Gladden — Privacy Policy
Last updated: 13 August 2026 (fourth revision)
Gladden is a private gratitude journal. This policy explains exactly what it collects, why each piece is needed, and what you can do about it.
The short version: Gladden collects what it needs to show your entries back to you on the right day, on whatever phone you're holding, and nothing else. There is no advertising, no tracking, and nothing is sold.
What measurement there is exists to find faults — crashes, a notification that never arrived, a photo that didn't upload — and nothing else. Not to study you, not to grow engagement, and not to build a picture of who you are.
One thing is sent to a company other than us: a crash report, if the app stops working. It says what broke and what kind of phone it broke on. It never contains anything you wrote. It is in the table below and described in full under "When the app crashes".
What Gladden stores, and why each thing is needed
| What | Why it's needed | Where it lives |
|---|---|---|
| Your email address | To sign you in, and to reach you if you forget your password | Our database |
| Your password | Stored only as a one-way hash — we cannot read it | Our database |
| The entries you write | They are the app | Our database |
| Photos you attach | Same | Our file storage — see below |
| Category, mood, and names you type | So you can search and filter your own entries | Our database |
| Your time zone | So a memory arrives in your evening, not somebody else's | Our database |
| A notification token | So your phone can be sent a memory. It identifies the app on your device, not you | Our database |
| Your streak and grace days | To show the streak | Our database |
| Which memories have been sent, and whether you opened them | So the same one isn't sent twice, and so we can tell whether memories are arriving | Our database |
| A crash report, only if the app crashes | So a fault that hits real phones can be found and fixed | Sentry — the only third party, see below |
| App version and OS version | So a bug report can be matched to a build | Sent with the notification token only |
That is the complete list. If something isn't on it, Gladden doesn't collect it.
What Gladden deliberately does not collect
- No behavioural analytics. No record of which screens you open, how often you write, how long you spend in the app, or what any of it might say about you. The crash reporter is capable of all of that and it is switched off — it is allowed to report failures and nothing else.
- No cross-app or cross-site tracking. Nothing follows you anywhere. Gladden has no idea what else is on your phone.
- No advertising identifiers, no ad networks, no trackers.
- No contacts. Contacts are read on your device in two places, and only if you allow it: when you choose someone to thank, and when Gladden suggests names as you type into "Is this about someone?". Both match against your address book on the phone itself. No contact data is ever uploaded — the only thing that leaves your device is the single name you choose, which is stored exactly as if you had typed it. Gladden never sends a message on your behalf.
- No biometric data. If you turn on the screen lock, your face or fingerprint is checked by the phone's own security hardware. Gladden is told only whether it matched. It never receives, stores or transmits anything about your face or fingerprint.
- No location data. Gladden never reads or records where you are, and the photos you attach have their location stripped before they leave your phone.
- No microphone, no camera access except when you take a photo for an entry.
What *is* measured, in full, because "minimal" is a word anyone can write:
- Crashes. What broke and what kind of phone it broke on. Never anything you wrote. Described in its own section below.
- Whether a resurfaced memory was opened. One true-or-false per memory we send you. It stops the same one being sent again, and it is the only way we can tell whether memories are arriving at all — a notification that silently fails looks identical, from our side, to one nobody felt like opening.
- Whether an email we sent was delivered or bounced, recorded against the *domain* it went to and never the address.
- How much of our own storage and database is in use, which is about our capacity and says nothing about any individual.
That is all of it. If it ever grows — and it may, as more people use Gladden — this list grows with it, and so does the table above. See Changes to this policy: anything that meaningfully expands what is collected gets told to you in the app, before it takes effect, rather than buried in a document you would have to think to re-read.
Where photos are kept
Photos are uploaded to our storage, on the same servers as the database. They have to be: it's how a photo you attached on your phone still appears when you sign in somewhere else, and how a memory can come back to you complete years later on a device you haven't bought yet.
They are not published. The storage is closed — there is no public address for your photos, and none can be reached by guessing. Each file sits in a folder belonging to your account, which the storage itself enforces, and the app fetches them using links that expire shortly after they're issued.
Photos are resized before upload, which also removes any location, camera, and timestamp data the original carried. That happens to every photo, always, and is not something you can turn off.
Who can see your entries
You can. Your account is the only one that can read your entries through the app. This is enforced by the database itself, not just by the app — every row is locked to the account that created it.
We can, technically. Being straight with you: your entries are encrypted in transit and encrypted at rest on disk, but they are not end-to-end encrypted. That means whoever operates Gladden's database has the technical ability to read them. We don't, we have no interest in doing so, and there is no process that does. But an honest policy says what is possible, not just what is intended.
And we don't test on you. Building the app, testing it, working out how it is behaving, and chasing down faults are all done against accounts we create ourselves, holding entries we wrote ourselves. Real people's journals are not used for any of it. When something does go wrong for someone, we work from the error itself and from technical facts about the account — whether a photo finished uploading, whether an entry reached the server — rather than by reading what they wrote. If a problem can only be understood by looking at a particular entry, we ask first.
Nobody else can. Your entries are never sold, shared, licensed, published, or used to train anything.
Companies involved in running Gladden
Gladden can't work without a few services. Each one gets the minimum it needs:
- Supabase — hosts the database, file storage, and sign-in. Your entries and photos live here, on servers in the United States (Oregon).
- Expo — delivers push notifications. Receives the notification token and the text of the memory being sent, because that text is what appears on your lock screen.
- Apple (APNs) and Google (FCM) — carry the notification the last step to your phone. Same content as above.
- An email provider — sends confirmation and password-reset emails. Receives your email address and nothing else.
- Have I Been Pwned — checks whether the password you're choosing already appears in a public data breach. It never receives your password. Your password is scrambled on your phone into a fingerprint, and only the first five characters of that fingerprint are sent. Hundreds of breached passwords share those five characters, so the service is answering "here is everything starting like this" without ever learning which one you asked about, or whether any of them matched. The comparison happens on your phone.
- Sentry — receives a report if the app crashes. See the next section for exactly what that contains, and what it is prevented from containing.
None of these are given your entries for any purpose of their own.
When the app crashes
If Gladden stops working, it sends a report so the fault can be found. This is the only thing in the app that sends anything to a company other than the ones above, and it happens only on a failure — never during ordinary use.
What the report contains:
- What went wrong, and where in the code it happened
- The kind of phone, its operating system version, and the version of Gladden
- Whether the app was in the foreground, and how long it had been running
What it cannot contain, and why you can rely on that:
- Nothing you have written. No entry text, no names you typed, no search terms.
- No photographs. The reporter is capable of attaching a picture of the screen at the moment of a crash, and of a description of everything on it. Both are switched off.
- Nothing identifying you. No email address, no name, no account number, no IP address.
- No record of ordinary use. Performance and usage tracking are available in the same tool and are set to zero. It reports failures or nothing at all.
These are set in the app's own code rather than left to the reporting service's defaults, so they do not change when that service changes its mind.
If you would rather send nothing at all, there is no way to crash-report selectively — but there is also nothing to switch off, because nothing is sent unless the app breaks. If that is not acceptable to you, we would rather you told us at support@gladden.app than uninstalled quietly.
How long it's kept
Until you delete it.
- Delete a single entry — removed from your device and our database, and its photo removed from storage.
- Delete all entries — Settings. Empties the journal, keeps the account.
- Delete your account — Settings. Removes your entries, photos, notification tokens, settings, and the account itself. This cannot be undone, and we keep no copy afterwards.
Backups of the database may hold deleted content for up to 30 days before rotating out.
Your rights
- See your data — it's in the app.
- Take it with you — Settings → Export entries produces a file you keep.
- Correct it — any entry can be edited.
- Delete it — as above.
If you're in the UK, EU, or a jurisdiction with similar law, you also have the right to object to processing and to lodge a complaint with your data protection authority. Write to us first and we'll try to sort it out.
Children
Gladden isn't intended for children under 13, and we don't knowingly collect anything from them. If you believe a child has created an account, contact us and we'll remove it.
Changes to this policy
If what Gladden collects ever changes, this policy changes with it, and the date at the top changes too. Anything that meaningfully expands collection will be told to you in the app before it takes effect — not buried in a document you'd have to check.
Contact
Gladden is operated by Gladden Apps, which is who "we" and "us" mean throughout this policy and who is responsible for the data described in it.
privacy@gladden.app