Your entries, for your eyes only
You can turn on end-to-end encryption: entries are locked right on your device. Without your passphrase, they can't be read.
How it works
Your text turns into gibberish before it ever leaves your device.
The same entry. This is how it looks on your device: decrypted with your passphrase. Tap "Server / hacker" to see what's stored in the database.
What it protects, and what it doesn't
Encryption covers a lot, but not everything.
✓ Protects from
- ✓Access from the service side. The server holds only ciphertext, with no key. Entries can't be read, and there's nothing to hand over on request.
- ✓A database breach. If the data is stolen, an attacker gets "gibberish", not your thoughts.
- ✓Curious eyes. Inside there's only ciphertext, nothing to read or show.
△ Keep in mind
- !A forgotten phrase. If both the phrase and the recovery key are lost, entries can't be recovered. That's the flip side of no one being able to read them.
- !A review by the AI assistant. When you ask to review an entry, it's decrypted on your side and sent to the AI for that one reply. It isn't stored, but in that moment it leaves your device.
- !Someone at your unlocked device. Whoever picks up an unlocked phone or computer can read it. That's what the separate PIN is for.
- !Metadata. Dates and the number of entries are still visible; only the text is hidden.
🔑 Recovery key: save it
When you turn encryption on, the recovery key is shown once. If you forget your passphrase, it's the only way back in. Store it somewhere safe: a password manager or a note in a drawer.
V8RG · L7CB · 2GBH · ZWN3Why a separate "encryption phrase"?
Sign-in usually goes through Google or Apple, where there's no password to build a key from. So encryption asks for a separate short phrase, just for the journal. It isn't stored on the server and lives only in your head and on your device.
What happens when you turn it on
Off by default. You turn it on and off yourself, anytime.