What Daylogue can and cannot read

No vague tiers. No marketing language. Here is what stays readable by default, what you can encrypt yourself, and what we can always see on our servers.

The full picture, item by item

Every piece of data you put into Daylogue falls into one of two buckets. No exceptions.

Client-side encryption is an optional setting in Settings > Privacy & Security, and it is off by default. The left column below describes what happens once you turn it on. Until you do, that same content is stored in readable form on our servers, protected by TLS in transit and strict per-user access controls.

What we CANNOT read (if you turn on encryption)

Encrypted on your device. Your keys only. Optional, off by default.

Your journal entries

The actual words you wrote in your vault, for entries written after you turn on client-side encryption

Your check-in notes

What you typed or dictated during a check-in, once client-side encryption is on

Your chat messages with the AI companion

The full conversation, question by question, when stored under client-side encryption

Your voice conversation transcripts

Everything you said out loud in a voice check-in, when stored under client-side encryption

Your photos

When photo encryption is enabled in your settings

Your goal descriptions and habit notes

The personal details behind your focus areas, when stored under client-side encryption

Your focus area observations

The reflections and notes you write about what you are noticing, when stored under client-side encryption

This means: For any content written while client-side encryption is on, even a database breach would only expose unreadable ciphertext. If you have not turned encryption on, that same content is stored in readable form, protected by TLS and access controls rather than by ciphertext.

What we CAN see

Stored server-side. Powers your features.

Your mood score

A number (1-10) or the emoji you selected

Your energy and stress levels

Numeric scores from 1-10

Your sleep hours

How many hours you reported sleeping

Your tags and themes

Labels like "work", "family", "stress", "gratitude"

AI-generated summaries

A condensed version of your entry, not your raw words

Your daily narrative

The story the AI writes about your day

Pattern insights

"Stress has been rising this week" or "Sleep improved over the last month"

Your chromascape color and soundtrack choices

The palette and song tied to each day

Weather data

The conditions at your location when you checked in

Check-in dates and times

When each check-in happened

Your account email and subscription status

So you can log in and we can manage billing

Why does Daylogue need to see that second column?

Your daily narrative is written by AI that needs to know your mood, tags, and summary to tell a coherent story about your week. If those were encrypted, we could not generate it.

Pattern detection needs to compare your stress levels across weeks to notice "stress has been elevated lately." Encrypted numbers cannot be compared.

Your chromascape maps mood and energy to color palettes. That mapping happens on our servers.

In short: everything in the right column exists because a specific feature you use depends on it. We do not collect data we do not use. We never sell it. We never share it with advertisers or third parties. We never use it to train AI models.

A Real Example

What each layer actually sees

Say you write this in a check-in:

“Had a terrible fight with Mom today. She said some things that really hurt. Feeling really low and I just want to be alone.”

Your entry, with client-side encryption on

What Daylogue stores on our servers if you've enabled this optional setting

aGFkIGEgdGVycmlibGUgZmlnaHQgd2l0aCBNb20g dG9kYXkuIFNoZSBzYWlkIHNvbWUgdGhpbmdzIHRo YXQgcmVhbGx5IGh1cnQuIEZlZWxpbmcgcmVhbGx5 IGxvdyBhbmQgSSBqdXN0IHdhbnQgdG8gYmUgYWxv bmUu...

With client-side encryption on, this is all we have: unreadable without your encryption key. If that setting is off, we store the readable text instead, protected by TLS and access controls.

AI-generated summary

What powers your narrative and insights

“Difficult family interaction. Low mood, wanting solitude.”

Condensed by AI. No specific names, no exact quotes, no private details.

Structured metrics

The numbers and tags extracted from your check-in

mood: 3stress: 8energy: 4tags: [family, conflict]

Numbers and categories. No context about who, what, or why.

Notice the gap between what you wrote and what we can see. That gap is the point.

What happens if our database is breached?

We build for the worst case. Here is exactly what an attacker would get, assuming you have client-side encryption turned on (it is optional and off by default):

Your journal entries, check-in notes, chat messages, voice transcripts (with client-side encryption on)

Unreadable ciphertext. Useless without your encryption key, which never leaves your device. If you have not turned this optional setting on, this content is stored in readable form, protected by TLS and access controls instead.

Your AI summaries, mood scores, tags, pattern insights, narratives

Readable. An attacker could see that you had a "difficult family interaction" on Tuesday with a mood of 3 and stress of 8. They would not see the actual words you wrote.

Your email address and subscription status

Readable. Same as any other service you have an account with.

The bottom line: If you turn on client-side encryption, your raw words stay protected even in the worst-case scenario. If you don't, your raw words are stored in readable form, protected by TLS and access controls rather than by ciphertext. Either way, AI summaries and metrics are always stored readable server-side and would be exposed in a breach, but they contain a fraction of the detail and none of the specifics from your original entries. We never sell your data to third parties. We never share it with advertisers. We never use it to train AI models. Our only revenue is subscriptions.

Your Rights

You still own everything

Export your data anytime. Delete everything with a single request. Your data, your call.

Export anytime

Download all your data in JSON format with one click

Delete within 30 days

Request deletion and we remove everything

No shadow copies

When deleted, your data is gone from our systems

No surprises

We tell you exactly what we can see before you sign up

Your data lives here

Protected in transit and by access controls, with optional device-side encryption you control.

Optionally encrypted
Exportable
Deletable

Now you know

Turn on optional client-side encryption and your raw words stay encrypted, even from us. Your patterns and summaries are always readable on our servers so we can build features around them. If that tradeoff sounds fair, we would love to have you.