Privacy Policy
Last updated: September 6, 2026
Pensio is a journaling app. Your journal is private. This policy explains what data we collect, why, and what we do with it — in plain language.
Our privacy promise
- We do not train AI models on your data. Your entries are never used to improve or fine-tune any AI model — ours or third-party.
- We do not sell or share your data. No advertisers, no data brokers, no "partners." Your journal is yours.
- No human reads your entries. Your journal content is only accessed by automated systems to provide the service. No Pensio employee or contractor reads your entries unless you explicitly share them with us for support purposes.
- AI providers do not store your data. We route AI requests through OpenRouter with data retention disabled. Your text is processed in-memory and discarded after the response is generated.
- You can export or delete everything, anytime. No lock-in, no dark patterns.
What we collect
- Account info: Email address and display name (to create your account and personalize your experience).
- Journal entries: The text you write, including any metadata (dates, tags, entry type). Stored in our PostgreSQL database on a server we control.
- Relationships: Names you mention in entries using @mentions. These are names only — we don't collect contact information about other people.
- Emotions and themes: Extracted from your entries by our AI. Includes emotions (primary and secondary), intensity (1–10), emotional direction (positive/negative), life themes (e.g. relationships, career, health), triggers, and a brief summary. Stored as structured data alongside each entry.
- Explore conversations: Your chats with the Explore AI feature, including the questions you ask and the AI responses.
- User Memory: As you talk with Explore, Pensio may write down a few things you tell it — a name, a preference, a pattern, a thread you left open — so later conversations have context about you. These are stored in your account. You can view, correct, set aside, or permanently delete any of them on the Memory page.
- Insights: AI-generated weekly and monthly reports about your emotional patterns, recurring themes, and shifts over time. These are summaries derived from your entries, stored in your account.
- Photographs of handwritten pages: If you photograph paper journal pages, we store the photographs and send each one to an AI service that reads the handwriting into text — anything else visible in the frame goes with it. The photograph stays attached to the entry it becomes; nothing is saved to your journal until you review the reading and add it yourself.
- Sign-in records: Each time you sign in or out — including a sign-in attempt that fails — and each time you change your password, turn two-factor on or off, download your journal, connect or stop an app, change your email address or ask to delete your account, we write one line to your account's security log: what happened, when, the IP address the request came from, and how the browser or app described itself. It is your record before it is ours: you can read the whole log in Settings under Security, which is where you would go to find out whether a sign-in was you.
- Devices you are signed in on: For each device that currently holds a session we keep the IP address it was last used from, how the browser or app described itself, and when it was last active, so that the list in Settings can show you what is signed in and let you sign it out.
- Requests to our API: Beside the website, Pensio has an interface that apps talk to — the Obsidian plugin, the mobile apps, and any assistant you have connected. Every request through it writes one line to a log: which address inside Pensio was asked for, which can name the entry being fetched, what kind of request it was, whether it succeeded, how long it took, and the identifier the app gave for the device it runs on. There is no IP address in it and nothing you wrote. We keep it for 90 days, so we can see the service working and notice an app being misused.
- How you found us: When you create an account we write down four short facts about how you arrived, and we ask you nothing to get them. First, a two-letter country code — "PT", "BR", "MX" — worked out by Cloudflare, the network that sits in front of Pensio, from the connection your sign-up came over: it reaches us already reduced to those two letters, and no address is kept as part of this record. Read that narrowly, because it is a sentence about this record and not about Pensio as a whole: creating an account also signs you in, and signing in writes the address the request came from to your security log and to your list of signed-in devices — both described above, and both kept for as long as your account exists. Second, how you reached the sign-up page: through search, through an AI assistant, from a social post, from a link on another site, from a tagged campaign link, or by going straight there. Third, if you arrived at the sign-up page from another Pensio page, which one of ours it was. Fourth, if you came to us through a link we tagged ourselves, which of our links it was: a short word such as "google_ads" or "reddit_ads" that we wrote into our own advertisement. It says which advertisement you clicked, it is a word about us and not about you, and it means nothing to anybody outside Pensio. We do not keep the click identifier that an advertising network adds to its own links, because that one can be matched back to a profile the network holds about you. That is all of it. It is not your address, not your city, not your coordinates, and never the address of a page on somebody else's site. It is also deliberately coarser than the exact spot a camera writes into a photograph, which is why we strip that out of every photo and keep this: a country can tell us a language may be worth translating into, while a coordinate tells us where you were standing. We write these four once, on the day you sign up, and never change them — they describe how you arrived, not where you are now. They exist for two decisions. One is which language to translate Pensio into next: Pensio is in English, Brazilian Portuguese and Spanish, and we read these facts only as totals on an internal screen, to see where the demand for the next one is. The other is whether an advertisement we paid for brought anybody, which is why the fourth fact was added in September 2026, when we started running small paid tests: without the name of the link, every campaign looks like every other campaign to us. No part of Pensio looks up yours on its own, none of it is used to target you or to decide anything about you, and none of it follows you to another site. All four are in your data export, and they are deleted with your account.
What we don't collect
- We don't sell your data. Ever.
- We don't show ads.
- We don't share your journal content with third parties (except the AI providers listed below — and they don't keep it).
- We don't track you across the web.
- We don't build advertising profiles or sell behavioral data.
We may disclose your data if required by law (e.g. a valid court order), but we will only do so when legally obligated and will notify you if permitted.
How we use AI
Pensio uses large language models (LLMs) for two features:
- Emotion extraction: Your entry text is sent to an LLM to identify emotions. The extracted emotions are stored; the LLM does not retain your text.
- Explore chat: When you ask a question in Explore, only the journal entries relevant to your question are sent as context to the LLM — not your entire journal. We send the minimum necessary to generate a useful response.
- User Memory: Pensio stores facts from your Explore conversations (like names and preferences) so future sessions have context. This is stored in your account on our server, not on AI provider servers. You control it entirely — view, correct, set aside, or delete any memory on the Memory page.
How this compares to using AI chatbots directly: When you use ChatGPT, Claude, or Gemini through their own apps, your conversations may be used to improve their models unless you opt out. With Pensio, your journal content is never used for AI training, profiling, or marketing — by us or by the AI providers. Your text is processed in-memory and discarded immediately. The only data that persists is what Pensio stores in your account, which you own and can delete at any time.
Connecting external AI assistants (MCP)
If you are on Pensio Pro, you can optionally connect an external AI assistant — such as Claude, ChatGPT, Claude Desktop, or Cursor — to Pensio through the Model Context Protocol (MCP). This is off by default and only happens if you create a connection from Settings → Connected apps.
- Read-only: A connected assistant can read and search your journal. It cannot create, edit, or delete entries — this is enforced on our servers, not just by the assistant.
- Where your words go: When you ask a connected assistant about your journal, the relevant entries are sent to that tool's own AI model to form the answer. That model runs under the assistant vendor's terms and privacy policy — not Pensio's zero-retention OpenRouter configuration. We cannot control how a third-party AI tool you choose handles that content, so review your assistant's privacy terms before connecting.
- A fully private option: If you self-host Pensio and connect a local AI model (such as Ollama), your entries never leave your own machine — zero third-party egress.
- You stay in control: Each connection is a revocable, device-specific token. Revoke it anytime from Settings → Connected apps and the assistant immediately loses access.
Open Questions, and what it reads
Explore answers when you ask it something. Open Questions works the other way round: it looks across your entries for something worth pointing out, without being asked. It does that when you open its page — the analysis runs while the page loads — and once a day on our own server, so we can leave you a note in the app when the page has something on it you have not seen. It is in testing with a small number of accounts, and this section describes exactly what that involves.
- The daily check reads no more than the page does. It runs the same arithmetic, on the same derived data, and calls no AI model. It writes nothing about what it found: the note in the app says only that there is something on the page, never what it is, and nothing about it is ever emailed to you.
- It reads derived data, and the names you gave things. It uses what the app already extracted from your entries — the emotion, the themes, the dates, and who you mentioned — plus the title you gave an entry, so a card can say which one it means. The body of what you wrote is not read.
- No AI model is called. The analysis is plain arithmetic on our own server. Nothing about your journal is sent anywhere for it.
- What we keep is deliberately thin. Each time the page decides something, and each time you press one of its buttons, we store a short record of it: which of our own sentence templates was used, a couple of counts, and whether you muted it, marked a thread settled, or followed a link. Where a record is about a person or an entry it holds a one-way scrambled stand-in — it cannot be turned back into the name or the entry, and the same entry scrambles differently on every account. What stays readable is numbers and our own labels. That record is also what stops the page offering you the same thing twice.
- This is us building the feature. We look at those records to find out whether Pensio notices anything worth saying. That is internal research, and we would rather say so here than describe it as something else.
- Off means it does not look. You can turn it off in Settings → What it reads. When it is off, your entries are not analysed at all — nothing about your journal is examined or recorded, rather than examined and kept quiet. The daily check is part of that: an account with this switched off is skipped before anything is read.
What AI does not do
- AI providers do not remember you — there is no persistent profile of you on any AI provider's servers. Pensio's User Memory feature stores facts you share in conversations, but this data lives in your account under your control, not on AI provider infrastructure. You can delete it anytime.
- Your data is never mixed with other users' data when processed by AI. Each request contains only your content, isolated from all other users.
- We never send the words you wrote to an analytics tool, and nobody here reads your entries to do research.
- AI providers do not build behavioral profiles based on your entries.
- AI models are not personalized or adapted based on your data. Every user's request is processed by the same general-purpose model.
AI providers and data handling
All AI requests are routed through OpenRouter, an API gateway. OpenRouter forwards your request to the AI model and returns the response. We have configured OpenRouter with the no data retention flag via their API — your text is processed in-memory and not stored, logged, or used for training by OpenRouter or the downstream model providers. This means your data exists only for the duration of the request and is not written to disk by AI providers. Requests are not logged, cached, or stored at any layer.
The AI models we currently use:
- Claude by Anthropic — primary model for Explore chat and emotion extraction.
- Gemini by Google — used as an alternative model for some features.
Both Anthropic and Google, when accessed via OpenRouter's zero-retention API, do not store or train on the data sent through these requests. If we change AI providers in the future, we will update this page and maintain the same zero-retention configuration.
Voice recordings
If you speak an entry instead of typing it, the recording is sent to the same zero-retention transcription service to be written down, and is discarded there once the words come back. The written words are stored in your journal like any other entry.
A recording captures whoever is audible, not only you. If someone else is in the room, their voice is on it, and it is sent for transcription along with yours — so please consider the people around you before you record.
Nothing is ever worked out from the sound of your voice. The recording becomes text first, and from then on only the text is read — the same way an entry you typed is read. Your tone, your pace and how you sounded are not measured, not stored as a signal, and not used to decide anything.
You choose: delete it as soon as it has been written down, keep it for a while, or keep it indefinitely. What you said stays in your journal either way, on every plan and for as long as your account exists — the choice is only about the audio.
Your choice applies to recordings you make from now on. Recordings you have already made keep the terms they were made under. You can change this, or delete every recording you still hold, in Settings under Data.
Location data is removed from every photo.
Analytics
We use two analytics tools, separated by purpose:
- Google Analytics 4 — on our public marketing pages only (landing page, blog). Tracks page views and traffic sources. IP addresses are anonymized. Not used on any authenticated pages. Loaded only after cookie consent is given.
- PostHog — on the app (authenticated pages). Records which pages you open and which features you use, against your account ID (a UUID, not your name or email). It also records when an email we sent you is opened or a link in it is clicked, and which of our own pages that link led to — by its internal name, never the address itself, so the one-time sign-in links some of our emails carry are not part of it. Beside those events it keeps a short profile of the account, refreshed each time you sign in: your plan, how many entries you have written, whether you have connected the Obsidian plugin, whether you have a paid subscription, and whether the account is on our live site or on one of our test ones. Page addresses are cut back before they are sent: the query string and anything after a "#" are dropped, and any identifier sitting in the address itself — an entry ID, or the one-time link from an email we sent you — is replaced with a placeholder. No location is worked out from your IP address, and none is stored against you; PostHog's servers do see the connection your browser makes to them, as they would for any analytics script anywhere. Your browser also reports its time zone, language, window size, browser and operating system, as it does by default. Nothing you wrote is sent. Autocapture and session recording are disabled — we only track specific events we've defined. Hosted in the EU.
Deleting your account removes everything above from our own database, and we ask PostHog to erase what it holds as well: the profile, the properties recorded on it, and every usage event stored against your account ID. That request goes out at the moment your account is destroyed — not when you ask for it, so if you change your mind inside the 72 hours nothing has been erased anywhere. PostHog removes the profile promptly and sweeps the event rows in a later batch, so for a short while afterwards those events are queued for erasure rather than already gone.
We also record how people reach the sign-up page, so we know whether they find us through search, a link, or a recommendation. When you open that page we note the website you came from (the domain only, such as "google.com", never the full address and never what you searched for) and any campaign tags in the link. If you arrive through a link we tagged ourselves, usually an advertisement, we take that note on the page the link brought you to instead, because by the time you reach the sign-up page the tags are no longer there and we would only see that you came from Pensio. If you came from another Pensio page, we note which one. If you do not create an account, that note stays on our own server for the length of your visit and is then discarded. If you do create one, it is copied onto your account — together with the country described under "What we collect" above — and kept for as long as the account exists: it is part of the account details in your export, and it is deleted when you delete your account. It is also attached to the sign-up event we send to PostHog, the analytics tool described above: the channel, the website you came from, any campaign tags, and, if it was one of our own pages, which one. Nothing you wrote is in it, and it is keyed to your account ID like every other event there — which makes it one of the events that stay with PostHog after the account is gone. We do not use advertising identifiers, we do not follow you to other websites, and we never build a profile about you.
Crash and error reporting
To keep Pensio stable we collect technical diagnostics when something goes wrong — never your journal content:
- Sentry — server-side error reports for the web app. No personal data is attached (PII sending is disabled). Processed in the EU.
- Firebase Crashlytics — crash diagnostics from the Android app (stack trace, device model, OS and app version). No journal content and no email or name are sent, and advertising-ID collection is disabled. The iOS app currently includes no crash reporting.
Cookies
The Pensio app uses only essential cookies:
- Session cookie — keeps you logged in. It ends when you close the browser or after four hours, or after 14 days if you ticked Remember me.
- CSRF token — prevents cross-site request forgery (a security measure).
- Session cookie on a campaign page — if you arrive on one of our pages through a link we tagged ourselves, usually an advertisement, we set that same session cookie there, so that we can still remember how you arrived if you go on to sign up. It holds a random key and nothing else: the note itself stays on our server, and it is thrown away with the session if you do not create an account. Reaching any other page of ours sets no such cookie, and reading Pensio without signing up sets none either.
Marketing pages may set a Google Analytics cookie if you accept analytics cookies via the consent banner. No tracking cookies are used inside the app. Essential cookies do not require consent under EU ePrivacy rules. We want to name one exception rather than file it quietly under that sentence: the campaign cookie above is set for our benefit, not yours. It is first-party, it carries no identifier that follows you anywhere, and it exists only so that a sign-up can be matched to the link that brought it, but it is measurement, so we would rather tell you it is there than let it hide behind the word essential.
Security
- Encryption in transit: All connections use TLS (HTTPS). We enforce HSTS.
- Encryption at rest: Our server disk uses LUKS full-disk encryption.
- Passwords: Hashed using Argon2id, a memory-hard algorithm resistant to brute-force attacks. We never store plain-text passwords.
- Two-factor authentication: Available via TOTP (authenticator app). Recommended for all accounts.
- Backups: Daily automated database backups, encrypted, retained for 7 days.
Like any online service, Pensio is not immune to security risks. We minimize risk by limiting data exposure, encrypting all stored data at the disk level, and ensuring AI providers do not retain your content. We regularly review our security practices and update them as needed.
Email communications
We send the following types of email:
- Transactional: Password resets, email verification, account security alerts. These are required for the service to work — you cannot opt out.
- Product emails: Weekly insights, streak milestones, inactivity nudges. You can disable any of these individually in Settings → Notifications.
- Newsletter: Product updates and journaling tips. Requires separate opt-in (double opt-in). Unsubscribe in one click from any newsletter email.
Every product email ends with a link to your notification settings, where each kind is switched off separately. Pensio sends at most three product emails a week, and most weeks none. We use Brevo to send emails (see Sub-processors below).
Your rights
You own your data. Under GDPR and regardless of where you live, you can:
- Access: All your data is visible in the app, and the download below is the machine-readable copy of it. If you would rather ask us, write to us and we will send it.
- Export (portability): Download the lot from Settings → Export, as one ZIP: every entry and draft as a Markdown file, the people you have named, your weekly and monthly insights, your photos and voice recordings, and a file of your account details — your name, your email address, the date you signed up, your language, your display preferences, your plan and the choices you have made about your own data. It holds nothing about anybody else's Pensio account — the people you have named are in it as the notes you wrote about them, never as records of theirs.
- Rectification: Edit your entries and profile information at any time.
- Erasure: Delete your account from Settings. This permanently removes all your data — entries, relationships, insights, Explore conversations, your account details, and your sign-in and security history with the IP addresses in it. Deletion is completed within 30 days and is irreversible. Because we prioritize privacy, we cannot recover deleted data — there is no hidden backup or shadow storage we could restore you from. What stays behind is bookkeeping, and none of it is anything you wrote. We keep what running Pensio for you cost: a date, a price, which feature asked and which model answered, and a reference to the entry or conversation it was for that by then points at something no longer there. Your account comes off that record, and the record stays, because money that was really spent cannot be un-spent and a service that cannot say what it paid cannot be run honestly. We keep the request log described near the top of this page: your account is detached from it and the device identifier is wiped as the account goes, so what remains is a list of times, addresses and response codes, and it ages out within 90 days. And the usage events held by our analytics provider outlive the account as well, which the Analytics section above describes rather than leaving you to infer.
- Restrict processing: Some of what Pensio does with your entries can be switched off in Settings: Open Questions, where that feature is available to you, and anything Explore has remembered, which you can set aside or delete on the Memory page. Emotion extraction is not one of them — reading emotions and themes out of an entry is how the app shows you your own patterns, so it runs on everything you publish here. Deleting an entry deletes what was read from it, because the emotions and themes are stored on the entry itself. If you want processing restricted beyond what those controls reach, write to us at [email protected] and we will arrange it with you.
- Object: You can object to any processing by contacting us at [email protected].
- Memory control: View, correct, set aside, or permanently delete any fact the AI has remembered about you on the Memory page. A memory you set aside is excluded from AI conversations but kept in your account until you delete it.
Data retention
- While your account is active: Your data is stored for as long as you have an account. We do not delete entries unless you do.
- After account deletion: All your data (entries, emotions, relationships, insights, Explore conversations) is permanently deleted from our database within 30 days. Automated backups containing your data expire within 7 days after that.
- AI providers: Do not retain your data at all — processing is in-memory only.
- Sign-in records and the device list: Kept for as long as your account exists. We do not delete them on a timer: a security log that forgets cannot answer the question it is there for. The device list is tidied rather than expired — a device whose session has already ended drops off the next time you open that page or sign devices out, not at the moment the session ends, so an entry can outlive the session it describes. Deleting your account erases both, IP addresses and all. One line survives it: a note that an account was deleted and how many entries it held, with nothing attached that says whose it was.
- Photos and recordings you delete: Removed from your account immediately, and kept in isolated storage for up to 30 days before being permanently erased. This exists so that a fault on our side cannot destroy your media beyond recovery — it is not accessible to you or to anyone else in the meantime. Deleting your account, or deleting a recording through the voice settings, erases the files straight away with no 30-day window.
Sub-processors
These are the third-party services that may process your data as part of providing Pensio:
| Service | Purpose | Data access |
|---|---|---|
| OpenRouter | AI API gateway | Entry text, voice recordings on their way to transcription, and photographs of handwritten pages on their way to being read (all in-memory only, zero retention) |
| Anthropic (Claude) | AI model provider | Entry text (in-memory only, via OpenRouter zero-retention API) |
| Google (Gemini) | AI model provider | Entry text, voice recordings sent for transcription, and photographs of handwritten pages sent for reading (all in-memory only, via OpenRouter zero-retention API; nothing is kept by the provider) |
| Hostinger | Server hosting | All data (stored on encrypted disk) |
| Cloudflare | CDN, DDoS protection, and media storage (R2) | Photos, voice recordings and photographs of handwritten pages you add, stored at rest in Cloudflare R2 (EU jurisdiction, AES-256 encrypted). Other traffic passes through and is not stored. It also works out which country a connection comes from and hands us that as a two-letter code, which we record once when an account is created. We chose it over adding another company to this list precisely because Cloudflare already sits in front of every request. |
| PostHog | Product analytics | Usage events keyed to your account ID — which pages you open and which features you use, with query strings and identifiers stripped out of the addresses — plus a short profile of the account: your plan, how many entries you have, whether the plugin is connected, whether there is a paid subscription. No journal content, no name or email, no location. |
| Brevo | Email delivery | Email address, display name, language preference (for transactional and product emails) |
| Sentry | Error tracking | Technical error reports (may include anonymized request metadata, never journal content). PII sending is disabled. |
| Google (Firebase Crashlytics) | Crash reporting (Android app) | Crash diagnostics from the Android app — stack trace, device model, OS and app version. No journal content, no email or name. Advertising ID collection is disabled. |
| Google Analytics 4 | Marketing analytics | Anonymized page views on marketing pages only (not inside the app). Loaded only after cookie consent. |
Data location
Your data is stored on a dedicated server in Europe (EU), provided by Hostinger. Photos, voice recordings and photographs of handwritten pages you add are stored in Cloudflare R2 under the EU jurisdiction. Cloudflare also handles CDN and DDoS protection for other traffic, which passes through their network without being stored. PostHog analytics data is processed in the EU. Brevo is an EU-based email provider. Error reports (Sentry) are processed in the EU. Crash diagnostics from the Android app are processed by Google (Firebase Crashlytics), which may store them outside the EU under Standard Contractual Clauses. No personal data is transferred outside the EU/EEA except through providers with adequate safeguards (Standard Contractual Clauses or EU adequacy decisions).
Children's privacy
Pensio is not intended for anyone under 16 years of age. We do not knowingly collect personal data from children. If we learn that a user under 16 has created an account, we will delete their account and all associated data promptly. If you believe a child under 16 is using Pensio, please contact us at [email protected].
Data breach notification
In the unlikely event of a data breach that affects your personal data, we will notify you via email within 72 hours of becoming aware of it, as required by GDPR. We will also notify the relevant supervisory authority. The notification will describe the nature of the breach, the data affected, and the steps we are taking to address it.
Legal basis for processing
Under GDPR, we process your data based on:
- Contract: Processing your journal entries, generating insights, and providing the service you signed up for.
- Legitimate interest: Error tracking, service security, and product analytics — including the three facts about how you arrived described under "What we collect". Those are kept on your account rather than anonymously, so we say so here rather than filing them under a word that would not fit: we read them only as totals, and only to decide which language to translate Pensio into next. You can object to anything we do on this basis at any time — see Your rights above.
- Consent: Marketing emails, newsletter, and analytics cookies on marketing pages.
You can withdraw consent at any time without affecting the lawfulness of processing before withdrawal.
Changes to this policy
If we make meaningful changes, we'll notify you via email or an in-app notification before the changes take effect. Minor wording updates won't trigger a notice. Previous versions of this policy are available upon request.
Contact and complaints
Questions about your privacy? Email us at [email protected].
If you believe we are processing your data unlawfully, you have the right to lodge a complaint with a data protection supervisory authority in your country of residence.