In His Steps

How your writing is kept private

Who can read your entries

Only you. Every entry is encrypted with a key that is locked by your passphrase. The server stores only the encrypted version, so whoever runs this site (or the hosting company) sees unreadable data. Signing in with Google only proves who you are; Google never sees your journal.

Because of this, nobody can reset your passphrase. If you forget it, your recovery key is the only way back in. Without either, the entries can't be recovered by anyone.

Why a passphrase as well as Google?

The two do different jobs. Google answers “who are you?” It lets the site know it's really you, so nobody else can get to your journal's front door. But everything Google shares at sign-in (your name, email and account number) is also known to the server. A lock made from those would have its key stored right next to it: anyone who ran the server, worked at the hosting company, or broke into it could open every journal.

Your passphrase answers “is this really your journal to open?” It's the one secret the server never keeps. Your entries are locked with a key that only your passphrase (or your recovery key) can unlock. So the stored journals, the server's backups, or a stolen copy of its disk are just unreadable scrambled data, and that includes to the person who runs this site.

In short: Google keeps strangers out; your passphrase keeps everyone out, including the people who run the site. A journal is only private if both are true.

To be fully transparent: while your journal is unlocked, the server uses your key to show you your entries and to ask Claude for reflections, and it forgets the key when the journal locks. Someone who took control of the server and secretly changed its code could, in principle, watch for passphrases as they're typed. The passphrase protects against everything short of that.

Unlocking with a passkey

Instead of typing your passphrase, you can unlock with a passkey: your fingerprint, face or device PIN (Settings → Security & Data → Passkeys). It keeps the same promise. When you add one, your device creates a secret that only that passkey can produce, and only after your fingerprint, face or PIN. Your journal's key is locked once more under that secret. The server stores only the locked copy, never the secret, so it can't unlock your journal with it any more than with your passphrase.

Your passphrase and recovery key keep working. Removing a passkey in Settings stops it unlocking your journal. Passkeys that sync (through Apple, Google or a password manager) work on your other devices too.

When something leaves the journal

No analytics, advertising or tracking scripts are used. The only cookies keep you signed in and remember that this browser has unlocked your journal.

What's counted

So whoever runs In His Steps can see how it's being used, the server keeps a few simple counts for each person: which days they opened their journal, how many entries they wrote each day, and how many reflections and writing prompts they asked for. These are shown with your email address, only to the person who runs the site. That's all: nothing you write, no titles, no times of day, and nothing about what you read or click.

Limits

To share one Claude account fairly, each person gets 3 reflections and 10 writing prompts a day. Entries are always saved, with or without a reflection.

Leaving

Use Settings → Export to keep a copy, then Settings → Wipe journal to delete your entries, including from the server's backup copies.

← Back to In His Steps · Sources