Back to Blog
Ethical AI in Digital Journaling: How to Tell Real Privacy From Privacy-Washing
Digital Privacy

Ethical AI in Digital Journaling: How to Tell Real Privacy From Privacy-Washing

MindfulFlow Journal

Open the website of almost any journaling app today and you'll find the same reassuring phrases. Your privacy matters to us. Bank-level security. Your data is safe. Add an AI feature, and a new line usually appears: Our AI is built responsibly.

Some of those statements are backed by careful engineering. Some are backed by a sincere but loose policy. And a few are mostly marketing. From the outside, they can look identical.

That's the problem this guide is meant to solve. If you're deciding between journaling apps (maybe even between us and someone else), the useful question isn't "does this app say it's private?" Nearly all of them do. The useful question is: can I check whether what this app says about my data is actually true?

Below, we'll define what ethical AI in digital journaling really means, walk through the red flags of "privacy-washing", and give you a checklist and a short list of questions you can apply to any app, including ours.


Why This Matters More for a Journal Than for Most Apps

A journal is often the most honest record of you that exists anywhere: the worries you haven't said out loud, the thing you're working through on a bad night.

When an app adds AI to that, the stakes shift. AI features work by processing what you write. So the ethical questions stop being abstract. Where does my text go to be analysed? Who can see it on the way? Is it kept? Could it be used to train a model that other people will use?

It's also worth being realistic about how most of us evaluate apps. Researchers Aleecia McDonald and Lorrie Faith Cranor estimated back in 2008 that actually reading the privacy policies of the websites a typical person visits would take hundreds of hours a year. Nobody does that. So short, confident marketing phrases do most of the persuading, and that gap is where privacy-washing lives.


What "Ethical AI" Actually Means in a Journaling App

"Ethical AI" is a phrase that's easy to say and hard to pin down. In a journaling context, we think it comes down to six concrete principles. None of them are exotic, and you can check for every one.

1. Data minimisation. The AI should receive the least amount of your writing needed to do its job, not your full entries by default. If a feature only needs to know an entry's overall mood or recurring themes, it shouldn't need your verbatim words, names and places.

2. No training on your entries. Your journal should never become raw material for improving a product that other people use. An ethical app says this plainly, not as a setting you have to discover and switch off.

3. User-held keys. The strongest privacy promise is one the company can't break, not just one it won't. That happens when your entries are encrypted with a key only you hold. (If you'd like the plain-language background on how that works, see digital journaling app encryption explained.)

4. Plain-language disclosure. You should be able to find out, in a few minutes and in normal words, what is sent where, what is kept, and who can access it. If the answer requires a law degree, that's information too.

5. No dark patterns. "Dark patterns" is the term designer Harry Brignull coined for interface tricks that nudge you into choices you wouldn't otherwise make: pre-ticked boxes, guilt-laden "No, I don't care about my wellbeing" buttons, opt-outs buried four menus deep. Privacy that depends on you winning against the interface isn't really yours.

6. Honest marketing. The claims on the homepage should match the claims in the policy, and both should match how the product actually works. Ethical apps also say what they don't protect against, because no system protects against everything.

Notice what's not on this list: perfection. An app can be genuinely ethical and still have tradeoffs. What matters is that they're disclosed, not disguised.


The Red Flags of Privacy-Washing

"Privacy-washing" borrows from "greenwashing": using the language and imagery of privacy to create an impression that the product's actual design doesn't support. It's rarely outright lying. More often, it's true statements arranged to imply something bigger.

Here are the patterns worth noticing.

"Bank-level" or "military-grade" security. These phrases sound impressive but don't describe anything specific. They usually refer to standard encryption that protects data while it travels and while it's stored, which is good and normal, but says nothing about who can unlock it.

"We encrypt your data" without saying who holds the key. This is the single most common gap. Encryption is only as private as the key. If the company holds it, the company (or anyone who compromises the company, or anyone who legally compels it) can read your entries. An honest app tells you which it is.

AI features that quietly need your verbatim text on a server. Many AI features work by sending your full entry to a server, sometimes a third-party AI provider, for processing. That isn't automatically wrong, but it should be disclosed clearly: what's sent, to whom, and whether it's stored.

"Anonymous" analytics that aren't. Removing your name isn't the same as anonymising data. Journal text is full of identifying detail: your city, your partner's name, your workplace, the date of a specific event. Look for apps that describe how data is de-identified, not just that it is.

Opt-outs buried or reset. If training on your data, sharing with partners or personalised advertising is on by default and the off switch is hard to find (or turns itself back on after an update), the default is telling you what the business actually prefers.

Policy language that contradicts the homepage. "We never sell your data" on the homepage, alongside "we may share information with partners for business purposes" in the policy. Both can technically be true at once. If you've ever wondered will journaling apps sell my data, this mismatch is the place to look.

Partial coverage. Sometimes encryption covers your entries but not attachments, backups, AI summaries or mood tags. Ask whether it covers everything derived from your writing.

A fair note before we go further: seeing one of these flags doesn't mean an app is acting in bad faith. Plenty of journaling apps are run by thoughtful people who are honest but imperfect, or who simply haven't written their documentation clearly. Independent reviews, like the Mozilla Foundation's Privacy Not Included guide, have repeatedly found wellbeing apps with weak or unclear privacy practices, but also apps that do well. The point of the red flags isn't to condemn. It's to tell you where to ask a follow-up question.


The Ethical AI Checklist: Apply It to Any App

Here's a checklist you can run through in about fifteen minutes with any journaling or AI app, using its homepage, privacy policy and help pages.

Encryption and access

  • The app states clearly whether entries are end-to-end encrypted.
  • It says who holds the encryption key: you, or the company.
  • It answers directly whether staff can read your entries.
  • It explains what happens if you forget your password (this reveals who holds the key).

AI and processing

  • It says exactly what data the AI features receive: full text, a reduced version, or only on-device processing.
  • It names whether a third-party AI provider is involved.
  • It states that your entries are not used to train models, in plain words.

Data use and sharing

  • It states whether data is sold, shared or used for advertising.
  • It describes how analytics are de-identified, if they're collected at all.
  • Privacy-protective options are on by default, not hidden opt-outs.

Control and honesty

  • You can export your entries in a usable format.
  • You can delete your account and data, and it says what deletion covers.
  • The homepage claims match the privacy policy.

You won't find a perfect score everywhere, and that's fine. A mostly-ticked list with honest explanations for the gaps is a better sign than a confident homepage with no detail behind it. For a broader version that covers storage, backups and device settings too, our privacy-first journaling app checklist is the natural companion to this one.


Five Questions to Ask Any Journaling App

If the documentation doesn't answer something, ask the company directly. These five questions cut through most privacy-washing.

1. "Can anyone at your company read my entries, even if they wanted to?" A good answer is a direct yes or no, with an explanation. A vague answer about policies and trusted staff usually means yes, technically.

2. "When I use an AI feature, what exactly is sent to a server, and is it stored?" Look for specifics: the full entry, a reduced or de-identified version, or nothing at all. "Your data is handled securely" is not an answer to this question.

3. "Are my entries ever used to train or improve AI models?" The ethical answer is a plain no. "Only with your consent" is acceptable if that consent is genuinely opt-in and clearly explained.

4. "If you were acquired or shut down, what would happen to my journal?" This one tests whether the protection is architectural or just contractual. If the company can't read your entries, a new owner can't either.

5. "What don't you protect against?" Honest companies have an answer. Maybe it's a compromised device, or metadata like when you sync. Silence or defensiveness here is worth noting.

If you want a deeper look at the specific question of can AI journaling tools read private data, we've answered that separately in can AI journaling tools read your private data?. And for the broader picture of what makes a digital journal safe in the first place, start with are digital journaling apps safe and private?


How We Hold Ourselves to This Standard

Here's how MindfulFlow Journal answers the questions above.

Your entries are end-to-end encrypted, and you hold the key. That means we can't read your journal. Not as a policy we've promised to follow, but because of how the system is built. Our AI insights are generated from a de-identified copy of your writing, and your verbatim entry is never sent to an AI server.

We designed it this way because of how journaling actually works. We think about it in three steps: Record, Reflect, Refine. You Record honestly, which is far easier when you're not quietly editing for an imagined reader. You Reflect, which is where AI can help, by noticing themes and patterns across weeks you might miss on your own. And you Refine, adjusting one small thing based on what you've noticed. Ethical AI means the Reflect step adds something without costing you the honesty of the Record step.

There are tradeoffs, and we'd rather name them: because we never hold your key, we can't simply reset your way back into your entries if you lose it, so keeping your recovery details safe genuinely matters.

If you'd like to run the checklist on us yourself, you can see what an honestly private journal looks like — no credit card needed.

And one honest note: journaling can be a helpful way to notice your thoughts and feelings, but it isn't therapy and isn't a replacement for it. If you're struggling, a therapist, counsellor or doctor is the right person to talk to, and a journal can sit quietly alongside that support.


The Bottom Line

Ethical AI in digital journaling isn't a badge an app can award itself. It's a set of choices you can check: how little of your writing the AI needs, whether your entries ever train a model, who holds the key, how plainly the company explains itself, and whether the interface respects your decisions.

Privacy-washing works because confident language is cheaper than careful design, but a few pointed questions are usually enough to tell them apart. Most apps will pass some and miss others, often through honest gaps rather than bad intent. You're looking for an app whose claims hold up when you look closer.

You deserve to write freely. Choosing a journal whose privacy you've actually verified is how you get to.

When you chose your current journaling app, did you check who holds the key, or did you take the homepage at its word? Share in the comments.

Private journaling, clearer insights

Start journaling with privacy built in

Turn reflection into a consistent habit with end-to-end encrypted journaling and AI-powered insights designed to help you notice patterns without giving up your privacy.

Related articles

More from Digital Privacy

Explore more articles in the same pillar.

    MindfulFlow

    We use essential cookies for security (like reCAPTCHA), and — with your permission — analytics cookies to understand how the site is used. You can change your mind any time. See our Privacy Policy.