Privacy & Trust
Can an App Read My Journal?
What “private” actually means — and what to look for before trusting an app with your inner life.
Most journaling apps can read your entries. Daylogue is one of them, and it is worth saying that in the first sentence rather than the last. Daylogue reads your entries to write your narratives — that is how the product works. Any app that reflects your week back to you, names a pattern, or writes you a summary is reading what you wrote, whatever its marketing page says. What follows is what that actually means, what protects your entries anyway, and what to check before you trust any app with your inner life.
What most journaling apps actually do with your data
The default in the journaling app industry is server-side storage. You type an entry, it gets sent to a server over HTTPS (encrypted in transit), and then it sits in a database. Some apps encrypt the database at rest using keys that the company controls. Others store entries as plain text. In either case, the company has the technical ability to read your entries. They may promise not to, but the capability exists.
This matters because databases get breached. Employees sometimes have overly broad access. Legal requests can compel companies to turn over data they have the ability to decrypt. If the company can read your entries, those entries are only as private as the company is trustworthy and secure — and that is a high bar for content as personal as a journal.
The difference between “encrypted” and “end-to-end encrypted”
Many apps advertise that your data is encrypted. This is technically true but misleading. There are two very different kinds of encryption:
- Server-side encryption: The company encrypts your data on their servers using keys they control. They can decrypt it at any time. This protects against external attackers but not against the company itself.
- End-to-end encryption: Your data is encrypted on your device before it leaves. The encryption keys exist only on your devices. The company never has the ability to read your data, even if they wanted to.
When an app says your data is “encrypted,” ask: who holds the keys? If the answer is the company, your data is only as private as their security practices and policies. Ask it about Daylogue too — the answer is below, and it is the first kind, not the second.
Where Daylogue sits
Your entries are stored in readable form on Daylogue's servers. They are protected in transit by TLS and by strict per-user access controls in the database, and employees do not have routine access — but readable by Daylogue in principle, the same way most journaling apps store data. There is no setting that makes your entries unreadable to Daylogue, and you should not go looking for one. If end-to-end encryption is a hard requirement for you, Daylogue is not the tool that meets it, and a plain-text notes app on a device you control will serve you better than any app that reads you.
The trade is straightforward. A narrative that tells you your stress runs higher on the nights you logged under six hours cannot be written by something that cannot read the nights. You are trading a cryptographic guarantee for a system that reads four streams — what you write, what you say, what your week looks like, what your body's doing — and hands the pattern back to you. That is a real trade, and it should be made knowingly.
What happens to an entry when you save it
You write or speak an entry. The text travels to Daylogue over TLS and is sent to the AI provider (AWS Bedrock), which pulls out themes, mood, energy, and a short line that captures the essence of what you said. Provider handling follows Daylogue's configured service terms and current subprocessor disclosures. Those extracted results are stored in readable form, because pattern detection runs on them — the connection between your Sundays and your energy is computed on Daylogue's servers, not on your phone. Your entry text is stored too, and later the narrative engine reads it to write your daily read.
The consequences are worth stating rather than burying. A breach that reached the database would expose entries in readable form. Entries could be produced in readable form if Daylogue were legally compelled. Those are the same terms as any journaling app that does not hold keys it cannot use, and pretending otherwise would be the more comfortable choice, not the more honest one. You can read more about how Daylogue handles AI safety and the technical details of AI processing.
What actually protects your entries
These are the controls that exist, stated at the size they actually are:
- Everything between your device and Daylogue travels over TLS
- Per-user access controls in the database keep one account out of another account's entries
- Entry text is kept out of Daylogue's application logs and error reports
- Daylogue does not run emotion recognition on your face or on the tone of your voice — only from what you choose to share
- We do not sell your data and we do not run ads. Daylogue makes money from subscriptions
What none of that does is put your entries out of Daylogue's reach, and none of it is offered as a substitute for that. A log-redaction rule is a smaller promise than a key you hold — it is also a promise Daylogue actually keeps, which is the difference this page is about.
Red flags to watch for in journaling app privacy policies
If you are evaluating a journaling app, read the privacy policy carefully. These phrases should raise concerns:
- “We may use your data to improve our services” — this often means AI training
- “We share anonymized data with partners” — anonymized emotional data is often re-identifiable
- “Your data is encrypted at rest” without mentioning who holds the keys — this is likely server-side encryption
- No mention of encryption at all — your data is likely stored as plain text
Daylogue publishes its privacy architecture in plain language, not just in legal documents. If you are concerned about how apps use psychological pressure, that is worth reading too.
Ready to see your patterns?
Two minutes a day. No blank pages. No streaks. Just questions that lead somewhere.
Try your first check-in