PRIVACY & SECURITY
Privacy &
data protection
This page explains, feature by feature and without hedging, how far your journal and talk content is shared — who can read it, and who cannot.
SHARING
Only the items you choose are shared.
Journal text is never shared. What reaches the other person is only the items you choose: mood, energy, and the care hint.
Your journal
The text never reaches the person you connect with.
What reaches them
It looks like work has been tiring for a while. Taking time to listen today might help them feel at ease.
Only how they are doing, and a gentle hint.
The text never reaches them
Your journal entries and your exchanges with AI are never shared with the person you connect with through Emopi.
You decide the scope
Mood, energy, care hint — you choose which items to show, item by item, and can change it at any time.
AI shapes it to land gently
What reaches them is not your journal text, but how you are doing and something they can quietly do.
Screen preview
ENCRYPTION
Protected by two encryption schemes
Emopi uses a different scheme for the journal and for talk. Journal entries use application-level encryption; talk uses end-to-end (E2E) encryption once the E2E keys are ready. Messages sent before that, and legacy messages, are encrypted at rest at the application level.
Journal
Application-level encryption
Journal text is encrypted by the application before it is stored on the server. It is decrypted only to provide features such as summaries and mood analysis; we do not routinely read the text.
- Can read
- You, and AI (only while providing a feature)
- Cannot read
- The person you connect with (only shared items reach them)
Talk
E2E encryption (once keys are ready)
Once a connection’s E2E keys are available on supported devices, talk messages are encrypted on the device before they are sent. The keys needed to decrypt them live on your device and theirs, and the ciphertext and wrapped keys stored on our servers are not enough to recover the text. Messages sent before the E2E keys are ready, and legacy messages, are stored encrypted with AES-256-GCM on the server and can be decrypted by our systems where necessary to operate the service.
- E2E
- Only your supported devices and theirs
- Before keys / legacy
- Decryptable by our systems where necessary to operate the service
In talk, the only thing AI sees is the draft you choose to show it for advice before sending.
When you change or add a device, the design allows an existing supported device to hand the encrypted keys to the new one.
E2E encryption uses a shared key per connection; there is no per-message forward secrecy. Device public keys follow a trust-on-first-use (TOFU) model against a directory our servers manage.
What we protect,
in the journal and in talk
No message text in notifications
Push notifications carry only fixed phrases such as “a new message has arrived”. Message content never appears on the lock screen.
All traffic encrypted
Traffic between the app and the server is always encrypted (TLS).
Change the scope at any time
Among mood, energy, and the care hint, you can reselect what the other person sees at any time. Journal text and your exchanges with AI are never shared.
Delete your account and data at any time
Account deletion is done from within the app. See the account deletion page for the steps.
Account Deletion →What we want to be honest about
- Even with device-to-device encryption, usage information such as send and receive timestamps and message counts is handled on the server to operate the service.
- AI processes journal text only to provide features such as summaries and mood analysis, and to check for safety. We do not use the text for any other purpose.
- The legal details, including how we respond to disclosure requests under applicable law, are set out in the Privacy Policy.
For the legal details, see ourPrivacy Policy.