Naja

Privacy Policy

Last updated: May 2, 2026

1. Introduction

Naja ("we", "us", "our") operates the Naja mobile application ("App") and website at najalog.com ("Site"). This Privacy Policy explains what information we collect, how we use it, and your rights regarding your data.

Your journal entries are private. We do not read, sell, or use your content for advertising or model training.

2. Information We Collect

Information you provide

  • Account data: Email address, display name, and authentication identifiers when you sign up via Sign in with Apple, Google Sign-In, or email and password.
  • Journal content: Reflection templates, journal entries, badge definitions, and any other content you create in the App. This data is stored to provide you the service and is not accessed by us for any other purpose.
  • Preferences: Theme selection, notification settings, and other in-app preferences.

Information collected automatically

  • Device information: Device model, operating system version, and app version, collected by Firebase for service operation.
  • Subscription status: Purchase history and subscription state, managed by RevenueCat to determine your access level.

3. Information We Do Not Collect

We want to be explicit about what we do not do:

  • We do not use third-party analytics or tracking SDKs.
  • We do not collect advertising identifiers (IDFA).
  • We do not collect location data.
  • We do not access your contacts, camera, photo library, or health data.
  • We do not serve ads of any kind.
  • We do not sell or share your personal data with data brokers.

4. How We Use Your Information

  • To provide, maintain, and improve the App.
  • To authenticate your identity and secure your account.
  • To process and manage your subscription.
  • To schedule local notifications on your device (notifications are handled entirely on-device using Notifee — no notification data is sent to our servers).
  • To respond to support requests if you contact us.

5. Third-Party Services

We use the following third-party services to operate the App:

  • Firebase Authentication (Google LLC) — Handles sign-in and account management. Processes your email and authentication tokens. Data is processed in the United States. See Firebase Privacy and Security.
  • Firebase Firestore (Google LLC) — Stores your account data, templates, and journal entries. Google acts as a data processor; we are the data controller. Data is stored on Google Cloud infrastructure in the United States.
  • RevenueCat — Manages subscription status and purchase validation. Receives your device identifier and purchase history from the App Store. See RevenueCat Privacy Policy.
  • Apple App Store — Processes subscription payments. Governed by Apple's Privacy Policy.

We do not share your journal entries or personal content with any of these services. They receive only the minimum data necessary for their function (authentication, storage, or payment processing).

6. Data Storage and Security

Your data is stored in Firebase Firestore, secured by Firebase security rules that restrict access to authenticated users viewing only their own data. Authentication is handled via industry-standard protocols (OAuth 2.0 for Apple and Google sign-in, bcrypt-hashed passwords for email accounts).

While we implement reasonable security measures, no method of electronic storage is 100% secure. We cannot guarantee absolute security.

7. Data Retention

We retain your data for as long as your account is active. If you delete your account, all associated data — including journal entries, templates, badges, and account information — is permanently deleted from our systems. We do not retain backups of deleted accounts.

8. Your Rights

Depending on your location, you may have the following rights:

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Request correction of inaccurate data.
  • Deletion: Delete your account and all associated data from within the App.
  • Portability: Export your data in a portable format (JSON or CSV) from within the App before deleting your account.
  • Objection: Object to processing of your data where we rely on legitimate interests.

To exercise any of these rights, contact us at naja_support@najalog.com or use the account management features in the App.

9. Account Deletion

You can delete your account at any time from the Profile tab in the App. Deleting your account permanently removes:

  • Your user profile and authentication credentials
  • All journal entries
  • All templates and badge definitions
  • Notification and preference settings

This action is immediate and irreversible. We recommend exporting your data before deleting your account.

Note: Deleting your account does not automatically cancel an active App Store subscription. You must cancel your subscription separately in iOS Settings > Apple ID > Subscriptions.

10. Children's Privacy

Naja is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, please contact us and we will delete it.

11. International Data Transfers

Our data infrastructure (Firebase Authentication and Firestore) is hosted in the United States. If you are located outside the United States, your data will be transferred to and processed in the United States. By using the App, you consent to this transfer.

12. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you through the App or by updating the "Last updated" date above. Continued use of the service after changes constitutes acceptance of the updated policy.

13. Contact

If you have questions about this Privacy Policy, contact us at naja_support@najalog.com.