All posts

· 6 min read · By Garrett

Journaling With AI Without Giving Up Your Privacy

There is a version of this article that tells you AI journaling is perfectly private and you should relax. It would be a nicer article and it would be false. An AI feature has to see something in order to respond to it. That is not a bug in anyone’s implementation, it is what the feature is. So the useful question was never “does this stay private,” it is “what does it see, for how long, and who keeps a copy.” Those have real answers, they differ enormously between products, and you are allowed to ask for them before you type anything real.

Why the honest framing is better for you

Storage and processing are two different promises. A journal app can encrypt your entries on your device so that its database only ever holds ciphertext it has no key for. That claim is about storage and it can be airtight. The moment you ask an AI to help you think through something, your device has to decrypt the relevant part and send it somewhere that can read it.

Watch for products that blur those two into one badge. “Fully encrypted, including AI” is doing something dishonest with the word including. If a company will not separate the two sentences for you, assume the weaker of the two applies to everything.

The four questions

What does it see?There is a large difference between an assistant that receives the paragraph you highlighted and one that receives your entire archive on every request so it can be “contextual.” Ask what gets sent per request. A good answer is specific: this conversation, these recent entries, this summary.

Where does it go? Almost nobody runs their own model. Your text goes to a model provider, usually through infrastructure the app operates. That means at least two parties, and you want to know both of them by name. An app that will not tell you which provider it uses is asking for more trust than it has earned.

How long is it kept?This is where the useful detail hides. Model providers commonly retain requests for a period for abuse monitoring, whether or not the app itself keeps anything. A company that tells you the exact retention window is being straighter with you than one that says “we take your privacy seriously.”

Is any of it used for training? Commercial API terms usually say no. Free consumer chat products frequently say yes by default. If you are pasting journal entries into a general-purpose chatbot, check which one you are in, because those are different products with different defaults even when they come from the same company.

The one control that matters most

Whether the AI reads your journal at all should be a decision you make, not a default you inherit. This is the setting to look for before any other one.

The distinction is between an AI that only sees what you say to it and an AI that also draws on entries you wrote for yourself. The second is genuinely more useful. It is also a much larger disclosure, because the entries you write when nobody is listening are not the entries you would compose for an assistant. Both are legitimate choices. What is not legitimate is making that choice for you at signup and mentioning it in a settings page you never open.

In KindMind, an AI feature never reads your journal entries unless you explicitly turn that on. The guide remembers your conversations with it, because that is what a conversation is. Your journal is a separate source with a separate switch, off until you flip it, and reversible. On the free Journal plan there is no AI in the product at all.

How to use AI journaling carefully without ruining it

You do not have to choose between an assistant and a private journal. A few habits get you most of the value at a fraction of the exposure.

  • Keep a hard line for the things that are nobody’s business. The entries about your health, your marriage, your family, the thought you have never said out loud. Write those in the journal, not in the chat. Nothing is stopping you from using both surfaces differently.
  • Bring the situation, not the file.You will often get a better answer from a described problem than a pasted archive, and you send far less. “I keep avoiding a conversation with my manager and I want to understand why” is enough to work with.
  • Leave out identifying detail you do not need. Names and employers rarely change the quality of the reflection.
  • Turn journal memory on deliberately, once you trust the product. It is a reasonable thing to want. It is an unreasonable thing to have happen to you.
  • Reread the whole trip once. If a company publishes the path your text takes, spend five minutes on it. If it publishes nothing, that silence is the finding.

What we do, specifically

Your entries are encrypted on your device before they are stored, and we do not hold the key that decrypts them. When you use an AI feature, your browser decrypts exactly what that request needs and sends it through our AI proxy to Anthropic’s Claude API. The proxy has no database, keeps no memory of past requests, and does not log message bodies. Anthropic does not train on what flows through their commercial API, and under the standard commercial terms that apply to our account they may hold a request and its response for up to thirty days. We do not have a zero-retention arrangement with them, and we would rather say so than let you assume otherwise.

Anything the AI produces for you, including the summaries it keeps as memory, is encrypted with your key before it is stored. The whole trip, including the automated safety check that runs along the way, is written out step by step on our AI privacy page. It is more detail than a marketing page usually carries, on purpose. The underlying storage design is on the encryption page.

The trade is fine when you can see it

An AI that helps you notice the thing you have been circling for three weeks is worth something real. So is a journal nobody can read. You can have both, in the same product, as long as the boundary between them is yours to draw and the company is willing to describe exactly what crosses it.

Ask the four questions. If the answers come back specific, you are in good hands. If they come back warm and vague, keep the hard entries for the page.

Related

September 9, 2026Moving Your Journal to a New App Without Losing Your HistoryMarch 16, 2020The Case for Keeping a Digital JournalMarch 18, 2019Why Your Journal App Shouldn't Have a Social Feed

Ready to start?

Start for free

Journal free foreverGuide and Path free for 14 daysNo credit card