365x100 legal
365x100 Privacy Policy
Effective date: 19 August 2026
365x100 is an independently operated service administered from Singapore ("365x100", "we", "us" or "our"). This Policy explains how we handle personal data when you use the Service.
For privacy questions or requests, contact Privacy Contact, 365x100 at hello@365x100.com.
1. Who may use the Service
You must be at least 18 years old to use 365x100.
365x100 is not offered to persons ordinarily resident in the European Union, European Economic Area or United Kingdom. Residents of those territories must not create an account or use the account-based service.
2. Information we collect and process
We may collect and store:
- Your email address, account identifier and authentication information.
- Basic profile information supplied by Google if you choose Google sign-in.
- Journal entries, rich-text formatting, entry dates, word counts and completion status.
- Optional entry titles and user-owned chapter editorial drafts.
- Optional photographs attached to journal entries, together with processed dimensions and file size.
- Your timezone, prompt preferences and optional weekly-review preferences.
- Streaks, writing statistics, allow-listed writing milestones and email-delivery diagnostics.
- Support messages.
When you attach a photograph, your browser corrects its orientation, resizes it, converts it to WebP and removes embedded metadata such as EXIF and GPS information before upload. We do not retain the original filename or original file. Photographs are not analysed by artificial intelligence.
Search phrases are processed to return matching entries from your own account. We do not intentionally store search phrases in product analytics or place them in URLs. Export selections and generated downloads are assembled in your browser. Your private photographs are retrieved from Supabase only so they can be included in your requested download; they are not sent to another service to create the export.
Our infrastructure providers may process limited technical and security information, such as IP addresses, browser or device information and errors, in their operational logs.
Journal entries may contain sensitive information that you choose to write. Journal text and search terms are not included in product analytics or routine application error messages.
3. Local drafts
Before registration or synchronisation, drafts may be stored locally in your browser. Clearing browser data, changing devices or using private-browsing mode may delete an unsynchronised draft.
4. How we use information
We use information to:
- Create and secure accounts.
- Save, synchronise, display, search and export entries and optional photographs.
- Calculate word counts, streaks and progress.
- Provide prompts and optional weekly writing reviews.
- Resolve support and saving issues.
- Protect and improve the Service.
- Comply with law and enforce our Terms of Use.
Journal entries and attached photographs are private to your account by default. We do not routinely read or view them, sell them, use them for advertising, publish them, analyse photographs with artificial intelligence or use journal content or photographs to train artificial-intelligence models.
Eligible users may create Monthly Chapters and Annual Books from their original entries. Accounts with manually enabled AI access may separately choose AI editorial processing for a specific book. Before the first request, we identify OpenAI as the processor and ask for dedicated consent. We send only that book’s entry dates, titles and authoritative plain text, together with opaque source references. We do not send photographs, rich-format documents, filenames, signed URLs, user identifiers, email addresses or unrelated profile data. Requests use API controls that disable application-state storage, but OpenAI may retain API data for abuse monitoring for up to 30 days. We do not permit OpenAI to use journal content to train its models.
Journal text is treated as source material rather than instructions. Automated checks validate generated source references and quotations against the original entries. AI-generated material can still be inaccurate, so users must review and approve it before an AI-edited PDF is made available. A user may remove any generated section, use an original-only chapter instead, or delete generated output without deleting source entries or photographs.
5. Service providers
We use service providers to operate the Service, including:
- Supabase for authentication, database, private photograph storage and backend services.
- Google for Google sign-in, if selected.
- Resend for authentication and optional weekly-review emails.
- Render for website hosting and delivery.
- OpenAI for optional, user-requested editorial processing.
We may also disclose information where required by law, reasonably necessary to protect the service or another person, or as part of a future incorporation or transfer of 365x100, subject to appropriate safeguards.
6. Storage locations and overseas processing
365x100 is administered from Singapore. Its primary production database is hosted by Supabase in Sydney, Australia. Render distributes the static website through a global content-delivery network. Our providers and their subprocessors may process limited information in other countries where they operate.
Where required by Singapore law, we take reasonable steps to ensure that personal data transferred overseas receives a standard of protection comparable to the protection under Singapore's Personal Data Protection Act.
7. Email
We may send authentication, security and service emails. Optional weekly writing reviews can be disabled in your settings. We do not send daily writing-reminder emails. Weekly reviews are designed not to include journal text.
8. Retention and account deletion
We retain account, journal and user-owned approved editorial information while your account is active and as reasonably necessary to operate and secure the Service. Generated PDFs are assembled on demand in your browser and are not retained by 365x100.
Removing a photograph removes its live metadata immediately and schedules its private storage object for deletion. Deleting your account removes your account, journal entries, attached photographs and associated live data promptly. Deleted information may remain temporarily in protected backups until those backups are overwritten through normal retention cycles. Those copies are not available through the service or used for another purpose. Limited security or legal records may be retained where reasonably necessary.
9. Security
We use reasonable safeguards, including encrypted connections, authentication, access controls, private photograph storage, short-lived access links and database rules designed to prevent users from accessing another user's entries or photographs. No online service can guarantee absolute security.
Contact hello@365x100.com promptly if you suspect unauthorised access. If a data breach occurs, we will assess it and provide notifications where required by applicable law.
10. Your choices
You may:
- Access, edit, search and export your entries.
- Create, edit, approve, export or delete generated chapter output without deleting source entries.
- Add, replace, download or remove photographs attached to your entries.
- Disable optional weekly reviews.
- Delete your account.
- Request access to or correction of personal data by emailing hello@365x100.com.
We may request reasonable information to verify that you control the relevant account.
11. No emergency monitoring
365x100 is not monitored as an emergency or crisis service. Journal entries are not routinely reviewed for threats, self-harm or other emergencies.
12. Changes
We may update this Policy as the Service changes. We will show the revised effective date and provide prominent notice if a change materially affects how journal content is used or disclosed.
13. Contact
Privacy Contact, 365x100
- Email: hello@365x100.com
- Location: Singapore