Hearth

privacy

Why We Built a Journal That Forgets Your Password on Purpose

Here's a confession that sounds like a bug report: Hearth has a mode that can't email you a link back into your journal, no matter how nicely you ask.

It's called Private Vault, and in it your entries are locked with something only you hold — a passphrase and a recovery key. Lose both, and we genuinely cannot wave your journal back into existence for you. We built it that way on purpose. It's not an oversight we haven't gotten around to fixing. It's one of the most important design decisions in the whole product, and we'd like to defend it, because on the surface it looks insane.

The thing every other app quietly does

When you forget your password almost anywhere, you click a link, prove you can read an email, and you're back in — with all your stuff exactly where you left it.

Have you ever stopped to ask how that's possible? It's possible because the company had your stuff in a form they could read the whole time. The "lock" on your data was really just a setting on their server, and the reset link tells the server to flip it for whoever clicked. Your data was never truly locked to you. It was locked to them, and they agreed to share.

That's fine for your food-delivery app. It is not fine for your diary. Because the exact same capability that lets them hand your journal back to you after a forgotten password is the capability that lets them read it, hand it to a court, lose it in a breach, or change their mind in an "updated terms" email. "We can give it back to you" and "we can read it" are the same sentence.

The trade, said plainly

You can't have both of these things at once:

  1. A journal that absolutely nobody but you can read.
  2. A company that can recover your journal for you if you lose your key.

Pick one. Truly. They're mutually exclusive, and any app offering both is quietly lying about the first. We weren't willing to fake either side, so we made it a choice instead.

Hearth's default picks the second, and says so out loud: your entries are always encrypted, but we keep one sealed spare key, so signing in opens your journal and you can never be locked out. We don't read anything with it — that's a tested rule in our codebase, not a vibe — but it's a don't, not a can't.

Private Vault picks the first. Set a passphrase, and our spare key is deleted. From then on nobody but you can read your journal, including us — and the price of that lock is that we're also unable to pick it for you. The thing that protects you from us keeps protecting you from us even when you'd really like us to make an exception. We can't make exceptions. That's what makes it a real lock instead of a curtain.

What we do so this isn't reckless

Now — "lose your key and it's gone forever" would be a genuinely irresponsible thing to hand people if we just shrugged. We don't. The cliff has railings:

  • The forgetting is never accidental. You only stand near the cliff after deliberately flipping the switch, reading the warnings, and telling us you understand.
  • When you set your passphrase, we generate a recovery key and walk you through saving it somewhere real — a password manager, a drawer with your passport. Two spares, both yours, so a single lost passphrase doesn't mean a lost journal.
  • We warn you, loudly and early, instead of burying it. Because the worst version of this is finding out the rules after you've lost something.

The goal is simple: make losing your access genuinely hard, while never making it possible for us to get in. Railings on the cliff, not a secret elevator.

Why we think it's worth it

A lot of people, hearing all this, still flinch. "What if I lose it?" It's a fair fear, and we take it seriously — it's the whole reason the spare-key default exists.

But flip it around. In Private Vault, the reason we can't get back in for you is the same reason a hacker can't, a future owner of the company can't, a curious employee can't, a subpoena can't. The inconvenience and the protection are not two features. They're one feature, seen from two sides. You can't keep the protection and delete the inconvenience, any more than you can have a lock that only opens for nice people.

We'd rather hand you a journal that's genuinely, provably yours — with clear warnings and good railings — than pretend there's a version of "nobody can read it" that comes with a customer-service exception. A diary that someone else can open for you is a diary they're holding. Private Vault is the other thing, and we built it on purpose.

privacyproduct