Privacy Policy
Red Start Journal (“Red Start Journal”, “we”, “us”) is an independent project run by Dhrona. It has two parts: this public website, and the Red Start Journal app, where you can sign up and keep your own portfolio and transaction log. This policy explains what we collect across both, and what we do with it.
The short version: we collect only what the product needs to work, we don’t run ads or third-party analytics, and we never sell your data.
What we collect
| What | When | Why |
|---|---|---|
| Email address | When you sign up, log in, or subscribe to the newsletter | To identify your account, send sign-up and password-reset codes, and (only if you opt in) send the newsletter |
| Password | When you sign up with email | To let you log in. We store only a salted, one-way hash, never the password itself |
| Name, profile picture and account ID | When you sign in with Google, or edit your profile | To link your Google sign-in to your account and show your name and picture in the app |
| Your transactions | When you add, edit or delete entries in the app | This is the journal itself: to calculate and show your net worth, invested amount, fees, debt and returns |
| Member number | When you sign up | To number members in the order they join (#1 was the first). It appears on your welcome card, which we email to you once as a thank-you. The card is public at its own link so you can share it, and shows only the number, the month you joined and our branding: never your name or email. When a member number is a milestone (like the 100th member), we get an email with that member’s name and email so we can celebrate |
| Collectibles | When you check out wallpapers from the Marketplace | To keep the wallpapers you’ve collected in your account, so you can download them again and the Marketplace can hide ones you already own. We record which wallpapers and when |
| Newsletter preference | When you subscribe or change the toggle in your profile | To know whether to email you updates |
| Session cookie | When you log in | To keep you logged in (see Cookies below) |
| Public identity and settings | Only if you turn on “Make my portfolio public” in your profile | To show your portfolio in the Community list and your public journal page under your username. If you have a display name or profile picture, those are shown with that public identity; your email is never shown |
| Problem reports | Only when you press “Report this problem” after an error | To find and fix the problem. A report contains the error message, the page, your browser and screen size, recent errors on that page, your account email if you’re logged in, and anything you write in it. For a failed import it also contains the file’s name, size and column headings, but not your trades or amounts. It’s sent to our support inbox by email |
| Wallpaper download counts | When you download a wallpaper | To see which wallpapers are popular. We record the wallpaper, your country, and the page or campaign link you came from. No IP address, name or email, so it can’t identify you |
We do not ask for or store brokerage logins, bank details, card numbers or government IDs. We do not connect to your broker. Everything in your journal is data you type in yourself or import from a report file you choose. Imported files are read on your device; only the entries you confirm are saved.
The assistant
The app has an optional assistant: tap the microphone and say (or type) what you want, like adding an entry or opening a page. When you use it, we send your voice recording or typed request, your transactions and your portfolio totals to Google’s Gemini AI service, which works out what you asked for. Anything that would change your journal is shown to you to confirm first.
We don’t keep the recording. This feature is currently in beta mode and runs on Gemini’s free tier, where Google may use what is sent to improve its products and people at Google may review it. It will be updated to the paid version in the coming future soon (which does not use customer data for model training). If you’d rather not share that, don’t use the assistant: every feature also works by hand.
Journal posts from a video
You can have AI write a journal post from a video or audio recording you upload, or from a public YouTube video you link. We store your upload in our cloud storage and send it (or the YouTube link) to Google’s Gemini AI service, which writes the post and a transcript. Gemini’s copy is deleted as soon as it’s done (Google deletes it within 48 hours at the latest), and we delete your upload once the draft is written. The draft and transcript stay in your account until you post the draft or throw it away. Nothing is published until you post it yourself. The same Gemini terms apply as for the assistant (see above).
Things your browser handles, not us
- Exchange rates. To show amounts in other currencies, your browser fetches public exchange rates from a third-party rates service. No personal data is sent, but that service can see your IP address, like any website you load.
Cookies and local storage
We use two cookies, both strictly necessary:
- Login: a random token that keeps you logged in. It can’t be read by scripts on the page, is only sent over secure connections, and expires after 7 days or when you log out.
- Wallpaper downloads: after checkout, a signed pass that lets this browser download the wallpapers you chose. It can’t be read by scripts on the page, and expires after 1 hour or when you log out.
Your browser’s local storage keeps display preferences such as light/dark theme and your chosen currency. These never leave your device.
We don’t use advertising, tracking or analytics cookies. Our hosting provider may set strictly necessary security cookies to protect the site from abuse.
Who processes your data
We use a small number of service providers to run Red Start Journal. They process data only on our behalf, to provide their service:
- Cloud hosting and security: runs the website and app, stores the database, and protects the site against abuse. It keeps standard request logs (such as IP address and browser type) for security and reliability.
- Email delivery: sends our emails, such as sign-up and password-reset codes, and delivers problem reports to our support inbox.
- Google sign-in: if you choose “Continue with Google”, Google shares your name, email, profile picture and account ID with us.
- Google Gemini: runs the assistant and writes journal posts from your videos, only when you use them (see “The assistant” and “Journal posts from a video” above).
We choose reputable providers with strong security practices, and give them only the data they need to do their job.
These providers may process data outside your country, including in the United States.
The public portfolio
The portfolio shown on this website is the founder’s own portfolio, published on purpose. Your journal is private by default. Transactions you add in the app are visible only to you when logged in.
You can choose to make your portfolio public in Profile → Public Portfolio. Then anyone can see it under your chosen username, and it appears in the Community list:
- By default only percentages are shown: your returns, how your holdings are split, and the dates and names of your trades. Amounts never leave our servers.
- If you also turn on “Show amounts too”, visitors see your full journal: net worth, debt and every amount. Notes you wrote on entries stay private either way.
Public pages are marked so search engines don’t index them. Switch back to private at any time and your portfolio disappears from the website within minutes (the Community list is refreshed at least every 10 minutes). Deleting your account also removes it.
How long we keep it
- Account, transactions and collectibles: until you delete your account. Your member number is never given to anyone else, even after you delete your account.
- Sign-up and reset codes: 5 minutes, then deleted automatically.
- Login sessions: 7 days, or until you log out.
- Newsletter email: until you unsubscribe.
- Problem reports: until the problem is fixed, then deleted from our support inbox.
- Hosting logs: kept by our hosting provider for a limited period for security purposes.
Your choices and rights
- See and edit your name and newsletter setting on your Profile page, and edit or delete any transaction.
- Delete your account from your Profile page. This permanently removes your account, your transactions and your newsletter subscription from our database. It cannot be undone.
- Unsubscribe from the newsletter any time using the toggle in your profile, or by emailing us.
- Get a copy of your data, or ask any question about it, by emailing redstartjournal@gmail.com.
Depending on where you live (for example under India’s Digital Personal Data Protection Act, 2023, or the EU/UK GDPR), you may have further rights, such as to correct your data, withdraw consent, or complain to a data protection authority. Email us and we’ll help within 30 days.
Security
All traffic uses HTTPS. Passwords are hashed and salted. Sign-up and password-reset codes expire after 5 minutes. No system is perfectly secure, though, and your transactions are stored in our database in readable form so the app can calculate your numbers. If we ever learn of a breach affecting your data, we’ll tell you without undue delay.
Children
Red Start Journal is not meant for anyone under 18, and we don’t knowingly collect data from them. If you think a minor has signed up, email us and we’ll delete the account.
We don’t sell your data
We don’t sell, rent or trade your personal data, and we don’t share it with advertisers. We would only disclose it if the law requires us to.
Changes to this policy
We’ll update this page when what we collect or how we use it changes, and change the date at the top. If a change is significant, we’ll also email account holders before it takes effect.
Contact
Questions, requests or complaints: redstartjournal@gmail.com.