Almost every app tells you that your data is yours. Then it locks that data inside a database only the app can read, hides export behind a paid tier, or treats export as an afterthought that quietly drops your formatting and your photos. Ownership that ends the moment you try to leave is not ownership. It is a nicer word for renting. This page is about what it actually means to own your journal, why most apps fail the test, and what real ownership looks like when someone builds for it on purpose.
✦
A journal is the one kind of data where this matters most. It is not a spreadsheet you can rebuild or a playlist you can recreate. It is years of your own writing, the record of your people and the moments that made a life. You cannot regenerate it if it gets stranded. So the question is not whether an app is nice today. It is whether your words are still yours in twenty years, on your terms, no matter what happens to the company that made the app.
What "own your data" is supposed to mean
Ownership of anything real comes down to a few plain powers. You can hold it. You can copy it. You can read it without asking permission. You can take it somewhere else and it still works. Apply that to a journal and the test becomes simple.
- You can hold it. Your writing lives as files on your own device, not only on a server you are borrowing.
- You can read it. The format is open and documented, so any tool, and any future version of you, can make sense of it without the original app.
- You can copy it. Backing up your entire journal is as easy as copying a folder.
- You can leave. Export is free, complete, and always available, and it keeps your formatting and your media intact.
- You never had to ask. No account, no login, no permission needed to reach your own words.
If an app can honestly say yes to all five, you own your data. If it cannot, you are a tenant, and the landlord sets the terms.
Why most apps fail the test
The failures are rarely loud. They are small design choices that add up to a locked door.
- The proprietary database. Your entries sit in a format only that one app understands. Technically the file is on your machine, but you cannot open it, read it, or move it without the app that wrote it. That is possession without access.
- Export as a hostage. The feature exists, but it is buried, rate limited, or fenced off behind an upgrade. An escape hatch you have to pay to unlock is not really an escape hatch.
- Lossy export. You do get your data out, and it arrives as a flat text dump with the formatting stripped, the links broken, and the photos missing. Your writing survives. Your journal does not.
- The account requirement. Your journal lives behind a login on someone else's server. If the company folds, changes its terms, or decides your plan no longer qualifies, your access to your own writing can change overnight.
None of this requires bad intent. It is just what happens when export is the last feature built instead of the first principle. The result is the same either way: a life archive you do not fully control.
What real ownership looks like in Ember
Ember is built the other way around. Ownership was the starting point, not a feature bolted on at the end.
Your writing lives as an open, documented JSON archive on your own Mac. Not a locked database, not a format known only to me. You can open it in any code editor, search it with the same terminal tools you would use on any other file, and read it with your own eyes. If you want to understand exactly how it is structured, it is public: you can read the archive format reference and see every field for yourself.
Because it is just files, backing up your whole journal is copying a folder. Because there is no account, nothing stands between you and your words. Because the format is documented and open, it will still be readable long after any single app, or any single company, is gone. Export is not a paid escape hatch here. The export, in a real sense, already happened the moment you typed, because the readable file is the journal.
Getting in is just as open as getting out. Import from Day One and Apple Journal is free, so bringing years of existing writing into Ember does not cost you anything. Doors that open both ways are the whole point.
Ownership means you decide, including about AI
Here is where true ownership does something most privacy promises cannot. Ember has no AI reading your entries, ever. But because you genuinely own an open, documented archive, you are not stuck with that as your only option. You can take your own JSON and feed it to ChatGPT, Claude, or any AI you choose, on your own terms, when you decide it is worth it.
That is the real difference. In most apps, AI is something done to your writing by default, quietly, whether or not you asked. When you own the open format, the choice moves back to you. You decide if a machine ever reads your journal, which machine, and for what. Ownership is not just about keeping your data safe. It is about who holds the decisions, and the answer should always be you. If you want the fuller picture of what stays private and what never leaves your Mac, that is the story in yours to keep.
A journal you can actually keep
The core of Ember is free forever, and that includes export, because export is not a premium favor. It is what ownership means. Ember Plus is there if you want private sync through your own iCloud account and the full theme catalogue, but your data, and your right to take it anywhere, was never the thing being sold.
That is the whole idea behind Ember, the life archive app: a quiet, native journal for macOS where your words live as open files you hold, read, back up, and carry anywhere, for as long as you want to keep them. The app is a way in. It was never meant to be a way of holding your life hostage.
Ready to start writing?
Ember is a private life archive for your Mac. Local-first, no lock-in, no AI, no noise.
Try the Beta