WinsSign in
Guides

Private by default

Why the notebook is private

When I started writing wins down I put them on a Twitter account that was not connected to my name. I was not building an audience. I needed somewhere to put the lines, and somewhere technically public gave me a small amount of accountability.

It worked for a while, and then it did the thing that audiences do.

Writing changes when somebody might read it

Nobody knew who that account belonged to, and it still crept in. Woke up is a true line and a bad post. Had lunch is a true line and a worse one. Without deciding to, I started reaching for the entries that read well, which is a different activity from noticing what happened.

That is the whole argument for private. A record kept for an audience becomes a performance of a life, and the performance is always slightly better than the life. Then on the day you most need to look back, what you find is the edited version.

So this one has no audience at all. Not a small one, not a private circle. There is no way to publish a win, no profile, no feed and nobody to see it.

What private means here, concretely

Vague privacy promises are easy to write and hard to check, so here is the specific shape of it.

  • There is no feed, no followers, no public profile, and no sharing feature. Nobody else using the app can reach your notebook.
  • Database rules restrict every row to the account that wrote it, so signing in with your email is what opens your archive.
  • Your wins are never put into page metadata, analytics or advertising.
  • Your writing is not used to train models, and it is not sold.
  • You can export the whole archive, and delete your account and everything in it, from Settings.

What we do store, and why

Your email, a username, your timezone and appearance preference, session data for signing in, and the wins you save. The win text is stored as plain text in our database, which is what lets the same archive open on your phone and your laptop.

That is the trade being made, and it is worth naming rather than glossing: syncing between devices and end-to-end encryption pull in opposite directions, and this product currently chooses syncing.

The part we do not claim

It is not end-to-end encrypted. Our hosting and database providers hold the data, and staff with database access could in principle read it. That sentence is on the privacy page too, in those words.

I would rather say it plainly than let private do work it cannot do. Private here means no audience, no feed, no advertising and no training — not that the text is mathematically out of everyone's reach.

If what you need to write requires that stronger guarantee, this is the wrong notebook for it today, and you should know that before you start rather than after.

Questions

Can anyone else see my wins?
No other user can. There is no feed, no followers, no profile and no sharing. Your archive is only reachable from your own signed-in account.
Is my writing end-to-end encrypted?
No. Win text is stored as plain text so it can sync between your devices, which means our hosting and database providers hold it and staff with database access could in principle read it. It is not hidden from us by cryptography.
Do you train models on what I write?
No. Your writing is not used to train models, not sold, and not shown to anyone.
Can I get my writing out, or delete it?
Both, from Settings. Export gives you the whole archive. Deleting the account removes your profile, your wins and your sign-in.
Why not just use a paper notebook?
If paper works for you, use paper. The reason this exists is the looking back: a year of paper is a shelf, and a year here is a timeline you can scroll to any date in.

More on this

The other guides