Privacy
How this stays private
Your answers are encrypted on your device before they are sent. The server stores them, backs them up, and serves them back to you without ever being able to read them. Here is exactly what that does and does not cover.
Where the key lives
When you created your account, this site generated an encryption key inside your browser. That key has never been sent anywhere. Your passkey — the fingerprint or face scan you use to sign in — is what unlocks it, and the unlocking happens on your device too.
So the server holds a locked box and no key. That is not a policy or a promise about who is allowed to look. There is nothing to look at: what arrives here is unreadable, and no password reset, court order, or mistake on our side can turn it back into words.
What the server knows
- What you wrote never
- Your name yes
- Your timezone yes
- Which days you wrote yes
- Roughly how much yes
The dates cannot be hidden: entries lock at midnight where you are, so the server has to know which day is yours and when it ended. Length shows through because a longer answer is a longer piece of ciphertext. A system that claimed to leak nothing at all would be lying to you.
If you lose your passkey
Add a second device while you still can — Settings, then "Add this device". Any device with a passkey on your account can read everything you have written.
The recovery code shown once at signup is the other way back in. If you lose every passkey and that code, your entries are gone. Not withheld pending verification — gone, because the only keys that could open them were the ones you held. That is the cost of the guarantee above, and it is the reason Settings offers a download.
That download is a plain, unencrypted file. It is meant to be — keep it somewhere you would keep a paper diary.
The honest limit
This is a website, and the server sends the code that does the encrypting. Someone who took over the server could serve altered code and capture the key from people who visit afterwards. Everything already written stays unreadable, and the site is locked down hard to make that attack difficult — but a web app cannot promise what a signed, installed program can. Anyone telling you otherwise about browser encryption is overselling it.
How to check, rather than trust
Write a strange, distinctive phrase into today's answer — something that appears nowhere else. Then, in Settings, download your journal and search the file for it. It will be there.
Then ask whoever runs the server to search the database and the logs for that same phrase. It will not be there. One phrase, present in the copy only you can make and absent from every file on the server, is this entire page demonstrated from both ends.