Bethany
Privacy
Bethany is a private journal. What you write is yours, it is not shared, and it is not used to build a profile of you. This page says exactly what is stored and why.
What we store
- Your account
- Your name, email address, timezone, and a one-way hash of your password. The password itself is never stored and cannot be recovered from the hash.
- What you write
- Your daily reflections, your goals, how each goal turned out, and any notes you add about why. This is the content of the service.
- Your settings
- Your reminder time, statistics window, and theme preference.
- Security records
- The IP address and email address used for each sign-in attempt, kept for 24 hours to limit password guessing. Session and "keep me signed in" tokens, stored hashed.
There is no analytics package, no advertising, no tracking pixels, and no third-party scripts of any kind. Nothing about your use of Bethany is sent anywhere else.
Cookies
Two, both strictly functional. A session cookie keeps you signed in while you use the app. If you tick "keep me signed in", a second cookie holds a token that lets you return without signing in again; it lasts 30 days, rotates each time it is used, and is invalidated entirely if you change your password or sign out. There are no advertising or analytics cookies, so there is nothing to consent to.
We send email only for things you asked for: confirming your address, resetting your password, and — if you switch them on — one daily reminder at an hour you choose. You can turn reminders off in settings at any time. We do not send marketing email.
Mail is delivered through our hosting provider's mail service. The contents of a reminder never include what you have written.
Keeping it and deleting it
Your writing is kept for as long as your account exists. Sealed days cannot be edited — that is a rule about editing, not a claim on ownership.
If you delete your account, everything goes with it: entries, goals, notes, settings, tokens and the account record itself. This is permanent and immediate, and cannot be undone. Security records containing your email may persist for up to 24 hours until they expire.
Security
Traffic is served over HTTPS. Passwords are hashed with bcrypt. Sign-in and reset tokens are stored as hashes, so the values in the database cannot be used to access an account. Sign-in attempts are rate-limited.
No system is perfectly secure, and Bethany is run by one person. Please do not store anything here that would seriously harm you if it were exposed.
Your choices
You can see everything stored about you from within the app, correct your name, email, timezone and settings at any time, and delete your account and all its contents. If you are in California, the CCPA gives you rights to know, delete, and correct your personal information, and not to be discriminated against for exercising them. Bethany does not sell or share personal information, so there is nothing to opt out of.
To make a request, email hihello@bethany.devnascode.com.
Children
Bethany is not intended for anyone under 13, and accounts are not knowingly created for them. If you believe a child has created an account, email us and it will be removed.
Changes
If this policy changes in a way that materially affects what is collected or how it is used, the date at the top will change and you will be told before it takes effect.