All posts

· 6 min read · By Garrett

How to Tell Whether Your Journal App Can Read Your Entries

You can answer this question yourself, today, without a security background and without waiting on a support reply. Every app leaves fingerprints. A product that can read your entries needs to read them to deliver features you can see from the outside, and a product that cannot read them has to work around that in ways you can also see. Here is the checklist, in the order that gets you an answer fastest.

1. Start the password reset and read the warnings

This is the fastest test and the hardest one to fake. Go to the sign-in screen, click “forgot password,” and read carefully before you finish. You are looking for one specific sentence: some version of “resetting your password will make your existing entries unreadable unless you have your recovery key.”

If the reset flow is smooth and silent, and you land back in your account with everything intact, the company holds a key to your writing. That is not necessarily sinister. It is how most software works. But it is a definite answer to the question in the title.

2. Open the web app in a private window

Sign in from a browser that has never seen your account. Watch what happens after you enter your password. Does the app ask for anything else, or pause for a moment before your entries appear?

An app that decrypts in your browser has to derive a key from your password before it can render a single word, and then fetch and unlock each entry. You feel that as a brief setup step or a short spinner on first load. An app that renders your entries instantly, from nothing but a session cookie, assembled that page on a server. The server had your words in readable form to do it.

3. Search for a word you know is buried deep

Pick a distinctive word from an entry you wrote a long time ago, ideally one far outside anything currently loaded on screen. Search for it.

Instant results across your entire archive, from a fresh session, on a phone, means the search ran on a server. Servers search text. They cannot search ciphertext. If instead the app searches only what it has already loaded, or takes a moment to work through your history the first time, that is the shape of client-side search, and it is a good sign in this particular context even though it feels like a worse feature.

4. Check whether the app ever quotes you back

Look through your email from the company and the notifications on your phone. Has it ever shown you your own words outside the app itself? A “one year ago today” email with the entry in it. A weekly recap that summarizes what you wrote. A push notification with the first line of yesterday’s entry.

Every one of those is generated by a server on a schedule, while you are asleep and your device is nowhere in the loop. A server that composes that email can read everything you have written. This test is underrated because these features are usually presented as thoughtful touches, and they are, but they cost exactly one thing and it is the thing you are checking for.

5. Read what the privacy policy reserves, not what it promises

Marketing pages describe intentions. The policy describes rights. Search the policy for the words content, scan, improve our services, third parties, and legal process, and read what each one is attached to.

The question is not whether the company promises to behave. It is whether the architecture leaves them the option to change their mind. A company that reserves the right to analyze content for product improvement is telling you the content is analyzable. A company whose database holds only ciphertext it has no key for has nothing useful to hand over under legal process, and its policy usually says so plainly rather than hedging.

Pay attention to acquisition clauses too. “Your data may be transferred as part of a merger or sale” is standard and mostly unavoidable. What matters is whether the thing transferred is readable.

6. Try to leave, and see what you get

Export your data. An app that can hand you a clean, readable file instantly, from a link in your email, produced that file on a server from readable text. An app built the other way either exports an encrypted archive you unlock with your own key, or does the export work in the browser while you wait.

Either way, do the export. The result answers this question and also tells you something more important, which is whether you could ever get your history out. We wrote about that separately in moving your journal to a new app without losing your history.

What a “yes” actually means

If your app can read your entries, nobody is sitting in an office reading them for fun. Companies are busy and your Tuesday is not interesting. The real exposure is structural, and it has three parts.

There is the breach, where an attacker inherits whatever access the company has. There is the subpoena, where readable data has to be handed over and unreadable data cannot be. And there is the change of ownership or business model, where the company that made you a promise in 2024 is a different company by 2028 and the data is still readable.

There is also a quieter cost that shows up in your own writing. When some part of you knows the entry is legible to someone else, you write a slightly more presentable version of your life. The most useful journaling is the kind you would be embarrassed to have read, which is exactly the kind you stop doing when you are not sure.

Where AI features fit

One caveat, because it is the place honest apps get sloppy. Storage and AI are two separate claims. Stored entries can be ciphertext the company has no key for while an AI feature still needs to see something in order to answer you. The right question is not whether the app has AI but what that AI sees, for how long, and who keeps it.

For KindMind the answer is that your entries are encrypted on your device before they are stored and we do not hold the key that decrypts them, and that when you use an AI feature your device decrypts what that request needs and sends it through our AI proxy to our AI provider, where it is not stored or logged. The mechanism is written out on the encryption page, in enough detail to check.

Run the six tests on whatever you use now. Two minutes, and you will know.

Related

September 9, 2026What Zero-Knowledge Encryption Means for a Journal AppFebruary 18, 2026KindMind Is Moving to Zero-Knowledge EncryptionFebruary 15, 2021Why Most Journal Apps Get Encryption Wrong

Ready to start?

Start for free

Journal free foreverGuide and Path free for 14 daysNo credit card