Begin with the threat you actually care about

Privacy discussions become vague because different people mean different things. You might want protection from somebody holding your unlocked phone, from advertising profiles, from an app employee reading an entry, or from losing an archive when a service disappears.

Those are different risks with different controls.

Privacy layerWhat it can protectWhat it does not answer
Face ID or passcodeCasual access on the deviceServer storage and processing
Encryption in transitData moving over the networkWho can decrypt stored content
Encryption at restStolen disks or storage mediaWhich services hold the keys
End-to-end encryptionProvider access, if implemented correctlyWhat happens while AI processes plaintext
Local-first storageContinued access and reduced cloud dependenceWhether features upload temporary copies
No account requiredIdentity collection at signupDevice identifiers and technical analytics
Deletion controlsUser agencyRetention periods, backups and offline retries

An app can truthfully offer several rows without offering all of them. Look for precise statements rather than the number of times a page uses the word “secure.”

Seven questions to ask

1. Is the original audio kept?

Some products retain recordings for replay; some delete audio after transcription; some let the user choose. Retention is not automatically good or bad. It changes the value of the journal and the consequences of unauthorised access.

2. Does audio leave the device?

Remote speech recognition can be fast and multilingual, but the recording must be sent to a provider. On-device recognition limits that transfer but may have different accuracy, battery or language constraints. The product should state which path it uses.

3. Where does the transcript live?

“Audio deleted after transcription” does not mean the written entry is local-only. Ask separately about audio, transcript, generated entry, title, tags and backups.

4. Is identity required?

An email account simplifies web access and cross-platform sync. An account-free app reduces the obvious identity attached at signup. Neither eliminates technical identifiers required for security, purchases or diagnostics.

5. What reaches analytics?

Counts such as “recording completed” can improve reliability without containing journal content. Entry text, titles, search queries, filenames and extracted themes do not belong in product analytics.

6. Can the company read entries?

Look for a technical and policy answer. “We never read your journal” can mean access is cryptographically impossible, operationally prohibited, or simply not part of normal work. Those are not equivalent.

7. What exactly happens when I delete?

A credible policy describes device deletion, server deletion, third-party processing copies, backups and what happens if the device is offline.

Journo’s current privacy model

Journo requires no name or email to begin. Audio is saved locally before processing and can sync through the user’s private iCloud account. Face ID can protect the app on the device. Journo sends audio for remote processing and retains the journal data needed to provide the entry and recovery experience; it does not claim that transcription happens entirely on the phone.

Journo’s product analytics are designed around events, states, duration buckets and opaque identifiers—not journal text, titles or audio. Journal content is not sold and is not used to build an advertising profile.

Deleting an entry removes local audio and content and sends a deletion to the processing service. If the device is offline, that request must retry later. The full, controlling description remains the Journo Privacy Policy.

The honest standard

The most private product is not necessarily the one with the loudest privacy headline. It is the one whose data flow matches your needs and whose claims remain understandable after you replace “secure” with specific questions.

Sources and verification

We use first-party product documentation and original research wherever possible. Features and prices can change.

  1. Apple Platform Security
  2. Apple — App privacy details
  3. Untold privacy commitments
  4. AudioDiary security FAQ
  5. Journo privacy policy