Epistula

Privacy Policy

Effective 16 August 2026  ·  Last updated 9 September 2026

Epistula is a place where people write honestly, sometimes about God, sometimes about the hardest thing in their week. That only works if you know what happens to the words. This page tells you, plainly: what is held, why, who touches it, and what we have deliberately made ourselves unable to read.

The short version

  1. Who is responsible
  2. What this policy covers
  3. What we hold
  4. Why we may hold it
  5. Religious belief, and other sensitive things
  6. The journal, and what encryption really means
  7. Voice
  8. Images, text, and moderation
  9. Letters
  10. Who else touches your data
  11. Where your data lives
  12. Cookies, tracking, and advertising
  13. How long we keep things
  14. Your rights
  15. Age
  16. Security
  17. Changes
  18. Contact and complaints

1. Who is responsible

Epistula is made and operated by Julia Duro, an individual based in Portugal. Under the General Data Protection Regulation, she is the data controller for everything described here.

Post: EC Avenida — Apartado 19, 4711-909 Braga, Portugal
Email: hello@epistula.app

There is no data protection officer, because one is not required at this size. A real person reads that address.

2. What this policy covers

This policy covers the Epistula mobile app, this help site, and the marketing website at epistula.app. Where they behave differently, this policy says so rather than averaging them into a comfortable half-truth.

3. What we hold

What you give us when you join

WhatNotes
Email addressHow you sign in, and how we reach you about your account.
PasswordStored only as a cryptographic hash. Nobody, including us, can read it back. It also derives the key to your journal — see section 6.
Display nameYour real name, or the name you go by. It is shown to other members.
HandleGenerated from your name.
Date of birthHeld to confirm you are old enough. Not shown to anyone.
GenderAsked once during onboarding.
State of lifeOptional — single, married, discerning, ordained, and so on.
City and bioOptional, and shown on your profile if you fill them in.
Profile photoOptional.
Onboarding answersKept only as anonymous counts, never tied to you. We can tell that forty people chose an answer; we cannot tell that you were one of them.

What you write

WhatNotes
Posts and commentsIn Acta, the community feed. Visible to signed-in members.
Threads and repliesIn the Forum. Visible to signed-in members.
ReactionsWhich posts you responded to, and how.
LettersWritten to one person, delivered slowly. See section 9.
Journal entriesEncrypted on your device. See section 6.
ImagesPhotos you attach to posts, and your profile photo.

What the app records as you use it

WhatNotes
Who you walk withThe connections you make.
Blocks and mutesSo the app can keep people apart when you ask it to.
Reports you fileIncluding the reason you chose.
NotificationsWhat the app told you, and whether you have seen it.
Subscription statusWhether your subscription is active. We never see your card.
App launchesWhen the app opens, it tells Meta that it opened. Nothing about you and nothing about what you write travels with it. See section 12.
Technical logsOur hosting provider records the details of each request its servers handle: the time, your account identifier, your IP address, the city and internet provider that address implies, your device type, and which part of the service you were using. It does not record what you wrote. These logs exist to keep the service running and to investigate abuse. They are kept briefly — see section 13.

There is no list here of pages you looked at, how long you lingered, or what you almost wrote and deleted. We do not collect that. An app about slow, honest writing has no business watching over your shoulder.

4. Why we may hold it

The GDPR requires a lawful basis for every use. Ours:

BasisWhat it covers
Performance of a contractRunning your account and the service you signed up for: showing your posts to members, delivering your letters, storing your journal, handling your subscription.
Legal obligationTax and accounting records for payments, and our duties under the Digital Services Act regarding illegal content.
Legitimate interestsKeeping the service secure, preventing abuse, moderating content, and measuring which advertisements bring people to Epistula. We have weighed each of these against your privacy and limited it to what the purpose actually needs.
ConsentThe optional things: your bio, city, photo, and any marketing email you ask for. You can withdraw consent at any time, and withdrawing it does not affect what came before.
Explicit consentFor data revealing religious belief — see the next section.

5. Religious belief, and other sensitive things

Epistula was built on Catholic ground and does not pretend otherwise. Which means the plain fact of your being here, and much of what you write, can reveal your religious beliefs. Article 9 of the GDPR treats that as a special category of data, deserving stronger protection than an email address.

We treat it accordingly. We rely on your explicit consent, given when you create an account, and we use it for one thing only: to run the service you came here for. It is never used for advertising, never sold, never shared with anyone outside the list in section 10, and never used to build a profile of your beliefs.

The same care applies to anything else you happen to write that the law protects — health, sexuality, politics. You did not fill in a form about those things. If they appear, it is because you were writing honestly, and we hold them with the weight that deserves.

6. The journal, and what encryption really means

Your journal entries are encrypted on your device, before they ever reach our servers. The key is derived from your password and held in your device's secure storage. What our database contains is unreadable text.

We cannot read your journal. Not the founder, not any future employee, not anyone who compels us with a court order. This is not a promise about our intentions; it is a fact about the mathematics.

The honest cost. A guarantee that had an exception would not be a guarantee. So there is no back door for us, which means there is no back door for you either. If you lose your password and you are not signed in on any device and your key has not synced through iCloud Keychain, your past entries are unreadable, permanently. The app tells you this at the moment it matters, and offers you the choice to start fresh.

Two things about the journal are not encrypted, and you should know which: the prompt you were answering, and which kind of practice you used. Those are public text and a category label, not confession. The words you wrote are encrypted.

There is one moment when this protection does not apply, and it is a moment you choose: dictating an entry instead of typing it. Section 7 explains exactly what happens then.

7. Voice

The journal lets you speak instead of type. If you use it, your recording travels first to our own server function, which passes it to OpenAI's audio transcription service to be turned into text. The text returns along the same path and is encrypted on your device.

This is the point at which your journal words leave the protection of Epistula's on-device encryption. They travel encrypted in transit, as everything on the internet does. But both our server and OpenAI necessarily handle them in readable form, because that is what transcription is. We tell you plainly because letting you believe a spoken entry is as private as a typed one would be a lie by omission. If that does not sit right with you, type.

Epistula stores neither the recording nor the resulting text. Our function holds them in memory for the seconds it takes to pass them along, writes nothing down, and keeps no log of what was said. Our hosting provider handles the request in the course of running the service and records technical details about it — timing, status, and the like — as described in section 3.

OpenAI states that content sent to its API is not used to train or improve its models unless the customer explicitly opts in. We have not opted in. As at 16 August 2026, OpenAI's data controls documentation lists its audio transcription endpoint as having no abuse-monitoring retention and no application-state retention.

8. Images, text, and moderation

Images uploaded to public parts of the app are held in a private holding area and checked automatically before anyone else can see them. The check is done by Google Cloud Vision, which returns a safety rating. Approved images become visible; images that fail are not published. If the check cannot run at all, the image stays unpublished rather than being let through unchecked.

Text posted publicly — posts, comments, forum threads and replies, and letters cast into the sea — is screened automatically by OpenAI's moderation service, which returns a set of scores rather than reading for meaning. The text appears immediately and is withdrawn only if it scores very highly on a narrow set of categories: threats, and instructions to harm. Disagreement, doubt, anger, and difficult subject matter are not moderated. This app exists for those.

Your journal is never moderated. It cannot be: it is encrypted, and there is nothing to screen. Private letters, written to one person, are not screened either. A letter cast into the sea for a stranger is, because nobody chose to receive it.

When a report is filed, a human — today, the founder — reads what was reported in order to decide. That is the only circumstance in which someone reads your writing outside its intended audience.

9. Letters

Letters are written to one person and delivered after a delay you choose. They are held on our servers until then. Letters are not end-to-end encrypted — they are encrypted in transit and at rest, but unlike the journal, we hold the ability to read them. We do not, and we do not screen them, but the honest word is private, not impossible.

If the person who wrote to you deletes their account, the letter survives with their name removed, shown simply as a fellow. The reverse is also true. A letter dies only when both people have gone.

10. Who else touches your data

These companies process data on our behalf, under contract, for the purposes named. Nobody else.

WhoWhat for
SupabaseDatabase, authentication, file storage, and server functions. The core of the service.
AppleApp distribution, and all subscription payments. Apple handles your payment details — we never receive them. Apple also runs the attribution system described in section 12.
RevenueCatTells our servers whether your subscription is active. Receives an anonymous account identifier, not your name or email.
OpenAITwo things: turning your voice recordings into text when you dictate, and screening public text for threats. It does not touch your journal, except when you choose to dictate it.
Google CloudAutomated image safety checks.
MetaTells us which of our advertisements bring people to Epistula. Receives a signal that the app was launched, and nothing else. See section 12.
ResendPassword resets and other account emails.
HostingerHosts this help site.
SquarespaceHosts the marketing website. See section 12.

We do not sell your data. We do not share it with advertisers or data brokers. We do not use your writing to train artificial intelligence. The two providers that process your words with artificial intelligence — OpenAI and Google — both state in their terms that content sent through their services is not used to train their models.

11. Where your data lives

Your account and everything you write are stored on Supabase's infrastructure in Ireland (eu-west-1), inside the European Union.

Some of the work described in section 10 happens outside it. When you dictate a journal entry, and when public text is screened, the data is handled by OpenAI in the United States. Image checks are handled by Google. The launch signal described in section 12 is handled by Meta. Supabase itself is an American company, even though your data sits in Ireland.

Those transfers are covered by the Standard Contractual Clauses approved by the European Commission, which each of these providers builds into its data processing agreement. Google and Meta are additionally certified under the EU-US Data Privacy Framework. OpenAI and Supabase are not certified under that framework and rely on the clauses alone.

12. Cookies, tracking, and advertising

The Epistula app shows no advertising and contains no tracking pixels. Nothing you write, read, or do inside it is sent to anyone outside the list in section 10.

It does send Meta one signal: that the app was launched. That is how we can tell which of our advertisements brought people here, and it is the only reason it exists. The signal carries no advertising identifier. The app never asks for permission to track you, because it does nothing that would need that permission, and Meta cannot connect what you do inside Epistula to your activity in any other app or website. Attribution runs through Apple's SKAdNetwork, which reports to us in aggregate — how many installations a campaign produced — and never about a single person.

This help site carries nothing at all: even its typefaces are served from our own domain, so that reading this page does not tell Google you are reading it.

Our marketing website at epistula.app is hosted by Squarespace and carries a Meta advertising pixel, which is how we measure whether our advertisements bring people to that page. Squarespace itself sets a small number of functional cookies and collects basic visit statistics as part of hosting the site. The help site you are reading, where the legal pages live, carries no pixel of any kind. That was deliberate: a privacy policy is the one page in the world that should not be watching you read it.

We use no advertising cookies inside the app and no cross-site tracking anywhere. If that ever changes, this section will be rewritten first, and nothing will load without your consent.

13. How long we keep things

14. Your rights

The GDPR gives you rights over your data. Two of them we built into the app, because a right you have to send an email to exercise is a right with a queue in front of it:

You also have the right to access your data, to have it corrected, to restrict or object to how it is used, and to withdraw consent where consent is what we rely on. Write to hello@epistula.app and we will answer within one month.

The export deliberately leaves out your blocks, mutes, and reports. Those are lists of other people, and the right to portability does not extend to carrying away someone else's data. What you get is your writing.

15. Age

Epistula is for people aged 16 and over. We ask your date of birth when you join and do not create accounts below that age. If you believe a child has an account, write to us and we will remove it.

16. Security

Everything travels over HTTPS. Passwords are hashed. Access to your data is enforced at the database level, row by row, so that the rules do not depend on the app asking politely. Journal entries are encrypted on your device, as described in section 6.

No service is perfectly safe, and anyone who tells you otherwise is selling something. If a breach ever puts your rights at risk, we will tell you and the Portuguese supervisory authority, within the deadlines the law sets.

17. Changes

If this policy changes in a way that matters, we will tell you inside the app before the change takes effect, and update the date at the top of this page.

18. Contact and complaints

Write to hello@epistula.app. A person reads it.

If you think we have handled your data badly and we have not put it right, you can complain to the Portuguese data protection authority, the Comissão Nacional de Proteção de Dados (CNPD), at cnpd.pt. If you live in another EU country, you may complain to your own national authority instead.