WinJar

WinJar Privacy Policy

Last updated: 13 September 2026

WinJar is made by Digilife Software ("we", "us"). This policy explains exactly what the WinJar app and website (winjar.digilifesoftware.com) collect, why, and what we do with it. It is written to be read, not to be survived.

The short version

What we collect

Your email address. Needed to create your account and to send the sign-in link. WinJar has no passwords — there is no password to store, leak, or reset.

Your wins. The text you type into your jar, and the date and time you saved it.

Your attachments. Any image you attach to a win. Images are stored in Cloudflare R2 object storage and are served only to you, or to someone holding a share link you created.

Your display name, if you set one.

Technical data needed to keep the service safe. When you request a sign-in link, we record a rate-limiting entry derived from your IP address and the endpoint you called, so that the sign-in endpoint cannot be flooded. These entries are short-lived and are swept on a rolling basis. Our hosting provider (Cloudflare) also processes request metadata such as IP address and user agent as part of delivering and protecting the service.

We do not collect: contacts, location, calendar, photos beyond the image you deliberately attach, advertising identifiers, device identifiers for tracking, or usage analytics from third-party SDKs.

What we do with it

We do not use your wins for advertising or profiling, and we do not share them with anyone except as described below.

AI processing

WinJar includes a server-side feature that can rewrite a win into a cleaner, quantified accomplishment line. When and only when you trigger it, that single win's text is sent to Cloudflare Workers AI, which runs the model within Cloudflare's network. Your text is not used to train that model, and the feature never runs on its own — nothing leaves your jar for AI processing unless you ask for it.

Who else touches your data

That is the whole list. No advertising networks, no analytics vendors, no data brokers.

Share links

A share link is a capability URL: anyone who has it can read your jar without an account. You choose whether it expires in 24 hours, 7 days, 30 days, or never, and you can revoke it at any time from the app. A revoked or expired link stops working immediately. The public view carries your display name (if set) and your wins — never your email address.

Treat a share link like a key: anyone you send it to can forward it.

How long we keep things

Your choices

Depending on where you live, you may also have the right to access, correct, or port your data, and to object to processing. Write to the address below and we will handle it.

Children

WinJar is meant for working adults and is not directed at children under 13. We do not knowingly collect data from children. If you believe a child has created an account, write to us and we will delete it.

Security

Everything travels over HTTPS. Sign-in tokens are hashed before storage and are single-use. Sessions are held in an HTTP-only cookie on the web, and as a token held in the operating system's secure app storage in the mobile apps. There are no passwords in the system to be stolen.

No system is perfect. If you find a security problem in WinJar, please write to us — we would much rather hear from you.

Changes to this policy

If we change what we collect or what we do with it, we will update this page and the date at the top, and note the change in the app's release notes.

Contact

Digilife Software

Bandung, West Java, Indonesia

astefanus17@gmail.com

WinJar is a product of Digilife Software. Back to WinJar · Delete your account