Skip to content

Legal · Effective 2026-02-01

Privacy Policy

Your journal is yours. Here's exactly what happens to your data — and what doesn't.

Version 2026-02-01. This Privacy Policy explains what personal information Umbra Shadow Speak Journal ("Umbra," "we") collects, how we use it, and your rights.

1. Data We Collect

You give us directly

  • Account: email, display name, profile photo (from Google Sign-in), preferred narrator voice, birthdate (for age gate), parental email (for minors 13–15).
  • Journal content: text entries, audio recordings (transient — see §2), AI-generated reflections, mood tags, comments on the public blog, star ratings.
  • Payment: name, billing address, and card details entered directly into Stripe's PCI-DSS-compliant checkout — Umbra never stores your full card number.

We collect automatically

  • Device type, browser, operating system, IP address (used for rate-limiting, fraud prevention, and audit logs).
  • Usage events (page views, feature clicks) via first-party analytics — no third-party ad networks.
  • Cookies for session authentication (essential) and preference storage.

2. Audio Recordings — Special Handling

When you record a voice entry, your audio is uploaded to our server, forwarded to OpenAI Whisper for transcription, and permanently deleted from our servers within 60 seconds of successful transcription. Only the resulting text is stored in your journal. OpenAI does not retain audio sent through the API for their model training.

3. How We Use Your Data

  • To operate the service: create your account, save your entries, transcribe your voice, generate reflections, print your keepsake books, sync across your devices.
  • To bill you: process subscription payments, calculate applicable tax, issue refunds.
  • To communicate: send transactional email (receipts, password recovery, keepsake shipping updates), and — with your explicit opt-in — a weekly digest or product announcements.
  • To improve the product: aggregate, anonymized usage metrics (no individual journal content is used).
  • To keep the service secure: rate-limiting, abuse detection, fraud prevention.
  • To comply with law: respond to lawful legal process.

4. What We Do Not Do

  • We do not sell, rent, or trade your personal data. Ever.
  • We do not use your journal content to train AI models — ours or anyone else's.
  • We do not share your entries with third parties except (a) service providers under strict contract (see §5), (b) with your explicit consent (e.g., comments you choose to post publicly), or (c) if compelled by legal process.
  • We do not run third-party advertising networks or trackers on the site.

5. Third-Party Service Providers

To operate Umbra we rely on carefully selected sub-processors, each under a Data Processing Agreement:

  • Stripe — payment processing and billing
  • OpenAI — Whisper transcription and reflection generation
  • Anthropic — blog essay drafting (never touches journal content)
  • Google (Gemini) — cover and OG image generation
  • Emergent Auth / Google OAuth — sign-in only
  • Resend — transactional email delivery
  • Lulu — print-on-demand keepsake books (receives only the content you choose to print + your shipping address)
  • MongoDB Atlas — encrypted database hosting (US-East region)
  • Emergent Object Storage — encrypted file storage

6. Data Retention

  • Journal entries, reflections, comments: kept while your account is active. Deleted permanently within 30 days of account deletion.
  • Audio recordings: deleted within 60 seconds of transcription.
  • Financial records: retained for 7 years to meet US tax and accounting obligations, even after account deletion.
  • Server logs: 90 days.
  • Parental consent records: retained for the duration of the minor's account plus 3 years, for COPPA compliance.

7. Your Rights

Depending on where you live, you may have rights to:

  • Access the personal data we hold about you (Settings → Export My Data)
  • Correct inaccurate data (Settings → Profile)
  • Delete your account and associated data (Settings → Privacy → Delete Account)
  • Object to processing or withdraw consent
  • Data portability — export your entries in JSON format
  • Opt out of marketing email (link in every marketing email)

To exercise any of these rights, use the in-app controls or email hello@shadowspeakjournal.com. We respond within 30 days.

8. Children's Privacy (COPPA)

Umbra is not directed at children under 13. We do not knowingly collect personal information from anyone under 13 without verified parental consent. Users aged 13–15 must complete a verified parental consent flow — the parent receives an email, verifies their identity via Stripe SetupIntent (small card authorization, no charge held), and expressly authorizes the minor's use. If we learn we have collected personal information from a child under 13 without proper consent, we delete it within 30 days. Parents may contact hello@shadowspeakjournal.com to review, delete, or revoke consent at any time.

9. Security

We use industry-standard practices: encryption in transit (TLS 1.3), encryption at rest (AES-256), least-privilege access controls, rate limiting, and continuous monitoring. No system is perfectly secure — if we discover a breach affecting your data, we'll notify you as required by law.

10. International Transfers

Umbra is operated from the United States. If you access Umbra from outside the US, your data is transferred to and processed in the US, which may have different data-protection laws than your country. By using Umbra you consent to that transfer.

11. State-Specific Rights (US)

California residents (CCPA/CPRA): You have rights to know, delete, correct, and opt out of "sale" or "sharing" of personal information. Umbra does not sell or share personal information as defined by the CCPA. Submit requests via hello@shadowspeakjournal.com.

Colorado, Virginia, Connecticut, Utah, and other state-privacy-law residents: You have similar rights of access, correction, deletion, and opt-out. Same process — email hello@shadowspeakjournal.com.

12. EU/UK Users (GDPR/UK GDPR)

Our lawful basis for processing is (a) contract (to deliver the service you signed up for); (b) legitimate interest (security, fraud prevention, product improvement); and (c) consent (marketing, cookies beyond essential). You have the rights listed in §7 above, plus the right to lodge a complaint with your local supervisory authority.

13. Changes

Material changes will be announced via in-app notice and, where required, email. Continued use after the effective date means you accept the updated Policy.

14. Contact

Privacy questions or requests: hello@shadowspeakjournal.com.


This Policy is a good-faith SaaS boilerplate — it is not legal advice. Consult a qualified attorney before relying on it for a public launch, GDPR audit, or investor diligence.