Language
← All articles Mood Tracking

Your Data Belongs to You: What Locally Stored Mental Health Data Means

Why mental health data deserves special protection, what really happens with cloud apps, and how local storage solves the problem at its root

7 min read

The most sensitive data you have

Think for a moment about what goes into a mood journal. When you felt bad and why. Your fears, your sleeplessness, your relationship, maybe hints of a diagnosis or medication. These are not shopping preferences, this is the most intimate thing anyone can know about a person.

The law treats such data as special, too. Under the General Data Protection Regulation that applies across the EU and UK, health data counts among the "special categories of personal data" and enjoys the highest level of protection, and in the US health-privacy rules such as HIPAA point in the same direction. The only question is: who actually sticks to this, and what really happens when your mood ends up in a provider's cloud?

What happens with cloud mental health apps

Most mental health apps store your data on their servers. It is sold as convenience, "synced across all your devices", and technically it is. But it means your inner emotional life sits on someone else's computers.

What a 2019 study found

29 / 36Apps sent data to Facebook or Google

But only 12 of the 28 apps that sent data to Google disclosed it (for Facebook sharing, only 6 of 12). The study examined top apps for depression and smoking cessation.

Huckvale, Torous & Larsen, JAMA Network Open 2019

How big the problem is was shown by a widely noted study. Kit Huckvale, John Torous and Mark Larsen analyzed 36 top apps for depression and smoking cessation and published their findings in JAMA Network Open. 29 of the 36 apps transmitted data to Facebook or Google services, but only 12 of the 28 apps that sent data to Google disclosed it (for Facebook sharing, only 6 of 12). So anyone who trusts the terms of service often does not know where their most sensitive data flows.

The independent series *Privacy Not Included by the Mozilla Foundation also reached a sobering conclusion: a large share of the mental health apps reviewed did poorly on privacy.


Four risks that all share one prerequisite

What can happen with cloud storage

Sharing with third parties

Data flows to advertising and analytics networks, often buried deep in the terms of service.

Data breaches

Any server can be hacked. What is not stored cannot leak.

Change of ownership

If the company is sold, your data changes hands with the owner.

Government access

Depending on the country, servers are subject to different access rights.

None of these risks is scaremongering. All of them require the data to reach a server in the first place.

The difference: local means it never leaves your device

Here is the decisive point. Local storage means your entries live solely on your device. There is no provider server they land on. No account, no login, no transmission.

This does not solve the problem with a promise, but with architecture. A provider that never receives your data cannot share it, cannot lose it, cannot sell it and cannot hand it over. The safest server is the one that does not exist. This is exactly the principle behind private, offline-capable mood tracking.

It is also why such a model can work without a subscription and without an account: whoever runs no servers and monetizes no data does not need you as a monthly-paying data source. More on this in mood tracker without a subscription.

What about optional Apple services

"Local" does not mean "magically sealed off", and that deserves an honest account. If you use optional features like Apple Health or iCloud backup, these exchange data with Apple, not with the app provider. That is an important difference: you stay within the device ecosystem you already trust, instead of additionally handing your data to a third provider. How Apple handles health data is described by Apple in its privacy overview. And it remains your decision whether to enable these bridges at all.

With version 6, InnerPulse adds another bridge: the optional Device sync, which keeps iPhone and iPad in step. It is off by default. If you turn it on, the app encrypts every record on the device (AES-GCM, 256-bit key) before it goes to your private iCloud database. Your iCloud Keychain holds the key, and Apple encrypts it end to end even without Advanced Data Protection (Apple's iCloud data security overview). Apple does not see what you write, only when and how many encrypted data packets are stored. This, too, needs no server of the app provider and no account.

Three questions to vet any app

Quick check for any mental health app

1

Do I need an account?

If yes, your data probably sits on a server. If no, that points to local storage.

2

How does the app make money?

Free plus no clear business model often means: you or your data are the product. A fair one-time price is usually more honest.

3

What does the privacy policy say?

Look for "sharing", "third parties" and "advertising". If it talks about passing data on, you know enough.

Why this matters especially for mental health

With much data you can argue about the risk. With mental health data you cannot. A leaked piece of information about a depressive phase, an anxiety disorder or a therapy can have real consequences, at work, with insurers, in your social circle. That risk is not carried by the provider, but by you.

That is why data sovereignty here is not a technical gimmick, but part of caring for yourself. An app that records your inner life should treat it so it can never catch up with you again. How InnerPulse implements this is in the chapter Privacy & Security, and how you can export or delete your data at any time is explained in Data Management.

The core in one sentence

With every mental health app, ask yourself one thing: where is my data when I close the app? If it is only on your device, you have control. If it is on someone else's server, you only have a promise. For the most sensitive data you own, architecture is worth more than any promise. Your data belongs to you, and that should be technically true, not just an advertising slogan.

This article is not a substitute for legal advice. It helps you make an informed decision about your own data.

Further reading

You might also like

Mood Tracking

Recognising Patterns in Your Mood

Mood data alone says little. Here's how to learn to read patterns, triggers and correlations in your journal - and …

Mood Tracking

InnerPulse 2.0: Capture factors faster

InnerPulse 2.0 makes capturing factors faster: create new factors straight from the search, three new default factors, …

Mood Tracking

InnerPulse 3.0: New Insights, Themes and Health

InnerPulse 3.0: a new Insights tab with Year in Pixels, four themes, Apple Health, weather as a factor, PDF export and …