The Book

What "encrypted" really means for a private journal

Almost every app says your data is encrypted. The word covers three very different promises. How to tell which one you are being given, and what each protects you from.

Privacy · Updated 5 October 2026 · 4 minute read

A journal holds the things you would not say aloud: who you are seeing, what was said, what you are worried about. Any app that offers to keep one will tell you it is encrypted. That statement can be perfectly true and still mean that the company's staff, anyone who breaks into its servers and anyone with a court order can read every word. The question to ask is never whether data is encrypted. It is who holds the key.

Three promises that share one word

Encrypted in transit

Your words are scrambled while they travel between your device and the company's server. This is the padlock in a browser's address bar, and it stops someone on the same café network from reading along. It protects the journey only. On arrival the text is unscrambled, and the server sees it plainly.

Encrypted at rest

The company's disks are encrypted, so a stolen hard drive is useless to a thief. The company holds the key, because its software has to read your data to show it to you, search it and back it up. Anyone who can act as that software can read it too: an employee with access, an attacker who gets inside, or the company itself answering a legal demand.

End-to-end encrypted

Your words are encrypted on your own device, with a key that the company never receives. What reaches the server is ciphertext, text that looks like random noise without the key. The company stores it and syncs it and cannot read it. A break-in at the server yields nothing readable, and a legal demand can only be answered with the same noise.

Only the third is what most people imagine when they read the word.

Where the key comes from

In an end-to-end design the key is usually made from something only you know, such as a PIN or a passphrase. A deliberately slow calculation, called a key derivation function, turns that secret into a long key. The slowness is the point: it costs you a fraction of a second once, and it makes someone guessing millions of passwords pay that cost millions of times.

Two things follow from this, and both are worth knowing before you choose.

  • The strength of the key is the strength of the secret. A four digit PIN has ten thousand possibilities. That is adequate when the device itself limits the number of guesses and weak against someone who has copied the encrypted data and can guess freely. A longer passphrase is far stronger.
  • If you forget the secret, nobody can help. This is the honest cost of the design, and it is also the proof that it is real. A service that can reset your password and hand your journal back has a way in, which means it holds a key.

How to tell which promise an app is making

  • Try the "forgot password" route in your head. If the answer is an emailed reset link and all your entries are still there afterwards, the company can read them.
  • Look for a recovery key. End-to-end apps often give you a long code to write down at setup and warn that it cannot be recovered.
  • Check what happens to search and to automatic summaries. If the server can search your text or summarise it, the server can read it.
  • Read the privacy policy for the sentence about access. "We cannot read your entries" is a claim. "We do not read your entries" is a policy, and policies change.
  • Ask what is left unencrypted. Many end-to-end systems still store dates, sizes, titles or the names of contacts in the clear. That metadata can say a good deal.

What encryption does not protect

Encryption guards the data while it is locked. It does nothing once the app is open in front of someone. The risks that remain are ordinary ones:

  • An unlocked phone. An app that locks itself after a short idle time and asks for a PIN or a face to reopen closes most of this gap.
  • Notifications and previews. A reminder that prints a name on the lock screen has told everyone in the room.
  • Backups and exports. A plain copy saved to a shared cloud folder undoes the protection of the original. Check whether an app's own backups are encrypted.
  • Screenshots and the app switcher, which can show the last screen you had open.
  • Someone who can make you unlock it. Some private apps answer this with a decoy: a second PIN, or several wrong ones, opens an empty journal.

Keeping your record on your own device

The simplest way to keep a secret from a server is not to send it. An app that stores everything on your device and works with no account has no copy to leak. The cost is that the record lives in one place, so a lost or broken phone can take it along. The sensible combination is local storage first, encrypted backups you control, and sync that is end-to-end when a second device is needed.

The short test

Before trusting an app with a private record, ask three questions. Can the company read my entries? What happens if I forget my password? What can someone see if my phone is picked up unlocked? An app built for privacy will have a plain answer to each.

Keep reading

Every guide