InnerSight - A journal designed so even I, the founder, can't read it.

by
Most journaling apps ask you to trust them with your most private thoughts. InnerSight is built so you don't have to. Every entry is encrypted on your device with a key only you hold; even I, as the founder, can't read what you write. No forced sign-up. No ads. No selling your data. Ever. A private place to think before you're ready to say it out loud. Free on iOS, live today.

Add a comment

Replies

Best
Maker
📌
Hey Product Hunt 👋 I'm Yasir. I've spent the last year building InnerSight on evenings and weekends alongside my full-time engineering job. This launch has been a long time coming, and I wanted to share the why honestly rather than the marketing version. The inspiration. I built InnerSight because I needed it. A few years ago, I was quietly going through a hard period: job worries, financial pressure, and, honestly, the accumulated weight of things I'd never told anyone. Like a lot of men, I'd grown up with the unspoken rule: keep it together, sort it out yourself, don't put any of it on anyone else. The thing that started to shift it for me wasn't therapy at first. It was journaling. Just getting the words out of my head and onto a screen. It helped more than I expected. When the worries were sitting in front of me instead of bouncing around inside me, they started to look smaller. More defined. I could see what was actually causing me pain instead of just feeling the shape of it. The problem I was trying to solve. But every notes app I used synced my most private thoughts to a cloud I didn't control. The stuff I was writing, things I'd never said out loud, was just sitting there. Backed up, searchable, one careless screenshot away from being seen by someone else. I realised: if I was going to write down things I'd never told anyone, I needed a place I could actually trust. Not "we have good security practices" trust. Mathematically trust. How it evolved. So I made one early decision that shaped everything downstream: I, the founder, should not be able to read user entries. Ever. Not if I wanted to. Not if I were compelled to. Every entry is encrypted on your device with AES-256, using a key derived from a passphrase only you know (Argon2id key derivation). My servers only ever see ciphertext. The database has no path to your data. I don't have a backdoor. That's not marketing, the math genuinely doesn't allow it. The hardest decision fell out of this: if the key only exists in your head, forgotten passphrases can't be recovered. Any recovery path would be a backdoor for phishers, subpoenas, and any future me with worse intentions. So I chose no recovery, and built a user-held recovery-code ritual at signup instead. Iris, the optional AI companion, is the thorniest part of the design. It needs to see plaintext to be useful, so I've made it fully opt-in, no content is ever sent unless you explicitly send it. I'm working toward on-device inference to close that gap. I'd rather be transparent about the trade-off than pretend it's magically private. Where it's for. I built this for the people who are carrying things they don't say out loud. The ones who've trained themselves not to. Who keep it together at work, keep it together at home, and then lie awake with all of it pressing on their chest. If that's you, I hope this gives you somewhere honest to put it. Genuinely happy to answer any questions in the thread , about the architecture, the decisions, the mental health angle, or what it's like building a privacy-first consumer product as a solo founder. And I'd genuinely love to hear from you if any part of this resonates. Thanks for being here 🙏