Private Journal App: 2FA, Sessions, and a Security Log You Can Read
Your most personal thoughts deserve real protection. Once two-factor is on, every sign-in asks for it. Here is what is built, and what is next.
Benefits
Every sign-in asks for the code
The password form, a Google or Apple sign-in, and a password reset all ask for it. Apps you have already connected keep their access until you stop them, and the codes page lists them so you can.
Backup codes you can keep
One-time codes for the day the phone is gone. They stay on screen long enough to write down, they copy in one press, and you can replace the whole set whenever you want.
A security log you can read
Sign-ins, exports and changes, each written as a plain sentence about what happened. The lines worth a second look are marked, and a refused attempt is in there too.
Delete is a request, not a switch
Asking to delete your account signs every device out and starts a wait. Your inbox gets one link that keeps the account, and nothing is gone until the wait is over.
Your data
Two-factor on every sign-in, every device listed, and a security log written in plain sentences
Your words are yours. You can take every one of them out at any time, you can see and end anything that has a way in, and once two-factor is on, every door asks for it.
An example
56 entries, 25 people, six months of writing.
- Files one per entry
- Format Markdown with YAML front matter
One ZIP: a Markdown file per entry with its date, feelings and themes in the front matter, drafts in their own folder, your people and reflections as JSON, and any photos or recordings. It asks for your password first and writes a line in the security log. Obsidian opens the folder as a vault.
What you can do
- Turn on two-factor, and then every door asks
- Scan the code with any authenticator app. After that the password form, a Google or Apple sign in, the verification link and a password reset all ask for the code. A reset link changes nothing on your account until the code passes, so someone reading your inbox cannot take it from you.
- Keep your backup codes
- One-time codes for the day the phone is gone. They stay on screen long enough to write down, they copy in one press, and you can replace the whole set whenever you want. Each one works once, and spending one writes a line in the log.
- Read the security log
- Every sign-in, export and change, written as a sentence about what happened rather than a code. The lines worth a second look are marked, and a refused attempt is in there too. It is where you go to check whether something was you.
- See where you are signed in, and sign out the rest
- Every device, with a Sign out beside each. Disconnect everything else also stops the Obsidian plugin and any assistant.
- Lock the app with your fingerprint or face
- On Android, the app asks for it every time you open it, and that is what lets Keep me signed in last on a phone. It runs on the phone itself, so it still asks with no signal, and it stays locked if anything goes wrong. Turning it off asks you to prove it is you. The iPhone app does not have this yet.
- Hear about it when it happens
- Turning two-factor off, replacing your backup codes and connecting an app each send you an email. If it was not you, the message is what reaches you while you can still act.
- Prove it is you before anything sensitive
- These ask for your password and your two-factor code: export your journal, connect an app, connect an AI assistant, change your email, change your password, set a password, replace your backup codes, turn off two-factor, and delete your account. If you sign in with Apple or Google, a recent sign in stands in for the password. Proving it once does not open a window for the next thing.
- Give your account a password, if it never had one
- An account made with Google or Apple has no password. You can add one in Settings, and then your email address opens it too, which is how you sign in on a browser. It asks you to sign in with Google or Apple again first, it does not take either button away, and we email you to say a new way in exists.
- Some changes ask for the password only
- You can turn on two-factor, and turn off the app lock, with the password alone. One adds a control and the other removes something that only lives on your phone, so neither hands your journal to anybody.
- Take a copy of everything
- Settings, then Your data, then Download your journal. Confirm it is you, and the ZIP streams.
- Change your email, and undo it
- The old address gets a link that puts it back, and the link does not last forever. Using it signs every device out, and for password accounts it changes the password too, so whoever made the change cannot simply repeat it.
- Delete your account
- Confirm it is you and type DELETE. Nothing is gone right away: every device is signed out, a wait starts, and the email carries the link that stops it. The export link sits above the form, on purpose.
- Decide what happens to voice recordings
- Keep the audio, or keep only the words.
How It Works
Sign up, then turn on two-factor
Email and password, or Apple and Google. Two-factor is one screen: scan the code with any authenticator app, then put the backup codes where you keep your passwords.
Every door asks after that
The password form, a Google or Apple sign-in, and a password reset all ask for the code. A reset link changes nothing on your account until the code passes, so someone reading your inbox cannot take the account from you. Wrong passwords and wrong codes run out of tries together.
Watch the doors
Every device with a sign-out beside it, and no location shown, on purpose. Signing out everywhere also stops the Obsidian plugin and any connected assistant.
Keep the exits yours
Downloading your journal asks you to confirm it is you every time, and a refused attempt is logged. Changing your email can be undone from the old address. Deleting the account waits, and one link in your inbox stops it.
Use Cases
Privacy is not a feature. It is the foundation of everything we build.
Privacy-first journaling
Entries go to the model that answers or reflects through a zero-retention route. Photos and recordings are stored in the EU with their location stripped, and a recording is kept only as long as you chose.
A protected diary
TLS in transit, a full-disk encrypted server, argon2 passwords, two-factor on every sign-in, sessions you can end, an app lock on Android, and a log of all of it that you can read.
Honest about AI
For Pensio to extract emotions and write reflections, its automated systems read your entries on our server. No human reads them, we never train on them, and a connected assistant is the one exception, under its own terms.
What is next
Passkeys are next, so a face or a fingerprint can stand in for the code. An app lock for iPhone is planned too. Codes by email are not coming, because whoever reads your inbox would read them too. Nothing has a date, and none of it is on this page as built until it is.