Is your AI journal actually private? Five questions that get a real answer
Most AI journaling apps say they are private and never say what that means. Five questions that separate a real privacy claim from a marketing one.
Every app says it is private. That word means nothing on its own.
Go look at the landing page of any AI journaling app, including this one. Somewhere near the top it will say private, safe, or yours alone, over a photo of someone looking peaceful near a window. None of that is a claim. It is a mood.
A real privacy claim is boring and specific. It names where the text is stored, who processes it, how long it is kept, and what happens when you delete it. If a company will not put that in plain sentences, it is usually because the plain sentences are worse than the mood.
This is not paranoia. In 2023 the FTC fined BetterHelp $7.8 million and banned it from sharing health data for advertising, after it handed email addresses and mental-health questionnaire answers to Facebook, Snapchat, Criteo and Pinterest — while telling users it would not. That company had a calm landing page too.
So here are five questions. Ask them of any app you are considering. They work on us, and further down we answer them about ourselves, including the parts that are not flattering.
Question 1 — Where does the text physically live?
There are three honest answers and one dishonest one. Honest: it lives only on your device; it lives on our servers tied to your account; it lives on our servers encrypted in a way we cannot read. Dishonest: silence, or the phrase "stored securely," which describes the lock and skips the question of whose house it is in.
Each real answer has a trade-off, and anyone telling you otherwise is selling something. Device-only is the strongest privacy position and the weakest product — lose the phone, lose the journal, and there is no syncing to a laptop. Server-stored means your entries survive a dead phone and follow you across devices, and it means a company holds them. End-to-end encrypted storage is the best of both and is genuinely hard to build, which is why very few small apps actually have it, and why you should look for a specific technical description rather than the word "encrypted" floating alone.
The follow-up question is the one that catches people: if the app talks back, the text has to leave your device at least momentarily to reach a model, even if it is not stored anywhere afterward. A journal that only records can be device-only. A journal that responds cannot be, unless the model is running on your phone. That is not a scandal — it is physics — but an app that implies otherwise is being slippery.
Question 2 — Does anyone train a model on what you wrote?
This is the question people actually mean when they ask if an AI journal is private. Not "will a hacker get it," but "is my worst night going to end up inside some model."
Almost no small app builds its own model. They call someone else’s, which means the answer depends on the terms of the specific tier that app pays for, not on the app’s own vibes. And those tiers differ sharply. The major providers’ API terms are a clean example: on a free tier, a provider will typically say it uses submitted content to improve its products and that human reviewers may read and annotate it, and the terms literally tell developers not to submit sensitive or personal information. On the paid tier, the same provider will say it does not use prompts or responses to improve its products, and logs them only briefly for abuse detection and legal requirements.
Same company, same model, opposite answers, entirely depending on whether the app is paying. So the useful question is not "do you train on my data" — every app will say no. It is "which provider do you use, on which tier, and what do their terms say about that tier." An app that can answer that in one sentence has thought about it. An app that gets vague has told you something.
The related trap: free apps. If an app is free, has no subscription, and is not a hobby project, the data is doing the earning somehow. That is not always sinister, but it is always worth naming out loud.
Question 3 — Who else gets a copy, quietly?
The BetterHelp case was not a breach. Nobody broke in. The data walked out the front door through ordinary marketing plumbing — advertising pixels, conversion tracking, analytics SDKs, the same tools every app installs without thinking hard about it.
This is the most common failure by far, and it is invisible from the outside. Things worth checking: does the app run third-party advertising or attribution trackers, does its analytics tool receive the contents of what you type or only that a screen was viewed, and can you turn analytics off entirely. "We do not sell your data" is a famously narrow promise — sharing, licensing, and letting a partner use it for their own purposes are all technically not selling.
The blunt version: an app whose business model is a subscription has no reason to be in the ad-tech ecosystem at all. If a paid mental-wellness app still has advertising trackers in it, that is a choice someone made, and it is worth asking why.
Question 4 — Does delete actually delete?
Try it. Genuinely. Delete a conversation, sign out, sign back in on a different device, and see whether it comes back. That thirty-second test tells you more than the privacy policy does.
Then ask about the parts you cannot see: does deleting a conversation remove it from backups and on what timeline, does deleting your whole account remove the underlying records or just close the door, and does anything derived from your entries — a summary, a profile, a memory the app built about you — survive the delete. That last one matters more than people expect. Plenty of apps delete the transcript and keep the notes they took on it.
Also worth knowing: whether the app keeps a long-term profile of you at all, and whether you can turn that off. An app that remembers you across sessions is more useful and stores more about you. Both things are true at once, and you should get to pick.
Question 5 — What happens if someone outside the company asks for it?
This is the uncomfortable one, and it is the one 2025 and 2026 forced into the open. A conversation with a licensed therapist has legal confidentiality protections. A conversation with an app, in almost every case, does not. Whatever a company holds, it can generally be compelled to produce in litigation, and stored data that exists can be subpoenaed while data that was never stored cannot.
Most consumer apps are also not covered by HIPAA, which people find surprising. HIPAA follows the type of entity, not the sensitivity of the feeling. Your data being medically intimate does not by itself put it under medical privacy law.
This is not a reason to never use one — it is a reason to know which conversations belong where. We wrote a longer piece on the ChatGPT court-order situation and what it actually meant for people using chatbots for emotional support, and it is worth reading before you assume any chat window is legally sealed.
Our own answers, including the ones that are not flattering
It would be pretty weak to publish that list and dodge it. So, specifically, for Haven.
Where the text lives: on your device, and in your account on our servers, so your conversations follow you between phone and laptop. Not end-to-end encrypted — we could technically access account records, the same as most services of this size. If you turn "remember chats" off in settings, conversations are not persisted at all: they work for the current session, and they are cleared locally and emptied from the account copy. That switch is the honest device-only-ish option, and it costs you your history, which is the trade-off we described above rather than a free win.
Who processes it: your messages go to a major AI provider’s API, on a paid tier, to generate a reply. Paid tier is the load-bearing detail — it is what moves you out of the "may be used to improve the product and read by human reviewers" bucket and into terms where your prompts and responses are not used to train their models, and are logged only briefly for abuse detection and legal requirements. We do not train any model on your conversations, and we do not have one to train.
Who else gets a copy: nobody. No advertising identifiers, no cross-site tracking, no data sold or shared with marketers. Analytics are optional, nameless, and never include what you typed — they count that something happened, not what it said. There is an older post on this site about what we deliberately do not collect that goes through the reasoning.
Delete: deleting a conversation removes it from your device and from the account copy on our servers, and the deletion propagates to your other devices rather than quietly resurrecting. There is a separate memory feature — a short profile the guide keeps so it does not reintroduce itself every session — and you can turn it off, which makes each conversation start clean.
And the legal one: Haven is not a licensed provider, our conversations do not carry therapist confidentiality, and we are not going to imply otherwise. What we hold, we could in principle be compelled to produce. That is a real limit and it belongs in the sentence right next to the word "private," not three pages away in a policy. The page on what Haven will not do is where we keep the rest of those limits.
When privacy is not really the question you are asking
Sometimes people research this question for hours and what they are actually circling is different: they want to say something out loud and they are looking for a place safe enough to say it. If that is where you are, the honest answer is that a private place to think is a genuinely good tool and a limited one. It is good for getting the pressure down, sorting a loop, and figuring out what you actually think before you take it to a person. It is not a clinician, it is not confidential in the legal sense, and it is not a crisis service.
If what you are carrying is heavy enough that the privacy question is really a fear of being judged, a therapist is worth the search — real confidentiality, real training, and no version of them that is also a company. Plenty of people use both: an app between sessions to work out what to bring, and the session for the actual work. There is a guide on this site about preparing for therapy that assumes exactly that pairing.
And if things are genuinely unsafe right now — if you are thinking about hurting yourself — please put this article down and call or text 988, the Suicide and Crisis Lifeline, in the US. That is what it is there for, and it is a bigger priority than anyone’s data policy including ours.