Private Journaling With Optional AI: What Actually Leaves Your Phone?
A precise guide to what stays on your device in Grith, what optional Cloud AI sends, what other online flows collect, and what local deletion cannot reach.
“Private” can mean several different things in a journal app. It can describe where notes are saved, whether an account exists, whether a feature uses the internet, or whether a third-party service receives anything. Those are separate questions.
Short answer: ordinary journals and chat history stay on your phone by default. When you use Cloud AI, requested content can leave the phone; AI chat automatically adds text from up to 20 recent journal entries, capped at 8,000 characters total. Purchases, feedback, updates, and aggregate analytics use separate online paths. Delete All My Data clears local data when it reports success, not records controlled independently by third parties. The details below reflect the current app and Privacy Policy, not a promise that the architecture can never change.
A 2024 systematic review of 33 studies found that patients' awareness and concerns about privacy, security, and confidentiality in mobile health apps varied across the included studies. A 2024 systematic review of patient perspectives on mHealth privacy does not tell us what any one reader expects, but it is a reason not to treat “private” as self-explanatory.
A 2025 meta-analysis of 65 articles about sharing health data for secondary purposes found estimates of willingness ranging from 24% to 100%, with a pooled estimate of 77% in predominantly high-income-country samples; between-study heterogeneity was very high, and participants still reported concerns about privacy, consent, and transparency. The 2025 health-data-sharing meta-analysis was not about Grith or personal journaling, so it cannot decide whether an optional AI feature is acceptable for you.
What stays on your device by default
Journal entries—including text, mood ratings, emotions, tags, and related metadata—are stored locally on your device by default. Chat sessions and message history are also stored locally.
Your optional display name, personal note, onboarding answers, and About You preferences are stored locally. Grith does not currently create a traditional cloud account for them.
Most progress data and locally generated personalization remain on the device. You can write, reread entries, manage local chats, and use non-AI parts of the app without sending that writing to Cloud AI.
“Local-first” is not the same as “no backup can exist.” Grith does not provide its own cloud sync or cloud backup service, but iOS may apply system-level backup and restore depending on your device and operating-system settings.
What Cloud AI changes
Cloud AI is optional. The app asks for consent before the first Cloud AI use, and you can turn Cloud AI off later in Privacy & Data settings.
When Cloud AI is off, Grith does not send journal or chat text for an AI reply, AI journal analysis, or AI Weekly Insights. Other online flows—such as purchases, app updates, aggregate product analytics, or feedback that you choose to submit—are separate and are explained below.
When you request an AI feature, the app sends the content and context needed for that request through Grith's backend to configured AI service providers. The request may also include bounded technical context such as locale, timezone, local time, and detected message language.
For AI chat, each request includes your current message and recent messages from the current chat. It also automatically includes text from up to 20 recent journal entries, capped at 8,000 characters total, plus selected personalization fields when they are present. There is no separate journal-context switch. If you have 20 or fewer short entries, text from all of them may fit within that bounded context.
For AI journal analysis, the selected journal text is sent for that analysis. The saved journal remains in local app storage; the online request is a separate processing step.
AI Weekly Insights has a broader window than one message. When you enable both Cloud AI and Weekly Insights, the feature can send up to the last seven days of journal and chat text to generate the requested summary.
Turning on one of these features is therefore a choice to transmit the content described for that feature. Turning Cloud AI off stops future Cloud AI requests; it does not recall a request that has already been processed.
What the Grith backend keeps
The mobile AI backend processes the request without creating an ongoing server-side journal, chat archive, or user-profile history from it. It forwards the content needed for the requested feature and returns the result.
One narrow exception applies to successful AI chat responses. A response remains eligible for replay of the same request for approximately ten minutes so that a retry can return the same result without consuming another allowance. After expiry, it is not returned for replay. The expired row is physically pruned opportunistically during a later idempotency lookup, so ten minutes is not a guarantee of physical deletion. The stored value is the successful response, not an ongoing copy of your journal or request history.
Current production AI security-event logs redact configured sensitive text-preview fields. Other application logs may still record operational metadata and upstream error messages; Grith cannot guarantee that an upstream error message never contains sensitive text. This statement does not cover logs or retention operated independently by infrastructure or AI providers.
Online AI processing can involve Railway, OpenRouter, OpenAI, and model providers selected through the configured route. Grith sends online requests over HTTPS, but HTTPS protects data in transit; it does not mean the receiving service never processes or retains anything. Provider processing remains subject to the applicable service arrangements and policies.
Other data that can leave the phone
Purchases and app delivery use separate systems. Apple, RevenueCat, Expo, and related infrastructure may receive the device, app-version, purchase-state, and network metadata needed for purchases, renewals, restores, subscription management, and updates.
Grith's backend stores limited RevenueCat webhook analytics about subscription lifecycle events. These records can include event type, product or offering, store, country code, currency, price, purchase and expiration timestamps, plus keyed hashes of RevenueCat user and transaction identifiers. The backend does not store the raw RevenueCat identifiers, aliases, receipts, subscriber attributes, or full webhook payloads described in the Privacy Policy.
Grith also records aggregate product interaction counts for onboarding, paywall, feature reliability, and app health. Those aggregate analytics do not include journal text, chat text, onboarding answers, display name, or a persistent analytics user or device identifier, and they are not used for advertising or cross-app or cross-website tracking.
Feedback is different because its purpose is to deliver what you write to support. If you submit the in-app feedback form, the message and technical details—including device ID, platform, device model, operating-system version, app version, build number, and IP address—may be forwarded to Grith's Telegram support inbox.
The app also generates a random device identifier for online-feature rate limiting, feedback continuity, and abuse prevention. It is not your real-world identity, but “random identifier” should not be rewritten as “no identifier.”
What Delete All My Data does
When Delete All My Data reports success, it has removed the app's local data on that device, including local journals and chats, local personalization, the PIN secret, the locally generated device ID, local caches, and local app state. If critical PIN or device-ID deletion cannot be completed, the app reports deletion failure instead of claiming all data was deleted.
It does not cancel a subscription purchased through Apple. After a local deletion, an active entitlement can still belong to the Apple ID and can be recovered through Restore Purchases.
A local wipe also cannot promise to erase records controlled independently by Apple, RevenueCat, infrastructure providers, AI providers, or a support inbox. Those systems have their own purposes and retention boundaries. If you have a privacy request about an online flow, use the contact options in the Privacy Policy.
A 60-second before-you-send privacy check
This is a Grith editorial checklist, not a studied privacy protocol, and it promises no safety or wellbeing outcome.
First, name the feature: local journaling, AI chat, AI journal analysis, Weekly Insights, feedback, or subscription management.
Second, read what the feature says it needs. For Cloud AI, identify the text and context that will be sent for this request. For feedback, remember that the message is meant to reach support.
Third, ask one practical question: am I comfortable sending this material for this purpose right now?
Fourth, choose the smaller data path if that fits better. You can keep Cloud AI off and continue writing locally.
If the data path is unclear or you are not comfortable with it, stop before sending. Keep the feature off and check the in-app disclosure or Privacy Policy first.
The short version
Ordinary journals, chat history, personalization, and most app data stay on your device by default. Optional Cloud AI sends the content needed for the feature you choose; AI chat automatically includes bounded recent-journal context as described above. Purchases, updates, aggregate analytics, and feedback have separate online data paths.
That is why the accurate description is “local-first with optional Cloud AI,” not “nothing ever leaves your phone.” The useful privacy control is not a slogan; it is knowing which path you are choosing before you send.
Grith is a self-reflection tool — not medical care, therapy, diagnosis, or crisis support.