Local Journal

Privacy Policy

Last updated 8 August 2026

The short version

What you write is stored on your device and is not sent to us. Local Journal runs in your browser — there is no account, no sign-up and no sync, and we operate no service that receives your entries. The only server it talks to is the one that serves the app's own files: the page, its script, its icons, and the PDF engine when you first export a PDF. The app page carries a Content-Security-Policy that names no host other than the one serving it, so the browser blocks the page from loading or contacting anything else.

What you write is stored on your device and is not sent to us. Local Journal runs entirely on this device — there is no account, no sign-up and no sync, and we operate no service that receives your entries. It talks to no server at all: everything the app needs, including the PDF engine, is inside the app itself. The app's main screen also carries a Content-Security-Policy that names no host whatsoever, so nothing there can load or contact anything off this device.

What it stores, and where

Everything you write is saved in this browser's own storage on this device:

Everything you write is saved in this app's own private storage on this device, sandboxed to Local Journal the way any other app's data is:

The app sends none of this anywhere. Clearing your browser's site data for this site removes all of it, permanently — there is no copy elsewhere to restore from.

The app sends none of this anywhere. Deleting the app removes all of it from this device, permanently — we hold no copy to restore from, so export a backup before you delete it. One copy can exist outside the app without us: if your iPhone backs itself up, to iCloud or to a computer, that backup may include this app's data along with every other app's, kept under whatever protection Apple gives the backup itself — and that is usually what brings a journal across when you set up a new phone.

Working offline

The app installs a service worker — a small piece of the app that the browser keeps — which stores a copy of the app's own files so the journal opens and works with no connection. That copy is why this site shows a megabyte or two of cache storage if you look at it in your browser's site-data settings — browsers each count it a little differently; it is the app, not your journal. Your entries are not in it, and it is not sent anywhere. Clearing this site's data removes it along with everything else, and the app reinstalls it the next time you open the page online.

There is nothing to load. The app's own files — its screens, its script, its styles, its icons and the PDF engine — are inside the app you installed, so the journal opens and every part of it works with no connection at all, including search, the calendar and every export. Turning the device off the network changes nothing about how it behaves.

What the app sends

Nothing you write. The app contains no analytics, no advertising, no error-reporting and no payment code of any kind — it is free and has no billing. The app page carries a Content-Security-Policy that names no host other than the one it is served from — every source is 'self', alongside the data: and blob: forms the page generates for itself and its own inline styles — so the browser blocks the page from loading or contacting anything else. This policy is set on the app page. These supporting pages hold nothing you have written and reach for nothing beyond this site — their own text, a small script that matches the theme you chose, and the site icon.

Nothing you write — and, in this app, nothing at all. It contains no analytics, no advertising, no error-reporting and no payment code of any kind: it is free, and there is no purchase to make. The app's main screen carries a Content-Security-Policy naming no host — every source is 'self', meaning the app's own bundled files, alongside the data: and blob: forms it generates for itself and its own inline styles — so nothing on that screen can load or contact anything off this device. These few supporting pages carry no policy of their own; they hold nothing you have written and load only what is already inside the app.

Two ordinary things do happen that are worth naming plainly. Requesting the app's own files leaves an entry in the access log of whatever host is serving it — an IP address, a timestamp and a browser string, as every website records. And some things happen at the level of your browser or operating system rather than inside this app: dictation, predictive keyboards, and browser spell-checking can send what you type to the company that makes them. The app turns spell-checking off on the entry fields for that reason, but the rest sits outside what any web page can control.

One thing is worth naming plainly, because it sits outside the app. Some text handling happens at the level of your device rather than inside Local Journal: dictation and predictive keyboards can send what you type to the company that makes them. The app turns spell-checking off on the entry fields for that reason, but the rest is your device's own behaviour, not something any app can switch off for you.

The optional passcode lock

You can turn on a passcode that encrypts your entries where they are stored. From then on, entries are written encrypted. If you do:

The passcode lock protects your entries where they sit in browser storagethe app's storage. It is not a defence against someone using your unlocked device while the journal is open on screen.

One honest limit: if you journalled for a while before turning the lock on, the app rewrites those entries in encrypted form, but browsers do not let a page erase the bytes the old versions occupied — the browser reclaims that space in its own time. If you want the earlier unencrypted copies gone for certain, clear this site's data after exporting a backup, or start again in a fresh browser profile.

One honest limit: if you journalled for a while before turning the lock on, the app rewrites those entries in encrypted form, but it cannot erase the bytes the old versions occupied — the system reclaims that space in its own time. If you want the earlier unencrypted copies gone for certain, export a backup, delete the app, and install it again.

Exports

Exported JSON, Markdown and PDF files are built on your device and saved straight to your downloads. They are not encrypted, even when the passcode lock is on — that is what makes them readable elsewhere. Keep them somewhere you trust.

Exported JSON, Markdown and PDF files are built on your device. The finished file is handed to your device's own share sheet, where you choose what happens to it next — save it to Files, mail it to yourself, or send it somewhere else. The app does not choose, and it sends the file nowhere on its own. Exports are not encrypted, even when the passcode lock is on — that is what makes them readable elsewhere. Making one writes that same unencrypted file into the app's own cache folder on the way to the share sheet, and the app removes it again once the share sheet closes — whether you sent the file somewhere or changed your mind. If one is ever left behind, by the app being closed mid-share say, the next start looks for it and clears it; deleting the app removes anything still there along with everything else. Keep them somewhere you trust.

Permissions

The app asks for no device permissions at all — no contacts, no photos, no location, no camera, no microphone, no notifications. The system interactions it makes are the standard share sheet, used to hand a file you exported to an app you pick; the standard file picker, used when you choose a backup to import; and writing that exported file into the app's own cache folder on the way to the share sheet, then removing it afterwards. Those happen when you ask for an export or an import. The one thing you do not ask for is the tidy-up when the app starts, which looks in that same cache folder for an export left behind and clears it.

Children

Local Journal is not directed at children under 13. It has no account system and no way to collect personal information from anyone who uses it.

Changes

If this policy changes, the date at the top changes with it.

Contact

Questions about privacy? Email support@edenapps.app.