Self-discovery, self-love, personal growth.
← All posts
·3 min read

Can Your Journal App Read Your Entries? Questions to Ask

A lock icon tells you that an app wants to communicate security. It doesn't tell you who has the key. Before putting sensitive writing into a journal app, look for answers to the questions below. “I couldn't find an answer” is a useful result too.

Keep a small note with three headings: the claim, the supporting documentation, and what remains unclear. That makes comparing two apps much easier than remembering which privacy page sounded more reassuring.

Who can unlock stored entries?

Look for an explicit explanation of where encryption happens and who controls decryption keys. Encryption on the provider's disks can protect stored data while still allowing the application to read it. Client-side encryption with keys unavailable to the provider describes a different access boundary.

If the page only names a cipher, such as AES-256, keep looking. The algorithm name does not tell you who can use the key.

What restores access after a forgotten password?

Read the recovery documentation. You don't need to reset your real account to investigate it. Ask whether recovery relies on a saved phrase, an already trusted device, a key held by the company, or another mechanism.

For example, Proton distinguishes account recovery from data recovery. User-controlled recovery can restore encrypted content. Successful recovery is not, by itself, evidence that staff can read the archive.

Where do search, notifications, and AI run?

Features offer questions to investigate, not verdicts. A notification might be prepared on a device. Search might use an index that was already downloaded. Speed alone does not establish where readable text exists.

Hosted AI deserves a direct question: which text is sent, to which companies, for what purpose, and for how long? Check whether using the chat also permits access to journal entries. Those can be separate controls.

What happens to copies?

Read the retention and deletion sections, including backups, service providers, and exceptions. Ask what an export contains and whether you can open it independently. Removing an app from your phone is not necessarily an account-deletion request.

Keep the difference between architecture and policy visible. A policy describes permitted handling; a technical explanation describes what the system can access. Neither should be replaced by a marketing slogan.

A question you can send support

Before I store private entries, could you link to documentation explaining who can decrypt them, how data recovery works, and what text leaves my device when I use AI? Please include provider retention and what happens when I delete my account.

This is an example message, not a security audit. Specific answers help you make a decision; unresolved questions may be a reason to keep sensitive material elsewhere. For KindMind, start with the storage design and the separate AI processing explanation.