Privacy
Is an AI journal private? A straight answer
A journal holds things you have told no one. So “is this private?” is a fair question to ask before you write a single entry, and it deserves a specific answer rather than a reassuring adjective.
Here is what actually happens to what you write in Mento.
Your entries are never used to train AI models
This is the concern most people mean first, so it goes first.
Mento uses OpenAI’s API to power search, the companion, transcription, and reflections. Data sent through that API is not used to train OpenAI’s models — that is OpenAI’s stated API policy, and it is a meaningfully different arrangement from typing into a consumer chatbot, where different terms can apply.
We also do not train models on your entries ourselves, and we do not sell your data or share it with advertisers.
What “AI processing” actually means
Being straight about this matters more than sounding reassuring: the features work by sending relevant parts of your journal to a model. That is not a loophole — it is the mechanism. There is no way to answer “how was I feeling about work in March?” without something reading what you wrote in March.
What that looks like in practice:
- Writing an entry — it is stored, and turned into an embedding so it becomes searchable by meaning.
- Asking the companion — your question and the entries relevant to it are sent to the model to compose an answer. Not your whole journal; the parts the search actually matched.
- Voice entries — audio is transcribed, then cleaned up into readable text.
- Weekly and monthly reflections — the period’s entries are summarized in the background.
Processing happens to power a feature you used, and for no other purpose.
Where it lives, and who can reach it
Entries are stored in our database (PostgreSQL, hosted on Supabase), with per-user isolation and authenticated access, encrypted in transit.
To be precise about what we are not claiming: Mento is not end-to-end encrypted. Server-side features — semantic search, the companion, background reflections — require the service to be able to read your entries in order to work. Any journal app offering AI search over your writing has this property, whether or not it says so plainly. We would rather say it plainly.
Crash and error monitoring is configured not to send personal information; events are tagged with an account identifier so a report can be traced to a session.
You can delete it all, from inside the app
You can delete your account and its data from inside the app — not by emailing support and waiting on a reply. If you are in the EEA, the UK, or California, the usual statutory rights (access, correction, deletion, portability) apply, and the Privacy Policy spells out how to exercise them.
Self-serve export is not built yet; until it ships, a portability request goes through [email protected].
The design rule underneath all of this
One principle shapes the rest: the companion is built to answer from your entries, and to tell you when it found nothing rather than invent a memory to fill the gap. When a search comes back empty, that outcome is detected in code, not left to the model’s judgement.
That is a privacy property as much as an accuracy one. A tool that quietly fabricates your past is not a memory — it is a story about someone who resembles you, and you would have no way to check it.
The full details, including the complete list of sub-processors and data retention terms, are in the Privacy Policy. If something there is unclear, write to [email protected] and ask.