Nisshi 日誌 ← Back to Nisshi
Privacy

We don't collect anything, because there is nowhere for it to go.

Nisshi has no company servers, no user accounts, and no analytics. Your journal lives on your device. If you want it on more than one device, you install the sync server yourself — on a machine you own.

Last updated 6 August 2026
0
Trackers, analytics SDKs, and advertising identifiers in the app.
0
Third parties with access to your entries, in any form.
0
Personal details asked for. There is no sign-up, ever.
01 — On device

Your entries stay on your phone.

Everything you write — logs, collections, locations you tag, attachments — is stored encrypted in the app's own storage on your device and on your Apple Watch. Nisshi does not upload it, index it, or send it anywhere for processing. The app works completely offline, and that is its normal state.

02 — Sync

Sync is optional, and the server is yours.

There is no Nisshi cloud to sign up for. If you want your journal on more than one device, you install Nisshi Sync Server on hardware you control. Your entries are encrypted on your device before they leave it, so the server holds only opaque ciphertext keyed by a random account id. It never receives your key and cannot read your content, titles, or history — and neither can we, because we never see any of it.

Your account id is derived on your device and tied to no real-world identity.
The server makes no outbound requests, so there is no third party to leak to.
Turn sync off and nothing leaves your phone at all.
03 — Location

Location is only ever what you attach.

Nisshi asks for your location only at the moment you tag an entry with a place, and it is stored with that entry like any other text you write. There is no background location tracking and no location history kept outside your entries.

04 — Leaving

You can take it all with you, or delete it.

Export the whole journal as a single Markdown file, or write an encrypted backup you restore with your recovery password. Deleting the app removes your data from the device; if you run a sync server, its vault is a single file you delete yourself. There is no account to close, and nothing of yours is retained anywhere else.

Questions about any of this?
Write to us, or read the sync server source — the code is public, so the claims on this page are checkable.
info@nisshi.app Sync server source