Changelog
A history of changes to Onsen's legal documents.
This page tracks all changes to our Terms of Use and Privacy Policy. We keep this updated so you can see exactly what changed and when.
Terms of Use
Version 1.1 — 9 May 2026
Minor update describing Onsen's new image features. No changes to user rights or obligations.
- AI features and limitations now mentions image attachments in chat and the avatar photo face-reference for personalised journal entry images, sent to AI providers under the same data-handling terms as text.
- Plans and pricing calls out that image attachments and personalised journal entry images are Premium features, with a link to the Plans doc.
- Your content adds one line confirming that by attaching an image you have the right to share it and that it does not include other identifiable people without their consent.
- View archived version.
Version 1.0 — 1 April 2026
Initial version. First Terms of Use document for Onsen.
Privacy Policy
Version 2.6 — 29 September 2026
One addition about how we measure our own ads on iPhone.
- Google's on-device conversion measurement is now in the iPhone and iPad app (from version 2.17.1). It lets Google Ads tell, on your device, whether one of our ads led to an install, without identifiable information leaving your device. The attribution section explains it, with a link to Google's general page on how it uses information from apps that use its services.
Version 2.5 — 24 September 2026
A new attribution tool, and email on one service instead of two.
- AppsFlyer replaces Adjust for install attribution from app version 2.17.0. Earlier app versions use Adjust until you update.
- Google Ads added to the data-sharing table, for measuring our ad campaigns.
- Mailchimp removed. Product update emails moved to OneSignal, already listed for push notifications.
Version 2.4 — 23 August 2026
Two corrections so the policy matches what the app actually does, and one processor removed.
- Google (Gemini) removed. We stopped using Gemini in August 2026. It is gone from the AI providers section and the data-sharing table, and no data is sent to Google.
- Advertising identifiers, described properly. The previous version listed advertising identifiers under "What we do not collect". That was wrong: Adjust, our attribution tool, receives your Google advertising identifier on Android, and your Apple identifier on iOS only if you allow tracking when prompted. A new "Attribution and advertising identifiers" section explains exactly what is collected, what it is used for, and confirms it is never joined to your journal entries or conversations. Nothing about the app's behaviour changed — the previous description of it was inaccurate, and we have corrected it.
- AWS Bedrock search reranking is now explicitly noted as running in the EU (Germany).
- New "Two things that take a little longer" section under account deletion. The policy said your data was "fully erased" within 30 days without mentioning backups or security logs. Backups roll over within a further 7 days, and security logs holding account identifiers — never your writing — are kept for up to 12 months so a security incident can be investigated. Nothing about our practice changed; we were describing it incompletely.
- No re-consent required: no new data is collected, no purpose is added, and one processor was removed. View archived version.
Version 2.3 — 31 July 2026
Minor update introducing journal entry sharing. Sharing is opt-in per entry; nothing changes for entries you don't share, and no defaults change.
- New "Sharing journal entries" section: explains public links (a web snapshot anyone with the link can view) and direct shares (one named person, invitation by email, a rewritten copy they can add to their journal), and that stopping a share removes the page and any copies — including what the AI derived from them.
- Recipient email addresses: new data point, stored with a direct share to deliver the invitation and restrict access to that person; deleted with the share.
- Retention table: new rows for shared entry links and for copies of entries shared with you.
- "At a glance" gains "What happens if I share a journal entry?".
- Invitation emails are delivered through OneSignal (already listed as a processor); they contain the sharer's first name and a link, never entry content.
- No re-consent required: sharing is a new opt-in feature and no existing rights, defaults, or data uses change. View archived version.
Version 2.2 — 9 May 2026
Minor update introducing Onsen's new image features. Default behaviour is unchanged — these additions only apply when you opt in to the relevant Premium features.
- Image attachments in chat (Premium): New data category. Images you attach to chat messages are stored privately on AWS S3 (EU, Ireland, user-scoped path), sent to AI providers so the AI can respond to what you're showing it, and deleted when you remove the message or your account.
- Avatar photo retention for personalised journal entry images (Premium): Previously, the photo you took for your avatar was used once to detect appearance attributes and then deleted. Now, when you add a photo during avatar setup, Onsen keeps it securely on AWS S3 (EU, Ireland, user-scoped path) and uses it as a face reference when generating personalised journal entry images. If you'd rather not have a photo stored, you can skip adding one during avatar setup and enter your appearance attributes manually instead. Deleting your account permanently removes the photo along with the rest of your data.
- Updated AI Providers section to reflect vision (image inputs) and image generation with optional face reference.
- Added new "Image attachments" and "Avatar photo" subsections under "What we collect", with new rows in the data and retention tables.
- Existing users will be asked to re-consent inside the app via the standard consent flow. View archived version.
Version 2.1 — 1 April 2026
Minor update. Added disclosure that feedback may be featured on the website or marketing materials with user consent. Feedback displayed without consent is always shown anonymously.
- Added "Feedback and testimonials" subsection under "How we use your data"
- Updated "Feedback and ratings" row in data table to include testimonial use and consent basis
Version 2.0 — 1 April 2026
Initial version of the rewritten privacy policy. This replaces the previous version (effective 1 March 2026) with a complete rewrite for clarity, accuracy, and legal completeness.
Key changes from version 1.0:
- Added plain-language summary ("At a glance") at the top
- Added dedicated AI processing section
- Added special category (health) data disclosure and consent basis
- Added content safety system disclosure
- Added specific data retention periods for all data types
- Added detailed account deletion timeline (immediate + 30-day erasure)
- Added anonymised data retention disclosure
- Added all third-party services (Adjust, Sentry, AWS Bedrock, Google Gemini — previously missing)
- Added business transfer / acquisition clause
- Added data breach notification commitment
- Fixed age requirement from 16 to 18
- Removed location data collection claim (not collected)
- Updated "never sell your data" to "do not sell your personal data"
- Added Callout boxes throughout for readability
Version 1.0 — 28 September 2024
Original privacy policy. Covered data collection, third-party services (AWS, OpenAI, Amplitude, Mailchimp, OneSignal), user rights, cookies, and security measures. Replaced by version 2.0 on 1 April 2026. View archived version.