Hearth

privacy

Can Your Journaling App Read Your Diary? (An Uncomfortable Little Tour)

Let's do something a little uncomfortable. Let's find out whether the app you tell your secrets to could read them.

Not whether it does. Whether it can. Those are very different questions, and the gap between them is where all the trouble lives.

The "forgot password" giveaway

Here's the fastest test, and it takes ten seconds. Go to your journaling app and pretend you forgot your password. Tap the reset link.

Did you get back in, with all your old entries sitting there exactly as you left them?

If yes — and this is true for most apps — then the company can read your diary. There's no way around it. If resetting a password (which is just proving you control an email inbox) hands you back your readable entries, that means the entries were never truly locked to you. They were sitting on a server, readable, and the company simply chose to show them to whoever clicked the link in the right inbox. The lock was a curtain, not a vault.

This isn't a conspiracy. It's just how most software is built, because it's easier. Convenient password resets and "we genuinely cannot read your data" are mostly mutually exclusive, and most apps quietly pick convenience.

The other tells

A few more things to check, none of which require being a hacker:

  • Do entries show up instantly on a brand-new device, just by logging in? If the magic is "log in and everything's here," the server is handing over readable content. Real end-to-end setups make you bring a key or passphrase the server doesn't have.
  • Does the privacy policy talk about "analyzing your entries to improve our service"? Then something on their end is reading the text for them — their product, their models, their roadmap. You can't analyze what you can't read. (Reading to answer a question you asked is a different thing — but only if they say plainly when it happens and what's kept. Silence on that is its own answer.)
  • Is there server-side search across your entries? Searching the full text of your journal usually means the server has the full text of your journal. (There are clever ways around this, but they're rare and apps brag about them when they do it.)

None of these make an app evil. Plenty of perfectly nice apps work this way. But you should know, because you're the one deciding what to write in there.

Why "they pinky-promise not to look" isn't enough

The usual reassurance is some version of "we would never read your private entries." And maybe they wouldn't! Most people at most companies are decent and busy and not remotely interested in your Tuesday.

But "we won't" is a promise, and promises have an expiry date. Companies get acquired. Policies get "updated." Servers get breached by people who never made you any promises at all. A court can compel a company to hand over what it's able to hand over. The only promise that survives all of that is the one the company can't break because it doesn't have the keys.

That's the difference between "we won't read it" and "we can't." The first depends on everyone's good behavior forever. The second is just math.

What "can't" looks like

When an app genuinely can't read your journal, you'll notice some friction, and that friction is the feature working. Setting up a new device asks for more than a password. Losing your key is a real, scary thing the app warns you about loudly, because it can't quietly bail you out. Nobody offers to analyze anything, because nobody on their end can see your entries.

Where Hearth lands, honestly

Since we started this uncomfortable tour, we should take the test ourselves.

By default, Hearth passes the "forgot password" test the convenient way: sign back in and your journal opens. That's because your entries are always encrypted, but we keep one sealed spare copy of the key. It does exactly two jobs — opening your journal when you sign in, and letting the AI answer questions you ask — and nothing decrypted is ever stored or logged. That's not a pinky promise; it's a rule enforced by tests in our own codebase. So the default is a don't, said out loud, with the receipts published.

And if you want a can't, it's a free switch. Private Vault deletes our spare key: from then on the entries open only with something you hold, the friction above becomes your friction, and we genuinely couldn't read your diary if a court asked nicely.

So go run the ten-second test on whatever you're using now. Best case, you learn your secrets are safer than you thought. Worst case, you find out the curtain was never a vault — which is exactly the kind of thing worth knowing before you write the next entry.

privacyencryption