Legal

Privacy Policy

JAI: AI Chat and Journal · JAI LAB LLP · Last updated 26 July 2026

A journal only works if you can be honest in it. This page explains, in plain language, exactly what JAI collects, who else touches it, where it sits, and what you can do about all of it.

The three things people usually want to know:

  • Your journal entries are never used to train AI models — not by us, and not by OpenAI.
  • We do not sell your data and we do not advertise against what you write.
  • You can delete everything from inside the app, in two taps, and it is gone for good.

1. Who we are

JAI is made by JAI LAB LLP, a limited liability partnership registered in Singapore (UEN T26LL0791K), with its registered office at 32 Keppel Bay Drive
#04-62 Caribbean at Keppel Bay
098651, Singapore. In this policy "we", "us" and "JAI Lab" mean JAI LAB LLP, and "JAI" or "the app" means our iOS app JAI: AI Chat and Journal and the services behind it.

We are the organisation responsible for your personal data under Singapore's Personal Data Protection Act 2012 (PDPA). This policy applies to the app, to this website, and to any support conversation you have with us.

2. What we collect, and why

We collect only what the app needs to work. Each item below says what it is and why we hold it.

  • Account details — your email address and a user identifier, passed to us when you sign in with Google or Apple. We never receive or store your Google or Apple password. Why: to create your account, keep you signed in, and make sure only you can reach your entries.
  • Your onboarding profile — during setup you can tell us your first name, your age range, your gender (there is always a "prefer not to say" option), what fills your days, and how you've been feeling lately. All of it is optional. Why: so the very first conversation already knows something about you, rather than starting from a blank page.
  • Your journal content — the messages you write to JAI and the replies it writes back. Why: this is the journal. We store it so you can read it back and so the app can respond with some memory of what you've said.
  • Reflections derived from your content — structured notes we generate from your entries: emotional tone, mentions of sleep and exercise, events, goals, and recurring topics. Why: to produce your morning brief, your dashboard and the patterns view. These are derived from your own words and are tied to your account.
  • What you choose to track — the habits and areas you pick during setup or later on the tracking screen, and the values recorded against them. Why: so the app knows what to pay attention to and what to chart.
  • Usage analytics — product events such as screens viewed, features used, onboarding answers and paywall interactions, along with a user identifier and basic device and app-version information. Errors and crashes are captured the same way. Your journal messages and the app's replies are never sent to our analytics provider. Why: to see which parts of the app people actually use, and to find and fix bugs.
  • Subscription information — your subscription status and transaction identifiers. Apple handles the payment; your card details never reach us. Why: to unlock paid features on your account.
  • Device push token — only if you turn notifications on, plus the time of day you asked to be reminded. Why: to deliver your morning brief and check-in nudges to your phone.
  • Support correspondence — anything you email us, and our reply. Why: to answer you and keep a record of the issue.

We do not ask for your contacts, your photos, your precise location or your health records, and we do not read anything on your device outside the app.

3. Consent and purpose limitation

Under the PDPA we collect, use and disclose personal data only with your consent, and only for purposes a reasonable person would consider appropriate in the circumstances. Those purposes are the ones listed in section 2: running the app, generating your reflections, sending the notifications you asked for, handling your subscription, and keeping the service secure and working.

You give consent when you create an account and accept this policy. Notification permission and the optional profile questions are separate, explicit choices you can decline or change without losing the rest of the app.

We will not use your data for a new, unrelated purpose without telling you first. And to be explicit about the two things people worry about most:

  • We do not sell your personal data. To anyone, ever.
  • We do not advertise against your journal content. There is no advertising in JAI, and no advertising or data broker network receives your entries or anything derived from them.

We would only disclose personal data outside the providers named in section 5 where the law requires it — for example a valid court order or a lawful request from a Singapore authority — or where it is necessary to protect someone's life or safety.

4. We do not train AI on your entries

This deserves its own heading because it is the question we get asked most.

Your journal entries are never used to train, fine-tune or improve any AI model — not ours, and not OpenAI's. Your text is sent to OpenAI's API for one reason only: to generate your own replies, your morning brief and your structured reflections. The response comes back, we store it against your account, and that is the end of it.

This is consistent with how OpenAI's API works. Under OpenAI's API terms, data sent through the API is not used to train their models by default. OpenAI may retain API content for a limited period for abuse and misuse monitoring, after which it is deleted. We have not opted in to any model-improvement or data-sharing programme.

We also do not build aggregate products out of your writing, and we do not pool users' entries to create datasets.

5. Who processes your data

JAI Lab is a small studio, so parts of the service run on infrastructure we rent rather than own. Each provider below acts on our instructions, handles data only to perform its own function, and is bound by its own contractual and security terms. We do not give any of them permission to use your data for their own purposes.

Provider What it handles Where
OpenAI Processes the text of your messages to generate replies, your morning brief and your structured reflections (models gpt-4o and gpt-4o-mini). Not used for model training — see section 4. United States
Supabase Authentication, and the primary Postgres database holding your account, your entries and the data derived from them. Sydney, Australia (ap-southeast-2)
Render Hosting and compute for the JAI application programming interface. Singapore
DigitalOcean Hosts the Neo4j knowledge-graph server we manage ourselves, which holds the structured data derived from your entries. Singapore (SGP1)
PostHog Product analytics and error reporting. No journal content is sent. United States
RevenueCat Subscription management and entitlement checks. United States
Apple App Store distribution and payment processing. Your card details go to Apple and never reach JAI Lab. Global (Apple-operated infrastructure)
Expo Delivery of push notifications to your device. United States
GitHub Stores our weekly database backup as a private build artifact, encrypted at rest by GitHub. United States
Vercel Hosts this website. It is a static site and does not read your journal data. Global edge network

If we add or replace a provider, we update this table and the "last updated" date above.

6. Where your data is stored

JAI Lab is registered in Singapore, and our application servers run in Singapore. But some of the providers above sit elsewhere, and we would rather say so plainly than bury it:

  • The primary database holding your account, your entries and your derived reflections is in Sydney, Australia.
  • The knowledge graph derived from your entries sits on a server we manage in Singapore (SGP1).
  • Message text is transmitted to OpenAI in the United States to generate each reply and reflection.
  • Analytics, subscription and push-notification providers, and our backup storage, are in the United States.

Transfers out of Singapore

Because personal data leaves Singapore, the PDPA's Transfer Limitation Obligation (section 26 of the PDPA and the related regulations) applies. Before transferring personal data to a recipient outside Singapore, we take reasonable steps to satisfy ourselves that the recipient is bound by legally enforceable obligations to protect that data to a standard at least comparable to the protection under the PDPA. In practice that means each provider in section 5 is engaged under a written contract that restricts them to processing data on our instructions, requires appropriate security measures, and limits onward transfer.

By using JAI you acknowledge that your personal data will be stored and processed in the countries named above.

7. Retention and deletion

We keep your data for as long as your account exists. We do not have a background process that quietly deletes old entries — the point of a journal is that last year's entry is still there.

Deleting your account

You can permanently delete your account from inside the app at any time. Deletion is immediate and irreversible, and it removes:

  • your conversations and every message in them;
  • every derived reflection — emotional analysis, health and productivity metrics, events, topics, goals and tracked values;
  • your profile, notification preferences and device push tokens;
  • your entire subgraph in the Neo4j knowledge graph; and
  • your sign-in identity itself, so the account no longer exists.

There is a step-by-step walkthrough, including exactly what is removed, at jai-lab.co/jai/delete-account. If you cannot reach the in-app option, email jerry@jai-lab.co and we will do it for you.

The one exception: backups

We take an automatic backup of the database once a week, on Sundays, and store it as a private build artifact. Those artifacts are automatically deleted 28 days after they are created.

So while your live data disappears the moment you delete your account, a residual copy can persist inside those weekly backups for up to 28 days before it ages out automatically. Backups are used only to restore the service after a failure, are never queried for ordinary operations, and are not shared with anyone.

Some records outside your account data — for example an invoice or a support email — may be kept longer where we are required to keep them for legal, tax or accounting reasons.

8. Your rights under the PDPA

Access

You can read everything you have written inside the app at any time. Beyond that, you have the right to ask us for a copy of the personal data about you that is in our possession or control, and for information about the ways it has been used or disclosed in the year before your request. Email jerry@jai-lab.co and we will put it together for you. There are narrow cases where the PDPA does not require us to provide access; if one applies, we will tell you which and why.

Correction

If something we hold about you is wrong — your name, your age range, anything in your profile — you can change most of it directly in the app, and you can ask us to correct the rest at jerry@jai-lab.co. Note that we will not alter the content of a past journal entry to say something you did not write; the record of what you wrote stays as written. You are free to delete it.

Withdrawing consent

You can withdraw your consent to our collection, use or disclosure of your personal data at any time, by writing to jerry@jai-lab.co. We will act on it and stop the processing you have withdrawn consent for.

In plain terms, here is what that means in practice. Almost everything JAI does is processing your personal data. If you withdraw consent to us processing your entries, we can no longer generate replies, produce your morning brief, or build your dashboard and patterns — the app stops being able to function, and we would need to close your account. Narrower withdrawals are cleaner: you can turn notifications off in the app without affecting anything else, and you can decline or clear your optional profile answers.

Withdrawing consent does not make past processing unlawful, and it does not by itself delete your data — if you want the data gone as well, delete your account, which does both at once.

How to make a request

Email jerry@jai-lab.co from the address you signed up with, and tell us what you want. We may need to verify that the request really comes from you before we act on it. We aim to respond within 30 days. If we genuinely cannot meet that, we will tell you within 30 days when to expect our response.

If you are not satisfied with how we have handled your personal data, you may complain to Singapore's Personal Data Protection Commission (PDPC). We would ask you to raise it with us first so we have a chance to put it right.

9. Data Protection Officer

As the PDPA requires, we have designated a Data Protection Officer responsible for ensuring JAI Lab complies with the Act. You can reach the DPO here:

Data Protection Officer
JAI LAB LLP (UEN T26LL0791K)
32 Keppel Bay Drive
#04-62 Caribbean at Keppel Bay
098651
Singapore
jerry@jai-lab.co

The DPO handles access requests, correction requests, consent withdrawals, complaints, and any question about this policy, and aims to respond within 30 days.

10. Security

These are the specific measures we take:

  • Encryption in transit. Every connection between the app, our API, our database and the knowledge-graph server uses TLS.
  • Row-level security. It is enabled on every table in our database, so at the database layer itself no account can read another account's rows.
  • Per-user scoping. Every query the application makes — in Postgres and in the knowledge graph — is scoped by your user ID. In the knowledge graph this is enforced twice: queries are parameterised with your user ID, and an automated check rejects any query that is missing that scoping before it can run.
  • No password handling. Sign-in goes through Google or Apple. We never see, store or transmit a password.
  • Least access. Credentials are held as environment secrets, not in source code, and access to production systems is limited to the people who need it.

No online service can promise perfect security, and we are not going to pretend otherwise. What we can say is that we take these measures seriously, we keep them under review, and if a data breach ever occurs that is likely to result in significant harm to you, we will notify you and the PDPC as the PDPA requires.

11. Children

JAI is not directed to children. You must be at least 16 years old to use the app, as set out in our Terms of Service.

We do not knowingly collect personal data from anyone under the age of 13. We do not target the app at children, we do not build features for them, and we do not use age-based advertising or profiling of any kind. If we learn that we hold personal data belonging to a child under 13, we delete that data and the associated account promptly.

If you are a parent or guardian and you believe a child under 13 has given us personal data, email jerry@jai-lab.co and we will remove it.

12. Changes to this policy

We will update this page when our practices change — a new provider, a new kind of data, a change in where things are stored — and we will change the "last updated" date at the top. If a change materially affects how we use data you have already given us, we will tell you in the app or by email before it takes effect, so you have a real chance to object or to delete your account.

13. Contact

Privacy questions, access and correction requests, and anything about this policy: jerry@jai-lab.co. General support: support@jai-lab.co.

JAI LAB LLP
UEN T26LL0791K
32 Keppel Bay Drive
#04-62 Caribbean at Keppel Bay
098651
Singapore

JAI is a journaling companion for reflection and self-understanding. It is not a medical or mental-health service and is not a substitute for professional care. See our Terms of Service for the full position, including crisis contacts in Singapore.