You opened a wellness app to write something honest. The thing you wrote got uploaded to a database somewhere, sat in a logs table for a while, was probably backed up across two regions for resilience, and is now part of a system you cannot inspect. None of that was necessary for the writing to do what writing is supposed to do.
This is a plain case for a different default.
What "cloud" actually means in a wellness app
When a wellness app says it syncs to the cloud, it usually means a few specific things. The data you entered on your phone is encrypted in transit and sent to a server the company operates. The server stores it, usually in a managed database hosted by Amazon, Google, or Microsoft. The server makes backups of it. The server probably runs analytics queries on aggregate data. The server holds the canonical copy. Your phone holds a cache.
Some of the time, "cloud" also means an ML pipeline. The data is fed into models that personalize prompts, classify your mood, generate insights, or train future versions of the app. Most apps do not advertise this clearly. Some do. Most are somewhere in between.
There are real engineering reasons companies build this way. Cloud-first apps are easier to ship across devices. They make password recovery, support tickets, and analytics easier. They survive a phone being lost. They are also easier to monetize, because the company can see what users are doing and adjust the product to keep them coming back.
The problem is that almost none of those engineering reasons are reasons that benefit a person trying to journal in private.
Three things you give up when your journal is in the cloud
The first is the ceiling on what someone else can see. Once your data is on a company's server, the people who can read it include the engineers who maintain the database, the customer support team that uses internal tools to debug your account, anyone who finds a vulnerability before the company does, and anyone the company is legally compelled to share with. In practice, most of those access paths are well-managed at well-run companies. The point is not that bad things will happen most days. The point is that the ceiling has been raised.
The second is your recourse if the company changes its mind. A privacy policy on a cloud app is a snapshot of how the company intends to handle your data today. Privacy policies change. Companies are acquired. Business models pivot. Data that was never going to be sold can become data that is going to be sold after a board vote. With cloud-stored journal entries, you are trusting the future version of the company you signed up for, not just the current one.
The third is the audit surface. Even if nobody at the company misbehaves, even if the company is never acquired, even if the policy never changes, the data exists in a system where it can be subpoenaed. Law enforcement can request user records. Civil discovery can ask for them. Some of those requests are appropriate. Some are not. The point is that the existence of the data on a server creates a request surface that does not exist when the data is on your phone.
What you supposedly get in exchange
Cloud sync usually advertises three benefits.
The first is multi-device access. You can write on your phone and read on your laptop. For a productivity tool, this matters. For a wellness journal, most people only write on one device, and most who write on two prefer the writing to stay anchored to one of them.
The second is backup. If you lose your phone, the cloud has a copy. This is real. The honest counter is that you can solve the same problem with periodic local exports stored somewhere you control, like a password manager's encrypted notes or an encrypted external drive. Local-first does not have to mean no backup. It means the backup is yours.
The third is "smart features." Mood charts, personalized prompts, insight reports. Some of these are useful for some people. Most are decorative. None of them are the thing that makes journaling work. The thing that makes journaling work is the writing, and the writing does not need a model behind it.
Local-first is not extreme
Cloud-first became the wellness app default for product reasons, not for user reasons. It is worth saying out loud that the alternative is normal, not radical.
Your iPhone is a small, fast computer. It can store thousands of journal entries without breaking a sweat. It can encrypt them at rest using built-in iOS data protection. It can run all the small reset tools, reminders, routines, and check-ins a wellness app needs, without ever calling out to a server. The internet is convenient. It is not required for any of the actual jobs of a private wellness app.
Paper journals were local-first. Computers in the 1990s were local-first. The shift to cloud-first storage is roughly fifteen years old. It is also roughly contemporaneous with the rise of behavioral advertising. The two are related, not coincidental.
What we did with Unstuck
Unstuck stores journal entries, check-ins, reminders, routines, and tool history on your iPhone. There is no Unstuck-operated server holding a copy. There is no account, no sign-in, no password to forget, no email tied to your data, and no public profile to manage. Closing the app and never opening it again leaves nothing on any company server because nothing was ever there.
That is the entire design. It is not clever. It is what wellness apps used to default to, before defaults changed.
You can read the formal version of this on /privacy and the plain-English version on /privacy-pledge. The Consumer Health Data Notice at /consumer-health-data covers state-law specifics (Washington, Nevada, Connecticut) for users in those states.
The honest limits of local-first
Local-first is not magic. There are four limits worth naming.
The first is iCloud Backup. If you have iCloud Backup turned on at the iOS device level, your app data can ride along in your iCloud device backup. That backup is encrypted, tied to your iCloud account, and Apple's job to protect. It is not Unstuck's job, and Unstuck does not control it. You can exclude Unstuck from iCloud Backup in iOS Settings if that matters to you.
The second is device loss. If you lose your phone and have no backup of any kind, you lose the journal. The privacy upside is that nobody else has a copy. The personal downside is that you do not either. The fix is to export periodically and store the export somewhere you control.
The third is device transfer. When you set up a new iPhone using Quick Start, Unstuck's data moves with the device. If you download Unstuck fresh on a new phone without restoring from a backup, you start empty. There is a manual export-and-paste path for that case, with a one-tap import feature planned.
The fourth is forensic extraction. If someone has physical access to your unlocked phone and the right tools, no consumer security model protects you. App lock helps with casual access; it does not help with that. The honest answer is that this is true of every app on your phone, including the ones with cloud sync.
These limits are real. They are also smaller than the alternative of having every entry on a server you do not run.
A small example
A person came in saying she had stopped using her old journal app. The app was good. Her entries had been migrated to a new cloud the company moved to during an acquisition. She did not know who ran the new cloud. She did not know what the new owner's policy was. She had not been notified clearly. Six months of journaling that she had assumed was private was now somewhere she could not name.
She did not lose the entries. She lost the relationship with the app. Once she could not trust that the writing stayed where she wrote it, the writing felt different. She stopped writing.
Most people who care about a wellness journal eventually have a version of this experience. The privacy posture is not separate from the journaling. It is part of why the journaling works in the first place.
How Unstuck does this
The private journal in Unstuck stays on your device by default. You can lock it with a PIN and Face ID through app lock. You can export everything to a .zip of plain JSON files at any time. You can delete one entry, all entries, or the whole app from the app's Settings. None of those actions require an internet connection.
If you want to read the technical version, see /journal/what-local-first-actually-means-for-a-journal-app.
Sources
- American Psychological Association: Privacy in the digital age. https://www.apa.org/topics/privacy
- National Institute of Standards and Technology: Privacy framework. https://www.nist.gov/privacy-framework
Related reading
- The Unstuck privacy pledge: /privacy-pledge
- What 'local-first' actually means for a journal app: /journal/what-local-first-actually-means-for-a-journal-app
- How to start private journaling without pressure: /journal/private-journaling-without-pressure