Security

How Miday keeps your data safe, even from us.

The AI runs on your phone

This is the part most privacy policies can't claim. Miday's AI is a Gemma model that runs on your device — your writing is never sent anywhere to be processed, because there is nowhere to send it. We operate no inference servers and have no API keys to a company that does.

The trade-off is honest and worth stating: Miday needs a phone that can run the model, and a one-time download of about 1.3 GB. After that, everything — chat, transcription, understanding a photo you added — happens locally, and works with no connection at all.

Zero-Knowledge Architecture

Your notes, recordings and chats are encrypted on your device with a key only you have. If you turn on cloud backup, what reaches our servers is a blob of random-looking bytes.

Because we don't have the key, we cannot decrypt your data. That protects you from a breach on our side, and it protects you from us.

End-to-End Encryption (E2EE)

We use AES-256-GCM. Each vault has its own data key, wrapped by a vault key, which is in turn protected by your vault password and a 12-word recovery phrase. Changing your password re-wraps the vault key rather than re-encrypting your journal.

Recovery & Access

We don't store your password and cannot reset it. The 12-word recovery phrase (BIP39) generated at setup is the other way in, and it exists only on the device that made it.

This is why Miday requires a vault password before it will let you turn on cloud backup. A vault that opens only with a phrase written on one phone would produce a backup that no replacement phone could ever open — a backup that fails precisely when it is needed. We would rather block the purchase than sell that.

No account, by default

Miday does not ask who you are. There is no sign-up on first launch and no account behind any journaling feature. An account exists for exactly one purpose — finding your encrypted backup again on a new phone — and you only make one if you want that.