Hearth

How can we help?

A human reads every message. We usually reply within two working days, by email.

Your words

Is my journal really encrypted?

Yes — every entry is encrypted on your device before it leaves it, in every mode. The server only ever stores ciphertext, and that's enforced by tests, not just policy. Photos and voice notes are journal content too, so they get the same treatment.

What's the difference between the default and Private Vault?

In the default managed mode we keep a sealed spare copy of your key, so signing in on a new device just works. That means we could technically decrypt your entries, and our policy is that we don't — we only ever do it in the moment, for a feature you asked for, keeping nothing. Private Vault mode removes that spare copy: your passphrase is the only key, so we can't read your journal at all, no matter who asks. It's free, and you can switch on it in Settings → Security.

I forgot my Private Vault passphrase.

Your recovery key is the only other door. If you have it, use it on the unlock screen. If you have neither, nobody can open that vault — including us. That isn't us being unhelpful; it's the promise of Private Vault mode working exactly as designed.

I can't sign in, or it's asking for a passphrase I never set.

On a normal (managed) account you should never see a passphrase prompt — sign out fully and back in, and if a password is the problem use "Forgot password" on the sign-in screen. If you switched to Private Vault at some point, the passphrase or recovery key is what's needed. Still stuck? Write to us from the help page and we'll work through it with you.

Can I get my entries out?

Any time. Settings → Security and data → Export. Everything is decrypted on your device and saved as a file you keep — no request, no waiting, no permission needed.

How do I delete everything?

Settings → Account → Delete my account. This is crypto-erasure: your account, your entries and the keys that could ever decrypt them all go together, which makes the ciphertext permanently unreadable — including in backups. It cannot be undone. There's also a page at /delete-account if you'd rather do it from outside the app.

Are photos and voice notes protected too?

Yes. Audio and images are journal content, so they're encrypted on your device before upload, and the server has no code path that decrypts stored media. Photos are downscaled and stripped of their EXIF data (including location) first. If you ask for a voice note to be transcribed, that one recording passes through a model in the moment and nothing is kept.

AI and the Twin

What does the AI actually see?

Only what a feature you used needs, only in the moment, and only if AI is on. A reflection sends that entry's text, gets an answer, and keeps nothing; nothing you write trains anyone's model. Inkling's memory is a rolling summary that's re-encrypted on your device before it's stored, so the server holds it as ciphertext like everything else. In Private Vault mode there's no server-side AI at all.

Can I turn the AI off completely?

Yes — Settings → Companion, and it's off until you turn it back on. Nothing breaks: the journal, the letters and the archive all work exactly the same. Accounts registered as 16 or 17 start with AI off by default.

What is the AI Twin, and what can it tell people about me?

It's an optional public chatbot that speaks as you — and it knows only what you told it: the profile you filled in and the documents you uploaded to it. Your journal is not part of that. There's a separate opt-in that lets it draw on your entries, with its own consent screen and its own warnings, and every twin surface permanently says it's an automated chatbot rather than the real person.

What's the ChatGPT / Claude connector?

It lets an AI app you already use — Claude, ChatGPT, or anything else that speaks MCP — work with your journal on your behalf. A consent screen lets you choose exactly what it may touch: your streak and counts, Inkling's short summary, specific entries you picked, permission to write drafts back into your vault, and, only if you tick it, answers drawn from your whole journal. After that you can ask that app things like "what was I worried about last month?", or have it write an entry that arrives here and is encrypted into your vault like anything else. It's part of Glow, it's off until you turn it on in Settings → Companion, and you can revoke any connected app there in one tap. The trade to understand before you start: whatever you share into another AI app lands in that app's history, under their rules rather than ours.

How do I actually connect Claude or ChatGPT to Hearth?

Turn the connector on first, in Settings → Companion → Connect to AI apps. That reveals Hearth's connector address plus a step-by-step guide for each app — copy the address with the button there rather than typing it out. Then, in Claude: Settings → Connectors → "Add custom connector", paste the address, and approve the Hearth page it opens, ticking only what you want it to reach. In ChatGPT: Settings → Connectors, add a custom connector (in some versions that sits behind "Advanced" or a developer-mode switch), paste the same address, and approve. Any other MCP-capable app works the same way: find its connector, integration or MCP server setting, choose the remote or URL-based option rather than a local command, and paste. Two things that trip people up — custom connectors are a paid feature in both Claude and ChatGPT, and they're generally a browser or desktop feature rather than a phone one. If the menu names don't match what you see, look for anything called connectors, integrations, apps or MCP; the address is all any of them need.

Plans and billing

What do the plans include, and is there a trial?

Ember is free and always will be. Glow and Bonfire add the companion features, more storage and the Twin. Every paid plan starts with a 7-day trial, and you can cancel before it ends without paying anything. Full breakdown on the pricing page.

Who's charging me, and how do I cancel or get a refund?

Dodo Payments is the Merchant of Record for web purchases, so that's the name you'll see on your statement rather than Hearth. Cancel any time in Settings → Plan; you keep access until the period ends. There's a 7-day money-back window — write to us and we'll sort it. If you subscribed inside the iOS or Android app, that subscription is managed in your App Store or Google Play account instead.

Everyday

Can I install Hearth like a real app?

Yes. On iPhone, open it in Safari and choose Share → Add to Home Screen; on desktop Chrome or Edge, use the install icon in the address bar. It then opens in its own window, works offline, and syncs when you're back online.

Why am I not getting reminders?

Reminders are opt-in and deliberately gentle — at most one a day. Turn them on in Settings → Companion. On iPhone they only work once you've added Hearth to your Home Screen, which is an Apple restriction rather than a choice of ours.

Is Hearth therapy?

No. It's a journal with a companion in it — not a therapist, not a medical service, and not a crisis line. Writing things down helps a lot of people, and it isn't a replacement for talking to someone qualified. If you're in a hard moment, crisis resources are one tap away at the bottom of this panel.

Write to us

Can't get into your account, or something else we haven't answered? Tell us here — you don't need to be signed in.

If you need someone right now

Hearth is a journal — not a crisis line, not a medical service, and not a substitute for care. If things feel urgent, please talk to someone who can help.

Find a helpline →