Privacy notice
AI-assisted reflections
Correlas can use AI to help spot gentle patterns in your journal and mood entries. This is optional: you can keep using Correlas without AI reflections.
If you enable AI reflections, only the data needed for the reflection you actively request may be sent to OpenRouter and processed by approved AI model providers, such as Google Gemini, OpenAI, Meta Llama, or Amazon Nova depending on the active model.
AI reflections are not medical advice, diagnosis, or treatment. Turning AI reflections off in Settings stops future external AI requests immediately. It does not delete reflections already saved.
Approved recipients/processors
- OpenRouter
- Google / Gemini
- OpenAI
- Meta / Llama
- Amazon / Nova
If a materially new model provider is added, this notice must be reviewed before it is enabled in production.
Error reporting & session replay
We use Sentry to capture anonymous error reports and, when an error occurs, a redacted Session Replay of the page where the error happened. Replays are not recorded for sessions that don’t hit an error, and the integration is configured to mask all visible text, all form input values, and all images / video by default. Cookies and request bodies containing coordinates are stripped server-side before any event is stored.
What Sentry may still receive in an error report: your browser type, the page URL you were on when the error happened, and a structural trace of the JavaScript call stack. It will not receive your journal text, your location label, your saved places, or any values you typed into a form.
Sentry acts as a data processor on our behalf under a Data Processing Addendum. Their privacy practices are documented at sentry.io/privacy.
How your entries are stored
Your journal text, location label, the context you add, and any AI reflections are encrypted in transit (TLS) and encrypted at the application layer before they are written to our database. A database-level compromise alone would expose ciphertext, not your words.
To be fully transparent: this is encryption at rest, not end-to-end. Correlas holds the encryption key and decrypts your entries in memory when it shows them to you, runs search, or prepares an AI reflection you have opted into. We are not currently a zero-knowledge service — we are working towards stronger guarantees over time.
Analytics
We use privacy-friendly first-party analytics with no tracking cookies and no personal data retained. Analytics events are handled by our own server and stored in our EU-region database.
This is not a third-party analytics service: events are sent to our own server and stored in our own EU-region database. Raw analytics records are automatically deleted after 13 months; after that only aggregate statistics (page counts, referrer domains, coarse country) are kept. No advertising trackers are used, and no data is shared with advertisers.
We rely on the legitimate-interest basis under UK GDPR Article 6(1)(f) for the brief processing of an IP address and browser type solely to compute an anonymous, daily-rotating visitor identifier. These inputs are never stored, and the identifier cannot be linked to your account. Our legitimate interest assessment is available on request via the contact form.
Correlas is intended for use by people aged 18 and over. We do not knowingly collect analytics or other data from anyone under 18.
Private beta
Correlas is in a private, invite-only beta. New accounts can only be created with an invite code. If you don’t have one, you can join the waitlist and we’ll let you in as space opens up.