EFFECTIVE AUGUST 7, 2026
Privacy Policy
Inner Threads is designed as a private personal-growth journal. This policy explains what the app collects, why, and what control you have.
Information we collect
When you sign in, the hosting platform provides your ChatGPT account email and may provide your name. Inner Threads converts the normalized email into a one-way identifier for separating records; the journal database does not store your raw email or name. The service stores encrypted entry content, entry type, timestamps, and the encrypted key envelopes needed for password and recovery-key unlocking.
Client-side entry encryption
Journal titles, text, optional moods, dreams, reflections, saved Thread reports, Landscapes, and optional dream analyses are encrypted in your browser before storage using authenticated encryption. The service stores ciphertext rather than readable content. Your privacy password and recovery key are not sent to or stored by Inner Threads. Encryption substantially limits readable infrastructure access, but no software can promise absolute security.
Password and recovery responsibility
Inner Threads cannot retrieve your privacy password or recovery key. If you lose both, and no device has the journal unlocked, existing encrypted entries cannot be recovered. A password manager and a secure offline copy of the recovery key are strongly recommended. ChatGPT account recovery does not recover an Inner Threads privacy password.
On-device signals and optional AI reflections
After decryption, your browser can create early language signals and guided dream-reflection lenses on your device. Grounded Threads, Landscape, and deeper AI-assisted dream exploration are optional. They run only when you actively request them and consent to temporarily sending the relevant readable content to OpenAI through the Inner Threads server. Raw dreams are excluded from Grounded Threads and are sent for deeper dream exploration only when you choose that action on a saved dream. Saved Landscapes, previous Thread reports, and dream analyses are not reused as source entries. OpenAI states that API data is not used to train its models. Completed Thread reports, Landscapes, and dream analyses are encrypted in your browser before they are saved. Inner Threads does not intentionally retain a readable journal or generated-reflection copy, though OpenAI may retain standard abuse-monitoring logs for up to 30 days under its API data controls.
Voice transcription
Voice-to-text uses speech-recognition capabilities offered by your browser or device. Availability and processing practices may depend on that browser, operating system, and its provider. Inner Threads does not intentionally store an audio recording. The resulting text is encrypted before it is saved to Inner Threads.
Paper journal import is optional. When you choose to convert photographed pages, those images are temporarily sent to OpenAI for transcription after your explicit consent. Inner Threads does not save the page photographs. The transcription remains editable and is encrypted only if you choose to save it as a journal entry.
Artwork attachments are different from paper transcription. When you deliberately attach artwork to a journal or dream entry, the image is resized and encrypted on your device before it is stored. Inner Threads stores only the encrypted image data and basic technical metadata needed to connect it to your entry. Artwork is not sent to OpenAI unless you separately choose a feature that clearly asks for that permission. Deleting the entry or deleting your Inner Threads data also deletes its stored artwork.
Metadata
Entry type, including whether a record is a journal, dream, reflection, Thread report, Landscape, or dream analysis, and timestamps remain readable to the service so records can be stored and returned in order. Network, security, and operational systems may also process technical metadata such as request timing and device or connection information.
Service providers and legal disclosure
The app relies on OpenAI/ChatGPT sign-in and OpenAI Sites hosting, including platform-managed storage infrastructure. Those providers process information needed to operate the service under their own applicable terms. Stored entry content is designed to be unreadable without the user-held key, but metadata or ciphertext may be disclosed when legally required or needed to protect the service.
Security and retention
Server access controls separate records by signed-in identity in addition to client-side encryption. Active encrypted entries remain available until you delete them individually or use Delete all Inner Threads data.
Deletion and provider retention
Deleting all Inner Threads data removes active encrypted entries and the encrypted key profile tied to your identifier. Service providers may retain limited backups, security records, or operational logs under their own retention rules. Deleting Inner Threads data does not delete your separate ChatGPT account.
Children and HIPAA
Inner Threads is intended only for people age 18 or older. It is a consumer wellness tool, not a service offered by or on behalf of a healthcare provider or health plan. Do not assume it is a HIPAA-regulated record system.
Changes
This policy may change as the service evolves. Material changes will be reflected by an updated effective date and, when appropriate, an in-app notice.
Contact
For privacy questions, data requests, or help using these controls, email info@innerthreads.app.