Last updated: June 2026
Your journal is AES-256 encrypted on your device. Mend has no servers that hold your personal grief data and no analytics. We do not sell, share, or transmit your journal or check-in data. Ever.
On your device (local only):
All of this is stored in a SQLite database on your device. Nothing is uploaded to any server.
Mend offers optional email sign-in via Supabase Auth to back up settings across devices. This is strictly opt-in. If you do not sign in, no account data is created or stored remotely. If you sign in, only your email address and an anonymous user ID are stored — never your journal, check-ins, or session progress.
Mend scans journal text and check-in notes locally, on your device, to detect at-risk language and surface crisis resources (988 Lifeline, Crisis Text Line). This scan runs entirely on-device and the text is never transmitted.
Premium subscriptions are processed by Apple (App Store) or Google (Play Store), not by Mend. Their privacy policies govern payment data. Mend never receives your card details.
Mend is intended for adults. We do not knowingly collect data from anyone under 18.
If we ever make material changes, we will update the date above and note it in the App Store release notes. The core commitment — your data stays on your device and is never sold — will not change.
Questions? Use the contact form on our website, or reach the studio at tenderlab.studio.