold about you
- Deletion: Request that we delete your account and associated data
- Correction: Request correction of inaccurate personal data
- Portability: Request your journal entries in a portable format
Connecticut Residents (CTDPA)
Under the Connecticut Data Privacy Act (effective July 1, 2023), Connecticut residents have the right to:
- Know what personal data we collect and how it is used
- Access, correct, and delete their personal data
- Opt out of the sale of personal data (we do not sell your data)
- Opt out of profiling that produces legal or similarly significant effects (we do not engage in such profiling)
- Appeal our decision if we decline to act on a privacy request
California Residents (CCPA/CPRA)
California residents have the right to know, access, delete, correct, and opt out of the sale or sharing of personal information. We do not sell or share your personal information for cross-context behavioral advertising. California residents also have the right not to receive discriminatory treatment for exercising their privacy rights.
EU/UK Residents (GDPR/UK GDPR)
EU and UK residents have the right to access, rectify, erase, restrict, and object to processing of their personal data, as well as the right to data portability and the right to lodge a complaint with their supervisory authority.
How to Exercise Your Rights
To exercise any of these rights, contact us at GryphonJournal@gmail.com. We will respond to verified requests within 30 days (or 45 days for CCPA requests). We may need to verify your identity before processing your request.
9. International Data Transfers
Gryphon Collaborative LLC is based in the United States. If you are located outside the United States, your personal data will be transferred to and processed in the United States, where data protection laws may differ from those in your country.
For EU/UK users: We rely on standard contractual clauses (SCCs) or other legally recognized transfer mechanisms when transferring personal data from the EU/UK to the United States. If you have questions about international transfers, contact us at GryphonJournal@gmail.com.
10. Data Security
We implement commercially reasonable technical and organizational measures to protect your personal data against unauthorized access, disclosure, alteration, or destruction. These measures include:
- Encrypted data storage via Supabase
- HTTPS encryption for all data in transit
- Access controls limiting who can access production data
- Regular review of our security practices
No method of transmission over the internet or electronic storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security. In the event of a data breach that may affect your rights or freedoms, we will notify you as required by applicable law.
11. Children's Privacy (COPPA)
The Service is not directed to children under the age of 13, and we do not knowingly collect personal information from children under 13. If you are under 13, you may not use the Service.
If we become aware that we have inadvertently collected personal information from a child under 13, we will take immediate steps to delete such information. If you believe a child under 13 has provided us with their personal information, please contact us at GryphonJournal@gmail.com.
12. Links to Third-Party Sites
The Service may contain links to third-party websites or services. We are not responsible for the privacy practices of those third parties. We encourage you to review the privacy policies of any third-party sites you visit.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last Updated" date at the top of this page. For material changes, we will provide notice via email or in-app notification at least 14 days before the changes take effect. Your continued use of the Service after the effective date constitutes your acceptance of the revised Policy.
14. Contact Us
For privacy-related questions, data requests, or concerns, contact us at:
Gryphon Collaborative LLC
Email: GryphonJournal@gmail.com
Website: gryphonjournal.com