Privacy Policy

your life is yours.

Built privacy-first. Here's exactly what the app handles, where it lives, and what we never do.

Updated · September 25, 2026 (first published June 4, 2026)
Provider · Mark Pernitsch, operating as northOS (a sole proprietorship)

The short version: Your entries — words, photos, voice memos, places, moods — live on your devices and in your own private iCloud account. If you use Mark on a computer, what reaches our server is sealed on your device first: we store it, and we can't read it. Email to Mark is the one exception, and it's sealed the moment it arrives. No ads, no trackers, no analytics, nothing sold — ever.

This Privacy Policy explains how Mark — the iOS and iPadOS app, and its web companion at markjournal.app (together, the "App") — provided by Mark Pernitsch, operating as northOS (a sole proprietorship) ("we," "us"), handles your information.

01where your data lives

Everything you create in Mark is saved on your device and synced through Apple iCloud (CloudKit) using your own Apple ID. That is where your journal lives, and we cannot access, read, or retrieve it there. A few preferences — your favorites and appearance choices — sync through iCloud key-value storage, also in your own account. Apple's handling of iCloud data is governed by Apple's Privacy Policy.

Nothing reaches our own server unless you use one of the optional features in sections 03–05: writing on a computer, emailing a moment to Mark, or reading your journal on the web.

02device permissions — what each is for

Mark asks for a permission only when a feature needs it, and only with your consent. What's read stays on your device unless you add it to an entry:

  • Camera & Photos — to attach photos to an entry, and to show recent photos on Today and in the composer. When you keep a moment that arrived by email, Mark can save its photos to your library at full size.
  • Microphone — for voice memos, saved with your entries, and for dictation.
  • Speech Recognition — dictation is transcribed on your device; the text becomes part of your entry.
  • Location — opt-in, per entry. When you pin where a moment happened, your coordinates go to Apple's Maps services to find a place name. We never track you in the background.
  • Calendar — read-only, to show today's events on Today. Nothing is written back.
  • Health — read-only, if you tap the activity row: a walk, a run, the day's steps. Nothing is written to Health, and nothing is shared.
  • Apple Music — if you tap the music row, Mark notes the song playing and its cover in your entry. Your library is read on your device.
  • Notifications — reminders scheduled on your device. There is no push server.
  • Face ID — an optional lock for the App. iOS handles it; we never see biometric data.

Journaling suggestions from Apple, if you choose one, are picked on your device through Apple's own panel. Importing a Day One export happens entirely on your device.

03writing on a computer

At markjournal.app you can write on a computer and finish on your phone. When you pair a computer — by scanning its code with your iPhone, or typing a six-digit code — your phone hands the browser a key that never passes through us in readable form. Everything you write there is encrypted in the browser before it's sent.

  • What our server stores — the sealed draft (which we can't open), plus an identifier, the time it changed, and its size. A draft is deleted after 30 days, or as soon as your phone takes it. A small marker — an identifier, "kept" or "discarded", and a date — stays for 90 days so every computer learns what happened to it.
  • Pairing — the key your phone hands over is wrapped by the code and held for at most ten minutes, then destroyed on first use.
  • Who you are to us — nobody. There's no account, name, or email. Your devices and browsers are recognised by a code derived from that key; we store only a one-way fingerprint of it.

04your journal on the web (Premium)

If you turn it on — you'll be asked once when you pair a computer, and there's a switch in Settings › web app — your iPhone or iPad sends a copy of your journal to our server so you can read it on markjournal.app: entries, photos, voice memos, thread names and favorites. Each item is encrypted end to end on your device with a key only your devices and paired browsers hold.

  • What our server can see — for each item: an identifier, what kind of item it is, when it last changed, and its size. Never its words, pictures, sounds, dates, or places.
  • In your browser — the web page keeps the sealed copy in the browser's own storage so it opens quickly, and decrypts it only in memory. Unpairing the computer erases it.
  • Turning it off — deletes the web copy from our server at once. So does "stop syncing". If Premium ends, the web copy becomes read-only and is deleted 90 days later.
  • Your journal itself — stays on your devices and in your iCloud. The web copy is only a copy.

05email to Mark (Premium)

If you turn on your private Mark address, you can email a moment to your journal. Email arrives as ordinary email, so our server necessarily sees that message while it handles it: it reads the subject, the text, and the photos, seals them at once to a key that only your phone holds, and stores only the sealed copy until your phone collects it (at most 30 days). We don't keep the unsealed message, we don't log its contents, and we don't store the sender's address with it. Mail to an address with no phone behind it is refused.

06Premium and how we check it

Premium is sold through Apple In-App Purchase. Apple processes the payment; we never receive card or payment details. For the web journal only, the App sends our server Apple's signed record of your purchase — the product, its dates, and Apple's transaction number — or, if you've had Mark since before Premium, Apple's signed record of when you first got the App, or, for family access, your family phrase. We check it, then keep only the date your access runs to and a link between that purchase and the fingerprint in section 03 (so one purchase can't be passed around).

07sharing

Mark doesn't share your entries with anyone. When you share a recap card or an entry, it's made on your device and you send it through the app you choose.

08service providers and where data is stored

There are no third-party analytics, advertising, attribution, or tracking SDKs in the App, and we never sell or share data for advertising. We rely on:

  • Apple — iCloud, the App Store, Maps, Speech, and the other system frameworks above.
  • Cloudflare, Inc. — hosts markjournal.app and its storage, and routes email to Mark. Like any web host, it processes technical information such as IP addresses to deliver and protect the service; our own server logs keep no content and are kept only a few days. We use a visitor's IP address, for one minute, to limit repeated pairing attempts.

Cloudflare's servers may be outside Québec and Canada. What we store there is sealed so that neither Cloudflare nor we can read it — except an emailed moment during the moment it is sealed.

09children

Mark is not directed to children under 13, and we do not knowingly collect personal information from children.

10keeping and deleting your data

Your journal lives in your iCloud, so you control it: delete any entry in the App (it waits 30 days in recently deleted, then it's gone), or remove the App's data in your device's iCloud settings. You can export your journal from Settings at any time. On our server: drafts go after 30 days or when your phone takes them; emailed moments when your phone collects them or after 30 days; the web journal copy when you turn it off, stop syncing, or 90 days after Premium ends. Unpairing a computer erases what that browser holds.

11your rights, and who is responsible

The person responsible for protecting personal information at northOS is Mark Pernitsch, reachable at support@northos.xyz. You may ask what information we hold about you, have it corrected, or have it deleted; because what we store is sealed and anonymous, the quickest way is usually to turn the feature off in the App, which deletes it. We'll answer within 30 days. If you're in Québec and not satisfied with our answer, you may contact the Commission d'accès à l'information. If a confidentiality incident ever risked serious harm to you, we would tell you and the authorities as the law requires.

12changes to this policy

If we update this policy, we'll revise the date above and, for material changes, note it in the App or on this page.

13contact

Questions about privacy? Email support@northos.xyz or visit mark.northos.xyz/support.