Zero-Knowledge Encryption Overview · KindMind Labs
How KindMind Protects Your Data
When you write in KindMind, your words are scrambled into unreadable code on your device before they are saved to your account. The scrambled data is what gets stored on our servers. Our storage system does not hold the unlocked key needed to read those encrypted records.
This is called zero-knowledge encryption. Here, that term describes private content at rest. It does not mean every part of the Service operates without readable information.
This account-key explanation applies after account creation. Try-before-signup writing uses a separate key kept with its encrypted records in your browser, without account password or recovery protection. AI processing still involves readable requests. See the Privacy Policy for that flow.
That covers the content. It does not cover everything: your email address, your settings and subscription status, and which guided program you chose are stored in a form we can read, because the app cannot run otherwise. Section 4.2 of our Privacy Policy lists those categories, and the section below on why this matters shows exactly where the line falls.
On this pageContents · 10 sections
Why This Matters
KindMind holds some of the most personal things you’ll ever write: journal entries about your struggles and honest conversations with your guide. Client-side encryption reduces the exposure of stored private content.
With zero-knowledge encryption:
- A database breach exposes what you wrote as ciphertext only. Reading that content still requires the key; weak passwords, compromised keys, or compromised devices can defeat this protection
- KindMind engineers cannot read your stored writing, even if they wanted to
- Legal requests may cover encrypted records and readable information, including account details, support communications, and safety categories. Provider-held AI requests are a separate source of readable data
- The protection is strongest when your password, recovery key, device, and software remain secure
Where the line sits. A breach would still expose the account and operational information we hold in readable form, listed by category in Section 4.2 of our Privacy Policy: your email address, your settings and subscription status, and which guided program you chose. A program on grief or sobriety would be visible by name, even though everything you wrote inside it stays encrypted.
Our servers also hold the locked copy of your Master Key. Anyone who took that copy could sit offline and guess at your password for as long as they liked, with no login screen or rate limit in the way. The 600,000-round key derivation described below makes each guess expensive, which is exactly why it is there, but it cannot save a password that was easy to guess. Use a strong, unique one here.
How It Works
For private content storage, think of a locked box:
- KindMind stores the locked box
- Your device holds the content key; your password or recovery key unlocks access
- Our storage system can copy the locked box but does not hold its unlocked key
- If every way to unlock it is lost, we cannot restore the content for you
The Two-Key System
KindMind uses a two-key system, with a content key and a password-derived wrapping key.
Master Key: A randomly generated secret that actually encrypts what you write. It never leaves your device in readable form.
Password-Derived Key: Created from your password using a slow, deliberate process (600,000 rounds of a key-stretching algorithm). Its only job is to lock and unlock your Master Key.
Worth being precise about: your account password itself does travel to our authentication provider when you sign in, the same as on any account anywhere. What never leaves your device is the Password Key derived from it, and the Master Key that key unlocks. We store the wrapped key and its derivation recipe, not the unlocked Master Key. This design still depends on the security of your device, the authentication path, and the application code delivered to you.
Why two keys? Because when you change your password, we only need to re-lock the Master Key with your new password. We don’t have to re-encrypt every piece of data you’ve ever written.
What Happens When You...
Write a Journal Entry
Sign Up
- Your browser generates a random Master Key
- Your password derives a Password Key
- The Password Key locks (wraps) the Master Key
- The locked Master Key is sent to our server (we can store it, but we can’t open it)
- A Recovery Key is shown to you. Save it somewhere safe!
- The unlocked Master Key stays on your device, ready to work
Where the unlocked key sits depends on the device. In a browser it lives in memory and session storage. Browser session restoration may preserve that storage, so use Sign out instead of relying on closing a tab. In the mobile app it is kept in your phone’s biometric-protected keychain, so it deliberately survives closing and reopening the app and clears when you sign out.
Log In
- You authenticate with your email and password
- Your browser fetches the locked Master Key from the server
- Your password derives the Password Key
- The Password Key unlocks the Master Key
- You can now read and write your data
Read a Journal Entry
When you log in, your browser uses your password to derive a Password Key locally. It then fetches your Master Key from our server (which is stored in encrypted form we can’t read) and decrypts it using that Password Key. From that point on, the Master Key stays on your device and handles all encryption and decryption: in the browser session on the web, in your phone’s biometric-protected keychain in the mobile app. The unlocked Master Key is never shared with us or anyone else.
Talk with Your Guide (AI Chat)
Your saved guide conversations are encrypted before account storage. Your browser talks to a standalone Cloudflare Worker edge proxy we run, a tiny function that injects our API key, runs an automated safety check, and forwards your messages to Anthropic. It processes message text during the request and keeps operational logs and content-free telemetry separately. Only the encrypted result is stored on our servers.
Our AI provider has its own retention and safety-review practices. See the AI Privacy page for those practices and exceptions; neither zero retention nor a strict 30-day maximum is promised.
- Your browser decrypts conversation history locally
- Your browser sends messages to a Cloudflare Worker edge proxy (KindMind-operated infrastructure that processes the request in readable form)
- The Worker injects the API key, runs an automated safety check on your message, and forwards to Anthropic. Message text is not intentionally persisted by this proxy.
- The AI response streams back through the Worker to your browser as plain text over an encrypted connection. If the safety check flags a serious concern, the Worker skips the AI reply and sends back a fixed supportive message with crisis resources instead.
- Your browser encrypts the response before storing it
Change Your Password
Your old password unlocks the Master Key. Your new password creates a new lock around it. Changing your password rewraps the same Master Key; it does not require rewriting each encrypted record. The Master Key itself didn’t change, just the lock around it.
Recover Your Account
If you forget your password, it takes two things, and you need both. First, we email you an account recovery link, and signing in through it proves the inbox is yours. Then your Recovery Key restores your Master Key, which is the part we genuinely cannot do for you. You set a new password, a new lock is created, and you’re back in with all your data.
What Gets Encrypted (and What Doesn’t)
The rule: Private journal, chat, plan, and memory content is encrypted before account storage. Structural metadata the app needs to function stays readable, and so does anything you write straight to us, like a support message or a piece of feedback, since we have to read those to answer them.
AI processing: When you use AI, your device sends readable messages and context through KindMind’s systems to Anthropic. Moving from KindMind Classic passes your entries through our servers too. Your saved entries, chats, plans and memories are encrypted on your device before they’re stored. What AI receives and keeps →
The Technical Details
What AES-256-GCM Means
- AES (Advanced Encryption Standard): the global standard for symmetric encryption
- 256: 256-bit key length (2256 possible keys)
- GCM (Galois/Counter Mode), which provides both encryption and tamper detection
Authentication checks are designed to reject modified ciphertext. They do not prevent deletion, replacement with an older valid record, compromised devices, or misuse of a stolen key.
What 600,000 Iterations Means
Turning your password into an encryption key is deliberately slow. The current PBKDF2 recipe uses 600,000 iterations for each password-derived key. This increases the cost of guessing; it does not guarantee a weak password is safe. Speed depends on the device and attacker resources. Stored key recipes are versioned so historical content can remain readable.
What We Cannot Do
With zero-knowledge encryption in place:
- We cannot read your stored journal entries or guide conversations. Those rows only ever hold ciphertext we cannot open
- We cannot reset your encryption if you lose both your password and recovery key
- We cannot decrypt stored private content for a legal request using the keys held by our storage system. We may disclose encrypted records and readable information, including support messages and the categories in Section 4.2 of our Privacy Policy
- We cannot restore your private content if you lose the password, recovery key, and every device that can still unlock it
Where plaintext does travel: when you use an AI feature, your device decrypts what that request needs and sends it through our AI proxy to Anthropic. Selected plans, titles, and goals also pass through our application server to prepare prompts. Private replies are encrypted before account storage. Provider retention and review are explained on our AI Privacy page; these protections do not promise that readable copies can never be retained by or legally requested from a provider.
One thing we do see: an automated safety check on your guide conversations can flag a safety concern and send us a category-level record (never the words themselves), so we can point you toward crisis resources when it matters. If the check itself fails, we receive a content-free error record so we know it is working.
The Trade-Offs
Encrypting private content with a key controlled on your device reduces storage exposure and comes with trade-offs:
How This Compares
This is a comparison of storage designs, not an audit of other services or a guarantee against every kind of compromise. It does not cover readable AI processing or a compromised device or application. In every row above, a breach of our database would still expose the readable account and operational information in Section 4.2 of our Privacy Policy, including which guided program you chose.
Common Questions
What does zero-knowledge encryption actually mean?
It means your writing is encrypted on your device before it is stored, and we do not hold the key that decrypts it. The private content fields in our database hold ciphertext; other records can be readable. It does not mean we hold nothing about you: your email address, your settings, your subscription status and the name of the guided program you chose are stored in a form we can read, because the app cannot run otherwise.
The longer version is in What Zero-Knowledge Encryption Means for a Journal App, and the story of why we rebuilt KindMind around it is in KindMind Is Moving to Zero-Knowledge Encryption.
What happens if I forget my password?
You can still get back in, and it takes two things. We email you an account recovery link, and signing in through it proves the inbox is yours. Then your Recovery Key restores your Master Key, you choose a new password, and everything you wrote is right where you left it. That second half is the part we genuinely cannot do for you, so an email reset on its own is not enough.
What is the recovery key, and what if I lose that too?
Your Recovery Key is your Master Key itself, written out in dashed four-character blocks with a short checksum on the end so it is easy to copy by hand. It opens your data without your password, which is exactly why it belongs in a password manager or somewhere physically safe. If you lose your password, your Recovery Key, and access to any device that can still unlock your data, we cannot restore your stored writing. There is no backdoor and no override, by design. If we could reset your encryption, so could anyone who convinced us they were you.
Can KindMind read my journal entries?
Not the stored ones. Every entry sits in our database as ciphertext with its own random initialization vector, and the key that opens it never leaves your device in readable form. What we can see is the shape around your writing rather than the writing itself: how many entries you have, when you wrote them, and which guided program you picked, right down to its name.
That distinction is the whole subject of Why Most Journal Apps Get Encryption Wrong, which walks through the simplest test you can run on any app that calls itself encrypted.
What happens to my entries when I use an AI feature?
Your device decrypts what the request needs and sends it, readable, through KindMind-operated infrastructure to Anthropic, which powers our AI. Replies are encrypted before they're stored. Your journal entries stay out of it unless you turn on Journal memory, which is off until you choose it, or paste them into a chat.
What if KindMind is acquired, or served with a subpoena?
We can't decrypt your stored journal entries and chats, because we don't hold the key. We can be required to share what we can read, like account details and support messages, and our Privacy Policy explains when.
Can I get my journal entries out?
Yes, whenever you like. Back up your data, in the web account menu, downloads a single self-contained HTML file. Open it in any browser and it asks for your password or your Recovery Key, then decrypts and shows everything locally. No KindMind account, no internet connection, no involvement from us. The file also carries the exact encryption recipe your account was created with, so it keeps working even if we change algorithms later.
Private content is encrypted on your device before account storage.
Our servers store it as encrypted blobs they cannot read. Your account details and settings stay readable, because the app needs them.
Your password unlocks your key. Your recovery key is your backup.
AI processing involves readable content. Encryption does not replace device security, a strong password, or safe backups.