Knowledge base › Tools
What the AI sees in your journal — and what it doesn't

The biggest obstacle to AI journaling isn't that writing is hard. It's a question everyone has in mind before typing something genuinely personal for the first time: where does this go, and who sees it? Most apps answer that with a reassuring marketing line. We'd rather tell you concretely what happens technically: the route your text takes, exactly how much travels in a single AI call, what we store about it, what we never do, and what the AI itself is instructed to do. The point isn't for you to take our word for it — it's for you to know what to hold us, and every other app, accountable for.
1. The route an entry takes
When you request an analysis, your text touches three stations and no more:
- Your device. This is where you write it. The entry is stored against your own account.
- Our server. The request passes through Mirrify's own server function. It checks that it's really you (sign-in), whether you have AI quota left, and this is where it is cut to size — exactly what may travel on.
- The AI provider. AI processing is carried out by Anthropic PBC (USA) as a processor acting on our instructions, via the Claude models. This isn't hidden information: it is listed among the processors in our privacy policy.
There is no fourth station. Your journal doesn't go into an advertising system, doesn't go to a data marketplace, and doesn't end up in any public model.
In short
- An AI call does not carry your whole journal — only a narrow, task-specific slice.
- Concrete caps: max. 30 entries, each up to ~800 characters, and for conversations the last 20 turns at most.
- The technical log kept about AI calls stores model, token counts and cost — not text.
- We don't train on your entries, don't sell them, and under our terms the AI provider doesn't train on API content either.
2. How much travels in a single call?
This is the part almost nobody writes down, and it's the most important. The AI does not get access to your journal and doesn't "read through" your account. Every analysis is a one-off request carrying exactly as much text as the task needs — and the system caps that hard:
- Entries: at most 30 entries may go into a single call.
- Length per entry: roughly 800 characters at most. Anything longer is truncated.
- Conversation: in a chat, at most the last 20 turns travel back as context.
- Other fields: longer text fields also travel with an upper limit.
These caps aren't accidental, and they aren't only privacy caution: they protect your privacy and keep cost predictable at the same time. But the practical consequence is what matters: there is no call in which your whole life story goes across. A slice always goes — the one that belongs to the question at hand.

3. What do we store about the AI call itself?
Every AI call produces a technical usage record. It contains: which function ran, in which mode, with which model, how many tokens went in and out, and what it cost. That's all.
What it does not contain: the text of your entry, the content of the conversation, or the AI's answer. None of that is needed for tracking quotas and costs, so we don't store it. If someone here looks at that log, they see "an analysis ran, with this many tokens" — not what you wrote.
4. What we never do
- We don't sell your data. Not raw, not in an "anonymised" bundle.
- We don't train AI models on your journals. Not ours, not anyone else's.
- We don't look out of curiosity. There is no feature that shows your entries to anyone.
- We don't hold you hostage. Your data can be exported in one click, and deleting your account deletes everything belonging to it.
That last point matters more than it sounds. A self-knowledge journal only works if you can be honest in it — and honesty assumes you can walk out at any time and leave nothing behind.
5. Who can reach your entries?
Storage works with row-level isolation: it's wired in at the database level that only your account can reach your rows. This isn't application-level filtering that a bug could bypass — it's a rule enforced in the storage layer.
On top of that come two practical rights you trigger yourself from the app rather than requesting: full export and permanent account deletion. Deletion cascades: with the account, the data belonging to it ceases to exist.
International note: some of our providers (including the AI processor) operate in the United States, and transfers take place with the safeguards required by EU rules. The details — legal bases, retention periods, your rights — are in the privacy policy.

6. What is the AI itself instructed to do?
Privacy is only half the question. The other half: what the AI may do with what it sees. Mirrify's AI mentor receives a safety instruction with priority over everything else on every call, which establishes the following:
- It is not a therapist or a doctor. It does not diagnose, does not name a disorder as yours, and gives no medication advice.
- Crisis protocol. If suicidal thoughts, self-harm or abuse appear, it does not continue normal coaching and analysis but responds briefly, warmly and without judgement, and points to concrete help: your local emergency number (112 in the EU, 911 in the US) or a local crisis helpline.
- It answers in your language. The app runs in five languages, and the AI is instructed to reply in the language you write in.
This sits at the deepest level of the system — rather than in a policy document or a help page — so that it applies to every feature, not just the ones we remembered.
7. What you can hold any app accountable for
You don't have to trust us in order to choose well. These seven questions can be answered from any journaling or AI app's documentation — and if one of them has no clear answer, that is an answer in itself:
- Who is the specific AI provider, and is it named in the privacy policy?
- Does the whole journal travel, or only a slice — and is there a stated cap?
- Is the text of the prompt and the response stored, and if so for how long?
- Is anyone training on the content — them or their provider?
- Is there one-click export, or do you have to request it by email?
- Does account deletion really delete everything, or just mark it "inactive"?
- What does the AI do if someone writes to it in a crisis?
Work through those and you'll know more about any app than any review could tell you. Our own answers are above, in one place — which is why we wrote them out this concretely.
Frequently asked questions
Does anyone read my journal?
Your entries are stored with row-level isolation: no other user can reach them, and no feature shows your journal's content to anyone. When you request an analysis, the necessary excerpt is transferred for processing to the AI provider — an automated process, not a human reading.
Does the AI get my whole journal?
No. A call carries at most 30 entries, each up to ~800 characters, and for conversations at most the last 20 turns. Anything beyond that is not sent.
Which AI does Mirrify use?
Anthropic PBC (USA) as a processor acting on our instructions, via the Claude models. This is stated in our privacy policy.
Do you train AI models on my entries?
No. We don't use them for training and we don't sell them. Under our terms, the AI provider doesn't train on API content either.
What do you store about AI calls?
Which function ran, with which model, how many tokens, at what cost. The text of the entry or conversation is not included.
Can I delete my data?
Yes — one-click export, and deleting your account deletes everything belonging to it. You start it from the app; it isn't a request process.
What does the AI do if I write something serious?
It doesn't diagnose and gives no medication advice. On a crisis signal it stops normal coaching, responds briefly and without judgement, and points to concrete help: your local emergency number (112 in the EU, 911 in the US) or a local crisis helpline.
An honest journal needs a safe place
Mirrify is a self-knowledge system: journaling, habits, goals, wheel of life, schema and decision journals in one place — plus an AI mentor that works from your own entries. Your journal stays yours: stored in isolation, never sold, never used for training, exportable or deletable at any time.
Try it free → 2 weeks of Pro for every new account · cancel any time