Privacy Policy
Built privacy-first. Here's exactly what the app handles, where it lives, and what we never do.
The short version: Your entries — words, photos, voice memos, places, moods — live on your devices and in your own private iCloud account. If you use Mark on a computer, what reaches our server is sealed on your device first: we store it, and we can't read it. Email to Mark is the one exception, and it's sealed the moment it arrives. No ads, no trackers, no analytics, nothing sold — ever.
This Privacy Policy explains how Mark — the iOS and iPadOS app, and its web companion at markjournal.app (together, the "App") — provided by Mark Pernitsch, operating as northOS (a sole proprietorship) ("we," "us"), handles your information.
Everything you create in Mark is saved on your device and synced through Apple iCloud (CloudKit) using your own Apple ID. That is where your journal lives, and we cannot access, read, or retrieve it there. A few preferences — your favorites and appearance choices — sync through iCloud key-value storage, also in your own account. Apple's handling of iCloud data is governed by Apple's Privacy Policy.
Nothing reaches our own server unless you use one of the optional features in sections 03–05: writing on a computer, emailing a moment to Mark, or reading your journal on the web.
Mark asks for a permission only when a feature needs it, and only with your consent. What's read stays on your device unless you add it to an entry:
Journaling suggestions from Apple, if you choose one, are picked on your device through Apple's own panel. Importing a Day One export happens entirely on your device.
At markjournal.app you can write on a computer and finish on your phone. When you pair a computer — by scanning its code with your iPhone, or typing a six-digit code — your phone hands the browser a key that never passes through us in readable form. Everything you write there is encrypted in the browser before it's sent.
If you turn it on — you'll be asked once when you pair a computer, and there's a switch in Settings › web app — your iPhone or iPad sends a copy of your journal to our server so you can read it on markjournal.app: entries, photos, voice memos, thread names and favorites. Each item is encrypted end to end on your device with a key only your devices and paired browsers hold.
If you turn on your private Mark address, you can email a moment to your journal. Email arrives as ordinary email, so our server necessarily sees that message while it handles it: it reads the subject, the text, and the photos, seals them at once to a key that only your phone holds, and stores only the sealed copy until your phone collects it (at most 30 days). We don't keep the unsealed message, we don't log its contents, and we don't store the sender's address with it. Mail to an address with no phone behind it is refused.
Premium is sold through Apple In-App Purchase. Apple processes the payment; we never receive card or payment details. For the web journal only, the App sends our server Apple's signed record of your purchase — the product, its dates, and Apple's transaction number — or, if you've had Mark since before Premium, Apple's signed record of when you first got the App, or, for family access, your family phrase. We check it, then keep only the date your access runs to and a link between that purchase and the fingerprint in section 03 (so one purchase can't be passed around).
Mark doesn't share your entries with anyone. When you share a recap card or an entry, it's made on your device and you send it through the app you choose.
There are no third-party analytics, advertising, attribution, or tracking SDKs in the App, and we never sell or share data for advertising. We rely on:
Cloudflare's servers may be outside Québec and Canada. What we store there is sealed so that neither Cloudflare nor we can read it — except an emailed moment during the moment it is sealed.
Mark is not directed to children under 13, and we do not knowingly collect personal information from children.
Your journal lives in your iCloud, so you control it: delete any entry in the App (it waits 30 days in recently deleted, then it's gone), or remove the App's data in your device's iCloud settings. You can export your journal from Settings at any time. On our server: drafts go after 30 days or when your phone takes them; emailed moments when your phone collects them or after 30 days; the web journal copy when you turn it off, stop syncing, or 90 days after Premium ends. Unpairing a computer erases what that browser holds.
The person responsible for protecting personal information at northOS is Mark Pernitsch, reachable at support@northos.xyz. You may ask what information we hold about you, have it corrected, or have it deleted; because what we store is sealed and anonymous, the quickest way is usually to turn the feature off in the App, which deletes it. We'll answer within 30 days. If you're in Québec and not satisfied with our answer, you may contact the Commission d'accès à l'information. If a confidentiality incident ever risked serious harm to you, we would tell you and the authorities as the law requires.
If we update this policy, we'll revise the date above and, for material changes, note it in the App or on this page.
Questions about privacy? Email support@northos.xyz or visit mark.northos.xyz/support.