Privacy
Written plainly, and describing what the software actually does.
Last updated 14 August 2026
What we ask you for
A username, a password, and a display name. That is the whole list.
We do not ask for your real name, your phone number, or your date of birth. There is no field for them and no column in our database to store them.
We cannot reset your password. If you lose it, the account and everything in it is gone for good. Please use a password manager.
Email, if you want it
You can add an email address, and you never have to. Signing up does not ask for one, and an account without one works exactly the same.
It is used for a single purpose: telling you that somebody replied to something you posted. Without it, a reply only reaches you if you happen to come back and look.
- The email never contains what anyone wrote — only that a reply is waiting. Inboxes get shared, synced to other devices and read by other people, so the content stays on the site behind your login.
- Nothing is sent until you confirm the address from that inbox, so a mistyped address cannot send a stranger mail about a mental health site.
- Your address is encrypted before it is stored, the same way journal entries and direct messages are.
- Other members never see it. We do not sell, share or rent it to anyone.
- Every email has a one-click unsubscribe that needs no sign-in, and it deletes the address rather than muting it. You can also remove it from your profile.
- It is not a way into your account. We never send sign-in links or password resets to it, so having one on file does not make your account easier to break into — and still does not let us recover it for you.
What you create
- What you write about your situation, and the topics detected from it
- Posts and comments in communities
- Direct messages, if you choose to connect one to one with a peer
- Private journal entries and mood check-ins
Tracking
There is none. No analytics package, no advertising pixels, no third-party trackers. We do not sell or share your data with anyone, and there is no advertising on this platform.
Two things are stored in your browser, and neither is used to track you. A secure sign-in cookie keeps you logged in and is removed when you log out, and your choice of country is saved locally so we show you the right crisis numbers.
Our hosting providers process technical information such as IP addresses to serve requests and to stop abuse, as any web host does. We do not build profiles from it.
Automated crisis detection
When you write about what you are going through, the text is scanned automatically for signs that you may be in crisis, so that we can immediately show you the crisis lines for your country. When that happens, a crisis alert containing the text that triggered it is recorded so it can be reviewed by a moderator.
To show the correct crisis numbers we need to know roughly which country you are in. That is worked out from your browser's timezone and your connection's approximate location, and you can override it yourself at any time. We do not store a location history.
Who can see what
Other members see your display name, your bio, and whatever you choose to post. They cannot see your journal, your mood check-ins, your email address, or messages you exchange with anyone else.
How your data is protected
- Passwords are stored only as bcrypt hashes. Nobody, including us, can read your password or recover it.
- All traffic between your browser and our servers is encrypted with HTTPS, and the connection between our application and our database is encrypted with TLS.
- Our database and hosting providers apply their own storage protections in addition to the above.
- Your journal entries, direct messages and email address are encrypted before they are stored. The key is held separately from the database, so a copy of the database on its own does not reveal what you wrote. Our service can still decrypt this content — it has to, in order to show you your own journal and to investigate reports — so this protects your writing from a database being copied or stolen.
No system is perfectly secure, and we will not claim otherwise. Please share only what you are comfortable sharing.
Deleting your account
You can delete your account from your profile. Doing so removes your profile, your challenges, your journal entries, your mood check-ins, your posts, your comments and your email address if you added one.
Messages you sent may remain visible in the other person's conversation, since they form part of their history too. If you started a community, the community and the posts other people made in it are kept and looked after by us rather than deleted. Backups may retain data for a short period before being cycled out.
Children
This platform is not intended for under-16s. If you are younger than that, please talk to a trusted adult or a service set up specifically for young people — several are listed in our crisis resources.
Changes
If this policy changes in a way that materially affects you, we will say so on the site.
Getting in touch about your data
Write to privacy@yourenotalone.app about anything on this page — what we hold about you, having it deleted, or a concern about how it is handled. For anything else, hello@yourenotalone.app or the contact form, which does not ask who you are.
You can delete your account yourself at any time from your profile, without asking us and without giving a reason.
Questions or something that looks wrong? This is an early-stage project and feedback genuinely changes it.