Privacy policy
Effective 9 June 2026
woop.day is a private journal. Your entries are yours — we don't sell them, share them, or use them to train AI models.
What we collect
- Account & sign-in. When you sign in with Google, Apple, or an email magic link, our authentication provider (Google Firebase) gives us your email address and a unique account ID. Your provider may also share a name or photo at sign-in, but we don't store them.
- Your journal. The WOOP entries, notes, check-ins, coach conversations, and bookmarks you write are stored privately and scoped to your account.
- Handwriting photos. If you use the handwriting reader, the photo you upload is stored with owner-only access and processed by optical character recognition to extract the text.
- Preferences. Settings like belief-tradition preferences and notification choices. Optional belief-memory content is encrypted at rest.
- Your AI key. If you add a language-model API key, we encrypt it at rest and use it for the app's model calls on your behalf — the coach and reviews you ask for, plus the smaller calls the app makes as you write: titling an untitled entry, spotting names when name masking is on, and the weekly pattern scan of your recent entries. If you haven't added one, those run on the house key we provide instead — see below for what that means. If you haven't added one, those requests run on the house key we provide instead — see below for what that means.
- Your phone number. Only if you turn texting on, which you do by verifying the number. Stored with your account so the coach can text you and match your replies to you. Removing the number in Texts settings deletes it; how texts travel and how to stop them is under Twilio below.
- Diagnostics. Crash and performance data (via Sentry) and lightweight in-app usage events (counts and metadata — never your journal content) so we can keep the app healthy.
- Notifications. If you opt in to reminders, a device push token.
Where your data lives & who processes it
We use a small set of service providers to run woop.day. Each processes data only to deliver the service:
- MongoDB Atlas — database for your journal and account data.
- Google Firebase — authentication, photo storage (handwriting pages, Core Sample scans and backups), and push notifications.
- Anthropic (Claude) — handwriting text recognition.
- The AI provider — coach and review requests are sent to a language-model provider. If you configured your own key, that means the provider you chose, under your own account and that provider's terms. If you haven't, the request goes to Anthropic on the house key, held under our account and bounded by a per-user daily cap. Either way the text of the request includes the entry or message you are asking about. You can add your own key, or avoid the coach and review entirely, at any time.
- Voyage AI — journal memory search. So the coach can recall related past entries, entry and note text is converted to numeric vectors (embeddings) on our key. The message you send the coach is turned into a search vector for that one lookup and not stored. Used only to compute that vector; Voyage's handling is governed by their API terms.
- Twilio — text messages. If you turn texting on by verifying a phone number, the body of every message in both directions passes through Twilio to reach your carrier, as it must for a text to be delivered. Your phone number is stored with your account so the coach can reply to the right person. Turning texting off — any kind in Texts settings, or replying STOP — stops the sends; you can remove the number entirely from Texts in settings.
- Supabase — the Core Sample. If you answer those questions, the answers live in a SECOND database, separate from your journal, and our servers hold no key that can read that database — your browser connects to it with your own credentials. When you run the safety screen, the coach, a scan, or the reading, your browser sends that text through our server to Anthropic on a key we fund; nothing is kept on the server. It has its own delete control at Core Sample → Your data, which is also why deleting your woop.day account does not reach it.
- Sentry — error and performance monitoring.
- Vercel — hosting.
How we use it
To provide the journal and coach, save your work, run the analysis you ask for, send notifications you opt in to, and keep the service secure and reliable. We do not sell your data, show you ads, or use your journal content to train our own models.
Your controls
- Edit or delete any entry. Deleted entries sit in trash for 15 minutes, then are permanently removed.
- Export your data from Settings.
- Lock the app behind a privacy lock and passkey.
- Opt out of belief content and notifications at any time.
- Delete your account from Settings → Account. It is disabled at once; you have 7 days to sign back in and cancel. After that everything under it is permanently removed — entries, notes, check-ins, coach history, memory, keys and handwriting images — and backups age out after that. Published templates and reviews stay up with your name removed.
- Nothing you write expires on its own. The one other exception: a chat you archive is removed after 28 days.
- For an access or correction request the app cannot cover, contact support.
Security
Your journal entries, notes, coach conversations, check-ins and saved highlights are encrypted before they are stored, each with a key derived per account. Someone who obtained a copy of our database could not read them. Your AI provider key is encrypted the same way, under a separate secret.
Four things that encryption does not cover, stated plainly because you would reasonably assume otherwise:
- The coach reads your words. When you ask the coach something, that entry goes to the model provider as ordinary text. A model cannot respond to what it cannot read. Nothing about storage changes that.
- A trace of meaning stays readable. So the coach can recall related past entries, we store a numeric fingerprint of each one alongside the encrypted text. The search that finds related entries only works on unencrypted numbers, so those stay readable — and with effort they could reveal roughly what an entry was about, though not what it said.
- Titles and tags stay readable. The journal sorts and filters on them, so they are stored as plain text. That includes the short title the app writes for an untitled entry — a one-line summary of what you wrote.
- Photos of handwritten pages stay readable. If you photograph a page, the text we read off it is encrypted — the photo itself is stored with owner-only access, but not encrypted with your key.
We hold the keys, which means we can decrypt your journal — to run the coach, the nightly check-ins and search on your behalf. Everything is encrypted in transit (HTTPS). No method is perfectly secure, but we would rather tell you exactly where the edges are than imply there are none.
Children
woop.day is for adults. You must be at least 18 to use it, and we do not knowingly collect data from anyone younger.
Changes
If we change this policy we'll update the effective date above. Material changes will be reflected here before they take effect.
Contact
Questions about your privacy? Reach us through support.