Yes. Sensitive fields are encrypted at rest using AES-256-GCM before being written to the database. Each user's data is encrypted with a unique per-user key derived via HKDF-SHA256 from the master key and your account ID — meaning your entries cannot be decrypted by anyone else's key, including other users or Tend staff. Data is also encrypted in transit via HTTPS/TLS.
Fields encrypted at rest include:
- Journal entries (title, body, AI reflection)
- Chat messages
- Mood notes
- CBT worksheets (situation, thoughts, reframe)
- Coping cards
- Gratitude entries
- Sleep notes
- Work reflections
- Diet log entries
- Safety plan content
- Partner question answers
- Relationship goal titles and descriptions
- Planner event titles and descriptions
- Mental health issue names and descriptions
- Mental health score log notes and triggers
- Occasion titles and notes
- Gift list item names
- AI personal context (your background, goals, substance history, partner name)
- Cycle log notes
- Illness log notes