Of all the data a wellness product can hold, the journal is the special case. Moods are sensitive. Habits are sensitive. But the journal is the one place in digital life where you deliberately write down what you actually think — about your marriage, your fear, your boss, your faith, yourself at 2 a.m. Earlier in this series we published seven questions to ask any wellness app about your data. This post is about why one of them — is my data used to train AI models? — deserves a flat, unqualified no when the data is a journal. Not a hedge. Not "with consent." No.
The mechanism the journal runs on
Start with why journals work at all. The research tradition from Pennebaker onward (1997) found that expressive writing — honestly processing significant experience on the page — produces measurable benefits. And the practical tradition, which our journaling post explored, locates the mechanism in noticing: the page is where vague things become specific, where "everything's fine" can't survive being written by a person for whom it isn't.
Both traditions depend on the same precondition: candor. The journal works exactly as far as you'll write the true sentence instead of the presentable one. Which makes the journal's privacy not a feature alongside the product — it is the product. Anything that installs an imagined audience between you and the page — a future reader, a data broker, a model — wakes the self-censor back up, and the writing quietly reverts to the presentable version. The entries keep happening. The mechanism stops. That's the deep problem with journals as training data, and here's the uncomfortable part: it operates even if nothing bad is ever done with the data. The mere reasonable suspicion is enough to break the tool, because the tool is made of trust.
"But it's anonymized" and the other hedges
The training question usually gets answered with hedges. Each one fails for this data specifically, and it's worth seeing why.
"It's anonymized." Journal entries are the worst case for anonymization. They're dense, longitudinal, first-person narratives about the writer's identifying circumstances — named relationships, workplaces, places, dates. Stripping the account email doesn't de-identify a diary; the diary is self-identifying prose. Treat "anonymized journal data" as close to a contradiction in terms.
"You consented." Consent harvested by a pre-checked box in an onboarding flow, for uses described as "improving our services," is not the considered agreement of someone who understood their midnight entries would season a model. The consent hedge shifts blame to you for a choice you never knowingly made. (The regulatory mood agrees: the FTC's 2023 BetterHelp action turned precisely on the gap between what users were assured and what was done with their health information.)
"The model doesn't memorize." Model-memorization risk is a real research topic, and genuinely improving — but notice that this hedge answers the wrong question. Even a hypothetically perfect no-leakage guarantee doesn't restore candor, because you can't verify the guarantee, and unverifiable guarantees don't quiet the self-censor. The journal's requirement isn't "leakage is unlikely." It's "no part of me is wondering."
"Everyone in AI does it." Increasingly untrue as a blanket claim — policies vary sharply by provider, plan, and product — and irrelevant where true. Categories have norms until products break them. "Everyone" is how the wrong default persists.
The line worth holding — and what AI can still do
Let's be precise about the claim, because it isn't "AI should never touch journals." Our AI post made the case that pattern-noticing across your own entries is one of the genuinely valuable things AI can do for reflection — surveying a year of your writing for themes you haven't named. The line is between processing in your service and incorporation into the product's brain:
- Processing: your (redacted) content is sent, used to generate your summary or your prompt, and not retained for training. The work product is yours; the model is unchanged.
- Training: your content becomes parameters — a permanent, unauditable, irrevocable contribution to an asset the company owns. You can delete your account. You cannot delete yourself from weights.
Irrevocability is why the journal deserves the flat no. Most data-sharing regrets are recoverable in principle — records get deleted, accounts get closed. Training is the exception: no undo, no export, no right-to-erasure that reaches inside a model. A category of data whose entire function depends on revocable trust should never flow into the one destination revocation can't reach.
What this means practically
For your own tooling, the checklist is short. A paper notebook passes trivially. A local file passes. For any app: the training question from the seven questions, asked specifically about journal content, answered flatly. Encryption at rest, so the diary isn't readable in a breach. Redaction before any AI processing. And a deletion path you actually believe. If an app's answers are vague, journal somewhere else — the practice is too valuable to run at half-candor, and half-candor is exactly what vague answers buy you.
Where NexTier fits, briefly
Our answers on this live on the trust page, and they're the flat kind: journal entries are encrypted at rest, are never used to train models — ours or anyone's — and reach an AI provider only after pattern-based redaction plus a second sanitizing pass, only to generate your reflections, with every access audit-logged. We say it in posts like this one because saying it plainly is part of what makes the journal usable: the mechanism runs on your confidence that no one is reading over your shoulder — including, especially, a model. Write the true sentence. That's the whole practice. Everything else is infrastructure for it.
—
This post is part of a series on personal development organized around what we call Maslow's extended hierarchy — our synthesis of his later work. Sources: J. W. Pennebaker, "Writing About Emotional Experiences as a Therapeutic Process" (Psychological Science, 8(3), 1997); U.S. Federal Trade Commission, In the Matter of BetterHelp, Inc. (2023) — ftc.gov. This post is educational content, not legal advice.