Privacy · a setting you turn on

Your entries, for your eyes only

You can turn on end-to-end encryption: entries are locked right on your device. Without your passphrase, they can't be read.

How it works

Your text turns into gibberish before it ever leaves your device.

Your device you write and read as usual
encrypted
Server stores only the cipher
What you see on your device
In today's meeting I was afraid to share my idea. Then I beat myself up all day for staying quiet.

The same entry. This is how it looks on your device: decrypted with your passphrase. Tap "Server / hacker" to see what's stored in the database.

What it protects, and what it doesn't

Encryption covers a lot, but not everything.

✓ Protects from

  • Access from the service side. The server holds only ciphertext, with no key. Entries can't be read, and there's nothing to hand over on request.
  • A database breach. If the data is stolen, an attacker gets "gibberish", not your thoughts.
  • Curious eyes. Inside there's only ciphertext, nothing to read or show.

△ Keep in mind

  • !A forgotten phrase. If both the phrase and the recovery key are lost, entries can't be recovered. That's the flip side of no one being able to read them.
  • !A review by the AI assistant. When you ask to review an entry, it's decrypted on your side and sent to the AI for that one reply. It isn't stored, but in that moment it leaves your device.
  • !Someone at your unlocked device. Whoever picks up an unlocked phone or computer can read it. That's what the separate PIN is for.
  • !Metadata. Dates and the number of entries are still visible; only the text is hidden.

🔑 Recovery key: save it

When you turn encryption on, the recovery key is shown once. If you forget your passphrase, it's the only way back in. Store it somewhere safe: a password manager or a note in a drawer.

V8RG · L7CB · 2GBH · ZWN3

Why a separate "encryption phrase"?

Sign-in usually goes through Google or Apple, where there's no password to build a key from. So encryption asks for a separate short phrase, just for the journal. It isn't stored on the server and lives only in your head and on your device.

What happens when you turn it on

1
You'll pick an encryption phrase. Short, but one you'll definitely remember. It's not your sign-in password.
2
You'll get a recovery key. Shown once, so save it.
3
Old and new entries get encrypted. On your device everything reads as before; you won't notice a difference.
4
A new device will ask for the phrase. Enter it and the journal opens. Sync keeps working.
Turn it on in settings

Off by default. You turn it on and off yourself, anytime.