Security at Intentional

A journal is one of the most personal things you can own. Here is exactly how we protect yours.

Encryption at rest

Your journal, intentions, gratitude notes, goal reasons and plans, meal notes and photos, screen-time data and AI reviews are encrypted with AES-256-GCM before they are written to disk. Each account uses its own key derived (HKDF-SHA256) from a master key kept outside the database, so a copy of the database alone reveals nothing private.

Encryption in transit

All traffic uses HTTPS with TLS 1.2+ and HSTS preloading. Plain HTTP is redirected.

Passwords done right

Passwords are hashed with Argon2id (memory-hard, the OWASP recommendation) and never stored in plain text. New passwords are checked against hundreds of millions of breached passwords via Have I Been Pwned’s k-anonymity API. Only the first 5 characters of a hash ever leave our server.

Two-factor authentication

Protect your account with any authenticator app (TOTP) plus single-use recovery codes. Codes can’t be replayed.

Passwordless & Google sign-in

Sign in with Google or a one-time email link that expires in 15 minutes and works once. Links open a confirmation page so email scanners can’t use them.

Session security

Sessions use random 256-bit tokens stored only as keyed hashes, in HttpOnly, Secure, SameSite cookies with the __Host- prefix. You can see every signed-in device and sign any of them out. Changing your password signs out everywhere else.

Alerts

We email you when your account is accessed from a new device, and whenever your password or 2FA settings change.

Attack protection

Rate limiting and per-account lockouts against password guessing, protection against account enumeration, CSRF protection, a strict nonce-based Content Security Policy, and hardened server isolation.

Photos

Uploaded photos are re-encoded on our server, which strips GPS location and other metadata. Screen-time screenshots are discarded after analysis.

Your data, your call

Export everything as JSON at any time. Deleting your account permanently removes all of your data. We have no ads and never sell data.

Found a vulnerability? Please email security@intentional.day. We appreciate responsible disclosure. See also our privacy policy.