Your journal outlives us.
A journal you cannot get back is not private. It is trapped. So the answer to "what happens to my words if Innerholm goes away" does not ask you to believe anything about us. It gives you the exit, today, and keeps it open.
Export everything, any time, free, on every account. The format is plain Markdown, one file per entry, and it is published in full so no software of ours is needed to read it. On-device journals never touched our servers, so nothing that happens to us reaches them. If we ever had to close, you would hear in advance, in writing, with the export open the whole time.
The exit is built in
Every Innerholm account can export everything it holds, whenever it likes, in two shapes: a ZIP of one Markdown file per entry, foldered by journal, with a few lines of front matter and your images alongside, or a Day One-compatible ZIP. Both are free. Both are on every tier. Neither has ever been a paid feature, and neither will be.
The Markdown shape is documented at innerholm.com/export-format: file names, front matter, body, images, ordering, and what is deliberately left out. That page is written so that a stranger holding a ZIP and no Innerholm account can make sense of it. It is the part of this promise you can check.
On-device journals never depended on us
An on-device journal lives in your browser's protected storage and, where the browser allows it, in a file you chose the location of. It is written and read on your device. It does not sync, and it never reaches our servers. If Innerholm's servers went dark tonight, an on-device journal would open tomorrow morning exactly as it did today, and it can be exported to the same Markdown ZIP from inside the app, on your machine.
The same is true in a narrower way of an encrypted journal: its words are sealed on your device before they leave it, and the export that unseals them runs on your device too. What we hold is ciphertext we cannot read, and what you hold is the key.
What we would do
- Tell you in advance, in writing To the address on your account, before anything changed, with the date and what it meant. Not a banner, not a blog post you had to find.
- Keep the export open the whole time Every account could export until the last day, free, in both shapes. Closing the door before the writers have left is the one thing a journal must never do.
- Leave the format documented The export format is already public and needs nothing of ours to read. It would stay public. A file you downloaded years ago reads the same in any text editor.
What we will not do
- Sell the archive Your journal is not an asset on our balance sheet. Nothing trains on what you write, and nobody buys it.
- Hold it hostage No "export is available on the paid plan." No thirty-day window that starts after the notice arrives. The exit is open now, and stays open.
- Change the answer if the name changes If Innerholm were ever acquired, the privacy policy binds whoever runs it, and this page would still be true: export everything, free, in the open format.
Built to run small and long
Innerholm is one person, no investors, no growth target that requires selling something later. It costs little to run and it is priced to keep running. That is the plan. But the plan is not the promise: the promise is the exit above, which holds whether the plan does or not. Nothing trains on what you write, every data-collection feature is off until you turn it on, and some journals never touch our servers at all.