Private journal · iPhone, iPad, and Mac
Reright Privacy Policy
How Reright handles journal writing, iCloud sync, AI assistance, voice input, and purchases.
Effective July 10, 2026
Reright is a private journal. The product is designed so writing stays local unless you choose a feature that needs sync, AI assistance, cloud dictation, or App Store purchase handling.
What Reright stores
Reright stores your journal pages, practices, mirrors, settings, local app state, and any writer-eligible pinned or approved guide memories on your device. If iCloud sync is on, those records are stored in your private iCloud database through Apple CloudKit so they can sync between your devices.
Reright’s developer server does not receive your private CloudKit database content. iCloud protection depends on your Apple account and iCloud security settings. CloudKit private database content is not the same as Reright-provided end-to-end encryption; if you use Apple’s Advanced Data Protection for iCloud, Apple provides additional end-to-end encryption for eligible iCloud categories.
When journal text is sent
Reright does not send journal text while you are simply writing.
Journal text may be sent in these cases:
- You invite the guide into the margin or choose a guided method such as “Work it through.” That request contains the current sitting plus at most four relevant memory items selected on your device. It does not send your complete journal, local search index, or rejected history candidates.
- After a sitting is saved, Reright may automatically send that bounded sitting to extract zero to three exact-evidence facts, commitments, changes, or open threads. Those records are stored in your journal, not on Reright’s server.
- For an Echo connection, retrieval happens locally first. Reright may send the current passage and at most two selected historical passages so the AI can identify one evidence-backed relationship; it does not send the surrounding pages or journal index.
- You turn on contextual prompts and Reright sends a small set of recent entries to write a prompt above today’s page.
- You ask Reright Plus to write a monthly mirror.
Those requests go through Reright’s server so provider keys stay server-side. The server forwards the selected text to the configured AI provider, currently OpenAI or Anthropic depending on the release configuration. Reright’s proxy does not persist prompt text. It also does not persist journal text or model responses. It uses short-lived rate-limit counters keyed by a SHA-256 hash of an anonymous install token. Cloudflare-native rate limits also apply short-lived per-location burst controls without storing journal content.
Guide-history storage and retrieval are part of the core Guide experience. Candidate extraction is stateless; the app verifies exact source evidence and stores accepted temporal records locally or in your private CloudKit database. You may clear structured Guide Memory in Settings without deleting journal pages or Mirrors, although later saved sittings can build new memory. The guide backend does not maintain a cross-request content profile or server-side journal memory.
Voice input
Voice writing uses cloud transcription. When you start a voice session, audio chunks stream through Reright’s server to ElevenLabs for realtime speech-to-text. Reright’s proxy does not persist the audio, and audio is not written to your journal; only the resulting transcript becomes journal ink.
Purchases
Reright Plus purchases are handled by Apple’s App Store and StoreKit. Reright does not receive your payment card details. Subscription management, refunds, and billing are handled through your Apple Account.
Tracking and advertising
Reright does not sell personal data. Reright does not use journal content, audio, or install identifiers for third-party advertising or tracking.
Export, import, and deletion
Reright includes Markdown export and a complete JSON archive export/import path; the JSON archive includes grounded automatic or pinned/approved guide memories that are eligible for use. You can delete an entry or day, including locally stored guide replies inside it and related Guide Memory, or erase all journal data from Settings. If you revise an earlier entry that has guide replies, Reright asks first and removes those replies and related Guide Memory because they were generated from the prior wording. Clearing an entry’s final writer text uses the same complete entry-deletion behavior.
Existing Mirror citation text is not rewritten when a source entry is deleted. Data already synced to iCloud is managed through Apple’s iCloud systems and your devices. Reright’s guide server does not retain journal entries or replies as conversation history, so entry deletion does not require a server-side conversation deletion request.
Third-party services
Depending on the features you use and the release configuration, these services may process data for app functionality:
- Apple iCloud/CloudKit for private database sync.
- Apple App Store / StoreKit for purchases and subscription management.
- OpenAI or Anthropic for guide replies, contextual prompts, and mirrors.
- ElevenLabs for realtime cloud speech-to-text when voice input is used.
- Cloudflare for the Reright proxy, short-lived rate limiting, and privacy-safe operational metrics that contain route/status labels and counts but no journal, memory, audio, evidence, or response content.
Contact
For privacy questions or support, contact support@minuet.studio.