Back to Home

Privacy & Security

Phase was built with one principle: your thoughts are sacred.

The Short Version

How Encryption Works

Encryption Standard

Phase uses AES-256-GCM (Advanced Encryption Standard with Galois/Counter Mode):

This is the same standard used by the US Government for classified information, banking institutions, and password managers like 1Password and Bitwarden.

Two Security Modes

1. Device-Bound Mode

2. Passphrase Mode

What's Encrypted

Data Encrypted? Why
Entry text Yes Your private thoughts
Mood Yes Mental health state is sensitive
Tags Yes Tags like "anxiety" or "therapy" are sensitive
Activities Yes Behavioral patterns are sensitive
Photos Yes Attached images are sensitive
Weather Yes Can reveal location patterns
Thought records (CBT) Yes Therapeutic data is sensitive
Timestamps No Needed for date organization
Follow-up reminders No Needed for scheduling notifications

All personal content is encrypted at rest. Only structural fields like timestamps and entry IDs remain unencrypted so the app can organize your data without decrypting everything.

No Cloud, No Servers

Phase has no backend servers. Zero.

Your data is stored in IndexedDB — a database built into your browser. It never leaves your device unless YOU export it.

How Backups Work

When you export a backup:

  1. Your encrypted entries are packaged into a JSON file
  2. The file downloads to YOUR device
  3. No data is transmitted anywhere

The backup file contains your encrypted data — it's still protected even if someone finds the file.

No AI, Ever

Many journaling apps now use AI to "enhance" your experience. We don't.

Why not?

We will never:

What We Can't Protect Against

We're honest about our limitations:

For most people, Phase provides more than enough protection. If you're a journalist, activist, or have nation-state adversaries, consider additional security measures.

Questions?

If you have security questions or concerns, please reach out through the feedback form inside the app. We take security seriously.


Remember: Your mental health matters. Your privacy matters. We built Phase to protect both.

— A fellow MH warrior