Privacy policy
Last updated: October 3, 2026Who is responsible
Journey-Log is run by a private individual, the operator named in the imprint, who is responsible for processing your data. For anything about your data, write to info@journey-log.com.
Your account
When you register, we store your name, your email address and a securely hashed password. If you sign in with Google, we receive your name, email address and profile picture from Google. We use this data to run your account and to send you emails you need, such as the email confirmation and password resets.
Your entries and photos
We store the entries, journeys, photos and likes you create. You choose who sees each entry and journey: public ones can be seen by anyone, including search engines; link-only ones by anyone you give the link to (revoking the link makes a new one); private ones only by you.
When you upload a photo, we read the date and location your camera stored and keep them privately, only to suggest where and when a photo was taken. They are never shown to anyone, including you, and are deleted with the photo. The stored photo itself has all metadata removed, including the GPS location.
Deleted entries, journeys and photos stay in your Trash for 30 days and are then removed for good.
Your profile page shows your name, username, tagline, bio, home country, follower counts and public entries. You can make it private in Settings. Comments you write are visible to everyone who can see the entry. We keep who you follow and block, and the entries you save (only you see your saved list). When you report something, we keep the report so it can be reviewed.
When you invite a co-author, we store the username or email address you entered and send them one invite email; open invites expire after 30 days. Co-authors of a journey can see its published entries, including private ones. We keep your notifications (who did what, and when) until you delete your account, and send notification emails only as a weekly digest, if you switch it on. An export is a zip file we build when you ask for it and keep for 7 days; its download link goes only to your email address.
When you or someone else shares a link to a public or link-only entry, journey or profile, apps like WhatsApp or Facebook show a preview image with its title, the author's name and a cover photo. We create these images on request and don't store them.
Server logs
When you use the site, our server records technical data such as your IP address, the requested page and the time. We use it to keep the service secure and to prevent abuse, for example with request limits. The logs are rotated automatically and kept only for a short time.
Cookies
We use a login cookie to keep you signed in and a language cookie to remember your language. Both are necessary for the site to work. Analytics cookies from PostHog are only set if you accept them. You can change your choice at any time with "Cookie settings" at the bottom of every page.
Analytics
If you agree, we use PostHog to understand how the site is used, for example which pages are visited and where errors occur. When you are signed in, this includes your user ID, name and email address. PostHog stores the data in the EU.
Separately, when our server runs into an error, it sends an error report to PostHog so we can fix it: the error, where in our code it happened and the kind of request. It doesn't include cookies, your IP address or your account.
Legal bases
We process your account, your content and the emails you need in order to provide the service you signed up for (Art. 6(1)(b) GDPR). Server logs, rate limits, server error reports and reports about content are based on our legitimate interest in a secure and working service (Art. 6(1)(f) GDPR). Analytics only run with your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time.
Service providers
These providers help us run Journey-Log and process data only on our behalf: OVHcloud (server hosting, Germany), Cloudflare (domain, email forwarding and photo storage), Resend (sending emails, USA), PostHog (analytics, EU, only with your consent; and our server's error reports) and Google (sign-in, only if you use it). To turn places into map pins and a photo's location into a place name, our server asks OpenStreetMap's Nominatim service, with locations rounded to about 1 km and without your identity. When a page shows a map (a journey, its map, a profile, or a share image you make), your browser loads the map images from OpenFreeMap (openfreemap.org), which sees your IP address. Where data leaves the EU, it is protected by the providers' standard contractual clauses.
How long we keep data
We keep your data for as long as you have an account. Things you delete stay in your Trash for 30 days, then they are removed. When you delete your account, your profile, entries, journeys, likes and photos are hidden immediately and deleted after 30 days; signing in again within that time cancels the deletion. Copies in our backups are deleted automatically after at most 30 days.
Your rights
You can ask for access to your data, have it corrected, deleted or its processing restricted, get a copy of it, object to its processing and withdraw your consent at any time. You can delete your account yourself in Settings; for everything else, write to info@journey-log.com.
You can also complain to a data protection authority: in Hungary the NAIH (naih.hu), in other EU countries the authority of your country, in Switzerland the FDPIC (edoeb.admin.ch).
Age
Journey-Log is intended for people aged 16 and over.