Walk into a therapist's office and disclose something you've never told anyone, and that disclosure is protected before you've even finished the sentence — by licensing law, by professional ethics boards, by decades of legal precedent about what confidentiality means and what breaks it. Open a journaling app and write the same disclosure, and the protection you get is whatever's written in a privacy policy the company drafted itself, updates unilaterally, and enforces against no one but itself.

People often write more honestly in a private journal than they do in therapy — there's no one in the room, no reaction to manage, no session clock. The content is, in a real sense, at least as sensitive. The legal protection around it is nowhere close.

What professional confidentiality actually guarantees

Therapist-client confidentiality isn't just an office policy — it's backed by structures most consumer software has no equivalent of:

What a privacy policy actually guarantees

Confidentiality (therapist)Privacy policy (typical app)
Backed by law and licensingA contract the company can amend with notice
Survives change of employerMay not survive acquisition or bankruptcy — data is often a transferable asset
Violation risks the professional's licenseViolation risks a support ticket, a lawsuit if you can prove damages, or nothing at all
Legal privilege can limit compelled disclosureCompany must comply with valid subpoenas — no privilege attaches to app data

A privacy policy is the company grading its own homework. Confidentiality law is someone else grading it, with real consequences for failing.

The honest gap, and the two ways to close it

I'm not arguing journaling apps should be regulated like licensed therapy — that's a different conversation with real trade-offs of its own. But if the legal backing isn't there, something else has to substitute for it, or the sensitivity of the content and the strength of its protection are simply mismatched. There are really only two credible substitutes:

  1. Trust a specific company's word — read their privacy policy carefully, trust their current leadership's intent, and hope it doesn't change under acquisition, funding pressure, or a subpoena.
  2. Remove the need for trust entirely — build the app so there's no server-side copy of your journal for a future owner, a breach, or a court order to reach in the first place.

MirrorNotes is built around the second option, not because the first is dishonest, but because it's fragile in a way that doesn't match what people write in a journal. Entries live on your device. The AI that reads them runs locally. Sync goes through your own iCloud, not a database I hold. There's no acquisition scenario, no leadership change, no subpoena that reaches a journal that was never on my servers to begin with.

That's a narrower guarantee than "your therapist is legally bound to protect you" — it doesn't cover advice, doesn't cover crisis support, isn't a replacement for care from an actual clinician. But for the specific question of "who can read what I wrote," it closes the gap that a privacy policy alone leaves open.

MirrorNotes

Private AI journaling for iPhone. Your entries are never held anywhere but your own device.