What each week held
Withheld: something was read in 1 week of the last 12. A series needs at least 2 to say anything a single reading does not.
What it declares
- end-to-end encryption (default or opt-in)
- on-device/local-only storage
- biometric/passcode lock
- iCloud or Google Drive backup sync
- data export (CSV/PDF)
- mood/emotion data sharing with friends or clinicians
- on-device AI processing for journaling suggestions
- no ads / no data selling
As the company’s own pages describe it. Forge did not test any of these.
What users raised
- opt-in rather than default encryption
- server-side encryption where company holds keys
- unclear data storage/location practices
- sensitive data routed through third-party cloud (e.g., Google Drive) without tailored protections
- data sharing with third parties for app performance/device IDs
- AI features processing entries server-side rather than on-device
Themes people raised in public. A complaint is somebody’s opinion, not a measurement of the product.
Everything on record
6 observed claims. Newest first; the tag on each row is what kind of claim you are reading.
- COMPLAINTUSER OPINIONOct 1, 2026
Some mental-health mood/symptom trackers (e.g., Bearable) use server-side encryption rather than local-only or E2EE storage, and app-store data-safety labels show such apps may share data types like location and personal info with third parties.
Indicates a subset of mental-health trackers collect/share more data than privacy-focused competitors, a recurring point of user scrutiny
play.google.com/store/apps/details?id=com.bearable&hl=en_US - PRODUCTFACTOct 1, 2026
Mood-tracking apps like Moodistory and Daylio store diary/mood data locally on-device by default with no data sent to company servers, and Daylio states 'No data is sent to our servers - No one can access your private diary, not even us.'
Local-only storage is a competing privacy model to cloud E2EE among mood trackers, relevant to users comparing mental-health app safety
play.google.com/store/apps/details?id=net.daylio&hl=en_US&gl=US - COMPLAINTUSER OPINIONOct 1, 2026
Journey's default architecture syncs entries to Google Drive, which 'is not designed for sensitive personal data,' with E2EE only available as an opt-in via Journey Cloud Sync rather than the default.
Highlights a recurring privacy criticism pattern (opt-in rather than default E2EE) used to differentiate 'privacy-first' apps from mainstream ones
medium.com/@didrik.hellman23/privacy-first-journaling-apps-how-the-main-options-actually-compare-7e21a316be2c - PRODUCTCOMPANY CLAIMOct 1, 2026
Apple Journal entries are end-to-end encrypted by default when iCloud is enabled with two-factor authentication, with no configuration required, and the Journaling Suggestions feature processes photos and activities locally on-device without sending data to Apple servers.
Positions Apple's native journal as a zero-effort privacy-by-default option, raising the baseline users expect from competitors
www.apple.com/legal/privacy/data/en/journaling-suggestions/ - PRODUCTFACTOct 1, 2026
Day One has end-to-end encryption enabled by default since 2019 for Premium subscribers, using AES-GCM-256 with RSA-2048 key exchange, and underwent a third-party security audit by nVisium.
Establishes Day One as the category benchmark for E2EE-by-default among mainstream journaling apps
medium.com/@didrik.hellman23/privacy-first-journaling-apps-how-the-main-options-actually-compare-7e21a316be2c - DISCOURSEUSER OPINIONOct 1, 2026
Commentary and comparison pieces consistently frame E2EE-by-default versus opt-in E2EE versus server-side-only encryption as the key differentiator for diary/mood-app privacy, noting that most journaling and mood apps still default to non-E2EE or local-only storage rather than true E2EE sync.
Buyers/users comparing mental-health diary apps are actively weighing E2EE-by-default as a trust signal, affecting which apps are seen as safe for sensitive content
medium.com/@didrik.hellman23/privacy-first-journaling-apps-how-the-main-options-actually-compare-7e21a316be2c
A record of what Forge read in public about Privacy of a mental-health diary — its own pages and what people wrote about it. Nothing here is a test of the product, a ranking or a score, and Forge has no relationship with this company.