How private is a journaling app, really?

Last updated: August 31, 2026

A watercolour of a journal tied with a ribbon, a small brass key resting on its cover.

Five checks answer it: where entries are stored, whether they are encrypted and against whom, what the app’s AI features send away and to whom, what analytics and ad software ships in the binary, and whether you can export and delete everything. Any journaling app can be checked in ten minutes with its own privacy policy and its App Store privacy label. Here is how.

The five checks

  1. Where do entries live? Three honest answers exist: on the device only, in the cloud, or your choice. Device-only is the strongest privacy posture and has a real cost the app should also state: lose the phone without an export and the journal is gone.
  2. Encrypted, against whom? “Encrypted” alone says little — everything is encrypted in transit these days. The questions that matter: are entries encrypted at rest, and who holds the key? True end-to-end encryption means the maker cannot read your words even if it wanted to; most apps do not offer that, and an honest one says which side of the line it is on rather than borrowing the term.
  3. What do the AI features send? Every AI feature works by sending something to a model. The private-enough question is: exactly what is sent, to whom, when, and is any of it stored or used for training? One plain sentence in the privacy policy answers this. Its absence is an answer too.
  4. What ships in the binary? Analytics, crash reporting, advertising and tracking SDKs are declared on the store privacy labels. Ads inside a diary should end the conversation. Anonymous analytics with an opt-out is a defensible middle; identifiers attached to journal behaviour are not.
  5. Is there a way out? Full export, free, in an open format; account deletion that works even after you uninstalled; and a page that says what deletion actually removes.

The AI trade nobody should hide

If a journaling app paints, summarises, chats or generates anything, your words make a trip to a model to do it. That trade can be worth making — but it is a trade, and you can only weigh it if the app names it. A trustworthy privacy policy states which provider receives the text, what exactly is sent, and what the provider may do with it. Be suspicious of “we use AI to enhance your experience” sentences that name no nouns.

The one sentence to look for

“To do X, the text of your entry is sent to Y.” If the policy contains that sentence, someone wrote it for you to read. If it does not, keep looking.

How to check an app in ten minutes

  • Open the privacy policy and search for “AI”, “model”, “provider” and “training”. Read what surrounds the words you find.
  • Read the store privacy label (App Privacy on the App Store, Data safety on Google Play): what is collected, what is linked to you, what is used for tracking.
  • Find the export. If you cannot find it before paying, that is the answer.
  • Find the deletion page. Google requires one for apps with accounts; an app that hides it did so on purpose.
  • Write a test entry you would not mind losing, and see whether the app asks for an account before it gives you anything. The order of those two events tells you who the app thinks the journal belongs to.

Where Bloom Journal fits

Bloom’s answers to the five checks, verifiable in our Privacy Policy: entries live on your phone by default and cloud is a choice; entry text is encrypted with AES-256-GCM before it is stored, and we say plainly that this is strong encryption at rest but not end-to-end; to paint an entry, the text of that entry is sent to our AI providers — that is the one sentence, and it is in the policy; the app carries anonymous analytics with a Settings switch to turn them off and crash reporting, with no advertising and no tracking identifiers on either platform; and export is free on every plan, with account deletion that works even if you already uninstalled the app. Your first entry and first painting happen before any account exists.