Privacy
How this site and Sonavra handle account and journal data.
This is a draft that a lawyer has not reviewed yet. It describes how Sonavra works today, and it will be reviewed before paid plans go on sale.
What this page covers
Sonavra is run by Kenzie Bullock, an individual in Alberta, Canada. "I" and "me" on this page mean Kenzie. This is the privacy policy for sonavra.ca, the Sonavra iPhone app, and kenziebullock.com. Sonavra is a personal journal. Journal entries, habits, meals, health numbers and similar notes stay in your account. They are not a public profile and they are not listed in search.
What I collect
An email address is how you sign in. If you write a name, I store that too. Anything you add to the journal, habits, goals, meals, check-ups, notes, library or quotes is stored so the app can show it back to you. If you allow it, the iPhone app sends health numbers from Apple Health, and the app can store an approximate location for weather and your phone calendar events. If you buy a plan, I store the plan, its status and renewal date, not your card. I also keep session cookies so you stay signed in, a record of sign-ins and password changes, and server logs that help me run the site.
Health information and your consent
Much of what you add is health information: sleep, mood, cravings, use, medications, check-up scores like GAD-7 and PHQ-9, and numbers from Apple Health or Oura. When you create an account you agree to Sonavra storing and using this to run the app for you, as this page describes. You choose what to add and what to connect, and you can disconnect a source or delete any record at any time. Health information is never sold, never used for ads or marketing, and never shared except with the providers below so the app can work. Data from Apple Health is used only to show your own records and patterns back to you. Canada's PIPEDA and Alberta's PIPA apply. Where a law where you live gives you more rights over health data, such as Washington's My Health My Data Act, you have those rights too.
What identifies you
Email is how you sign in. Anything you write may identify you. Do not store secrets here that you cannot afford to keep.
How I use it
I use your data to run the app for you: to store it, show it back, work out your patterns and send the reminders and emails you turn on. I also use it to fix problems and improve the app. I do not sell it or use it for ads.
AI features
AI features are optional. Each one sends only what it needs to OpenAI, and only when you ask, except the morning recap, which runs each morning after you turn it on. By default the website shows you exactly what will be sent and waits for you to say yes. In Settings you can turn each feature off, skip that step for it, or keep journal writing, meals, medications, check-ins, photos or voice out of every request. Requests go from Sonavra's own OpenAI account, not yours: your name, email and account are never sent, and photos have their location, date and camera details removed first. What you wrote is sent as written, with the dates it covers, so a name or detail in your notes goes with it. OpenAI says it does not train its models on data sent this way and keeps it for up to 30 days to check for abuse, unless the law requires longer. I do not sell it or use it for ads. These are every AI feature in the app:
- Day recap: Tap Recap on a day.
- Ask about this stretch: Ask a question on Review.
- Ask about meals: Ask a question on Meals.
- Ask about check-ins: Ask a question on Check-ups.
- Daily Review look: Open the Daily Review look.
- Ask about diet and body: Ask a question on your body page.
- Meal estimate: Estimate a meal you typed.
- Meal photo: Estimate a meal from a photo.
- Library suggestions: Ask for suggestions on Library.
- Voice transcription: Record a voice memo.
- Speak assistant: Speak a day.
- Feeling suggestions: Tap Suggest feelings on writing or a voice note.
- Page photo: Read a page photo into a day.
- Journal photo from Capture: Send a photo through Capture.
- Pattern explanation: Tap Explain on a pattern.
- Ask about a pattern: Ask a question on Progress.
- Weekly reflection: Ask for the weekly reflection.
- Recall what helped: Tap Recall.
- Goal to routine: Turn a goal into a routine.
- Goal from your words: Describe a goal when making a new one on Goals.
- Progress story: Ask for your story.
- Monthly letter: Ask for the monthly letter.
- Weekly sleep and stress note: Ask for the weekly note.
- Numbers from a screenshot: Read a screenshot on Sleep.
- AI morning recap: Turn on the AI morning recap in Settings; it then goes with each morning email.
Who else handles it
These services handle some of your data so the app can work. Each sees only what it needs for that job.
- Amazon Web Services (United States): the server and database that hold your account, stored photos and recordings, the queue for background work, and the email the app sends (Amazon SES).
- Auth0, by Okta (United States): sign-in for the website and the iPhone app, including Continue with Google and Continue with Apple.
- OpenAI (United States): the optional AI features listed above, only when you use one.
- Apple: Apple Health on your iPhone, which the app reads only for the types you allow; WeatherKit, which gets an approximate location for weather; and the App Store, which handles subscriptions bought on the iPhone.
- Stripe (United States and Canada): payment for plans bought on the website, once paid plans are on sale.
- Open-Meteo (Switzerland): air quality for an approximate location, when weather is on.
- Oura (Finland): only if you connect an Oura ring.
- Google: sign-in if you choose Continue with Google, and the web fonts your browser loads from Google Fonts.
Payments
Plans bought on the website are paid through Stripe, and plans bought in the iPhone app are paid through Apple. They handle your card and billing details under their own privacy policies. I receive your plan, whether it is active, when it renews and the country for tax. I never see your full card number.
When you share it
Some features send something to a person or app you choose: an accountability partner gets a yes or no check-in, not your writing; a calendar feed link shows your plans to any calendar app you give it to; and the clinician page is printed from your own device. After you send something to another person or app, what happens to it there is up to them. I may disclose data if the law requires it.
How I count usage
I count how often each section of the app is opened — Today, Habits, Workouts, and the rest — as a plain daily total with no account attached to it. The number can tell me that Workouts was opened forty times on a Tuesday. It cannot tell me, or anyone, who opened it. Sign-ins are counted the same way as a daily total, and so are a few feature choices: which habit starter was picked, whether an Inbox suggestion was kept or thrown away, a finished setup, and feedback sent. Separately, your own account stores the time you last signed in and how many times you have signed in, so I can see whether an account is still in use; that part is tied to you, it is not shown in the app, and it is never joined to the section counts.
Where it is kept and how it is protected
Your data is stored on servers in the United States, so it can be subject to US law, including requests from US authorities. It travels over encrypted connections, passwords are stored only as secure hashes, and only I can reach the server and database. If a breach puts you at real risk, I will tell you and the regulators the law requires.
How long I keep it
Account and journal data stay until you delete them. You can delete your whole account yourself from Settings, and that removes everything in it right away. Session cookies expire when the session ends. Backups exist so I can recover the app; they are not a second public copy of your journal, and a deleted account drops out of them as older backups are replaced.
A copy of your data
Signed in, open Settings and choose Download my data. You get one JSON file with every record your account holds and your settings. Photos and recordings are not in it, and your password and sign-in keys never are.
Your choices
You can see, correct, download and delete your data yourself, and withdraw your consent by deleting your account. If something isn't right, write to me first. You can also complain to the Office of the Privacy Commissioner of Canada or the Office of the Information and Privacy Commissioner of Alberta.
Age
Sonavra is for people 16 and older. If I learn an account belongs to someone younger, I will delete it.
Changes to this page
This page was last updated September 30, 2026. When it changes I will update the date and note it in What's new, and for a change that affects how your data is used, I will email you first.
Questions
To delete your account, use Delete account at the bottom of Settings. For a privacy question, email me from the contact form on kenziebullock.com.