Privacy Policy
Effective date: September 17, 2026
This Privacy Policy explains how Toadstool Labs LLC collects, uses, discloses, and retains information when you use Quillith, including its website, journal, email, reflections, membership, and related services (the "Service").
Toadstool Labs LLC ("Toadstool Labs," "we," "us," or "our") is an Oregon limited liability company. We are the controller of personal data described in this Policy. You can contact us at hello@quillith.com or at 5441 S Macadam Ave, Ste N, Portland, OR 97239, USA.
Journal content can include sensitive information about health, relationships, finances, beliefs, sexuality, and other private matters. Please also read our Consumer Health Data Privacy Notice, which is part of this Policy and gives added detail about health-related information.
1. Information we collect
1.1 Information you provide
- Account information: your email address, username, confirmation that you are 18 or older, country of residence, time zone, account status, consent records, and email preferences.
- Journal content: entries written on the web or sent by email, entry summaries, and any information contained in that writing.
- Remembered information: facts and tags that Quillith derives from your entries so future reflections can use context. You can view and delete these facts.
- Generated content: reflections, subjects, summaries, and other output created for you.
- Communications: messages that you send to support and information you provide in other communications with us.
- Payment information: subscription status, charge and refund records, payment method type, card brand and last four digits, and related Stripe identifiers. Stripe collects full payment card details directly. We do not store full card numbers.
1.2 Sensitive and health-related information
Your journal may contain information that privacy laws treat as sensitive data or consumer health data. This can include physical or mental health, symptoms, diagnoses, treatment, medication, reproductive or sexual health, substance use, disability, race or ethnicity, religious beliefs, precise location, citizenship, or other information that you choose to write.
Quillith also uses automated processing to derive entry summaries, remembered facts, and limited safety classifications. Safety classifications are limited to possible severe mental health crises, self-harm risk, or threats of violence. A classification can include the category, severity, an AI-generated reason, and the identifiers of the entries that support it. It does not constitute a medical diagnosis.
1.3 Information collected automatically
- Technical information: IP address, user agent, browser or device information, request path, timestamps, and security or diagnostic events.
- Session information: essential cookies and session records used to keep you signed in, protect magic links, remember session state, and secure the Service.
- Email delivery information: provider message identifiers and delivery, bounce, spam complaint, and unsubscribe events. In Quillith's database, delivery event records contain a digest instead of the provider's raw event payload.
- Service activity: records needed to operate entries, reflections, email delivery, account deletion, subscriptions, fraud prevention, rate limits, and error diagnosis.
- Advertising attribution: ad click identifiers supplied by Meta, OpenAI, or Reddit, the public page viewed, and records that an account signup or purchase occurred. We do not include journal entries, remembered facts, reflections, or safety information in advertising events.
1.4 Sources
We collect information directly from you, from the browser or device you use, from email you send to Quillith, and from service providers such as our email delivery provider, Stripe, Cloudflare, OpenAI, Railway, and RewindRewind. We also derive summaries, remembered facts, safety classifications, and reflections from your journal content.
2. How we use information
We use personal data only for the following purposes:
- Create, authenticate, secure, and manage your account.
- Receive and store journal entries submitted on the web or by email.
- Summarize entries, maintain user-correctable remembered facts, and generate reflections.
- Send journal prompts, reflections, account messages, receipts, and other transactional email.
- Detect possible severe safety concerns, stop an ordinary AI reflection when a concern is detected, support limited human review, and allow appropriate outreach.
- Process subscriptions, payments, refunds, disputes, taxes, and account deletion.
- Prevent spam, fraud, abuse, unauthorized access, and other security incidents.
- Find and correct errors, maintain reliability, and understand limited service events without using journal content for advertising.
- Measure public-page views, account signups, and purchases from our advertising campaigns.
- Respond to support requests, enforce our Terms of Service, comply with law, and protect rights and safety.
We do not use journal content to train public AI models. We do not use it for targeted advertising. We do not sell personal data or consumer health data. We do not share personal data for cross-context behavioral advertising.
3. AI processing
Quillith sends only the context needed for a requested AI task to OpenAI. Depending on the task, this can include current entries, summaries of earlier entries, remembered facts, recent reflections, and a one-way hashed account identifier used for safety controls. OpenAI returns entry summaries, fact operations, safety classifications, or reflections.
Quillith uses the OpenAI Responses API with response storage disabled. OpenAI states that API data is not used to train its models unless the API customer opts in. We do not opt in. Under OpenAI's standard API controls, prompts and outputs can still be kept in abuse-monitoring logs for up to 30 days, and longer when required by law or reasonably necessary to protect services or third parties. Provider practices can change, so OpenAI's own terms and privacy documentation also apply to its processing.
AI output can be incomplete, inaccurate, or inappropriate. A safety classification can also be wrong. An authorized person may review a safety classification and relevant account information. We do not continuously monitor journals, and we do not promise that automated processing or a human will identify or respond to any emergency.
4. Email privacy
Email is convenient, but ordinary email is not end-to-end encrypted. Messages can pass through your email provider and our email delivery provider before reaching Quillith. Anyone who can access your email account or device may be able to read messages or submit content, because entries are identified by the address they are sent from. Keep your email account secure.
When our email delivery provider sends a message from an address that has no Quillith account, we create a pending account for that address and send a secure confirmation link. We extract and store up to 5 messages as journal entries while the account is unconfirmed. After confirmation, later messages can also be stored as journal entries. We do not intentionally keep the original raw inbound email body or attachments in Quillith's database after extraction. Our email delivery provider and your own email provider may retain copies under their policies. Quillith does not accept attachments as journal entries.
5. When we disclose information
We disclose information only as described below. The categories in parentheses describe the information involved.
- OpenAI, AI processor: processes journal content, summaries, remembered facts, recent reflections, generated output, and a hashed account identifier to provide AI features.
- Email delivery provider: processes email addresses, email content, message identifiers, delivery events, generated reflections, and internal account or safety notices to receive and send email.
- Railway, hosting and database provider: hosts the application and PostgreSQL database and processes the personal data stored or transmitted by the Service, along with infrastructure logs and backups.
- Stripe, payment processor: processes account and contact information, payment credentials, customer and subscription identifiers, charges, refunds, disputes, fraud signals, and transaction records.
- Cloudflare, security provider: processes IP address, device and browser signals, and challenge results to prevent automated abuse during signup.
- RewindRewind, error and service event provider: processes error details, stack traces, request method and path, IP address, user agent, and limited event properties. We filter email addresses, tokens, journal bodies, and inbound email text from request parameters before logging and do not intentionally send journal content for analytics.
- Meta, OpenAI Ads, and Reddit, advertising measurement providers: receive limited server-side events for public-page views, account signups, and purchases. These events can include an ad click identifier, IP address, user agent, event time, public page URL, transaction value and currency, and one-way hashes of the account email and internal account identifier. We do not send journal content, remembered facts, reflections, or safety information.
- Professional advisers and authorities: may receive information when reasonably necessary to obtain legal, accounting, insurance, or security advice; comply with law or valid legal process; or protect the rights, safety, and security of users, Toadstool Labs, or others.
- Business transaction recipients: may receive information as part of a merger, financing, reorganization, bankruptcy, sale of assets, or similar transaction, subject to applicable confidentiality and privacy obligations.
We do not intentionally make journal or health data available to other products operated by Toadstool Labs, and we do not disclose consumer health data to a corporate affiliate. Some processors are managed under shared Toadstool Labs accounts, but Quillith uses separate Railway, email delivery, and RewindRewind project or server scopes. Stripe is a shared account and Quillith records are identified with product metadata.
6. Safety review
If automated processing identifies a possible severe safety concern, Quillith stores a safety record and sends an internal notice for possible manual review. The notice contains only your user ID and the safety category. It does not contain your email address, username, time zone, the AI-generated reason, or raw entry body. An authorized reviewer may open the secured application to access the safety record and relevant account information when reasonably necessary for a discretionary review.
We may use this information to contact you, provide general crisis resources, protect a person from a credible threat, or make a disclosure that is required or permitted by law. Quillith is not an emergency service and this review does not create a duty to monitor, intervene, contact you, or contact emergency services.
7. Cookies and tracking
Quillith uses essential cookies and similar local storage for authentication, security, form state, unsent entry drafts, and first-party ad attribution. Cloudflare Turnstile may use device signals and cookies to distinguish people from bots. We do not install third-party advertising pixels, use third-party behavioral analytics, or set cross-site advertising cookies. We send limited advertising measurement events from our server as described above.
Because we do not sell personal data or use it for targeted advertising, there is no sale or targeted-advertising opt-out needed at this time. Global Privacy Control and Do Not Track signals do not change the Service's behavior. If our practices change, we will update this Policy and provide any required controls before the change takes effect.
8. Retention and deletion
- Account and journal: we generally keep your account, entries, remembered facts, and reflections while your account is active. You can delete entries and remembered facts, or delete the full account.
- Safety records: Quillith deletes safety flags after 24 months, even if the account remains active. Deleting an entry also deletes a safety flag that cites that entry.
- Derived information: deleting one entry removes its stored original body and any safety flag that cites it, but does not automatically rewrite an older summary, reflection, or remembered fact that was derived from it. Delete related remembered facts separately. Delete the account to remove all account-linked journal content from the active database.
- Email events: Quillith deletes its email delivery event records, including hashed provider payloads, after about 90 days.
- Payment and legal records: we and Stripe may keep transaction, tax, fraud, refund, dispute, and automatic-renewal consent records for the periods required by law.
- Account-deletion records: after remote Stripe cleanup is complete, Quillith keeps the minimal deletion record, including Stripe customer identifiers and the last cleanup error if any, for 24 months and then deletes it.
- Advertising attribution: first-party ad click attribution is kept with the account until account deletion. Meta, OpenAI Ads, and Reddit retain the limited measurement events they receive under their own retention policies.
- Logs, queues, and backups: limited copies can remain for a short period in protected logs, job records, caches, and backups until normal deletion or overwrite schedules run. We do not restore deleted data to active use except as needed for disaster recovery, security, or legal compliance.
- Provider copies: service providers may keep information under their retention schedules, contracts, and legal duties. We send verified deletion requests to processors when applicable law requires it.
Account deletion removes the account and associated entries, remembered facts, reflections, safety records, sessions, and Quillith payment-customer records from the active database. It also starts deletion of the related Stripe customer profile. We may retain a minimal deletion record and information that applicable law permits or requires us to keep. For a verified consumer health data deletion request, archived or backup copies will be deleted within the period required by applicable law, which can be up to six months under Washington law.
9. Your controls and privacy rights
Quillith provides the following controls:
- View, create, edit, or delete journal entries. An entry cannot be edited after it has been included in a reflection, but it can be deleted.
- View and delete remembered facts.
- Export entries, remembered facts, and reflections in JSON. Large exports are provided in pages.
- Stop journal prompts and reflections through account settings or an unsubscribe link.
- Delete your account and its journal data through account settings.
Depending on where you live and subject to legal exceptions, you may also have a right to:
- Confirm whether we process your personal data and access a copy.
- Correct inaccurate personal data.
- Delete personal data, including derived data.
- Receive portable data.
- Obtain information about categories or specific third parties that received personal data.
- Withdraw consent to future processing of sensitive or health data.
- Opt out of sale, targeted advertising, or profiling that produces legal or similarly significant effects. Quillith does not perform these activities.
- Appeal a refusal to act on a privacy request.
- Exercise a right without unlawful discrimination.
Send a request to hello@quillith.com from your account email when possible. Use the subject "Privacy Request" and describe the right you want to exercise. To appeal a decision, reply or write with the subject "Privacy Appeal." We may verify your identity and an authorized agent's authority before acting. We will respond within the period required by applicable law. If an appeal is denied, you may contact the attorney general or privacy regulator in your jurisdiction.
You can withdraw consent to future processing of journal and health data by deleting your account or sending a request to that address. Because this processing is necessary to provide Quillith, withdrawal ends future journal and reflection processing and may require closure of the account. We will stop consent-based processing as soon as practicable and within any deadline required by law.
10. Security
We use reasonable administrative, technical, and organizational safeguards appropriate to the sensitivity of journal data. These include encryption in transit, access controls, filtered sensitive request parameters, signed or random account tokens, restricted production access, and service-provider controls. No internet transmission, email system, model provider, or storage system is completely secure. We cannot guarantee absolute security.
If a security incident requires notice, we will notify affected people and regulators as required by applicable law, including the FTC Health Breach Notification Rule when it applies. Under that Rule, an unauthorized disclosure can be a breach even without an intrusion.
11. Children
Quillith is only for people who are at least 18 years old. We do not knowingly collect personal data from anyone under 18. Contact us if you believe a person under 18 has provided information, and we will take appropriate steps to delete it.
12. United States-only service and processing
Quillith is offered only to residents of the United States. Do not create or use an account if you live in another country. Toadstool Labs is based in the United States, and the Service and its providers process information in the United States and possibly other countries.
13. Changes to this Policy
We may update this Policy as the Service or law changes. We will post the updated version and change the effective date. If a change materially expands how we collect, use, or disclose sensitive or consumer health data, we will give additional notice and obtain consent when required before applying the new practice.
14. Contact
For privacy questions, requests, or complaints, contact:
Toadstool Labs LLC
5441 S Macadam Ave, Ste N
Portland, OR 97239, USA
hello@quillith.com