1. Who we are
Health Journal is a personal health record and journalling platform operated by I Own My Health Ltd, a company registered in England and Wales (Company Number 17313073). When this policy refers to “Health Journal”, “we”, “us”, or “our”, it means I Own My Health Ltd acting as the data controller for your personal data.
Our Data Protection Contact can be reached at privacy@healthjournal.app for data-rights requests, objections to processing, consent withdrawal, privacy questions, and data-protection complaints. For general product support, contact support@healthjournal.app.
2. What this policy covers
This policy explains what personal data we collect when you use Health Journal, why we collect it, how we use it, and the rights you have over it. It covers:
- The Health Journal application (web and mobile)
- Your account and subscription
- The Community Insights feature — privacy-protected, aggregated statistical summaries of self-reported member experiences
- Our website at healthjournal.app
This policy does not cover third-party websites or services that you may link to from within the app.
3. Legal framework
We process your personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Your health data constitutes Special Category data under Article 9 UK GDPR and is afforded the highest level of legal protection.
Where we rely on your consent as a legal basis, you have the right to withdraw it at any time without affecting the lawfulness of processing before withdrawal.
4. Data we collect and why
4.1 Account data
When you create an account we collect your email address, authentication credentials, and subscription information. This is necessary to provide the service (Article 6(1)(b) UK GDPR — performance of a contract).
4.2 Health journal data
Health Journal is designed for you to record your own health information. This is entirely self-reported and may include:
- Conditions and diagnoses
- Medications, supplements, and complementary or alternative medicine (CAM) treatments
- Symptoms, notes, and journal entries
- Treatment ratings (effectiveness and tolerability, scored 1–10)
- Files and documents you choose to upload
Your private health journal data is processed to provide the service you subscribe to (Article 6(1)(b) UK GDPR — performance of a contract). Because it includes health information, we also rely on your explicit consent for Special Category data (Article 9(2)(a) UK GDPR). You control what you record. You may delete any entry at any time.
4.3 Treatment ratings
When you rate a treatment, you provide a numeric score (1–10) for effectiveness and tolerability in the context of a specific condition. Ratings are:
- Linked to your account for your own record-keeping
- Processed for Community Insights in the privacy-protected way described in Section 5
- Available to update at any time
- Prompted when you stop a treatment, to capture your end-of-treatment experience
4.4 Technical and usage data
We automatically collect limited technical data to operate and secure the platform, including IP address, device type, browser type, session timestamps, and error logs. This is processed on the basis of our legitimate interests in maintaining a secure and reliable service (Article 6(1)(f) UK GDPR).
4.5 Communications
If you contact us for support or send us feedback, we retain that correspondence to resolve your query and improve the service. This is processed on the basis of our legitimate interests (Article 6(1)(f) UK GDPR).
5. Community Insights — how your data contributes to the community
5.1 What data is used
Community Insights draws on self-reported health information that members enter into Health Journal, including conditions, treatments, treatment ratings, and related health records. Member-entered information may be inaccurate, incomplete, or not clinically verified.
Examples of the data types that may contribute to Community Insights include:
- Conditions and diagnoses recorded by members
- Treatments and medications logged (conventional and CAM)
- Treatment ratings — effectiveness and tolerability scores (1–10)
- Treatment duration and usage patterns
- Co-occurring conditions and treatment combinations
Raw individual records are never exposed to other members. The fact that names or direct identifiers are removed does not mean the underlying processing is anonymous; while we process member-entered source data, it remains personal data and, where health information is involved, Special Category data.
5.2 How it is displayed
Community Insights displays aggregated statistical summaries of Health Journal member records only. It does not represent clinically verified prevalence in the wider UK population or general population.
Examples of outputs may include:
- Banded numbers of members recording a condition
- The most commonly recorded treatments for a condition
- Aggregated member-reported effectiveness
- Aggregated member-reported tolerability
- Trends over time
- Privacy-protected geographical patterns where sufficient member data exists
Community Insights uses exact, rounded, banded, or suppressed results depending on the nature of the statistic, the number of contributors, and the risk of identifying or singling out an individual. More detailed analyses are subject to higher minimum contributor thresholds. Sample sizes may be displayed as exact numbers, rounded numbers, or broad bands.
Community Insights may show broad geographic patterns where sufficient member data exists. These outputs use aggregated regional measures and do not display precise member locations or individual-level information. Low-volume areas may be suppressed or combined. A map may show broad relative intensity bands or calculate the percentage of active Health Journal members in an area recording a condition. For example, an output may show “relative levels of flu recorded by Health Journal members by region”; it should not be read as clinically verified flu prevalence in the general population.
You should not use Community Insights independently to start, stop, or change any treatment. Always discuss treatment decisions with an appropriately qualified healthcare professional.
5.3 Legal basis
Community Insights processing is based on our legitimate interests in providing members with privacy-protected statistical summaries that help them understand self-reported experiences across the Health Journal member community (Article 6(1)(f) UK GDPR).
For health information, which is Special Category data, the intended basis for Community Insights is processing necessary for statistical purposes with appropriate safeguards (Article 9(2)(j) UK GDPR), supported by the relevant Data Protection Act 2018 condition.
We apply technical and statistical controls designed to reduce identification risk to a sufficiently remote level before any aggregated output is displayed.
5.4 What we will never do with Community Insights data
- Display raw health records, individual journal entries, or individual member profiles to other members
- Display precise location or precise demographic detail in Community Insights outputs
- Use Community Insights outputs to make decisions about you individually
- Deliberately identify or re-identify any individual from Community Insights data
- Share Community Insights data with third parties for advertising or data-broker purposes
Demographic and geographic information may be used only in broad, aggregated forms where each resulting group passes applicable privacy controls.
5.5 Objecting to Community Insights processing
Because Community Insights relies on legitimate interests under Article 6(1)(f) UK GDPR, you have the right to object to this processing. You can object by contacting privacy@healthjournal.app.
While we review your objection, we may pause your future contribution to Community Insights where technically practical. If your objection is accepted, your identifiable or pseudonymised source data will no longer contribute to future Community Insights processing. Because Community Insights is reciprocal, accepted objection may also mean you no longer have access to the Community Insights feature. Genuinely anonymised statistical outputs already produced may remain because they no longer relate to an identifiable member.
6. How we share your data
We do not sell, rent, or share your personal health data with third parties for commercial purposes. We share data only where strictly necessary:
6.1 Infrastructure and hosting
Your data is hosted using cloud hosting and infrastructure providers acting under contractual data-protection obligations. Our current cloud infrastructure is located in the United States. These providers process personal data only to provide, secure, and maintain the Health Journal service.
6.2 Payment processing
Subscription payments are processed by a PCI-DSS compliant payment provider. We do not store your full card details. The payment provider receives only what is necessary to process your subscription.
6.3 Other processors and recipients
Depending on the service you use and how you interact with us, recipient categories may include cloud hosting and infrastructure providers, payment processors, authentication and transactional email providers, customer-support systems, security monitoring and error-logging providers, contracted development or technical-support providers where they may access personal data, and professional advisers such as legal, accounting, or compliance advisers.
6.4 Legal obligations
We may disclose personal data if required to do so by law, regulation, or a binding order of a competent authority. We will notify you where legally permitted to do so.
6.5 Business transfers
In the event of a merger, acquisition, or sale of assets, personal data may be transferred as part of that transaction. We will notify affected users and ensure that any successor entity is bound by equivalent data protection obligations.
7. International data transfers
Because Health Journal uses cloud infrastructure and service providers that may process personal data outside the UK, your personal data may be transferred internationally, including to the United States.
Where we make restricted transfers of personal data, we use appropriate UK international-transfer safeguards. These may include applicable adequacy arrangements, the UK International Data Transfer Agreement, the UK Addendum to EU Standard Contractual Clauses, and associated transfer assessments where required.
8. Your rights under UK GDPR
You have the following rights over your personal data. You may exercise any of these rights by contacting our Data Protection Contact at privacy@healthjournal.app. We will respond within one calendar month.
| Article | Right | What this means for you |
|---|---|---|
| Art. 15 | Right of Access | Request a copy of all personal data we hold about you. |
| Art. 16 | Right to Rectification | Correct inaccurate or incomplete personal data. |
| Art. 17 | Right to Erasure | Delete your account and personal data (subject to legal retention obligations — see §9). |
| Art. 18 | Right to Restriction | Restrict processing while a dispute is resolved. |
| Art. 20 | Right to Portability | Export your health record in a structured, machine-readable format. |
| Art. 21 | Right to Object | Object to processing based on legitimate interests. |
| Art. 22 | Automated Decisions | Not subject to solely automated decisions with significant legal effect. |
You may also contact privacy@healthjournal.app to withdraw consent where we rely on consent, or to object to processing based on legitimate interests, including Community Insights processing.
9. Data retention
We retain your personal data only for as long as is necessary for the purposes described in this policy, and in accordance with our legal obligations. The table below summarises our retention schedule by data category.
| Data category | Retention period |
|---|---|
| Health journal entries, medications, conditions, treatments | Duration of account + up to 30 days after deletion |
| Account credentials and authentication records | Duration of account + up to 30 days after deletion |
| Subscription and billing records | 7 years (UK financial record-keeping obligation) |
| Pseudonymised security audit logs | Up to 12 months post account deletion (Article 17(3) — legitimate interest: security and fraud prevention) |
| Community Insights source data that remains identifiable or pseudonymised | Subject to the same account deletion and retention schedule as the underlying journal record |
| Genuinely anonymised Community Insights statistical outputs | May be retained after account deletion because they no longer relate to an identifiable member |
| Support communications | 3 years from last contact |
10. Security
We take the security of your health data seriously. Our measures include:
- Encryption in transit (TLS 1.2+) and at rest (AES-256)
- Magic link authentication
- Access controls and least-privilege architecture
- Detailed access logging — all access to personal data is recorded and auditable
- Regular security reviews led by a dedicated security lead
No method of transmission or storage is completely secure. If we become aware of a breach affecting your personal data, we will notify you and the ICO as required by law.
11. Cookies and tracking
We use a minimal set of cookies strictly necessary to operate the service, including authentication session management and security. We do not use advertising cookies, third-party tracking cookies, preference cookies, or any analytics that identify you individually.
Full details of the cookies we use are set out in our separate Cookie Policy, available at healthjournal.app/cookie-policy.
12. Children, young people, and family-managed records
Health Journal may be used by adults to manage their own records and, through family-managed records, to manage records for children in their care. Children and young people may also benefit from having a lifelong health record, particularly where they live with ongoing health needs.
Where parental authorisation is required by law or by Health Journal's account rules, a parent or guardian must authorise or manage the account. Family-managed records are controlled by the adult account holder until control is transferred to the child when appropriate. We intend to provide an age-appropriate process for transferring control as a child matures.
We are committed to handling children's information responsibly and in their best interests. In line with the UK Information Commissioner's Age Appropriate Design Code (Children's Code), we apply protective defaults and will provide age-appropriate privacy information where children use or take control of their records.
- Privacy settings are applied at their most protective level by default
- We do not profile children for commercial purposes
- We do not use children's data in ways that are detrimental to their wellbeing
- No data is ever sold or shared for advertising purposes
- We will use proportionate age-assurance and parental-authorisation measures where required
Children's health information may contribute to Community Insights only where lawful, appropriate safeguards are in place, and the processing is consistent with the child's best interests and applicable account settings.
These commitments are consistent with our subscription-only, zero data monetisation model, which applies equally to all users regardless of age.
13. Changes to this policy
We may update this policy from time to time. Where changes are material, we will notify members before those changes take effect. The version number and effective date at the top of this document will always reflect the current version. Where a change requires consent, we will obtain that consent separately.
14. Contact and complaints
For privacy questions, data-rights requests, objections, consent withdrawal, or complaints about how we handle personal data, contact our Data Protection Contact at privacy@healthjournal.app.
For general product support, contact support@healthjournal.app.
If you make a data-protection complaint, we will acknowledge it, investigate it, communicate the outcome, and explain your right to complain to the Information Commissioner's Office (ICO).
- Website: healthjournal.app
- I Own My Health Ltd, registered in England and Wales, Company Number 17313073
If you wish to make a complaint to the supervisory authority, you can contact:
- Information Commissioner's Office (ICO)
- ico.org.uk · 0303 123 1113
15. US privacy supplement
Before Health Journal is launched in the United States, we intend to publish a separate US privacy and consumer-health-data supplement. That supplement will address applicable US state consumer-health-data requirements and US breach-notification obligations, including requirements that may apply to consumer health apps outside HIPAA.
Health Journal is operated by I Own My Health Ltd. Registered in England and Wales, Company Number 17313073. UK GDPR data controller. Privacy Policy v2.1 — July 2026.