What Daylogue can and cannot read
No vague tiers. No marketing language. Here is what stays readable by default, what you can encrypt yourself, and what we can always see on our servers.
The full picture, item by item
Every piece of data you put into Daylogue falls into one of two buckets. No exceptions.
Client-side encryption is an optional setting in Settings > Privacy & Security, and it is off by default. The left column below describes what happens once you turn it on. Until you do, that same content is stored in readable form on our servers, protected by TLS in transit and strict per-user access controls.
What we CANNOT read (if you turn on encryption)
Encrypted on your device. Your keys only. Optional, off by default.
Your journal entries
The actual words you wrote in your vault, for entries written after you turn on client-side encryption
Your check-in notes
What you typed or dictated during a check-in, once client-side encryption is on
Your chat messages with the AI companion
The full conversation, question by question, when stored under client-side encryption
Your voice conversation transcripts
Everything you said out loud in a voice check-in, when stored under client-side encryption
Your photos
When photo encryption is enabled in your settings
Your goal descriptions and habit notes
The personal details behind your focus areas, when stored under client-side encryption
Your focus area observations
The reflections and notes you write about what you are noticing, when stored under client-side encryption
This means: For any content written while client-side encryption is on, even a database breach would only expose unreadable ciphertext. If you have not turned encryption on, that same content is stored in readable form, protected by TLS and access controls rather than by ciphertext.
What we CAN see
Stored server-side. Powers your features.
Your mood score
A number (1-10) or the emoji you selected
Your energy and stress levels
Numeric scores from 1-10
Your sleep hours
How many hours you reported sleeping
Your tags and themes
Labels like "work", "family", "stress", "gratitude"
AI-generated summaries
A condensed version of your entry, not your raw words
Your daily narrative
The story the AI writes about your day
Pattern insights
"Stress has been rising this week" or "Sleep improved over the last month"
Your chromascape color and soundtrack choices
The palette and song tied to each day
Weather data
The conditions at your location when you checked in
Check-in dates and times
When each check-in happened
Your account email and subscription status
So you can log in and we can manage billing
Why does Daylogue need to see that second column?
Your daily narrative is written by AI that needs to know your mood, tags, and summary to tell a coherent story about your week. If those were encrypted, we could not generate it.
Pattern detection needs to compare your stress levels across weeks to notice "stress has been elevated lately." Encrypted numbers cannot be compared.
Your chromascape maps mood and energy to color palettes. That mapping happens on our servers.
In short: everything in the right column exists because a specific feature you use depends on it. We do not collect data we do not use. We never sell it. We never share it with advertisers or third parties. We never use it to train AI models.
What each layer actually sees
Say you write this in a check-in:
Your entry, with client-side encryption on
What Daylogue stores on our servers if you've enabled this optional setting
With client-side encryption on, this is all we have: unreadable without your encryption key. If that setting is off, we store the readable text instead, protected by TLS and access controls.
AI-generated summary
What powers your narrative and insights
Condensed by AI. No specific names, no exact quotes, no private details.
Structured metrics
The numbers and tags extracted from your check-in
Numbers and categories. No context about who, what, or why.
Notice the gap between what you wrote and what we can see. That gap is the point.
What happens if our database is breached?
We build for the worst case. Here is exactly what an attacker would get, assuming you have client-side encryption turned on (it is optional and off by default):
Your journal entries, check-in notes, chat messages, voice transcripts (with client-side encryption on)
Unreadable ciphertext. Useless without your encryption key, which never leaves your device. If you have not turned this optional setting on, this content is stored in readable form, protected by TLS and access controls instead.
Your AI summaries, mood scores, tags, pattern insights, narratives
Readable. An attacker could see that you had a "difficult family interaction" on Tuesday with a mood of 3 and stress of 8. They would not see the actual words you wrote.
Your email address and subscription status
Readable. Same as any other service you have an account with.
The bottom line: If you turn on client-side encryption, your raw words stay protected even in the worst-case scenario. If you don't, your raw words are stored in readable form, protected by TLS and access controls rather than by ciphertext. Either way, AI summaries and metrics are always stored readable server-side and would be exposed in a breach, but they contain a fraction of the detail and none of the specifics from your original entries. We never sell your data to third parties. We never share it with advertisers. We never use it to train AI models. Our only revenue is subscriptions.
You still own everything
Export your data anytime. Delete everything with a single request. Your data, your call.
Export anytime
Download all your data in JSON format with one click
Delete within 30 days
Request deletion and we remove everything
No shadow copies
When deleted, your data is gone from our systems
No surprises
We tell you exactly what we can see before you sign up
Your data lives here
Protected in transit and by access controls, with optional device-side encryption you control.