The bar is “nobody but me”
A journal is not ordinary app data. One entry can connect a real name to a health issue, private relationship, location, fear or plan. The harm does not require a public breach; an unlocked family computer, account-recovery request or employee with technical access may be enough.
“Encrypted in transit” protects the connection between your device and the service. “Encrypted at rest” may protect server disks. Neither phrase tells you whether the provider holds the key. End-to-end or zero-knowledge encryption is the claim that matters: readable text should exist only on devices you authorised.
Apple Journal: a strong documented baseline
Apple says Journal entries are encrypted when your device is locked. With two-factor authentication on the Apple Account and a device passcode, entries stored in iCloud are end-to-end encrypted, so Apple cannot read them. You can add a Journal lock using Face ID, Touch ID or the device passcode, and Apple supports export and encrypted local device backups.
That is stronger than a generic “secure cloud” claim. The honest limits are the devices and credentials around it: someone who can unlock a trusted device may read the journal, and exported files need their own protection. Advanced Data Protection strengthens more of the surrounding iCloud account — including Photos, Notes, iCloud Drive and backups where available — although Apple documents Journal’s own end-to-end sync separately rather than making it depend on ADP.
Dedicated journal apps: use the recovery-path test
Some dedicated journal apps offer real end-to-end encryption; others make it optional, limit it to particular plans, or exclude attachments and metadata. Do not judge by the word “encrypted” alone. Find the sentence that says where keys are made, where they are kept, and which parts of an entry the server can still see.
Then apply the recovery-path test from zero-knowledge encryption explained: if you forget the app password, who can restore readable entries? Recovery from a trusted device, a key you kept, or a contact you chose can fit end-to-end encryption. Instant recovery by support needs a clear explanation of what secret they control.
Plain notes apps: convenient is not the same as private
An ordinary notes app may encrypt traffic and storage while the provider still controls the keys. That arrangement is useful for syncing, server-side search and easy password resets. It is not “nobody but me”. The provider may be able to produce readable content after an account takeover, internal mistake or lawful demand.
There are exceptions and special modes, including locked notes and services covered by stronger account settings. Read the exact documentation for notes, attachments and backups. If the privacy page speaks only about the connection or the disk, assume the journal content is not end-to-end encrypted until it says otherwise.
Three questions to ask any journal app
Where are the encryption keys created and kept? “On your device” is meaningful; “industry-standard encryption” without key ownership is not. Ask whether photos, audio, location, titles, search indexes and backups receive the same protection as the text.
What happens if I forget the password? Recovery is part of the encryption design, not a support detail. Decide whether you accept the trade-off between a vendor reset and a real possibility of permanent loss.
Can I export everything? Test the export before years depend on it. Check whether dates, attachments and readable text survive, then protect the exported copy because it may no longer have the app’s encryption.
When an encrypted vault fits better
A focused journal app is usually the better writing experience. A vault fits when the journal is a mixed private record: markdown entries beside photos, voice memos, scans and other files, all under the same local encryption and recovery plan. Deniable vaults add a different protection: the ability to keep a sensitive collection from being provable under pressure.
Sealby stores encrypted Markdown notes inside vaults alongside any file. It does not claim to replace every journaling feature. It is the stronger fit when the attachments, document context and existence of a particular journal need the same protection as the words.