Your journal is different from other data you store online. It contains your unfiltered thoughts, your fears and hopes, your struggles and secrets. The entries you write with the understanding that no one else will ever read them.
This kind of writing requires absolute trust in the platform that holds it. You need to know that your words are protected from hackers, from surveillance, from the company itself. Anything less makes true journaling impossible.
At DayCanvas, security and privacy are not features. They are the foundation everything else is built on. Here is exactly how we protect your most private thoughts.
Encryption at Every Level
Encryption transforms your readable entries into scrambled data that can only be unscrambled with the right key. Without that key, your entries are meaningless noise even to someone who accesses them directly.
We implement encryption at three distinct levels.
On Your Device
Before your entries ever leave your phone or computer, they are encrypted using keys derived from your account credentials. This means the data that travels from your device is already protected.
Even if someone intercepted the data during transmission, they would receive only encrypted content. Without your credentials, they could not read a single word.
In Transit
When encrypted data travels from your device to our servers, it is protected again by TLS, the same security protocol that protects banking and financial transactions online.
This creates a double layer of protection during transmission: your already-encrypted entries travel through an encrypted tunnel. This defense-in-depth approach means that compromising either layer alone is insufficient to access your data.
At Rest
When your entries reach our servers, they remain encrypted. The files stored on our infrastructure are not readable by anyone, including us.
Our system architecture is designed so that we genuinely cannot read your journal. This is not a policy decision. It is a technical implementation. The keys required to decrypt your entries are derived from your credentials, which we never store in readable form.
What This Means in Practice
This encryption architecture has important practical implications.
We cannot read your journal. Even if a court ordered us to, even if a hacker compromised our systems, even if a rogue employee wanted to snoop. The data on our servers is encrypted and we do not have the keys. This is not because we are trustworthy, though we strive to be. It is because we designed the system to make unauthorized access technically impossible.
You hold the keys. Your password is not just authentication. It is the source of your encryption keys. This is why we cannot reset your password and recover your data if you forget it. We literally do not have the ability to decrypt your entries without the password you created.
Security requires your participation. Because you hold the keys, you must protect them. Use a strong, unique password. Enable two-factor authentication. Do not share your credentials. Our security architecture protects your data from everyone except someone who has your login credentials.
Beyond Encryption: Our Privacy Commitments
Security protects your data from unauthorized access. Privacy policies determine what we do with data we can access. Both matter.
We Do Not Sell Your Data
Many technology companies monetize user data by selling it to advertisers or data brokers. We do not. We have never sold user data and we never will.
Our business model is simple: you pay for the product. This means our incentives align with yours. We make money by building something valuable enough that people choose to pay for it, not by extracting value from your private information.
We Do Not Show Targeted Ads
Even companies that do not sell data often use it to target advertising. They analyze your behavior, your interests, your patterns to show you more effective ads.
DayCanvas has no advertising at all. We do not analyze your journal entries to understand your interests. We do not track your behavior to build a profile. We do not monetize your attention through advertising of any kind.
We Do Not Train AI on Your Data
As AI tools become more prevalent, some companies use customer data to train machine learning models. Your journal entries, emails, documents, and photos become training data that improves the company's AI products.
We do not do this. Your journal entries are never used to train AI models. When you use AI features within DayCanvas, like voice transcription, processing happens in isolation without contributing to model training. Your private thoughts remain private.
We Collect Minimal Metadata
Beyond your encrypted entries, we collect only what is necessary for the service to function: account information for authentication, usage data for troubleshooting, payment information for billing.
We do not track which entries you write or when. We do not analyze patterns in your journal. We do not build behavioral profiles. The metadata we collect is the minimum required for reliable service, not the maximum we could justify.
Security Practices
Beyond encryption and privacy policies, we implement security practices that protect the overall system.
Regular Security Audits
Independent security experts periodically assess our systems, looking for vulnerabilities before malicious actors find them. These audits examine everything from our code to our infrastructure to our operational practices.
When audits identify issues, we address them promptly. Security is not a one-time achievement but an ongoing process of assessment and improvement.
Bug Bounty Program
We maintain a bug bounty program that rewards security researchers who responsibly disclose vulnerabilities they discover. This harnesses the broader security community to help identify issues we might miss internally.
Employee Access Controls
Our employees operate under strict access controls. Most staff cannot access production systems at all. Those who can have access only to encrypted data they cannot read.
We maintain detailed audit logs of all system access. Security training is mandatory for all employees. Background checks are conducted for roles with system access.
Infrastructure Security
Our servers run on hardened infrastructure with multiple layers of protection. Firewalls, intrusion detection, geographic distribution, and regular security updates all contribute to overall system security.
We maintain redundant backups in separate locations, encrypted at rest, to protect against data loss. Your journal will survive even significant infrastructure failures.
Your Role in Security
The strongest security architecture can be undermined by weak user practices. Here is how to maximize the protection of your journal.
Use a strong, unique password. Your password protects your encryption keys. A weak password is a weak lock on your most private thoughts. Use a password manager to generate and store a strong unique password for DayCanvas.
Enable two-factor authentication. Two-factor authentication requires both your password and access to a second device to log in. This protects your account even if your password is compromised.
Protect your devices. Keep your phone and computer secure with passcodes, biometric locks, and up-to-date software. A compromised device can expose your journal regardless of how secure our systems are.
Be cautious with public networks. While our encryption protects data in transit, public WiFi networks can be vectors for other attacks. Use trusted networks when accessing your journal, or use a VPN on public networks.
Review active sessions. Periodically check which devices are logged into your account. Revoke access for any devices you do not recognize.
Trust Is Earned
We ask you to trust us with your most private thoughts. That trust must be earned through consistent action over time, not demanded through marketing claims.
We have been committed to privacy and security since our founding. We have never experienced a data breach. We have never sold user data. We have never compromised on encryption despite the operational complexity it creates.
But words are easy. What matters is continued action. We commit to maintaining the security architecture described here, to being transparent about our practices, and to prioritizing your privacy even when it makes our work harder.
Your journal contains who you really are. We are honored that you trust us to protect it.