Aven Projects

presents

chapture

← chapture

chapture

Privacy Policy

Effective Date: June 2026Last Updated: July 2026

TermsPrivacySecurityDocs

Contents

  1. Introduction
  2. Who We Are
  3. Information We Collect
  4. Why We Process It
  5. How We Use Your Data
  6. Encryption & What We Cannot See
  7. How & Where We Store Data
  8. Service Providers
  9. Sharing & Disclosure
  10. International Transfers
  11. Data Retention
  12. Your Rights
  13. Exercising Your Rights
  14. Cookies & Local Storage
  15. Analytics & Insights
  16. Children's Privacy
  17. Security
  18. Changes
  19. Contact
Privacy

Privacy Policy

Your privacy is the point of chapture. This Privacy Policy explains what information we collect, why we collect it, how we store and protect it, who (if anyone) it is shared with, and the choices and rights you have. It applies to the chapture web application and its desktop and mobile builds. By using the Service, you agree to the practices described here.

The short version: your diaries, notes, and files are yours. We do not sell your data, we do not show ads, and we do not use your personal content for advertising or to train machine-learning models. Content is private by default and only leaves your account when you explicitly choose to share it.

1. Who We Are

chapture ("we", "us") is an independent product operated by Aven Projects. For the personal data we process about you, we act as the data controller. You can reach us at lifearchive.aven@gmail.com for any privacy question or request.

2. Information We Collect

We collect only what is needed to run the Service for you.

Account information. Your email address and a securely hashed version of your password. If you sign in through a provider (Google, Apple, or phone), we receive a basic identifier and, where applicable, your email from that provider; provider accounts do not have a password with us. You may optionally add a display name or chapture ID and a profile photo.

Guest accounts. If you continue as a guest, we create a lightweight account tied to your device without an email address. It is not linked to your identity and cannot be recovered across devices.

Your content. The diaries, notes, decisions, tags, moods, categories, and dates you create. This content can include highly sensitive personal information — that is what a journal is for — and you decide what to write.

Files & media. Photographs, images, and voice recordings you attach. These are uploaded to cloud object storage and served back only to you (or to the specific people you choose to share with).

Calendar connection data. If you connect Google or Outlook calendar sync, we store OAuth access and refresh tokens so we can read your calendar events on your behalf. These tokens are encrypted at rest. We request read-only calendar access and do not modify your external calendar.

Technical & log data. Basic technical information such as IP address, browser and device type, and request logs, used to operate the Service, keep it secure, and diagnose problems. This is retained for a limited period and is not used to build advertising profiles.

Communications. If you email us, we keep that correspondence to respond and for our records.

3. Why We Process It (Legal Bases)

Where data-protection law such as the GDPR applies, we rely on the following legal bases:

  • Performance of a contract — to create your account and provide the core Service (storing and returning your content, authenticating you).
  • Consent — for optional features you switch on, such as calendar sync, email confirmation, or making a diary public. You can withdraw consent at any time by turning the feature off.
  • Legitimate interests — to keep the Service secure, prevent abuse, and maintain reliability, balanced against your rights.
  • Legal obligation — to comply with applicable law when required.

4. How We Use Your Data

We use the information we collect solely to:

  • Create and manage your account and authenticate you when you sign in;
  • Store, retrieve, and display your content back to you across your devices;
  • Provide features you use — calendar sync, streaks, badges, analytics, search, and sharing;
  • Send account and security communications such as email confirmation or password resets;
  • Maintain, secure, and improve the reliability and performance of the Service;
  • Investigate and respond to security incidents or violations of our Terms.

We do not sell, rent, or share your personal information or content with third parties for marketing or advertising, and we do not use your personal content to train machine-learning models.

5. Encryption & What We Cannot See

All traffic between your device and the Service is encrypted in transit (HTTPS/TLS), and stored files and sensitive tokens are encrypted at rest.

chapture also offers optional zero-knowledge, per-diary encryption. When you enable it for a diary, that diary is encrypted on your device with a key derived from a passphrase only you know, before it is sent to us. We store only the encrypted envelope and cannot read the contents, reset the passphrase, or recover the diary if you lose your passphrase and recovery code. Tags, dates, and attachments on an encrypted diary are not part of the encrypted body. See the Security page for the full model.

6. How & Where We Store Data

Your account credentials and content metadata — and the text of your unencrypted entries — are stored in a managed PostgreSQL database. Files and media (photos and voice recordings) are stored in Cloudflare R2 object storage and served through an owner-only access proxy. Passwords are processed with a one-way cryptographic hashing algorithm before storage and are never recoverable or viewable by anyone, including chapture staff.

The desktop and mobile builds can additionally keep a local copy of your data on your own device so the app works offline; that local copy lives only on your device.

7. Service Providers

We rely on a small set of providers, each engaged only to operate the Service and not permitted to use your data for their own purposes:

  • Cloud hosting provider — runs the web application.
  • Cloudflare R2 — object storage for your files and media. Governed by Cloudflare's Privacy Policy.
  • Managed PostgreSQL — database for account data and content metadata.
  • Email delivery provider — sends transactional email such as confirmation and password-reset links, only if email features are enabled.
  • Sign-in providers (Google, Apple) and, for phone sign-in, an SMS provider — only if you choose those sign-in methods.
  • Google Calendar / Microsoft Graph — only if you connect calendar sync, and only to read your events.
  • GIF search provider — only if live GIF search is enabled and you search for a GIF in chat; your search term is sent to that provider.

We take reasonable steps to ensure these providers maintain appropriate privacy and security standards.

8. Sharing & Disclosure

Your content is private by default. It becomes visible to others only when you take an explicit action, such as marking a diary as public, sharing an item into a chat, or publishing a journal summary. You can change your sharing settings and stop sharing at any time, though copies others already saw or copied may persist outside our control.

We may disclose information if required to do so by law, to comply with valid legal process, to enforce our Terms, or to protect the rights, safety, and security of our users, the public, or the Service. We will not disclose the contents of diaries you have protected with zero-knowledge encryption because we cannot read them.

9. International Data Transfers

Our providers may process and store data in countries other than the one you live in. Where personal data is transferred internationally, we rely on our providers' safeguards (such as standard contractual clauses) to protect it in accordance with applicable law.

10. Data Retention

We retain your account information and content for as long as your account is active. When you delete an item, or your account, we delete or anonymize the associated data within a reasonable period, subject to any legal obligation to retain certain records. Residual copies may persist in encrypted backups for a limited time before being permanently purged. Guest account data may be removed sooner, including when the device data is cleared.

11. Your Rights

Depending on where you live, you may have the right to:

  • Access — obtain a copy of the personal data we hold about you;
  • Rectify — correct inaccurate account information, which you can do in Settings;
  • Delete — request deletion of your account and associated data;
  • Port — receive your content in a portable format, and export your writing from within the app;
  • Object / restrict — object to or restrict certain processing;
  • Withdraw consent — turn off any optional feature you previously enabled;
  • Complain — lodge a complaint with your local data-protection authority.

12. Exercising Your Rights

You can update your profile and export or delete much of your data directly from Settings. For any other request — including a full account deletion or a copy of your data — email us at lifearchive.aven@gmail.com. We will respond to verified requests within a reasonable time and in accordance with applicable law. To protect your privacy, we may need to verify your identity before acting on a request.

13. Cookies & Local Storage

We use only cookies and local storage that are necessary to run the Service — for example, a session cookie to keep you signed in, a short-lived state cookie during calendar authorization, and stored preferences such as your theme and language. We do not use third-party advertising or cross-site tracking cookies. Some in-app preferences and one-time notices (such as the "never show again" choice on the public-diary warning) are stored locally on your device.

14. Analytics & Insights

The Service includes personal analytics — such as writing streaks, a writing-rhythm chart, and optional insight summaries — computed from your own entries and shown only to you. If we introduce third-party product analytics in the future, we will update this policy and, where required by law, ask for your consent first. We do not currently run third-party advertising or behavioral-tracking analytics.

15. Children's Privacy

The Service is not directed to children under 13, and we do not knowingly collect their personal information. If we learn that we have collected data from a child under 13 without appropriate consent, we will delete it. If you believe a child has provided us information, contact us at lifearchive.aven@gmail.com.

16. Security

We implement reasonable technical and organizational measures to protect your data, described in detail on our Security page. No method of storage or transmission is 100% secure, so we cannot guarantee absolute security; using a strong, unique password (and, for the most sensitive entries, per-diary encryption) meaningfully protects you.

17. Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices, technology, or the law. We will revise the "Last Updated" date above and, for material changes, provide notice through the Service or by email. Your continued use after an update takes effect constitutes acceptance of the revised policy.

18. Contact

For any question or request regarding this Policy or your data, contact:

chapture
Email: lifearchive.aven@gmail.com

© 2026 Aven ProjectsTermsPrivacySecurityDocsContact