End-to-End Encryption FAQ

Day One encrypts your data, protects your privacy, and safeguards your data from end-to-end (client app to server).

See our blog post on Day One Encryption

What is end-to-end encryption?

End-to-end encryption (E2EE) utilizes a private key to encrypt all entries before they reach Day One servers. Your encryption key is held on your device, and can optionally be backed up to iCloud. Day One never has access to it, which means your journal data cannot be read by our servers or by Day One employees. This data not only includes text, but all media files added to entries as well.

How do I use this feature?

End-to-end encryption is enabled by default for all new journals created after version 4.2. For journals not previously encrypted, there currently is not a way to convert a Standard Encrypted Journal to End-to-End Encryption. The dev team has paused this as they look into how to improve this in a future update. For now, please create a new Journal and copy entries over.

What if I lose my encryption key?

When using end-to-end encryption, it is essential you save your encryption key in a secure location. Day One is currently storing the key securely using iCloud associated with your Apple ID. If the option to store the key in iCloud is disabled, please save a copy of the key. If the key is lost, encrypted journal stored in the Day One Sync cannot be decrypted. Day One does not have access to the private key at any point.

For tips on backing up your key, see Keeping Your Day One Encryption Key Safe. If you’ve already lost your key, see Finding a Lost Encryption Key.

Can I remove my encryption key from iCloud?

Yes. This removes Day One’s own iCloud copy of your key. It does not affect the copy held in your device Keychain, or in iCloud Keychain if you use it.

iOS: turn on Settings > Sync > Advanced Sync Settings > Only Store Encryption Key in Keychain

Mac: turn off Settings > Sync > Advanced > Automatically save key to iCloud

Do this on each of your devices. That device then deletes the record and stops uploading it again. Before you do, make sure you have your key saved somewhere safe, because Day One cannot recover it for you.

Can Apple access my encryption key stored in iCloud?

It depends which iCloud copy you mean, because there are two and they are protected differently.

iCloud Keychain. If you use iCloud Keychain, your key syncs between your devices through it. Apple end-to-end encrypts iCloud Keychain, whether or not you have Advanced Data Protection enabled.

Day One’s iCloud backup of your key. When “Backed up to iCloud” is on, Day One also stores a copy of your key in your private iCloud storage as an app data record. Advanced Data Protection only extends end-to-end encryption to app data fields that a developer has explicitly marked as encrypted, and Day One does not currently use that API for this record. Turning on Advanced Data Protection therefore does not add end-to-end encryption to this copy. The key is not stored in plaintext, because Day One encrypts it before uploading, but that is an additional safeguard rather than end-to-end encryption.

If you would rather Day One did not keep this copy, see Can I remove my encryption key from iCloud? above.

What is standard encryption?

This is the old encryption option prior to end-to-end encryption. Standard encryption encrypts your data “at rest” on our servers and securely transfers the data from our servers to the Day One app. This used to be the default. As of September 2019, new journals are generally created with end-to-end encryption as the default. While very secure, this standard security requires that Day One staff holds the keys to decrypt journal data.

How can I trust your encryption service? Has it been reviewed by third-party security experts?

After over a year of development work, we enlisted the services of nVisium, a noted security firm, to review our end-to-end encryption architecture. They found four medium-severity risks and three low-severity risks.  We have evaluated the remaining items and implemented solutions where we feel they are appropriate.

When was end-to-end encryption released?

End-to-end encryption is included in the 2.2 update for both iOS and Mac.

Does Day One Android support end-to-end encrypted journals?

Day One Android has supported end to end encryption since our release update from Day One Classic to Day One.

Does IFTTT work with encrypted journals?

Yes! If Day One is already connected in the IFTTT account, you may need to reconnect it for the encrypted journals to appear. See the troubleshooting steps in this guide: Using IFTTT with Day One

How does end-to-end encryption work with backups?

Day One Android supports two automatic backup methods—Day One Sync and text backups to Google Drive—and one manual backup method—JSON exports. Only Day One Sync backups are encrypted. Both text and JSON exports are not encrypted. Learn more about backups in Day One Android

Day One iOS supports three automatic backup methods—Day One Sync, text backups to iCloud, iCloud Device Backups—and one manual backup method—JSON exports. Only Day One Sync backups are encrypted. Text backups, iCloud Device Backups and JSON exports are not encrypted.

Day One macOS supports three automatic backup methods—Day One Sync, text backups to iCloud, Time Machine Backups—and one manual backup method—JSON exports. Only Day One Sync backups are encrypted. Text backups, Time Machine Backups and JSON exports are not encrypted.

Learn more about backups on MacOS and iOS.

Can I convert my existing Standard Encrypted Journal to End-to-End Encryption?

Currently, there is no direct way to convert a Standard Encrypted Journal to End-to-End Encryption. Our development team has paused work on this feature to explore ways to improve it in a future update. In the meantime, the recommended workaround is to create a new journal and copy your entries over. You can find instructions on how to move entries to another journal here: https://dayoneapp.com/guides/tips-and-tutorials/moving-entries-to-another-journal/

What if someone else has my encryption key?

You should never share your encryption key with anyone else, even when using shared journals. If someone else has your key, they can access your encrypted journal content. If someone who shouldn’t has access to your key, you will need to create a new account to get a new encryption key.

Is it possible for local malware to read encrypted journal data on macOS?

The macOS app uses a standard system application container, and the system permissions system will prevent other applications from accessing it unless the user gives that other app explicit permission. But it is not in a special encrypted container. If local malware were somehow installed with administrator rights that allow it to bypass those permissions, then it would also be able to read from such an encrypted container whenever the app is running; an encrypted container would not protect the data.

Can you share more technical details about how E2EE works?

Please refer to the following documents for more technical details.

I need more help. How can I contact you?

Please visit https://dayoneapp.com/contact to contact our support service.

Capture life’s moments, anytime, anywhere.

Download the free Day One journal app for free on iPhone, Android, iPad, Mac, and Apple Watch. Or access your Day One Journal from any browser.