Privacy Policy

Last updated: October 4, 2026

This policy explains what data Acornlog (“we”, “us”) collects when you use acornlog.com, why we collect it, who we share it with and how you can control it. In short: your journal is yours. We only use your data to run the app for you, and we never sell it.

Who is responsible

Acornlog is run by Lukas Kesch, who is the controller of your data under the GDPR. You can reach me at mail@kesch.dev. See also the Imprint.

Data we collect

Your Google account

You sign in with Google. We only ask Google for your basic profile (the openid, email and profile scopes) and store your Google account ID, name, email address and profile picture. We don't get access to your Gmail, Drive, contacts, calendar or any other Google data.

What you put into Acornlog

  • Activities: their descriptions, start and end times, durations and tags
  • A live timer while it is running
  • Tags and tag groups
  • Habits, their settings, check-offs and notes
  • Diary questions, how often they come up, and your answers to them

Stored in your browser

  • Session cookie: keeps you signed in. It is HTTP-only and expires after 30 days.
  • Time zone cookie: your browser's time zone, so days and times show correctly.
  • Preferences: your light or dark mode choice and your answer to the analytics question, kept in your browser's local storage.

Analytics, only if you agree

If you accept the cookie question, we use Google Analytics to see how many people visit and which pages they use. Google Analytics sets its own cookies and receives data like the pages you view, your browser and device type and an approximate location derived from your IP address. If you decline, Google Analytics is not loaded at all. To change your answer, clear this site's data in your browser and you'll be asked again.

How we use your data

  • To sign you in and keep your account separate from everyone else's
  • To show, sync and calculate your activities, habits, streaks and diary
  • To turn a description of your day into suggested activities, when you use that feature
  • To turn what you say you learned into notes and flashcards, or suggest flashcards for a note, when you use those features
  • To understand and improve the site, if you agreed to analytics

We don't use your data for advertising, we don't build profiles of you for anyone else, and we don't read your journal except when you ask us to help with a problem or when the law requires it.

Describe your day

When you use “Describe your day”, the text you enter is sent to OpenAI to turn it into suggested activities. Along with it we send the names of your tags and the activities you already logged that day, so the suggestions fit what you have. We ask OpenAI not to store the request. Nothing is saved to your journal until you review the suggestions and save them. If you don't use this feature, nothing is sent to OpenAI.

Learning

When you add a learning, the text you enter is sent to OpenAI to write it up as notes with flashcards. Along with it we send the names of your learning topics and the titles of your recent notes, so new notes are filed under the right topic. We ask OpenAI not to store the request. Nothing is saved until you review the notes and save them. When you use “Generate flashcards” on a note, its title, topic, text and existing flashcards are sent to OpenAI the same way. Writing and editing notes yourself and reviewing flashcards doesn't send anything to OpenAI.

Who we share data with

We don't sell your data, and we don't share, transfer or disclose it to advertisers, data brokers or anyone else. We use these service providers to run Acornlog, and they process data only on our behalf:

  • Vercel: hosts the app
  • Neon: hosts the database
  • Google: sign-in, and Google Analytics if you agreed to it
  • OpenAI: only for “Describe your day” and adding learnings, as described above

We may disclose data if the law requires it, for example in response to a valid court order.

Google user data

Acornlog's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We only use your Google account ID, name, email address and profile picture to sign you in and show your account, and we don't transfer them to anyone except the service providers listed above.

How we protect your data

  • All traffic to and from Acornlog is encrypted with TLS.
  • The database is encrypted at rest.
  • Every request checks that you can only see and change your own data.
  • We ask Google for the minimum sign-in scopes.
  • Access to the production systems is limited to the people who run Acornlog.

How long we keep it

We keep your data for as long as you have an account. When you delete your account in the app, it and everything in it are deleted right away. When you ask us by email, we delete it within 30 days.

Your choices and rights

  • Edit or delete entries at any time in the app.
  • Delete your account and all of its data under Profile → Delete account. You can also email us at mail@kesch.dev from the address you sign in with.
  • Get a copy of your data as a JSON file under Profile → Download my data, or email us to get a copy or to ask us to correct it.
  • Remove Acornlog's access to your Google account at any time in your Google account settings.

Depending on where you live, for example in the European Union, you may have further rights, such as to object to or restrict how we process your data, and to complain to your data protection authority. Contact us and we'll help.

Children

Acornlog is not meant for children under 16, and we don't knowingly collect their data. If you believe a child has created an account, contact us and we'll delete it.

Changes to this policy

If we change this policy, we'll update the date at the top. If the change is significant, we'll email you before it takes effect.

Contact

Questions or requests about your data: mail@kesch.dev. See also our Terms of Service and Imprint.