Write To Heal
Privacy Policy
Data Fiduciary / Operator: Nita Bajoria (sole proprietor)
Website: nitabajoria.com
Effective date: 14 July 2026 · Last updated: 14 July 2026
1. Introduction
This Privacy Policy explains how Nita Bajoria ("we", "us", "our") collects, uses, stores, shares, and protects your personal data when you use the Write To Heal mobile application and related services (the "Service").
We understand that a journaling and mood-tracking app handles deeply personal information. We are committed to protecting your privacy and handling your data responsibly and transparently.
This Policy is published in compliance with the Information Technology Act, 2000 and its rules, and the Digital Personal Data Protection Act, 2023 ("DPDP Act"), and should be read with our Terms & Conditions. By using the Service, you acknowledge you have read and understood this Policy and, where required, consent to processing as described here.
2. Who We Are (Data Fiduciary)
The Data Fiduciary — the entity that determines the purpose and means of processing your personal data — is:
Nita Bajoria, sole proprietor, operating "Write To Heal"
Based in Kolkata, West Bengal, India
Contact: support@nitabajoria.com
3. Definitions
-
"Personal data" — any data about an individual who is identifiable by or in relation to such data.
-
"Data Principal" — the individual to whom the personal data relates: you.
-
"Processing" — any operation on personal data, such as collection, storage, use, sharing, or deletion.
-
"Sensitive information" — information about your mental and emotional well-being, such as your journal content and mood data, which we treat with heightened care.
4. Information We Collect
We collect only the information needed to provide and improve the Service.
4.1. Account and Identity Information
Email address and, if provided, your name or display name; and authentication identifiers created when you sign up or sign in (managed through Clerk), including via email/password or third-party sign-in (Google or Apple).
4.2. Journal and Mood Content (Sensitive)
The text of your journal entries; your mood check-ins and history; titles, tags, and metadata you add; and your responses to writing prompts. This is the most sensitive information we handle and is protected using encryption (see Section 7).
4.3. Onboarding and Preferences
Responses to onboarding questions and preferences you set (reminder times, theme, app-lock, etc.).
4.4. Subscription and Purchase Information
Records of the plan you purchase and your entitlement/subscription status. We do not collect or store your payment card, UPI, or bank details — all payments are processed by the Apple App Store or Google Play Store under their own privacy policies.
4.5. Device and Technical Information
Basic technical information necessary to operate the app (device type/operating system, app version) and a push-notification token if you enable reminders/notifications. We do not currently use third-party analytics, advertising, or crash-tracking tools.
4.6. Communications and Feedback
Any feedback, support requests, or messages you send us, and their contents. We do not knowingly collect more personal data than necessary for the purposes described here.
5. How We Use Your Information and Legal Basis
We process your personal data for the following purposes, based on your consent and/or the necessity to provide the Service you requested:
6. What We Do NOT Do
-
We do not sell your personal data.
-
We do not use your journal content or mood data for advertising or marketing.
-
We do not send your journal entries or mood data to any third-party AI or large-language-model provider. Insights are generated on your device and/or on our own servers only.
-
We do not share your personal data with third parties except as described in Section 8.
7. Security and Encryption of Your Content
We take reasonable technical and organisational measures to protect your personal data against unauthorised access, disclosure, alteration, and destruction.
Journal content is protected using encryption. Your entries are stored in encrypted form, and access to readable content is restricted to the authorised read paths that serve the content back to you.
Data transmitted between the app and our servers is protected in transit using industry-standard secure connections (TLS/HTTPS). Access to systems and data is restricted to what is necessary to operate the Service.
No method of transmission or storage is completely secure. While we work hard to protect your data, we cannot guarantee absolute security. You are also responsible for keeping your device and login credentials secure and for enabling protections such as app-lock.
8. How We Share Your Information
9. Where Your Data Is Stored (Data Localisation)
Our primary cloud storage uses the AWS Asia Pacific (Mumbai) region (ap-south-1), so stored content is kept within India. Some providers (such as authentication and push-notification services) may process limited data on infrastructure outside India; where this occurs, we take reasonable steps to ensure your data continues to be protected consistently with this Policy and applicable law.
10. Data Retention
We retain your personal data for as long as your Account is active or as needed to provide the Service.
Account deletion. When you request deletion from within the app, your Account is deactivated and scheduled for permanent deletion. After a limited grace period (approximately 30 days), associated personal data is purged from our active systems and your authentication record is removed from our authentication provider.
We may retain certain limited information longer where required for legal, tax, accounting, or regulatory obligations, to resolve disputes, or to enforce our agreements. Residual copies may persist in backups for a limited period before being overwritten. Data stored locally on your device remains until you delete it or uninstall the app.
11. Your Rights
Subject to applicable law, including the DPDP Act, you have the following rights:
-
Access — a summary of the personal data we process and the processing activities.
-
Correction and updating — to correct inaccurate or incomplete data.
-
Erasure — to request deletion (e.g. by deleting your Account), subject to legal retention.
-
Withdraw consent — at any time (without affecting the lawfulness of prior processing).
-
Grievance redressal — to raise concerns with our Grievance Officer (Section 15).
-
Nomination — to nominate another individual to exercise your rights in the event of death or incapacity, per the DPDP Act.
To exercise any right, contact support@nitabajoria.com. We may verify your identity before acting and will respond within the timelines required by applicable law.
12. Children's Privacy
The Service is intended for users aged 13 and above. Users under 18 may use it only with the consent and supervision of a parent or legal guardian; where required by the DPDP Act, we rely on verifiable parental consent for processing a child's personal data.
We do not knowingly collect personal data from children under 13. If we become aware we have, we will delete it — contact support@nitabajoria.com if you believe this has occurred. Consistent with the DPDP Act, we do not undertake tracking, behavioural monitoring, or targeted advertising directed at children.
13. On-Device Storage
To support offline use and performance, some of your data (including entries and preferences) may be stored locally on your device. This local data is under your control; uninstalling the app, resetting the device, or clearing app data may remove it. We recommend enabling app-lock and device security features.
14. Cookies and Similar Technologies
The Service is primarily a mobile application and does not rely on advertising cookies. The app may use local device storage and standard mobile identifiers (such as a push token) strictly to provide functionality. Our website, if it uses cookies, will use only those necessary for its basic operation unless otherwise disclosed.
15. Grievance Redressal and Contact
Grievance Officer / Data Protection Contact: Nita Bajoria
Email: support@nitabajoria.com
Address: [To be added], Kolkata, West Bengal, India
We will acknowledge and resolve grievances within the timelines prescribed under applicable law, including the Information Technology Act, 2000, its rules, and the DPDP Act.
16. Data Breach Notification
In the event of a personal data breach likely to affect you, we will take appropriate remedial steps and, where required by law, notify the relevant authority (such as the Data Protection Board of India) and affected users in accordance with applicable legal requirements.
17. Changes to This Policy
We may update this Policy to reflect changes in our practices or legal requirements. For material changes we will update the "Last updated" date and, where appropriate, notify you within the app. Continued use after changes take effect constitutes acceptance.
18. Consent
By using Write To Heal and providing your personal data, you consent to the collection, use, storage, and sharing of your personal data as described in this Privacy Policy. You may withdraw your consent at any time as described in Section 11.
Your trust matters to us.
If anything in this Policy is unclear, please reach out at support@nitabajoria.com.


