Knowledge base › Tools
Who can read my journal? 7 questions to ask any journaling app

Your journal is probably the most personal data you will ever type anywhere. There is more in it than in your email: your fears, your relationships, your decisions, the sentences you have never said out loud to anyone. And yet most of us spend more time choosing a bank than choosing who to trust with this. This article does not tell you which app is the good one. It gives you a way to decide that yourself, in ten minutes, about any of them — including Mirrify.
Why this matters more than it did five years ago
With a classic journal, the question was whether it was stored encrypted. With an AI journal, more is happening: your text is also processed. It is sent to a language model that responds to it. That is not a problem in itself — it is exactly what makes pattern recognition useful — but it opens new questions: where does the text go, how long does it stay there, and does anyone learn from it.
The good news is that these are answerable questions, and the answers are written down. The bad news is that they are usually written in phrasing that does not reveal on first reading what it actually means. Hence the list.
In short
- Seven concrete questions — each with a clear good and bad answer.
- The answers live in the privacy policy and the app store data-safety label.
- If an app dodges the question, that is an answer in itself.
1. Who can technically reach my entries?
What to ask: can another user retrieve my data in any way? And can the provider's own staff read the text?
What counts as a good answer: the access rule does not live only in application code but at the database level — this is called row-level isolation. It matters because a single application-side bug is then not enough to expose someone else's journal: the database still says no.
Red flag: nothing on this anywhere, only "we store your data securely".
2. Do you train AI models on my entries?
This is the most important question on the list, and for most people it is the deciding one.
What to ask: does my text take part in training any model — the provider's own, or a supplier's?
What counts as a good answer: an explicit no, stated plainly. Not "we do not share with third parties", because that is a different question. You need a sentence specifically about training.
Red flag: the phrase "we use it to improve our services" with nothing saying what that includes. That wording can cover a very wide range of uses, and it is broad precisely so that it can.
3. What happens with anonymised or aggregated data?
Many policies resolve the tension by saying "we only use anonymised data". For journal text, that is a weaker guarantee than it sounds.
Your name can be stripped. But your entries are full of details — the nature of your job, your child's age, an illness, a city, a date — that together can lead back to you even with the name removed. So for a journal, the strong guarantee is not anonymisation; it is that the text is not used at all for any secondary purpose.

4. Who processes the AI, and what happens to the text afterwards?
If the app uses AI, your text most likely leaves the provider's own systems and reaches a model supplier. That is normal — what matters is that you know the rule.
What to ask: who is the supplier, how long is submitted text retained, and is training use contractually excluded?
What counts as a good answer: a named supplier, limited retention, and explicit exclusion from training.
Red flag: no mention anywhere that an AI supplier exists at all. If there is an AI feature, there is a supplier.
5. Is the data sold or shared?
What to ask: is data sold, is it shared for advertising or with data brokers, and which analytics tools run inside the app?
What counts as a good answer: no data sales, no advertising-purpose sharing. The app store data-safety label asks this as a separate question, so you can check it quickly there.
Red flag: a free app, with ads, that also holds your journal. Something has to fund it — and it is worth knowing what the revenue source is if it is not you.
6. Can I take my data out?
This is not only a privacy question but a dependency one. If your history is not portable, it is not yours — it is on loan.
What to ask: is there a one-click export, in what format, and does it include every entry rather than just a recent window?
Red flag: an export you have to request by email that takes days. That usually signals it was never a priority.
7. What happens if I delete my account?
What to ask: what exactly is deleted, within what timeframe, and how long do copies persist in backups?
What counts as a good answer: concrete, stated deletion with a concrete deadline. A backup lag is normal — what matters is that it is written down.
Red flag: deletion that only means "deactivating the account".
How to find the answers in ten minutes
- Open the privacy policy and search for: train, training, model, improve, development, anonymised, aggregated, third part, retention, deletion. The relevant sentences almost always cluster around these words.
- Check the app store data-safety label. Google Play's "Data safety" and the App Store's "App Privacy" section state in structured form what is collected and what it is linked to. That is faster than the legal text.
- Look for the supplier list. If there is an AI feature, search for "subprocessor" or "sub-processor". If no such list exists, that is information too.
- Send support one question. This is the fastest filter: ask in a single sentence whether they train models on your entries. How fast and how clearly they answer tells you a lot.
A glossary of suspicious phrasings
Not every broad phrase is written in bad faith — but every one of them means your question has not been answered, and you need to follow up.
| The phrasing | What to ask |
|---|---|
| "We use it to improve our services" | Does that include model training? Yes or no? |
| "We analyse it in anonymised form" | Does the journal text itself go in? Who can read the text? |
| "We work with trusted partners" | Who are they by name, and what may they do with the data? |
| "Stored to industry standards" | Which specific access rule protects it from other users? |
| "Your data is safe with us" | That is marketing, not a commitment. Where is it written down? |

And Mirrify? The same seven questions, answered
It would not be honest to hand you a checklist and then leave ourselves off it. Here are the same seven questions with our answers:
| Question | Mirrify's answer |
|---|---|
| 1. Who can technically reach it? | Row-level security rules in the database — another user's query cannot return your entries. |
| 2. Do you train models on it? | No. Journal entries are not used to train models. |
| 3. Anonymised use? | Not what we rely on: journal text is not used for secondary purposes. |
| 4. AI processing | Text is processed so the AI mentor can work; training use is excluded. |
| 5. Selling, advertising | No data sales and no advertising. We are funded by subscriptions. |
| 6. Export | One click, any time, with the full contents. |
| 7. Account deletion | Everything is deleted. You can export it all beforehand. |
The detailed, legally binding text lives in our Privacy Policy — and that is exactly what we would suggest for any other app too: read the policy, not the marketing copy.
Frequently asked questions
Is it safe to let an AI read my journal entries?
It depends on the provider, and it is worth deciding concretely rather than in the abstract: do they train models on your entries, who can technically reach them, who else receives them, how long are they retained, what happens on deletion. If an app will not answer clearly, that is an answer.
How do I find out whether an app trains on my journal?
Search the privacy policy for: train, training, model, improve our services, development, anonymised. A good answer is an explicit denial. A suspicious one points to improvement without saying what happens to the text.
What does anonymised data mean here?
That names and identifiers were stripped. For journal text that gives less protection than it sounds, because entries are full of details that lead back to you. The stronger guarantee is that the text is not used at all.
What is row-level isolation?
The access rule lives in the database itself, not only in application code: every row is bound to its owner. So an application-side bug alone is not enough to expose someone else's entries.
What happens to my entries if I delete my account?
Always check this specifically. With Mirrify, deleting your account deletes all your data, and you can export everything with one click first.
How does Mirrify handle journal entries?
Stored with row-level security rules in isolation. Not sold, not shared for advertising, not used to train models. Exportable at any time, and deleting your account deletes everything.
Ask us too
Mirrify is a self-knowledge system — not just another journal: journaling, habits, goals, wheel of life, Ikigai, a decision journal and finances in one place, plus an AI mentor that works from your own entries. Your journals are yours: never sold, never used for training, exportable any time. Run all seven questions above on us — that is exactly why we wrote them. In English, Hungarian and Polish, worldwide.
Try it free → 2 weeks of Pro for every new account · cancel anytime