Privacy Policy
Worrier is a private anxiety journal. This policy explains what the prototype stores, where it stores it, and what it never does with what you write.
The short version
- Your journal is private to your account. Nothing in it is published unless you tick the box to share one specific worry while you are writing it.
- Sharing a worry publishes its words, its category, and a wide area — never your name, and never a precise location. Locations are areas, never places. Your device turns your location into a grid square roughly 110km across and only that square is sent, so no coordinate ever reaches us. An area stays hidden until enough people are inside it.
- Trends is still seeded demo content. Everything on this screen is seeded demo content written for the prototype. It is never private journal data, and no worry you write is ever published here.
- There is no analytics, advertising, profiling, or third-party tracking in Worrier. We do not send your worry text, email address, session tokens, or device identifiers to any analytics service.
- You can delete your account and every cloud-synced worry from the app at any time.
What we collect
Account information
You sign in with Google. Google gives us your name, email address, and profile image so we can create your account and keep you signed in. We store an account record, a session record, and an encrypted OAuth token. We do not receive or store your Google password.
Journal content
We store the events, worries, categories, timestamps, and outcomes you enter. This content is owner-scoped: every query is restricted to the signed-in account, and records that do not belong to you return a generic not-found response.
Operational data
Our hosting and database providers process ordinary technical records such as IP addresses, request timing, and error signals to serve requests and to rate-limit abuse. Our application logs deliberately exclude worry text, email addresses, cookies, tokens, and connection strings.
When a server request fails unexpectedly, the only details we are able to record are the error’s class name, which route pattern was involved, the HTTP status, and an opaque request ID. Your worry text, email address, cookies, tokens, the request URL, the request body, and stack traces are never included, and error reporting is switched off unless it is explicitly enabled for a deployment.
On your device
The web app keeps an offline copy of your journal in IndexedDB, and the mobile apps use AsyncStorage and SecureStore, so your journal works without a connection. Signing out and deleting your cloud data clears this local copy. Your age eligibility confirmation is also stored locally as a single choice and timestamp.
What we never do
- We never publish your journal, or any total, trend, count, or excerpt derived from it. The only thing that is ever published is a worry you individually asked us to share.
- We never sell or rent your personal information.
- We never use your journal to train models or to build advertising profiles.
- We never read your journal to moderate, coach, or monitor you. Nobody is watching it.
The World map
The World map shows worries that people chose to publish. Sharing is per worry and off by default: the box in the composer starts unticked, ticking it applies only to the worry you are writing, and the next worry starts unticked again. Nothing else in your journal is affected, and a worry you never shared can never appear.
Sharing publishes the words you wrote, the category you picked, the time, and an area. It does not publish your name, your email address, your account, or a link back to the rest of your journal.
How location works
When you tick the box, your browser asks for your location and your device immediately rounds it to a grid square roughly 110 kilometres across. Only that square is sent to us. There is no latitude or longitude column in the table that stores shared worries, so a precise location has nowhere to be kept even by accident. You are shown which area will be used before you submit.
A square is only ever drawn on the map once at least 12 people have shared from inside it. Below that it merges into a larger area, and if even the largest area falls short it is not drawn at all. Zooming in cannot make a marker more precise than this.
Removing something you shared
A shared worry leaves the map on its own after 24 hours. Deleting your cloud data removes everything you have published immediately, along with your account and your journal. There is not yet a way to withdraw one individual shared worry ahead of its expiry; if you need one removed sooner, delete your cloud data.
Trends
The Trends list is still a demonstration. Every worry, count, and percentage on that screen is seeded demo content authored for the prototype, and none of it comes from any person’s journal or from the World map.
Third parties
- Googleprovides sign-in. Google’s own privacy policy covers what it does with your Google account.
- Vercel hosts the application and Neon hosts the PostgreSQL database in the United States (AWS
us-east-1). - OpenStreetMap serves the map tiles on the World screen. Your browser requests those tiles directly, so the tile server sees your IP address. It never receives journal content.
Security
Your journal is protected in transit and at rest, mutations validate their origin and payload, and API responses never return database errors or stack traces. Worrier is not end-to-end encrypted: the database operator can technically access stored rows. Please keep that in mind while the prototype is in testing.
Retention and deletion
We keep your journal until you delete it. Use Delete cloud data in the footer of the app to delete your account and every cloud-synced worry. Deletion is immediate and cannot be undone. Ordinary provider backups may retain residual copies for a short window before they expire.
Age requirement
Worrier is for adults. See the Terms of Use for the full eligibility rule. We do not knowingly collect information from children.
Not medical care
Worrier is a wellness journal and not a medical service, so it does not create a patient relationship or produce a medical record. Read Safety and Crisis Support before you rely on it during a difficult moment.
Changes
We will update this page and its date when the prototype’s data handling changes. Material changes will be announced to testers before they take effect.
Contact
For privacy questions, deletion help, or a copy of your data, use the contact address included in your prototype testing invitation.