Skip to content
Lanternly

Notes on keeping a journal · · 8 min read

A private journal app: 7 questions to ask before you trust it with your entries

Where the entries live, whether you need an account, who can read them and how to get everything back out. Seven questions for any journal app, each with a way to check the answer yourself.

  • private journal app
  • journal without account
  • secure diary
  • export
  • iCloud

A journal has two readers: you, and whoever has access to the server. The second half of that sentence is rarely printed in large type on an app's landing page. What you get instead is "secure", "encrypted", "we value your privacy". The words are the same everywhere. The machinery underneath is not.

Here are seven questions worth asking an app before your first entry goes into it. Each comes with a way to verify the answer with your own hands. I build a journal called Lanternly, and I answer the same questions about it below, so you can see what the answers look like in practice, including the spots where the answer is not perfect.

1. Where do the entries physically live

Three options. On the device and nowhere else. In the developer's cloud, under their account. In a cloud you own (iCloud, Google Drive) that the developer never touches.

The difference is practical, not ideological. If your entries sit in the developer's cloud, their fate follows the developer's business: a change of owner, a shutdown, a breach, a subpoena. If they sit in your iCloud, all of that is Apple's problem to handle, and Apple is not a three-person company.

How to check: open the privacy policy and search for "server". If the word does not appear at all, that is also an answer, just a bad one. Second method: turn off the internet and try to write an entry. If the app needs a network to save text, your entries do not live with you.

In Lanternly, entries are stored on the device and synced through the owner's iCloud. The app has no servers of its own. Nothing to praise there, it is an architecture choice: with no server, there is nothing to leak from.

2. Do you need an account

An account is required when the data lives with the developer, otherwise they could not tell whose it is. The reverse holds too. If an app asks for an email and password in the first minute, ask yourself why. Sometimes the answer is honest: sync through their own server, family sharing, a web version. Sometimes the reason is different: newsletters, a funnel, selling a subscription through "we miss you" emails.

An account is also a door. Passwords get guessed, email recovery gets intercepted. With no account there is nothing to break into; you need the phone itself, unlocked.

How to check: install the app and see whether you can write a first entry without typing anything about yourself. If not, look at what exactly is required and for what.

Lanternly works without registration. The profile is local, on the device. If you use an iPhone and a Mac, the entries meet through iCloud, because both devices are already signed into the same Apple ID.

3. Who can read the text

The word "encryption" on its own means nothing. Encryption in transit exists on every website. Encryption on the server's disk exists at every decent host. Neither stops the developer from reading your entries, because the key is theirs.

Only one thing matters: does anyone besides you hold the key. End-to-end encryption means the key lives only on your devices, and the server sees bytes without meaning. Even here a caveat applies: where the key is kept, and what happens if you lose it.

With iCloud there is a subtlety few people spell out. By default Apple keeps the keys to most data categories itself, so it can help you recover access. End-to-end encryption for app data in iCloud switches on only together with Advanced Data Protection in your Apple ID settings. While it is off, Apple can technically decrypt iCloud content on request.

How to check: find the phrase "end-to-end" in the description and look at the conditions under which it applies. If the app syncs through iCloud, an honest developer will mention Advanced Data Protection directly.

Lanternly says exactly that: sync is end-to-end encrypted when you have Advanced Data Protection turned on. Without it, entries in iCloud are protected by Apple's standard encryption, where Apple holds the keys. On the device itself, entries are under the system's protection either way, like everything else on the phone.

4. What leaves the device, apart from sync

An app can send things to the network even when entries are stored locally. Weather for an entry, geocoding a location, subscription checks, crash reports, analytics.

None of these requests is scary by itself. The question is what rides along. A weather request by coordinates tells the weather service roughly where you are. A crash report can accidentally capture a piece of text from memory. Event analytics of the kind "user opened an entry tagged X" already describes content.

How to check: the App Privacy section on the App Store. Apple requires developers to declare which data types are collected and whether they are linked to identity. A short declaration like "Location: used for app functionality, not linked to you" takes five seconds to read. A long list with "Identifiers" and "Usage Data" reads just as fast but says something else.

Lanternly makes one outside request: weather for an entry, by approximate coordinates, if you allowed location access. Nothing else goes to the network. In the App Store declaration that is a single line about location.

5. Are there analytics and trackers

A separate question, because it is the one most often hidden. An analytics SDK from an ad network inside a journal means a third company receives your device identifier, session times and events. Not the text of your entries, but enough to build a profile.

How to check: the same App Privacy page, the section "Data used to track you". If it is empty and reads "Data not used to track you", that is a good sign. You can also watch whether the app asks permission to track on first launch: the system dialog "Allow this app to track your activity" only appears for apps that track.

Lanternly has no analytics, trackers or ad SDKs. The developer does not know how many entries you write or what they are about. That is inconvenient for the developer and convenient for you.

6. Can you take everything back out

Five years of journal weigh more than any app. If the only way to get entries out is screenshots, you are tied for good. If export exists only in a proprietary format that one app can read, the difference is small.

Good export looks like this: plain text or Markdown, to open anywhere; JSON with dates, tags and metadata, to move to another journal; PDF or EPUB, to read as a book. And no gate: export should work in the free version, not unlock with a subscription.

How to check: find export in the settings before you have written a hundred entries. Make a test entry with a photo and try to pull it out. Look at the result: is the date there, did the photo make it, does the file open without this app.

Lanternly exports to text, JSON, PDF and EPUB from Settings, in the free version, with no limits. Printing a designed book in PDF and EPUB is part of Lanternly+, but plain export to the same formats is available to everyone. The reverse path exists too: import of a Day One JSON archive with dates, photos, locations and weather.

7. How the lock works

A lock on a journal does not protect you from hackers. It protects you from the person nearby: a partner, a child, a colleague who picked up your phone to look at photos. That is the most common leak and the easiest to close.

Face ID or Touch ID at the app entrance solves it. A separate PIN inside the app works too, but you have to remember it, and a forgotten PIN on a local journal with no account means losing everything. Biometrics are more reliable here: they are tied to the system, not to your memory.

How to check: turn the lock on, background the app, open it again. The lock should appear immediately, not after a minute. Check that the preview in the app switcher is hidden too, otherwise the last entry is visible without unlocking.

In Lanternly the Face ID and Touch ID lock is switched on in Settings. There is no separate app password, so there is nothing to forget.

What to do with the answers

If an app passes all seven questions, you can trust it with your entries in the sense that any program can be trusted. If it fails two or three, that is not a verdict, it is information: you know what you pay for convenience. The worst case is no answers at all. Silence in a privacy policy does not mean "nothing to hide".

One practical tip to finish. Check questions 1, 3 and 6 before the first entry. The rest can be clarified along the way. But storage location, keys and export decide whether the journal is still yours in five years, and in five years changing anything will cost a lot more.

If you want to see what these answers look like in one app, the privacy section on the home page is arranged along exactly this list. And there is a separate page about why we built it this way.

Sources

  1. Advanced Data Protection for iCloud, Apple Support (2026)
  2. App privacy details on the App Store, Apple Developer (2026)