What is End-to-End encryption?
Encryption is generally used to prevent unauthorized access to data. There are many kinds of encryption. Typical methods used by most mobile apps are "encryption at rest" and "encryption in transit". These are very basic and do not prevent the app operators from accessing the user data. If the servers get hacked, attackers might also be able to see the data.
End-to-End encryption solves this by encrypting everything in a way that even the app operators cannot access (decrypt) the data. The necessary decryption-keys are never visible for the operators. This way, even if the servers were accessed by hackers, they would not be able to see the user data. It is also not possible to train AI-models on encrypted data. That's why End-to-End encryption is the gold standard for privacy and also used by chat-apps like Signal.
Isn't this complicated to use?
Users do not have to take any additional steps for this to work. Just share the join-link with your family members and they can request access. The secure key exchange happens automatically, it just works™.
End-to-End Encryption in Journal Jar
In Journal Jar, end-to-end encryption is applied to almost all user data. For technical reasons, your name and profile picture, as well as your email address and some metadata, are only encrypted conventionally.
What this means for you
- Even as the site operators, we cannot see your collections, entries, photos, or comments.
- Anyone who got hold of the data on the server wouldn't be able to see or read anything either.
- Only the members of a collection hold the keys needed to decrypt the data.
Why iCloud Keychain matters
The key that decrypts your content is stored securely on your smartphone. We never have a copy of it.
If you turn on iCloud Keychain Sync, that key is stored securely and follows you to your other Apple devices (e.g. an iPad or a new smartphone). If it isn't, your key only lives on one device, and if that device is lost, reset, or wiped, the key is gone with it and your encrypted content (entries, photos) can no longer be recovered. Not even by us.
Our recommendation
- Turn on iCloud Keychain Sync under Settings → [Your Name] → iCloud → Passwords and Keychain, and keep it on while you use encrypted collections. (It is usually on by default.)
- Stay signed in to the same Apple Account on every device where you use Journal Jar.
Using it without iCloud or switching Apple Accounts
If you want to use end-to-end encryption without Apple's iCloud Keychain, we recommend storing your recovery key in a safe place, for example in your password manager. You can find the recovery key in the app under Menu → Edit Profile → Advanced → Recovery Key.
You can use the recovery key when you sign in on a device without iCloud or with a different Apple Account.
If you have any questions about encryption in Journal Jar, feel free to reach out to us.