Privacy Policy

How we protect and handle your personal information with care

Last updated: June 14, 2025

Information We Collect

We collect information you provide directly to us, such as when you create an account, write journal entries, or contact us for support. This includes your name, email address, and journal content.

End-to-End Encryption

Your privacy is our top priority. All journal entries are protected with end-to-end encryption using AES-256-GCM encryption with PBKDF2 key derivation. This means your journal content is encrypted on your device before being sent to our servers, and only you can decrypt and read it.

FERPA Compliance

When contracted by an educational institution, ZenQuill operates as a “school official” under the Family Educational Rights and Privacy Act (FERPA) with a “legitimate educational interest” in the student data it processes. Student education records are protected through encryption, access controls, and PII anonymization before any external AI processing.

Parents and eligible students may request access to, amendment of, or deletion of their education records at any time.

View Full Compliance Documentation

How We Use Your Information

We use the information we collect to:

Provide, maintain, and improve our services
Process journal entries for AI analysis
Send technical notices and support messages
Monitor and analyze usage patterns

AI Analysis and Processing

When you use our AI analysis features, your encrypted journal entries are temporarily decrypted on our secure servers to provide insights and analysis. This processing is done using OpenAI and Hume AI services. Your decrypted content is never stored permanently and is immediately re-encrypted after analysis.

Galaxy Team Data Sharing

When you join a Galaxy (team workspace), you agree to share certain performance data with your coaches and team administrators:

Data Shared with Coaches:

Your Zen Card scores and attribute ratings
Your baseline assessment results and category scores
Assignment completion status and progress
Skill drill completion records

Data NOT Shared:

Your journal entries remain private and encrypted (only AI-generated summaries visible to coaches, never raw content)
Your meditation session details
Your personal account information

This sharing is necessary for coaches to provide personalized training guidance and monitor team progress. You can leave a Galaxy at any time to stop sharing data with that team. By joining a Galaxy, you acknowledge and consent to this data sharing arrangement.

Information Sharing

We do not sell, trade, or otherwise transfer your personal information to third parties, except:

With your explicit consent
To comply with legal obligations
With trusted service providers

Data Retention

We retain your information for as long as your account is active or as needed to provide services. You may delete your account at any time, resulting in permanent deletion of your encrypted journal entries.

Third-Party Services

We use select third-party services to provide our features:

OpenAI

For journal analysis and AI insights

Hume AI

For emotion recognition in voice journals

Stripe

For secure payment processing

Cloudinary

For image storage and processing

Neon

For secure database hosting

Security Measures

We implement industry-standard security measures including:

End-to-end encryption for all journal content
Secure SSL connections for data transmission
Regular security audits and updates
Limited access by authorized personnel only

Your Rights

You have the right to:

Access and download your personal data
Correct inaccurate information
Delete your account and associated data
Opt out of marketing communications
Request information about data processing

Minor Athletes & Parental Consent

ZenQuill requires parental or guardian consent before any athlete under 18 can access the platform. When a minor athlete signs up, they must provide their parent or guardian's name, email address, and phone number. The parent or guardian is then contacted via email and SMS to approve or decline their child's account. The minor cannot access any ZenQuill features until approval is received.

What parents receive: Parents are notified in three scenarios only: (1) the initial account approval request, (2) an urgent safety alert if ZenQuill detects concerning content in their child's activity, and (3) a wellness check-in suggestion if elevated stress is detected. No journal entries, Zen Card scores, or specific content are ever shared with parents. Alerts are general wellness notifications only.

What parents cannot see: Parents do not have a login, account, or dashboard on ZenQuill. They cannot view their child's journal entries, mental performance reports, Zen Card, or any content submitted by the athlete. This boundary exists to protect the athlete's ability to journal honestly and openly.

Consent records: When a parent approves their child's account, we log the parent's name, email, phone number, the date and time of approval, the channel through which approval was given, and the version of the disclaimer acknowledged. This record is retained indefinitely for legal compliance purposes.

Our service is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If we become aware that we have collected such information, we will take steps to delete it promptly.

SMS Communications

ZenQuill sends SMS text messages to parents and guardians of minor athletes in the following scenarios:

  • Parental consent requests: A one-time message when a minor athlete signs up, asking the parent to approve their child's account.
  • Urgent safety alerts: If ZenQuill's monitoring system detects concerning content in a minor athlete's activity, the parent receives an SMS with crisis resources. No journal content is included.
  • Wellness check-in notifications: If the system detects elevated stress, the parent receives a brief SMS suggesting they check in with their child. No journal content is included.

All SMS messages are transactional and triggered by specific platform events. We do not send marketing messages, promotional content, or recurring campaigns. Message and data rates may apply.

Parents consent to receive SMS messages when they approve their child's ZenQuill account. Parents may opt out of SMS notifications at any time by contacting support@zenquill.ai. Opting out of SMS does not affect email notifications.

International Users

If you are accessing our service from outside the United States, please note that your information may be transferred to, stored, and processed in the United States where our servers are located.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date. Significant changes will be communicated via email.

Questions About Your Privacy?

If you have any questions about this Privacy Policy or our privacy practices, please contact us through the feedback system in the application or reach out to our support team.

Contact Support