Draft for legal review. Nothing here is final until this notice is gone; items in [brackets] are still to be decided.
Security.
Your journal is end-to-end encrypted: we hold it, but can’t read it. What we can read explains the exceptions in plain English.
How it’s protected
- Encrypted on your device (AES-256-GCM) before it syncs, with a key only your devices hold.
- That key is stored on our side only locked with your password or passphrase (PBKDF2, 600,000 rounds), which we never keep.
- Two-step sign-in with an authenticator app, recovery codes, and signing out a lost device from your account page.
- Everything over HTTPS, with strict security headers; the Mac app is hardened, and [signed and notarised by Apple].
- Logs and error reports carry no journal text, and no names or emails.
- Every change is tested and scanned for secrets and vulnerable dependencies before it ships.
Reporting a vulnerability
Write to [security contact email] with what you found and how to reproduce it. We’ll reply within [3] working days, keep you updated, and credit you if you’d like. Please give us reasonable time to fix it before telling anyone else, don’t access or change other people’s data, and don’t degrade the service. If you act in good faith within these rules, we won’t pursue legal action. Our security.txt has the same details.
Last updated [date of publication].