This guide is from Lapsus — the AI personal advisor built on Personal Pattern Intelligence. Through conversations and reflections with your board of four advisors, Lapsus uncovers the recurring patterns shaping how you think, feel, and decide — and turns them into personalized guidance and action.
A privacy policy is the document that tells you how an app actually treats your data — beneath the friendly marketing. For an AI journaling app, which holds your most personal reflections, reading it matters. But privacy policies are long and dense on purpose, so the skill is knowing what to look for and skipping the boilerplate. Here’s how to evaluate one, and the clauses that actually matter. (How to evaluate the privacy of AI reflection platforms is a broader companion; this piece is the privacy-policy-reading how-to.)
The clauses that actually matter
Don’t read a privacy policy front to back — hunt for the clauses that reveal how your data is really treated:
- What data it collects — and whether it’s minimized to what serves you, or a broad grab of everything possible.
- How it’s protected — look for encryption (in transit and at rest) and access controls. Vagueness here is itself a signal.
- Third-party sharing — whether your data is shared with or sold to anyone. This is a critical clause; sharing your reflections is a serious concern.
- Data use and training — whether your private content is used to train models, and whether you consented to that.
- Your control — whether you can access, export, and delete your data, with deletion that actually removes it.
These five tell you most of what you need. The rest is largely legal boilerplate — necessary, but not where the real answers live.
The business model is the biggest tell
The single most revealing thing — often implied by the policy rather than stated plainly — is how the app makes money, because that determines its incentives around your data:
- A subscription app is paid to serve you, so its incentive is to protect your data and keep you satisfied.
- An advertising- or data-sale app is paid to monetize you, so your data is a revenue source — and every other clause bends toward extracting value from it.
If the policy reveals (or hides) that your data is how the company profits, that colors everything else: broad data-use rights and vague sharing clauses make sense once you see the business model behind them. So always determine how the app makes money — it’s the clearest predictor of how it’ll treat your data, and the alignment question underneath the whole policy.
Red flags to watch for
Certain clauses are warning signs that the policy permits treating your data in ways that may not serve you:
- Vague data-use language — “to improve our services” with no limits is a blank check.
- Third-party sharing or sale — especially of your actual content.
- An advertising-based model — your data is likely the product.
- No clear deletion — if you can’t fully remove your data, you never really controlled it.
- Broad content rights — the app claiming wide license to use what you write.
- Model training without clear consent — your private reflections feeding systems you didn’t agree to.
Any of these, regardless of how warm the marketing sounds, means the policy allows something you may not want. The policy is the binding document; the marketing is not.
Why the policy beats the marketing
The reason to read the policy at all is that it’s what the company is legally allowed to do — while the marketing is only what it chooses to say. A friendly homepage promising “your privacy matters” means nothing if the policy permits selling your data; conversely, a plain but tight policy that minimizes collection, forbids sharing, and guarantees deletion is worth far more than any reassuring slogan. So evaluate the policy, not the pitch — the gap between them is often where the truth lives. An app whose policy is clear, tight, and user-protective is telling you something real; one whose policy is vague and permissive is also telling you something real, whatever its marketing claims. This is how you check whether it’s actually safe to share.
The takeaway
Evaluate an AI journaling app’s privacy policy by hunting for the clauses that matter — data collected, protection, third-party sharing, training use, and your control — and above all by determining how the app makes money, which sets its incentives around your data. Watch for red flags like vague use language, data sale, and no real deletion. The policy is binding where the marketing is not, so trust the policy. See a user-protective approach at Lapsus.