# Is an AI journal private? A straight answer

> What happens to your entries in Mento: where they are stored, what AI processing means in practice, and what we do not do with your journal.

Published: 2026-08-17 · Source: https://mentoapp.app/articles/is-my-journal-private/

---

A journal holds things you have told no one. So "is this private?" is a fair
question to ask before you write a single entry, and it deserves a specific
answer rather than a reassuring adjective.

Here is what actually happens to what you write in Mento.

## Your entries are never used to train AI models

This is the concern most people mean first, so it goes first.

Mento uses OpenAI's API to power search, the companion, transcription, and
reflections. Data sent through that API is not used to train OpenAI's models —
that is OpenAI's stated API policy, and it is a meaningfully different
arrangement from typing into a consumer chatbot, where different terms can apply.

We also do not train models on your entries ourselves, and we do not sell your
data or share it with advertisers.

## What "AI processing" actually means

Being straight about this matters more than sounding reassuring: the features
work by sending relevant parts of your journal to a model. That is not a
loophole — it is the mechanism. There is no way to answer "how was I feeling
about work in March?" without something reading what you wrote in March.

What that looks like in practice:

- **Writing an entry** — it is stored, and turned into an embedding so it becomes
  searchable by meaning.
- **Asking the companion** — your question and the entries relevant to it are
  sent to the model to compose an answer. Not your whole journal; the parts the
  search actually matched.
- **Voice entries** — audio is transcribed, then cleaned up into readable text.
- **Weekly and monthly reflections** — the period's entries are summarized in the
  background.

Processing happens to power a feature you used, and for no other purpose.

## Where it lives, and who can reach it

Entries are stored in our database (PostgreSQL, hosted on Supabase), with
per-user isolation and authenticated access, encrypted in transit.

To be precise about what we are not claiming: Mento is **not** end-to-end
encrypted. Server-side features — semantic search, the companion, background
reflections — require the service to be able to read your entries in order to
work. Any journal app offering AI search over your writing has this property,
whether or not it says so plainly. We would rather say it plainly.

Crash and error monitoring is configured not to send personal information; events
are tagged with an account identifier so a report can be traced to a session.

## You can delete it all, from inside the app

You can delete your account and its data from inside the app — not by emailing
support and waiting on a reply. If you are in the EEA, the UK, or California, the
usual statutory rights (access, correction, deletion, portability) apply, and the
Privacy Policy spells out how to exercise them.

Self-serve export is not built yet; until it ships, a portability request goes
through [support@mentoapp.app](mailto:support@mentoapp.app).

## The design rule underneath all of this

One principle shapes the rest: **the companion is built to answer from your
entries, and to tell you when it found nothing** rather than invent a memory to
fill the gap. When a search comes back empty, that outcome is detected in code,
not left to the model's judgement.

That is a privacy property as much as an accuracy one. A tool that quietly
fabricates your past is not a memory — it is a story about someone who resembles
you, and you would have no way to check it.

---

The full details, including the complete list of sub-processors and data
retention terms, are in the [Privacy Policy](/privacy). If something there is
unclear, write to [support@mentoapp.app](mailto:support@mentoapp.app) and ask.
