Hearth

privacy

What "End-to-End Encrypted" Actually Means, Minus the Jargon

"End-to-end encrypted." It's on every app's homepage now, right next to "bank-level security" and a stock photo of a padlock. The words have been said so many times they've gone fuzzy, like when you repeat "spoon" until it stops sounding real.

So let's make it sound real again. Especially since, for a journal, it's the whole point.

The diary-and-key version

Imagine an old-fashioned diary with a tiny lock on it. You write in it, you lock it, you keep the only key in your pocket.

Now imagine you want to store that diary somewhere safe — a friend's house, a bank vault, wherever. You hand it over locked. The vault holds your diary. But the vault does not get a copy of the key. So your diary sits there, safe and sound and completely unreadable to the people guarding it. They're babysitting a locked box. They could stare at it all day and learn nothing.

That's end-to-end encryption. The "ends" are you and... future you, basically. The lock happens on your device, before anything leaves. The key never goes to the vault. The company storing your stuff is the vault: very good at keeping the box safe, totally unable to open it.

What the "other" kind looks like

The version most apps actually use is more like leaving your diary unlocked at the bank, with a note that says "please don't read this." The bank promises it won't. It probably means the promise. But the diary is right there, readable, and the only thing standing between your private thoughts and a curious employee — or a hacker, or a subpoena, or a "we've updated our terms" email — is a promise.

This is called encryption "at rest" and "in transit," which sounds great and is genuinely better than nothing. It means your data is scrambled while it's sitting on their servers and while it's zipping across the internet. But the company holds the keys. They unscramble it whenever they need to. Which means they can. Which means, someday, under the right pressure, they might.

With end-to-end encryption, "we might have to" never comes up. There's nothing to hand over. The box doesn't open.

Why this matters more for a journal than for almost anything

Your email is mostly receipts and newsletters. Your photos are mostly brunch. But a journal? A journal is the unfiltered stuff. The grudges, the crushes, the 2am fears, the things you'd never say out loud and specifically wrote down because you'd never say them out loud.

That's exactly the material you don't want sitting unlocked in someone else's vault with a polite note on top. The whole reason to keep a diary is that it's safe to be honest in. The second some company is reading it, it stops being a diary and starts being a focus group.

So where does Hearth sit?

Honesty time, because under-claiming is the house style. Every entry you write in Hearth is encrypted on your phone or laptop before it reaches us, always. But in the default mode, we keep one sealed spare copy of the key. It exists for two reasons: so signing in opens your journal (no passphrase to lose, no lockout), and so the AI can answer questions you ask. It's never used to read anything beyond that — nothing decrypted is stored or logged, and tests in our codebase enforce it, not vibes. (Here's the machinery.)

So the default is a very good vault with one labeled spare key on a hook, and we're telling you the hook exists. That's a "we don't read it," not a "we can't."

If you want the full diary-and-key version this post describes — the vault babysitting a box it genuinely cannot open — that's Private Vault, and it's free on every plan. Flip it on, set a passphrase, and our spare is deleted. From then on, we could be the world's nosiest company and it wouldn't matter, because there's genuinely nothing for us to read.

The slightly inconvenient catch

Real keys come with real responsibility. In Private Vault, you hold the only keys, so if you lose your passphrase and your recovery key, nobody — not even us — can pick the lock for you. That's not a bug; it's the same fact from the other side. "We can't read your diary" and "we can't recover it if you lose your key" are the same sentence wearing two different outfits.

That's exactly why the spare key is the default and deleting it is a choice. We'll never keep a copy secretly — the spare is on the label, the delete switch is in your settings, and which trade to make is yours.

If you want the flip side — what actually happens when you hit delete — we wrote about that too: where your entries go when they're gone.

privacyencryption