A journal only works if you can write the true version. Here is exactly what happens to your pages — no legalese, no fine print.
Your pages are yours
Entries are private to your account. Nobody else can read them, and they are never shared, analyzed, mined, or used to train anything.
Encrypted in transit and at rest
Pages travel over HTTPS and sit in a database that is encrypted at rest. The usual, done properly.
An honest note about who could read them
There is no client-side end-to-end encryption here, which means the person operating this site could technically read the database. Why say that out loud? Because end-to-end encryption would also break search, the calendar that resurfaces your days, and any hope of recovering your journal if you lose your password — and because an honest sentence beats a fake lock icon. If you need a journal even the operator provably cannot read, this isn't that, and it won't pretend to be.
Deletion, honestly
Remove a page and it leaves your journal immediately — nothing in the app can see it or bring it back. In the database it lingers a little longer as a deletion-marked row, so a slipped finger or a bad bug isn't the end of a year of writing; the operator can restore it if you ask, and can purge it for good if you ask that instead. That's the honest description — a quiet safety net, not a trash folder.
Leave whenever you like
One click downloads everything as plain markdown files, one per page — export your journal. Your words shouldn't be hostages.