PRIVACY & SECURITY
How your words
are protected
The words Emopi holds are deeply personal. So this page explains, without hedging, which words reach someone and which words no one else can read.
SHARING
Only as much as you choose.
Being able to write freely is where everything starts. The journal stays your own place, and only what you want to pass on reaches the other person, in a gentle form.
Your journal
The text never reaches the person you connect with.
What reaches them
It looks like work has been tiring for a while. Taking time to listen today might help them feel at ease.
Only how they are doing, and a gentle hint.
The text never reaches them
Your journal entries and your exchanges with AI are never shared with the person you connect with through Emopi.
You decide the scope
Mood, energy, care hint — you choose which items to show, item by item, and can change it at any time.
AI shapes it to land gently
What reaches them is not the detail, but how you are doing and something they can quietly do. Secrets stay secret.
Screen preview
ENCRYPTION
Protected by two encryption schemes
Emopi uses a different scheme for the journal and for talk. Journal entries use application-level encryption; talk uses end-to-end (E2E) encryption once the E2E keys are ready. Messages sent before that, and legacy messages, are encrypted at rest at the application level.
Journal
Application-level encryption
Journal text is encrypted by the application before it is stored on the server. It is decrypted only to provide features such as summaries and mood analysis; we do not routinely read the text.
- Can read
- You, and AI (only while providing a feature)
- Cannot read
- The person you connect with (only shared items reach them)
Talk
E2E encryption (once keys are ready)
Once a connection’s E2E keys are available on supported devices, talk messages are encrypted on the device before they are sent. The keys needed to decrypt them live on your device and theirs, and the ciphertext and wrapped keys stored on our servers are not enough to recover the text. Messages sent before the E2E keys are ready, and legacy messages, are stored encrypted with AES-256-GCM on the server and can be decrypted by our systems where necessary to operate the service.
- E2E
- Only your supported devices and theirs
- Before keys / legacy
- Decryptable by our systems where necessary to operate the service
In talk, the only thing AI sees is the draft you choose to show it for advice before sending.
When you change or add a device, the design allows an existing supported device to hand the encrypted keys to the new one.
E2E encryption uses a shared key per connection; there is no per-message forward secrecy. Device public keys follow a trust-on-first-use (TOFU) model against a directory our servers manage.
What we protect,
in the journal and in talk
No message text in notifications
Push notifications carry only fixed phrases such as “a new message has arrived”. The content of the words never appears on the lock screen.
All traffic encrypted
Traffic between the app and the server is always encrypted (TLS).
Change the scope at any time
Among mood, energy, and the care hint, you can reselect what the other person sees at any time. Journal text and your exchanges with AI are never shared.
Deletion is in your hands
You can delete your account and data from the app at any time. See the account deletion page for the steps.
Account Deletion →What we want to be honest about
- Even with device-to-device encryption, usage information such as send and receive timestamps and message counts is handled on the server to operate the service.
- AI processes journal text only to provide features such as summaries and mood analysis, and to check for safety. We do not use the text for any other purpose.
- The legal details, including how we respond to disclosure requests under applicable law, are set out in the Privacy Policy.
For the legal details, see ourPrivacy Policy.