Privacy Policy
Last updated: 11 August 2026 (draft aligned to current LoJoRi mobile app behavior).
1. Who we are
LoJoRi (“we”, “us”) is a mobile journaling and decision-support product for traders. This policy describes categories of information the current product processes.
2. Contact
- Support contact (also for privacy questions): support@lojori.com
- In-app: Settings → Closed Beta feedback (share template) and Settings → account deletion for signed-in users
3. Information we process
3.1 Account authentication
LoJoRi uses Firebase Authentication (email/password). We process authentication identifiers such as your account email and Firebase user id to create and secure your account.
3.2 Profile
Profile fields stored in cloud data (Firestore) may include email, first name, account currency, experience level, markets, trading style, preferred session, starting balance, default risk percentage, account type, onboarding status, checklist preference, and related timestamps.
3.3 Journal and trading records
When you use the product, we store user-owned journal data under your account, including trades (and nested review/checklist content), notes, tags, goals, challenges, and import batch history associated with broker file imports.
3.4 Learning records
Learning commit records associated with your account may be stored in cloud data. Client apps create these records; trusted server deletion removes them with your account tree.
3.5 Import and export
Import flows read broker files you select on device and may create import history and trades in your account. Export flows generate PDF/CSV reports on device for sharing via the operating system share sheet. Exported files leave LoJoRi when you choose to share them.
3.6 Local device data
Some data stays on your device, including:
- Coach chat conversations scoped to your account
- Trading preferences, suggestions, and context presets scoped to your account
- Device-level preferences such as language/locale, product-analytics sharing preference, and AI “include notes” preference
- Device-global coach history that is not bound to an account id on the stored items
3.7 Crash diagnostics (Sentry)
When crash reporting is enabled for a build, technical crash and error diagnostics may be sent to Sentry. LoJoRi configures privacy-oriented defaults (for example, default PII sending disabled and message/context sanitization). Crash reporting is separate from the in-app product-analytics toggle.
3.8 Product analytics (PostHog)
When product analytics is enabled for a build and you have not opted out, LoJoRi may send a strict allowlist of anonymous product-usage events (for example screen/feature opens) to PostHog. Journal text, coach conversations, AI content, and trading results are not intended to be sent as telemetry content. You can turn off product analytics in Settings. Missing preference defaults to sharing on; a read failure fails closed to off.
3.9 Production AI backend
The production AI backend capability is currently disabled. Local coach behavior and mock AI modes may still operate without a production AI backend transport. This policy will need updating if a production AI backend is enabled later.
4. Processors / service providers
LoJoRi uses third-party processors to operate the product. Current processors reflected in the implementation include:
- Google Firebase (Authentication, Firestore, Cloud Functions)
- Sentry (crash diagnostics, when enabled)
- PostHog (product analytics, when enabled and not opted out)
- Apple / Google platform services for app distribution, OS share sheets, and device storage APIs
These providers process data on our behalf as part of providing the service. This draft does not claim absence of third-party processing.
5. Purposes
- Provide account, journaling, goals, import/export, and coaching features
- Secure authentication and account lifecycle (including deletion)
- Improve reliability via crash diagnostics
- Understand product usage via opt-outable analytics allowlist
- Respond to support and deletion requests you submit
6. Security
Access to cloud user data is gated by authentication and Firestore security rules that restrict user documents to the signed-in owner. Sensitive account deletion requires recent reauthentication. This draft does not claim SOC/ISO certifications or specific encryption-at-rest guarantees beyond what the underlying providers document.
7. Retention
Account-associated cloud data is retained while your account exists. After a successful account deletion, Firebase Authentication and the account’s Firestore user tree are removed by the trusted deletion backend. Some device-level preferences and device-global coach history may remain on the device after account deletion. Crash and analytics systems retain data according to those providers’ retention settings and our project configuration.
8. Account deletion
You can delete your account:
- In the LoJoRi app (Settings → Delete account), after password confirmation — this performs authenticated deletion via the trusted backend and then clears account-owned local app data
- Via the public deletion request page at /delete-account, which starts a verified support request (it does not delete an account merely because someone knows an email address)
Successful deletion removes, in particular:
- Firebase Auth account
- Cloud user tree under your account (profile, trades, imports, goals, challenges, learning records)
- Account-owned local files/state after in-app deletion completes (for example coach chat and trading preference files for that account)
Typically retained on device after deletion:
- Language/locale preference
- Product-analytics sharing preference
- AI include-notes preference
- Device-global coach history that is not account-bound
9. International processing
Firebase, Sentry, and PostHog may process data in regions configured for the LoJoRi project (for example Cloud Functions in europe-west4; PostHog host configuration may target EU or US ingest). Exact residency depends on project and provider settings and should be confirmed in operations configuration before making stronger residency claims.
10. Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, or export personal data, or to object to certain processing. You can export journal data from the app, adjust analytics sharing in Settings, and request deletion as described above. This section is not legal advice and does not assert a specific statutory legal basis or GDPR certification.
11. Children
LoJoRi is intended for adults who trade or journal trading activity. It is not directed to children.
12. Changes
We may update this draft as the product or processors change. Material changes should be reflected on this page with an updated date.
13. Contact for privacy questions
Email support@lojori.com (support inbox; no separate privacy@ alias yet) or use Support.
