Privacy Policy
Core Privacy Principle: Your Journey is designed as a personal, private journal and milestone companion. It is not an open public social network. Your journal entries, notes, photos, and personal memories are private by default and belong solely to you.
1. Introduction
PTK Studio ("we", "us", or "our") develops and operates the mobile application Your Journey (the "App") and related backend web services. We are dedicated to respecting and protecting your privacy.
This Privacy Policy provides clear, transparent information regarding what personal data we collect, why we process it, where it is securely stored, how third parties interact with it, and how you can exercise your statutory rights under applicable privacy legislations, including the Malaysian Personal Data Protection Act 2010 (PDPA), the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA/CPRA), and Google Play Developer Policies.
By creating an account or using Your Journey, you acknowledge and agree to the practices described in this policy.
2. Information We Collect
We strictly limit data collection to what is necessary to operate our features effectively.
A. Information You Provide Directly
- Account & Registration Information: When registering via email, we collect your
email address, username, display name, and password. Passwords are cryptographically salted and hashed on our server before being committed to our PostgreSQL database; we never view, process, or store raw, plain-text passwords.
- Profile Customization: You may optionally choose a profile
avatar photo and set a theme preference (light/dark mode).
- Memories & User-Generated Content: When you record a memory or adventure goal, we store your chosen
title, memory note/description, journey date, category (e.g., Beach, Mountain, Food, Culture, City, Nature), journey type (Solo, Couple, Family, Friends, Business), mood, and favorite flag.
- Photos & Media: Images you explicitly select from your device's photo library to attach to memories, groups, or your profile avatar.
- Geographic Location Data: Location label, city name, country name, country code, and exact coordinates (latitude and longitude) that you attach to a memory.
- Social & Group Interactions: Friend requests, accepted friendship records, blocked user entries, group creations, group descriptions, group roles, and group member lists.
- Feedback & Bug Submissions: User-submitted feedback messages, categorized type (problem, improvement, idea, other), app version, and device operating system.
B. Information Collected Automatically & Via Permissions
- Push Notification Tokens: Firebase Cloud Messaging (FCM) registration tokens and operating system platform (Android/iOS) to deliver incoming friend alerts, group invitations, and memory notifications.
- Session & Security Telemetry: To prevent brute-force attacks, detect unauthorized access, and manage sessions, our servers record client
IP addresses, device type, login timestamps, and authentication status (success/failure).
- Advertising Identifiers (Free-Tier Users): The Google Mobile Ads SDK (AdMob) processes the Google Advertising ID (AAID) on Android or the Identifier for Advertisers (IDFA) on iOS (only after receiving user tracking permission via Apple's App Tracking Transparency framework).
C. Information from Third-Party Authentication Providers
- Google Sign-In: If you sign in with Google, we receive an authorized Google Identity Token containing your Google user subject ID, verified email address, and profile name.
- Apple Sign-In: If you authenticate via Apple, we receive an Apple Identity Token, verified email address (or Apple private relay email), and your given/family name.
3. Photos and Media Handling
- Selective Photo Library Access: We request photo gallery access (
READ_MEDIA_IMAGES or standard gallery picker permission) strictly to let you select specific photos for your memories or avatar. We never scan, index, or access unselected gallery photos.
- Client-Side Compression & EXIF Stripping: Before any image leaves your phone, our mobile client compresses and converts it into modern, lightweight WebP format clamped to a maximum 2048px dimension. This re-encoding process strips standard camera EXIF metadata, removing device camera serials and hardware sensor details.
- Secure Cloud Storage: Compressed WebP images are uploaded over encrypted HTTPS channels to secure private object buckets hosted on Amazon Web Services (AWS S3).
- Permanent Photo Deletion: When you delete a photo, delete a memory, or wipe your account, commands are issued to AWS S3 to immediately and permanently delete the physical image files from the storage bucket.
4. Location Data Practices
Your Journey allows you to record the places where your journeys happen. We adhere to the following principles:
- Foreground-Only Access: Location permissions (
ACCESS_FINE_LOCATION and ACCESS_COARSE_LOCATION) are requested only when you open the map picker to attach a location.
- No Background Location Tracking: The App never collects, polls, or monitors your device location in the background or while the App is closed.
- User Discretion: You can choose your location by tapping the GPS button to use your device's current coordinates, by searching a city or landmark name, or by manually tapping a location pin on the map.
- Storage: Coordinates and reverse-geocoded place names are saved in PostgreSQL alongside your memory record.
5. Memory Privacy & Closed-Circle Social Features
- Private by Default: Personal memories have an
isPrivate toggle. When set to private, the entry is viewable strictly by you. It is never queried or shown in any social feed.
- Mutual Friendship Connections: Sharing memories requires explicit mutual consent. Users must send a friend request, and the recipient must accept before memories designated as shared become visible.
- Public User Search: When other users search for you, only your
display name, username, avatar, and current relationship status are visible. Your private email address, exact location, and personal journal logs are never disclosed in search results.
- User Blocking: You can block any user at any time. Blocked users are strictly prevented from viewing your profile, sending requests, or interacting with you in any way.
- Collaborative Groups: When you create or join a group, memories posted to that group are visible only to confirmed group members. Group owners maintain administrative rights to remove members or delete the group.
6. Third-Party Service Providers & Sub-processors
We work with trusted third-party providers to provide essential hosting, security, and functional infrastructure:
| Service Provider |
Purpose |
Data Transferred / Processed |
Privacy Information |
| Amazon Web Services (AWS S3) |
Secure cloud storage for memory photos and avatars |
Uploaded WebP image files |
AWS Privacy Notice |
| Google Firebase (FCM) |
Push notification dispatching |
FCM device registration tokens, notification routing payloads |
Firebase Privacy Policy |
| Google Sign-In |
OAuth 2.0 user authentication |
Google ID token, email address, profile name |
Google Privacy Policy |
| Apple Sign-In |
Native iOS user authentication |
Apple Identity token, email (or relay email), user name |
Apple Privacy Policy |
| Google Maps SDK |
Map display and coordinate selection |
Viewport coordinates, IP address, device telemetry |
Google Maps Terms |
| Google AdMob |
Rewarded video ads on the free tier |
Advertising ID (AAID/IDFA), ad impression & interaction metrics |
Google Ad Policies |
| RevenueCat |
In-app purchase validation & subscription entitlements |
App User ID (user_id), store receipt tokens, active plan status |
RevenueCat Privacy Policy |
| Google reCAPTCHA Enterprise |
Bot defense and abuse mitigation |
Device interaction signals, risk evaluation token |
Google reCAPTCHA Terms |
| SMTP Mail Relay (Nodemailer) |
Transactional verification and password reset emails |
Recipient email, one-time verification tokens |
Processed via secure TLS SMTP connection |
7. In-App Purchases, Subscriptions & Payments
Users can upgrade to Your Journey Premium to unlock expanded quotas, high-quality images, and a completely ad-free experience.
- Storefront Processing: All monetary transactions and billing are conducted directly by **Google Play In-App Billing** on Android or **Apple StoreKit** on iOS.
- Zero Payment Data Retention: PTK Studio does not collect, process, or store credit card numbers, debit card details, or banking information.
- Receipt Verification: Our backend communicates with RevenueCat solely to verify receipt tokens and maintain your active premium entitlement status.
8. Advertising Disclosure & Choices
Free-tier users may be presented with rewarded video advertisements provided by Google AdMob when saving or editing memories. You have the following choices regarding advertising:
- Ad-Free Experience: Active subscribers to Your Journey Premium bypass all in-app advertising automatically.
- iOS App Tracking Transparency: On iOS, we ask for your permission before tracking identifiers (IDFA) are accessed. You may adjust this at any time in your iOS device settings under Settings > Privacy & Security > Tracking.
- Android Ad ID Reset: On Android, you can reset or delete your advertising identifier under Settings > Privacy > Ads.
9. Data Security & Encryption
We implement appropriate technical and organizational safeguards to protect your personal data:
- Encryption in Transit: All communications between the mobile app, backend servers, and external third-party services are encrypted using Transport Layer Security (TLS 1.2+ / HTTPS).
- Cryptographic Credential Storage: Passwords, session refresh tokens, and email verification tokens are stored as secure hashes using strong cryptographic hashing algorithms.
- Device Keychain Protection: Client session tokens on your mobile device are stored strictly within hardware-backed system secure storage (
FlutterSecureStorage).
- Physical and Logical Access Controls: Our production PostgreSQL databases and AWS S3 storage buckets are shielded behind strict firewall configurations and access policies.
10. Data Retention Schedule
- Active Data: We retain your user profile, memories, uploaded media, and social connections as long as your account remains active.
- Verification & Reset Tokens: Verification tokens expire after one (1) hour. Password reset tokens are single-use and expire promptly.
- Security Logs: Server login audit logs and IP entries are retained for security auditing and threat analysis before routine pruning.
- Deleted Records: When you delete a memory or image, it is permanently removed from the active database and purged from AWS S3.
11. Permanent Account and Data Deletion
In accordance with Google Play developer policies and global data protection standards, you have the absolute right to permanently delete your account and all associated personal data.
Method 1: Instant In-App Deletion (Recommended)
- Open the Your Journey application.
- Tap on your Profile / Settings menu.
- Scroll to the bottom and select Permanently Delete Account.
- Confirm your choice. Your account, data, and photos will be purged immediately.
Method 2: External Web-Based Deletion Request
If you cannot access the mobile application or have uninstalled it, you can request account deletion online through our dedicated portal:
→ https://yourjourney.systems/delete-account
Alternatively, you may submit a request by emailing ptkstudio@gmail.com with the subject line "Account Deletion Request". Email-submitted deletion requests are verified and processed within thirty (30) business days.
What Happens When an Account is Deleted
When an account is deleted, our server executes an irreversible database cascade and storage wipe:
- Your primary record in
journey_users is deleted.
- All password hashes, OAuth associations, session refresh tokens, and verification codes are permanently deleted.
- All personal memories, notes, milestone progress, and adventure goals are deleted.
- All attached memory photos and your profile avatar are permanently purged from AWS S3.
- All friend relationships, pending requests, user blocks, and group memberships are deleted.
- Any groups owned by you are deleted along with their group memories.
12. Children's Privacy Protection
Your Journey is intended for a general audience and is not directed to children under the age of 13 (or under 16 where required by local law in the EU/EEA). We do not knowingly collect personal information from children. If we discover that a child under the legal age has provided personal data without verified parental consent, we will take immediate steps to delete that information and terminate the account. If you believe a child has registered with us, please contact ptkstudio@gmail.com.
13. Your Statutory Rights
Depending on your jurisdiction, you may have rights regarding your personal information:
- Right of Access: You can view and export all your personal memories, photos, and account details directly within the App.
- Right to Rectification: You can update your display name, username, avatar, and memory details at any time in the App.
- Right to Erasure: You have the right to request the permanent deletion of individual memories or your entire account.
- Right to Withdraw Consent: You can revoke device permissions (location, notifications, photos) at any time through your operating system settings.
- Right to Inquire / Complain: If you reside in Malaysia, you hold rights under the Personal Data Protection Act 2010 (PDPA) to inquire about your data handling.
14. International Data Transfers
PTK Studio manages cloud infrastructure across multiple geographical data center regions, including Amazon Web Services facilities. By using the App, your information may be transferred to and processed in countries other than your country of residence. We ensure that appropriate safeguards, including robust contractual agreements and encryption in transit and at rest, protect your personal data during cross-border transfers.
15. Updates to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our technical features, business practices, or legal requirements. When changes are made, we will revise the "Effective & Last Updated" date at the top of this document. We encourage you to review this Privacy Policy periodically.
16. Contact Information & Data Protection
If you have any questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:
PTK Studio
Attention: Privacy & Data Protection Team
Email: ptkstudio@gmail.com
Website: https://yourjourney.systems
Account Deletion Portal: https://yourjourney.systems/delete-account