How we protect your journal
No emotion inference. TLS in transit, per-user access controls in the database, and entry text is kept out of Daylogue's application logs and error reports.
What happens to an entry
The whole path, from the moment you write it to where it sits afterward.
You write
Your entry starts on your device
It travels over TLS
Encrypted in transit on every request
Daylogue reads it
Our systems read your words to write your narrative and find your patterns
We store it
In readable form for most content, and as AES-256-GCM ciphertext for vault entries where a key exists
Security in depth
Multiple layers of protection for your most personal thoughts.
We never read emotion off your face or your voice tone
Daylogue does not run emotion recognition on your face or on the tone of your voice. It works only from what you choose to share: what you write, what you say, what your week looks like, what your body's doing. It might tell you your stress ran higher on the nights you logged under six hours. It will never tell you that you sounded sad.
What actually guards your entries
Every request travels over TLS. On our servers, your rows are separated from everyone else's by per-user access controls and row-level security in the database. Entry text is kept out of Daylogue's application logs and error reports: application logging is off in production, and entry text, transcripts, and AI summaries are redacted before anything reaches error monitoring.
Where vault encryption applies, and what it covers
Where an account has an encryption key, journal vault entries are encrypted on your device with AES-256-GCM before they are sent, and the key is wrapped with PBKDF2-SHA256 at 600,000 iterations. Not every account has one, and there is no setting that turns this on or off. Vault encryption protects those entries from routine staff access and from most breaches, but you should not treat it as making them unreadable to us.
Daylogue reads your entries. We would rather say so.
Your narrative is written from your words, and your patterns are found by comparing your entries to each other. That work happens on our servers, which means our systems read what you wrote. Check-in notes, gratitude, wins, challenges, AI-generated summaries, narratives, and structured metrics are all stored in readable form, because the features you use depend on them being readable server-side.
Web security
We enforce a strict Content Security Policy (CSP) that prevents cross-site scripting attacks. All connections use HTTPS with modern TLS, and HSTS is enforced. Security headers protect against clickjacking (X-Frame-Options), MIME sniffing (X-Content-Type-Options), referrer leakage, and browser feature abuse.
Transit Security
TLS for all network requests, HSTS enforced
Access Control
Per-user access controls, row-level security in the database
Log Redaction
Entry text, transcripts, and summaries redacted from error monitoring
Vault Encryption
AES-256-GCM with unique 96-bit IV per entry
Key Derivation
PBKDF2-SHA256 at 600,000 iterations
Key Escrow
Where present, enables self-service recovery from your own signed-in session
Note: These specifications may evolve as we adopt stronger cryptographic standards. We will always communicate changes in advance and ensure backward compatibility for your existing data.
We never read your face or your voice tone
A lot of software in this category wants to guess how you feel from a camera or from the sound of your voice. Daylogue does not, and that boundary is built into the product, not left to a setting.
No inference from faces
Daylogue never analyzes your face or expression to guess your mood
No inference from voice tone
Voice check-ins are transcribed into your words. The sound of your voice is not scored
Health metrics are read, and we say so
Heart-rate variability and sleep quality are compared against the themes in your writing, so a theme can be flagged as landing on the days your body dipped
Only what you choose to share
What you write, what you say, what your week looks like, what your body's doing
Your words, on your devices
Sign in anywhere and your entries are there. Nothing about you is read from a camera or a microphone.