Privacy Policy
Your journal is private by default. We do not sell your journal content.
Effective Date: August 8, 2026 | Last Updated: August 8, 2026
This Privacy Policy explains how Wonderfarm LLC ("Wonderfarm," "we," "us," or "our") collects, uses, discloses, retains, and protects information when you use the Truffle Journal mobile application, website, connected ChatGPT experience, and related services (collectively, the "Service"). Wonderfarm LLC is the controller of personal information processed for the Service, except where another provider acts independently under its own policy.
1) Information we collect
Account and profile information
- Name and email address
- Internal account and user identifiers
- Authentication, email-verification, account-status, and account-recovery information
Journal and other user content
- Journal entries, titles, comments, tags, prompts, and related organization data
- Pin, archive, creation, modification, and deletion state
- Content and instructions you send through a connected ChatGPT workflow
- Support messages and other communications you send to us
Search and AI-processing information
- Entry text sent for creation of semantic-search embeddings
- Search queries sent for creation of query embeddings
- Numerical embedding vectors stored with journal records to provide semantic search
- Authorized requests and results exchanged with connected assistant services
Subscription, quota, and reward information
- Apple product, transaction, original-transaction, and app-account identifiers
- Purchase environment, subscription status, expiration, renewal, refund, and revocation information
- Effective Plus entitlement, retained-entry count, quota decisions, locked-entry state, and restore attempts
- Reward eligibility, balance, activation, duration, and status
Apple processes your payment method and full billing details. We do not receive your complete payment-card or bank-account information from Apple.
Technical and usage information
- App version, build, release channel, platform, and operating-system information
- Feature interactions, timestamps, request status, and operational events needed to provide and troubleshoot the Service
- IP address, request headers, and security or error logs that may be processed by our infrastructure and service providers
2) Information stored on your device
Truffle Journal may store drafts, cached journal data, reminder schedules, preferences, authentication material, and recovery state locally on your device. Local notifications and reminders are generally scheduled by the app on your device. Information may leave your device when you sync, authenticate, export, request semantic search, connect ChatGPT, contact support, or use another network feature.
3) How we use information
We use information to:
- Create, authenticate, secure, recover, and administer your account
- Save, sync, organize, search, display, export, and delete journal content
- Provide connected ChatGPT and other user-authorized integrations
- Verify Apple transactions, maintain Plus access, restore purchases, and respond to subscription lifecycle events
- Enforce the Free entry quota, apply locked-entry rules, and administer rewards
- Send authentication, deletion, security, support, and essential service communications
- Prevent fraud, abuse, unauthorized access, and security incidents
- Diagnose errors, maintain reliability, and improve Service functionality
- Comply with law, resolve disputes, and enforce our Terms of Service
4) OpenAI embeddings and connected ChatGPT use
To provide semantic search, Truffle Journal sends the text of a newly created or updated journal entry to OpenAI’s API to generate an embedding. When you perform semantic search, the search query is also sent to OpenAI’s API to generate a query embedding. The resulting numerical vectors are stored in our Supabase-backed database and compared to find relevant entries.
OpenAI states that data submitted through its API is not used to train or improve OpenAI models unless the API customer affirmatively opts in. Under OpenAI’s default API controls, abuse-monitoring logs may contain customer content and may be retained for up to 30 days, unless a longer period is legally required. OpenAI’s retention behavior can differ where approved data controls or particular API features apply. See OpenAI’s API data controls.
If you use Truffle Journal through ChatGPT, OpenAI independently processes your ChatGPT account, conversation, and interaction information under the policies applicable to ChatGPT. Truffle Journal receives and returns only the requests, account authorization, journal information, and results needed for actions you direct through the integration.
5) How we disclose information
We do not sell personal information or journal content. We do not share personal information for cross-context behavioral advertising.
We may disclose information to:
- Supabase: authentication, database, storage, and backend infrastructure
- OpenAI: embedding generation and user-authorized ChatGPT integration processing
- Apple: App Store purchases, subscription management, transaction status, device services, and related support
- Hosting and delivery providers: website hosting, networking, security, and transactional email delivery
- Professional advisers and authorities: where reasonably necessary to comply with law, protect rights and safety, prevent fraud, or establish and defend legal claims
- Business transaction participants: if Wonderfarm is involved in a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets, subject to appropriate confidentiality and legal safeguards
We may also disclose information at your direction, such as when you export journal content or authorize a connected service.
6) Tracking and advertising
Truffle Journal does not use journal content for advertising and does not track you across apps or websites owned by other companies for targeted advertising or advertising measurement. If our practices materially change, we will update this policy and request any permission required by Apple or applicable law before beginning the new activity.
7) Retention
We retain information only for as long as reasonably necessary for the purposes described in this policy, including to provide the Service, maintain security, comply with law, resolve disputes, and enforce agreements. Retention depends on the type of information and why we process it.
- Account and journal information: generally retained while your account is active or until you delete the relevant content.
- Scheduled account deletion: retained during the 21-day recovery period, then permanently deleted from active systems when deletion processing begins, except for information we must retain.
- Purchase and entitlement records: retained as needed to verify transactions, prevent fraud, provide subscription history, and meet accounting or legal obligations.
- Security and operational logs: retained for a limited period appropriate to troubleshooting, security, and abuse prevention.
- Provider copies: retained according to provider terms, our service configuration, and applicable law.
Deleted information may persist temporarily in encrypted backups until those backups are overwritten or expire. We may retain aggregated or de-identified information that cannot reasonably identify you.
8) Account deletion
You can schedule deletion from Truffle Journal under Settings → Danger Zone → Delete Account. Journal access stops immediately after deletion is scheduled. You can sign in and choose Restore Account during the 21-day recovery period. After the recovery period, permanent deletion begins and the account cannot be restored.
Account deletion is separate from Apple subscription management. Deleting your Truffle Journal account does not automatically cancel an Apple subscription. Cancel through your Apple Account subscription settings if you do not want future charges.
If you cannot use the in-app deletion flow, contact support@trufflejournal.com. We may need to verify account ownership before acting on a request.
9) Your choices and privacy rights
Depending on where you live, you may have rights to:
- Access or obtain a copy of personal information
- Correct inaccurate personal information
- Delete personal information
- Restrict or object to certain processing
- Receive portable data where applicable
- Withdraw consent for processing based on consent, without affecting prior lawful processing
- Appeal a privacy-request decision or complain to a local privacy or data-protection authority
You can edit or delete entries, export journal content, manage reminders, restore eligible purchases, and schedule account deletion in the app. For other requests, email hi@wonderfarm.app. We may verify your identity and may deny or limit a request where permitted by law.
10) Legal bases for EEA and UK processing
If European Economic Area or United Kingdom data-protection law applies, we rely on the following legal bases as appropriate:
- Contract: to provide the account, journal, search, subscription, reward, export, and support features you request
- Legitimate interests: to secure, maintain, troubleshoot, and improve the Service; prevent fraud and abuse; and protect users and Wonderfarm
- Legal obligation: to comply with tax, accounting, regulatory, law-enforcement, and other legal requirements
- Consent: where we specifically request consent and applicable law requires it
11) International processing
Wonderfarm and its service providers may process information in the United States and other countries that may have different data-protection laws from your country. Where required, we use contractual or other lawful safeguards for international transfers.
12) Security
We use reasonable administrative, technical, and organizational safeguards designed to protect information, including encrypted network connections, authentication, access controls, and separation of service roles. No method of storage or transmission is completely secure, so we cannot guarantee absolute security.
13) Children’s privacy
The Service is not intended for children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided information, contact hi@wonderfarm.app so we can take appropriate action.
14) Third-party services and links
Third-party apps, websites, and services have their own privacy practices. This policy does not govern information a third party independently collects from you, including information processed through your Apple Account or ChatGPT account outside Truffle Journal’s systems.
15) Changes to this Privacy Policy
We may update this policy as the Service or legal requirements change. If a change is material, we will provide reasonable notice in the Service, by email, or through another appropriate method. The “Last Updated” date identifies the current version.
16) Contact
Privacy questions or requests: hi@wonderfarm.app
Product support: support@trufflejournal.com