PrivacyAppsJournaling

Which Journaling Apps Train AI on Your Entries?

In July 2026 we read the current privacy policies, AI disclosures, and help docs of nine popular journaling apps — plus our own — and recorded exactly what each one says about sending your entries to AI, training on them, and encrypting them. Every claim below links to the page we checked.

12 min read · By Yoshita Bhargava · Psychotherapist, MSc Counseling Psychology

Last updated

Disclosure & method:This audit is published by the Dandelion Reflect team, so read the section about our own app with that in mind. Every claim about a competitor comes from a page we fetched in July 2026 — their privacy policy, help center, pricing page, or App Store listing — and is linked inline. Where a company's published documents don't answer a question, we write "unclear" rather than guessing. Policies change; if you spot something outdated, tell us and we'll fix it.

The short version

  • No audited app says it trains AI on your entries — but the promises range from an explicit policy sentence (Mindsera, Penzu, Journey, Day One) to total silence (Reflectly's policy, last updated December 2022, never mentions AI at all).
  • "No training" is not "no reading." AI-first journals like Rosebud and Mindsera send entry content to OpenAI, Anthropic, Groq, or Stability AI for processing — that's how the features work.
  • E2EE and AI features cannot cover the same entry at the same time. Day One and Journey both document this in their own help pages; Apple sidesteps it by processing on-device.
  • The most private architectures we found were the least glamorous: local-first apps (Daylio, Diarium) whose vendors never see your entries at all.

The comparison at a glance

AppAI featuresTrains AI on entries?End-to-end encryptionExport
Day OneYes — Daily Chat, summaries, prompts (opt-in, Gold tier)Policy: no, without explicit permissionYes, default for new journals — paused while AI processes an entryPDF, JSON, plain text/Markdown
JourneyYes — Odyssey AI chat (off by default)Policy: no training on personal dataOpt-in — enabling it disables AI and searchZIP, DOCX, ePub, PDF
Apple JournalOn-device suggestions onlyN/A — processing stays on deviceYes, default in iCloudZIP bundle; PDF on iOS 18+
ReflectlyMarketed as an AI diaryUnclear — policy (Dec 2022) never mentions AINo — entries shared with US cloud providersNo in-app export documented
PenzuNo — policy explicitly disclaims AIPolicy: explicitly noOptional user-key AES lock on Pro tiersPDF (Pro)
DiariumNoN/A — local-first, policy silent on AILocal device / your own cloud; DB encryption unclearDOCX, TXT, HTML, JSON
DaylioNoN/A — entries never leave your device/cloudLocal-first; platform-encrypted backupsPDF, CSV
RosebudAI-first — entries sent to OpenAI, Anthropic, GroqNo explicit policy promise; relies on ZDR agreementsNo (policy: transit + at rest; blog overclaims E2EE)Not addressed in policy
MindseraAI-first — analysis via OpenAI, art via Stability AIPolicy: explicitly noNo — AES-256 at rest, TLS in transitYes, anytime (even free tier)
Dandelion ReflectNone, by designNo — no AI processing existsNo — row-level security + encryption at restYes, anytime

All rows reflect each app's own published policies, help docs, and store listings as fetched in July 2026. Sources are linked in each app's section below.

App by app: what the policies actually say

Day One — careful AI, honest fine print

Day One (Automattic) now ships a full AI suite on its Gold tier: Daily Chat, "Go Deeper" prompts, entry highlights, summaries, and image generation. Its AI features guide (checked July 2026) is unusually direct: "No user content will be used to train AI models except in individual cases where explicit permission has been granted by the user," and the AI providers — Automattic-hosted models or third parties like OpenAI — "do not use your content for training purposes." Features are opt-in per use.

The same guide admits the catch most apps hide: content from E2EE journals "is temporarily not end-to-end encrypted while being processed with AI." E2EE is default for new journals, but it pauses, per entry, the moment you invoke AI. Exports come in PDF, JSON, and plain text — and note their docs say exports themselves aren't encrypted. Pricing: Silver $49.99/yr, Gold $74.99/yr (Silver is ₹4,999/yr on the India App Store as of July 2026). More in our Day One comparison.

Journey — opt-out AI, and E2EE that turns it off

Journey's Odyssey AI lets you chat with your journal. Its privacy policy and dedicated Odyssey AI policy (both updated May 2024, checked July 2026) state users are opted out by default and "We do not employ users' personal data for training language model." Which LLM vendor sits behind the "GPT" branding is unclear from their published policy.

Journey offers opt-in E2EE on all tiers — and its help center says enabling it "prevents Journey from indexing your journal entries," which disables both search and Odyssey AI. You pick: AI or encryption. Exports: ZIP, DOCX, ePub, PDF (no JSON documented). See our Journey comparison for pricing details.

Apple Journal — the on-device exception

Apple avoids the whole dilemma by keeping intelligence on the phone. Its Journaling Suggestions privacy page (checked July 2026) states suggestions use on-device processing, and Apple's iCloud data security overview lists Journal data as end-to-end encrypted even at standard data protection — a stronger default than any third-party app here. No cloud AI features for Journal are documented, so there's no training question to answer.

The trade-off is reach: export is a ZIP bundle (plus per-entry PDFs on iOS 18+), entries are excluded from normal iCloud Backup, and the app doesn't exist outside Apple hardware — the subject of our Apple Journal comparison.

Reflectly — an AI diary with a pre-AI privacy policy

Reflectly markets itself as a journal "utilizing artificial intelligence." Its privacy policy — a PDF last updated 9 December 2022, still current when we checked in July 2026 — contains zero mentions of AI, machine learning, or training. We searched the text. An app sold on AI whose policy predates its AI marketing cannot tell you what happens to your entries in AI terms; that's the definition of "unclear from their published policy."

What the policy does say: entry content — moods, feelings, notes, "Mental Health Data" in their own words — is shared with US-located cloud storage providers, security is described only as "encryption and pseudonymisation," and no in-app export feature is documented beyond the GDPR right to request your data.

Penzu — no AI, in writing

Penzu is the opposite surprise. Its privacy policywas refreshed effective February 2026 and answers the question head-on: "Your journal entries are not processed by artificial intelligence systems. We do not use your content to train machine learning models or generate automated insights." Entries live on Penzu's servers; the Pro-tier Encryption Lockadds 256-bit AES that the policy says even Penzu cannot read — with the classic zero-knowledge consequence that a lost password means lost entries. Whether the mechanism is truly client-side isn't technically specified. Export is PDF only, on paid tiers ($19.99–$49.99/yr as of July 2026).

Diarium and Daylio — private by architecture, quiet on paper

Neither app has AI features, and both are local-first, which makes most of the AI questions moot. Diarium's policy states the database stays on your device unless you sync via your own OneDrive/Google Drive — "We do not have access to your Cloud Storage or your database." It has the best export menu of the audit (DOCX, TXT, HTML, JSON) and a one-time price ($14.99 on iOS). Daylio's policy says data is "stored only locally on your device" with backups in your own Google Drive or iCloud; the app "does NOT collect any user-generated content." Exports are PDF and CSV.

The caveat for both: sparse paperwork. Neither policy shows a last-updated date, Diarium doesn't document whether the local database is encrypted at rest, and Daylio's at-rest encryption rests on whatever Google or Apple do with your backup files. Private by design, thinly documented.

Rosebud — AI-first, with a gap between blog and policy

Rosebud is an AI journaling companion: your entries are the input to the product. Its privacy policy (updated July 2025, checked July 2026) names OpenAI, Anthropic, and Groq as processors, says entry content is anonymized before processing, and cites zero-data-retention agreements under which providers "immediately discard data after processing." That's meaningful. But we could not find an explicit "we don't train on your entries" sentence in the policy itself — the no-training language lives in marketing copy. We also found the company's blog claiming "end-to-end encryption" while the policy describes standard in-transit and at-rest encryption on Google Firestore. When a blog and a policy disagree, believe the policy. Export isn't addressed in their published docs. Pricing starts at $12.99/mo or $107.99/yr.

Mindsera — AI-first, with the cleanest no-training sentence

Mindsera runs emotional analysis, summaries, and even artwork generation on your entries via OpenAI and Stability AI. Its combined terms and privacy page (updated January 2025, checked July 2026) contains the sentence every AI journal should have: "Your data is not used to train or improve AI models." Encryption is AES-256 at rest and TLS in transit — server-side, not E2EE, which is the honest baseline for any app whose features require reading your text. Export is available anytime, even on the free tier. Paid is $14.99/mo or $129/yr.

Why AI features and E2EE can't coexist

This is the architectural fact the marketing pages dance around. End-to-end encryption means your devices hold the keys and the server stores ciphertext it cannot read. A server-side AI feature — chat with your journal, weekly insights, mood summaries — requires plaintext at the server, or at minimum plaintext shipped from your device to a model provider. One design goal makes your entries unreadable to the company; the other only works because they're readable.

Every app in this audit lands on one of four resolutions. Day One suspends E2EE per entry, per use, and documents it. Journey makes you choose a mode: encrypted journals lose AI and search. Apple moves the compute onto your device, which limits what the features can do but keeps iCloud E2EE intact. And the AI-first apps — Rosebud, Mindsera — simply don't offer E2EE, because their product is the reading of your entries. None of these are scandals; they are the same constraint honored four ways. The scandal is only when an app implies you can have both at once.

A useful rule when you evaluate any journaling app: find the encryption claim, then ask "could their AI feature work if this were true?" If the answer is no and both are advertised, one of the claims has fine print.

Where Reflect stands (including what we don't have)

Dandelion Reflect's position in this landscape is simple, and we want to state it with the same precision we demanded of everyone else. Reflect has no AI features at all. Your entries are never sent to any AI provider, never summarized, never analyzed, and never used to train anything — not because of an opt-out toggle, but because no such code path exists. There are no ads and no streak mechanics either; that's a deliberate design position.

And the honest part: Reflect is not end-to-end encrypted. Entries are protected by Supabase row-level security — the database enforces that only your authenticated account can query your rows — and encrypted at rest on the server. In plain terms, that means a stolen disk or a stray query doesn't expose your journal, but the keys live with the infrastructure, not solely on your devices. We think this is a reasonable trade-off for a web app with full-text search that works everywhere — and if default E2EE is your non-negotiable, Apple Journal and Day One are the recommendations this audit supports. An app that tells you when a competitor wins is an app you can believe about everything else.

The checklist to run on any journaling app

  • Date the policy. Reflectly taught us this one: AI marketing plus a 2022 policy means nobody has told you, in binding terms, what the AI does with your entries.
  • Find the training sentence. "We do not use your content to train models" should appear in the policy or official docs — not just a blog post. Mindsera, Penzu, Journey, and Day One pass; Rosebud is implied-but-not-stated; Reflectly is silent.
  • Translate the encryption claim. "Encrypted" almost always means at rest on their servers. E2EE is a different, specific promise — and it's incompatible with server-side AI on the same entries.
  • Check the exit. An open export format (JSON, plain text, CSV) is the difference between a journal and a hostage situation. Diarium and Day One do this best of the apps audited.

Frequently Asked Questions

Which journaling apps train AI on your entries?+

As of July 2026, none of the ten apps we audited state that they train AI on your entries — but the promises vary. Mindsera, Journey, Penzu, and Day One make explicit written no-training commitments. Rosebud relies on anonymization and zero-data-retention agreements with OpenAI, Anthropic, and Groq rather than an explicit policy sentence. Reflectly's policy (last updated December 2022) never mentions AI at all, so its position is unclear.

Can a journaling app have both AI features and end-to-end encryption?+

Not for the same entries at the same time. Server-side AI needs readable entries; E2EE exists to make entries unreadable to the server. Day One documents that E2EE content is temporarily not end-to-end encrypted during AI processing, and Journey documents that enabling E2EE disables its AI and search. Apple Journal avoids the conflict with on-device processing.

Is Dandelion Reflect end-to-end encrypted?+

No. Reflect uses Supabase row-level security plus encryption at rest, with no AI features, no ads, and no training — but the server holds the keys. If E2EE is your hard requirement, Apple Journal or Day One are the honest recommendations from this audit.

What should I check in a journaling app's privacy policy?+

Four things: the last-updated date; an explicit sentence about AI processing and training that names providers; what the encryption claim actually covers (at-rest is not end-to-end); and whether you can export your entries in an open format.

A journal with nothing to disclose

No AI features, no ads, no streaks, no training — and a plain-language answer about encryption. Free for your first 100 entries.

Start Free

Related reading