Your Privacy,
by Design.

Your diary is one of the most personal things you'll ever write. WispDay is built so that it stays yours — readable by you, and only you.

Not by us, not by our servers, not by anyone who ends up with your phone. Here's exactly how that works, in plain terms — and because we'd rather show our work than ask for your trust, the security part of WispDay is open source for anyone to inspect.

The Architecture of a Secure Diary

When searching for the most secure private journal solutions, the difference is always in the architecture. Here is exactly how we treat a single entry from the moment you write it.

01

End-to-End encryption

You write an entry. Before it is saved, its contents are secured with End-to-End encryption directly on your device. Only you have the key that encrypts and decrypts your diary.

02

Encrypted at Rest

The local database is encrypted at rest, so the files on your device aren't readable on their own.

03

Sealed Syncing

What goes to our servers is already encrypted — we store locked boxes and only the information needed to sync them between your devices. Never your key.

04

Decrypted for You

It's decrypted only on your device, only for you, when you open the app and your key is available.

05

Memory Wiping

When you leave, the key is cleared from memory — so the app returns to a state where there's nothing readable sitting around.

Two Ways to Lock WispDay

WispDay gives you two kinds of locks. They feel similar in everyday use, but they protect entirely different things.

App Passcode — keeps casual hands out.

A passcode (or a quick Face ID check) puts a gate in front of the app. It's perfect for everyday privacy — a partner, a friend, or a coworker who picks up your phone won't get in. Think of it as a strong door on the room.

Maximum Security — protects the data itself.

This is the strongest protection WispDay offers, for when ordinary privacy isn't enough — when the safety of your device itself, not just who glances at your screen, is a real concern.

What's the difference between an app lock and Maximum Security?

This is the most common point of confusion, so it's worth being precise.

A normal app lock is a guard in front of an open safe. Your data is already unlocked underneath, and Face ID is simply deciding whether to show it to you. If the guard is ever stepped around, the safe was open the whole time.

Maximum Security works the other way. Your Face ID isn't a check in front of already-unlocked data — it's what releases the encryption key itself. The key is held in your iPhone's hardware-backed secure storage — the Keychain, protected by the Secure Enclave — and bound to your enrolled Face ID. It's released only on a biometric match; until then the key doesn't exist in usable form, and there's nothing decrypted to find.

You can see the difference in one observable way. A normal app lock, after a few failed Face ID attempts, falls back to your phone's passcode — because to the system, it's only asking "is this an authorized person?", and the passcode is an accepted answer. Maximum Security has no passcode fallback to your data. Only your biometric match can release the key, because the key is bound to it — there is no "enter passcode instead" path to your diary, because the passcode was never holding the door.

The binding is literal: your key is sealed to your enrolled Face ID. If you change or remove that Face ID, the thing the key was tied to is gone — so the key is erased with it, instantly. Your diary stays sealed and safe; you simply re-enter your twelve words to rebuild it. (Which is also why those words matter — they're the one thing that can always restore your access, and only you have them.)

In everyday use the two feel identical — you glance at your phone and your diary appears. The difference is in what's happening underneath: one decides whether to show data that's already open; the other is the only thing that can produce the key to open it at all.

Why does Maximum Security need an account first?

Because your key is sealed to your Face ID, certain changes — switching your Face ID, or other resets — erase that key by design. With an account, recovery is simple: re-enter your twelve words and your encrypted diary syncs back from the cloud.

Without an account, your entries live only on this device under that key — so if the key is ever erased, there may be no way to bring them back. To protect you from that, Maximum Security becomes available once you've created an account. After that, it's a setting you can turn on or off whenever you like.

Cryptography You Can Verify

WispDay uses well-established, widely-trusted cryptography — the same families of algorithms used across the security industry. We deliberately don't invent our own encryption; we use standard, peer-reviewed building blocks, correctly.

AES-GCM Authenticated Encryption

Your text, notes, and attachments are encrypted with AES-GCM, a modern authenticated encryption standard. "Authenticated" means it doesn't just scramble your data — it also detects if anything has been tampered with, and refuses to open altered data rather than showing you something forged.

Your key comes from you — in words you can actually keep.

The key that protects your diary is a long, random value — far too complex to type or remember on its own. So instead of handing you something unreadable, WispDay turns it into twelve ordinary words, using the BIP-39 standard. Those twelve words ARE your key, in a form a person can actually live with: write them down, keep them somewhere safe, tuck them away with the things you don't lose — and read them back later without a single mistake. The same strong key, in a shape that's simple to hold onto.

It's generated on your device, and the key it creates never leaves your phone. Because we never receive it, we can't read your diary — the only person who can open it is you.

Per-File Media Protection

Each photo or file you add is encrypted with its own individual key, which is in turn locked by your main key. This isn't a separate security level — your main key still protects everything — but it means each file is sealed on its own rather than sharing one lock.

On our servers, your diary is just locked boxes.

What syncs to our servers is already encrypted before it leaves your device. We store sealed data and the information needed to sync it across your devices — never your key, never your twelve words, never anything we could use to read your entries. Even with full access to our own servers, we cannot open your diary.

Where can I find my recovery phrase?

Your twelve words are always yours to keep. They're shown in your profile settings whenever you need them — so you can write them down or store them somewhere safe at any time, not only when you first set up.

Viewing them requires unlocking with Face ID, so they can't be copied by someone who simply has your phone open. They're the key to your diary, so treat them like one: anyone who has them can open your entries.

We protect your diary where it lives — on your device

Most encryption focuses on protecting your data on its way to the cloud, so a company's servers can't read it. WispDay does that too — but we don't stop there.

From what we've seen across journaling apps, most protect your entries with an app lock — a screen in front of your data — and otherwise lean on the phone's built-in protections, like the system sandbox and your device passcode, to keep what's already on your device safe. That's genuine protection, but it's a lock on the door, not a lock on the diary itself — and it's the operating system's protection, working on the app's behalf. If that layer is ever bypassed, the data underneath is just sitting there.

WispDay adds its own layer underneath. Your diary's local data is encrypted by the app itself, with your key — so even the copy stored on your phone isn't readable on its own. And when you step away, the key that opens it is cleared from memory. We don't assume the device around your diary will always hold; we protect the diary directly.

Your diary is protected on the device, not just in the cloud

Encrypting data on its way to a server is the part most people think of. WispDay does that — but the copy that lives on your phone is encrypted too, so it isn't readable on its own.

When you leave the app, WispDay clears the key that opens your diary from memory and closes its working data, so what remains on the device is sealed rather than sitting there in the open. With Maximum Security on, this is at its strongest: the key is held in your iPhone's Secure Enclave behind your Face ID and is wiped from memory the moment you leave — so if your device is examined, copied, or taken while WispDay is closed, there is nothing readable to extract. Not in the app, not in its stored files.

This is the part many apps leave to the phone alone. We protect the diary itself, not just the trip to the cloud.

Honesty in Privacy

We believe true privacy requires complete transparency about what the software can and cannot do, and who has access to it.

Our Core Principle

We believe that deep digital security should never be a premium luxury. Privacy is a basic human right that everyone deserves, which is why our core protection layers are never placed behind a paywall.

Who is eligible for end-to-end encryption and Maximum Security mode?

It is completely free and available for everyone using WispDay. You do not need a subscription to get end-to-end encryption or the Maximum Security feature. To enable Maximum Security, you simply need to create a free profile account. Once your account is active, you can toggle the feature on or off directly from the app settings whenever you like.

What happens if I lose my twelve words?

If you lose your twelve words, we cannot recover your diary — and neither can anyone else. This is the hard part of true privacy, and we want to be completely honest about it. Because your diary is encrypted with a key only you hold, and we never receive that key or your twelve words, there is no master switch, no support request, and no backend tool that can restore your access. It isn't that we won't — it's that we can't. The same design that stops anyone else from reading your diary stops us from rescuing it. So please keep your twelve words somewhere safe and lasting. They are the one and only way back in.

What can't WispDay protect against?

We want to be straight with you: no encryption can protect a diary that you are physically forced to open yourself. If someone compels you to unlock your phone and the app in front of them, the contents are visible — that's true of any app, and we'd rather tell you than pretend otherwise. WispDay protects your diary when it's closed, when it's syncing, and when it's stored on your device — but not in the moment you are made to open it yourself.

Verifiable Trust

Open for Review

We've published the security layer of WispDay so independent researchers can examine exactly how your data is protected. We'd rather show our work than ask you to take it on faith.

GitHub Logo View Repository