Skip to content

Guide chat, memory, and the Journal memory setting · KindMind Labs

How AI Works at KindMind

This page explains how AI features at KindMind actually work. That includes the Guide chat (an AI-guided self-reflection conversation), the memory it builds from your conversations over time, and the Journal memory setting that decides whether your journal entries contribute to AI responses and memory too.

Your private account content is saved encrypted. When you use AI, your messages travel through our proxy to Anthropic’s Claude API for readable processing. Plans, titles, goals, and descriptions you submit to the Path finder also pass through our application server. Provider retention and safety exceptions apply, and an automated safety check runs on chat requests. Guide and Path conversations can contribute to AI memory. Journal text contributes when you enable Journal memory. Saved memories are summaries encrypted on your device before account storage.

On this page

Does This Apply to You?

The free Journal plan does not include Guide, Paths, or AI memory. Your journal entries are not automatically submitted to those features on that plan. One thing happens before that, though: if you answered the questions on our signup flow, those answers were sent through the AI proxy so the flow could respond to them. That happens before any account or plan exists, and our Privacy Policy describes it.

On plans or trials that include AI features, Guide chat and Paths process the information needed to provide those features. Everything below, the data flow, the safety check, memory summarization, describes how those features work. Journal memory, which controls journal summaries and direct journal context in chats, stays off until you turn it on. Guide and Path conversations can contribute to memory either way.

You can also try Guide and Path discovery before signup. Those requests use our proxy and Anthropic, including safety checks and provider retention. A message submitted from the homepage can start a try-mode Guide conversation. Try mode keeps a separate browser copy and does not build account AI memories or automatically send its journal entries to AI before import. Chats imported into an account can later contribute to account memories. The Privacy Policy explains its local storage and limits.

The Data Flow

Your device
decrypts what the request needs
Our AI proxy
readable request processing
Our AI provider
retention and safety exceptions apply

When you send a message in the Guide chat, it takes this path:

  • Your browser decrypts the conversation locally using your master key, then sends the message over HTTPS.
  • It travels to a small KindMind worker (a Cloudflare edge proxy at ai-proxy.kindmind.com) that verifies a short-lived token bound to your session.
  • Before forwarding your message, the worker runs a quick automated safety check: a second, separate call to the same Anthropic API, under the same no-training commercial terms, that looks for signs of crisis or risk. It runs on the messages you actually write (Guide chat, path chat, and the questions on signup), not on every AI call the app makes.
  • The worker forwards the request to Anthropic’s Claude API.
  • Claude’s reply streams back through the worker to your browser, which renders it. The reply arrives as ordinary text over an encrypted connection, so there’s nothing to decrypt; your browser encrypts it when it saves the reply to your account. If the safety check flags a serious concern, the worker skips the AI reply and sends a fixed supportive message with crisis resources instead, and when the concern is milder a second check reads the reply before it’s released to you.

The proxy processes plaintext during a request and does not intentionally save message bodies. Our application server also receives selected plans, titles, goals, and related context to assemble AI instructions. The Path finder sends your free-text description to that server and then through the proxy to Anthropic; this recommendation request does not use the chat safety check. Operational logs, token counts, and safety classifications are separate from private message content. What Anthropic holds on their side is covered in the retention section below. If an account chat safety check flags a concern, KindMind keeps a category-level record of that (never the words themselves) so we can point you toward support, described more below.

AI requests are not anonymous merely because they use our API account. Your writing may identify you or other people. Avoid including information you do not want the AI provider to process. The former daily AI activity-email process has been retired.

What “Summarization” Means

While you use the web app, memory passes take eligible records, decrypt them in your browser, and send them through the worker for AI processing. Guide conversations are processed oldest first, with the guide’s replies included so the summary reads the whole conversation: right after you unlock, and on later page loads until older messages are caught up (up to 50 of your messages each time), and as you keep chatting (25 at a time). Path conversations, and your journal entries if Journal memory is on, are processed in a daily pass of up to 25 not-yet-summarized records per feature; it normally runs when due after a 24-hour interval, and retries and app activity affect timing. Neither has a date cutoff, so over time these passes reach older writing, not only the latest records. Claude returns summaries that are encrypted with your master key and saved to your Memories. Conversation recap and memory compaction can also send recent conversation messages and existing memories.

Summaries do not mean the AI never receives original text. Memory extraction processes source text. Chats receive recent messages, and enabling Journal memory permits up to 5,000 characters of today’s latest journal entry, including the whole entry if shorter, to be included on each web chat turn. The mobile app currently does not send this direct journal context or run the web memory pass; its awareness switch also controls inclusion of saved memories and recaps in mobile chats. Later conversations can continue to use saved memories until you remove them.

What Gets Stored, and Where

Memories live in a table called user_memories, encrypted with your master key. That key is only ever unlocked on your device. The copy we hold is wrapped by a second key that your browser derives from your password and never sends us. To us, a memory looks like a random string of bytes.

Your original records (journal entries, path responses, guide chat messages) stay encrypted in their own tables. Memory building sends eligible source text to the AI provider and saves a separate encrypted summary. Provider copies follow the retention rules below.

You can read more about how master keys, password-derived keys, and the underlying encryption work on the encryption page.

Anthropic’s Posture

Claude is built by Anthropic. We use its commercial API for responses, summaries, and automated safety checks. Models and request types can change; a model name alone is not a privacy guarantee.

Anthropic’s commercial training policy provides for no training on API inputs and outputs by default; separate feedback or opt-in arrangements can differ. KindMind does not use private writing for model training. Its retention policy describes a standard API window of up to 30 days, with longer safety and legal exceptions. Flagged inputs and outputs may be held for up to two years and safety scores for up to seven years. These are provider practices, not a guaranteed deletion deadline for every request.

We use provider prompt caching, which can temporarily retain repeated request content to reduce processing cost. Caching does not replace other provider retention. Authorized provider personnel may review content for safety or legal purposes. We do not offer a guarantee of zero retention or no human access at the provider.

Private Content and Operational Records

Your saved private content fields contain encrypted blobs and IVs (random values used by the encryption). AI requests and the server-side context preparation described above involve readable processing. Plenty of other things about your account are readable to us, though: your email, your subscription, your settings, product usage records, and the program and approach you picked for a path. The Privacy Policylists them. Alongside those, when an account chat safety check flags a concern, we store a category-level safety record (for example, “crisis resources shown”). If the check itself fails to run, we also store a content-free error record so we can keep an eye on it. We also keep operational records of supported input safety checks, noting the category it saw and how long it took. Those carry no account identifier and never include your words. We stop short of calling them anonymous, because one is written at the same moment as the account-linked record above, so in principle the two could be lined up by their timestamps. We do not use these timestamps to identify you. These operational records are scheduled for removal from the live database within 90 days. Backup copies follow the retention and deletion treatment in Section 12 of the Privacy Policy. Try-mode checks do not create account-linked safety records, and their operational classification records are not currently saved. The account storage design encrypts journal entries, chat messages, plans, and memories before saving. It does not treat the following as ordinary readable account records:

  • The plaintext of your journal entries, path responses, or guide chat messages
  • The plaintext of your memory summaries
  • Your unlocked master key, or your password in readable form
  • The content of your conversations with Claude

The worker sends category-level safety records and per-request token counts to the main app. Separately, your device sends readable plan and title context to the main app to prepare prompts. Support messages, feedback, and testimonials you address to us are readable; migration from an older service is another temporary processing exception. The Privacy Policy explains those flows.

Your AI and Memory Choices

Journal memory is optional. Where these controls are available, open Account → AI features → Journal memory. From there you can:

  • Turn Journal memory off to stop new journal excerpts and journal memory requests. Guide and Path conversations can still be processed and summarized.
  • Click Clear all AI memories to remove saved memories from your account. Eligible activity can create new memories afterward.

Turning Journal memory off stops journal entries from contributing new summaries going forward; memories created earlier stay until you clear or edit them. Clearing memories deletes the saved memory pool for the current product, but not your original writing or conversation recaps; later AI use can create new memories. A change does not recall an in-flight request or delete provider-held copies. The Journal memory switch is not a global AI-off switch. Stop using AI features and contact hello@kindmind.com for help with consent withdrawal or unavailable controls.

Common Questions

Does the AI read my journal entries?

Only if you turn on Journal memory, and it stays off until you do. Your entries are encrypted on your device before they are stored, and enabling Journal memory lets AI summarize entries and include up to 5,000 characters of your latest entry from today directly in each web Guide or Path chat request, including the whole entry if shorter. Eligible entries for summaries include older writing without a date cutoff. Mobile uses the same account setting, but currently sends saved memories and recaps instead of direct journal excerpts. With it off, those paths exclude new journal content. Existing memories remain until you delete them, and text you paste into an AI conversation is sent as part of that conversation.

What exactly gets sent when I use the guide?

When you send a message, your device decrypts what that request needs: the recent stretch of that conversation (up to 100 messages on web; mobile uses a smaller history window), saved memories and conversation recaps where enabled, and the guide’s instructions. Web requests can also include your display name, local time and time zone, Path titles and progress, and up to 40 turns from the other AI conversation today. That travels over HTTPS to our AI proxy at ai-proxy.kindmind.com, which is infrastructure KindMind runs, and on to our AI provider, Anthropic. The proxy does not intentionally persist message bodies. Guide and Path plans, titles, goals, and related context can also pass through our application server while it prepares instructions. If Journal memory is on, up to 5,000 characters from your latest journal entry today can be sent again on each web chat turn, including the whole entry if shorter. Mobile currently sends neither this journal excerpt nor the web cross-conversation context; its awareness switch also controls inclusion of saved memories and recaps.

Does KindMind train AI models on my writing?

KindMind does not use your private writing to train AI models. We send AI requests to Anthropic under its commercial API terms, which provide for no training by default. Retention, safety review, and exceptions are described below; this is not a zero-retention service.

Can I turn the AI off?

You can stop using Guide and Paths and turn Journal memory off in the available AI settings. The Journal memory switch stops new journal context and memory requests; it does not turn off every AI feature. You can separately clear saved memories. For help withdrawing consent or changing AI preferences where no control is available, contact hello@kindmind.com. Requests already sent and provider-held copies are subject to the retention rules below.

What does the AI remember about me?

Saved memories are summaries that can contain details from your writing. While you use the app, a web memory pass sends eligible records, including older writing without a date cutoff, through the proxy and saves encrypted summaries. Chats also use recent conversation history, plans, and, if Journal memory is enabled, current-day journal context. Available memory controls let you review, edit, or delete saved memories; contact us if your product or plan does not expose those controls.

This is the AI side of the story.

The underlying encryption that protects your journal entries, paths, guide chat messages, and memories is described on the encryption page. AI features sit on top of that. Private replies, plans, and memories are encrypted before account storage. Safety classifications, usage records, and other metadata are handled separately.

If you’re weighing all of this before you write your first entry, we wrote about why that instinct is a good one in why privacy matters when you journal online.