tellmewhy

A private place to talk about how you feel.

Talk it through with an AI that answers now — and, if you ever want one, a single trusted person who can read only what you choose to share. Your words are encrypted the moment they're stored, and no one reads your words unless you decide they should.

What stays private

Built so your words stay yours

  • Encrypted at rest, for you alone.

    Every message, conversation title, and folder name is encrypted with a key that belongs to you. Without it, nothing is readable — even with the database in hand.

  • Plaintext lives only in memory.

    Your words are decrypted only while the AI is composing a reply, then discarded. Once inference is done, only the ciphertext remains.

  • No-logging providers only.

    Every AI call denies data collection per request; the account's data policy must be set to exclude logging and training providers before anything real runs on it.

  • Nothing is shared by default.

    No one sees your conversations unless you choose to — one at a time, and revocable in an instant, to past and future messages alike.

  • Analytics that can't read anything.

    We count page views with our own self-hosted, cookieless analytics — paths and visits, kept on our own server, shared with no one. It sets no cookies and never sees a word you write.

  • Deletion means crypto-shredding.

    Delete your account from its settings and it happens at once — your key is destroyed, so nothing encrypted can ever be read again, by anyone, including us, and every row you own is purged. A linked therapist keeps the notes they wrote, plus a name-only marker that you left; those were always their record, not yours.

  • A forgotten password locks nothing away.

    Reset it by email and you're back in — your conversations are still there, still yours. The reset restores access, not a backdoor: your key is wrapped by our server, not your password, so it never decrypts a word, and it's no way for us to read them either. Recovery trusts your inbox, so keep that address yours.

This is not end-to-end encryption, and we won't claim it is. The AI has to read your words to reply, so plaintext briefly exists on our servers during inference. The encryption protects against database breaches and backup leaks — not against the processing that makes a reply possible.

Optional, and yours to end

A trusted person, if you want one

Some things are easier to face with someone in your corner. tellmewhy lets you invite one — entirely at your discretion, entirely revocable.

  • One person, only what you share.

    Link a therapist — or anyone you trust — to read only the conversations you hand them, one at a time. Revoke a share, or the whole link, and their access ends immediately.

  • Always in their own name.

    When your trusted person writes to you, it's labeled as them — never blurred into the AI. They can leave standing guidance that shapes how the AI responds in the conversations you've shared.

  • A plain record of what they did.

    A quiet audit trail logs every time they read, marked their place, wrote to you, or published a note — each with a timestamp — so you always know what happened, even when you weren't looking.

  • Mood and homework, opt-in by opt-in.

    Share a mood trend or an individual thought-record entry only if you choose to. Each is a separate, revocable decision — and your private notes never leave your view.

Questions

The honest answers

  • Is this end-to-end encrypted?

    No, and we won't pretend otherwise. Your messages are encrypted at rest with a key that's yours, so a database breach can't read them. But the AI has to read your words to reply, which means plaintext briefly exists in memory on our servers during inference. It's discarded the moment the reply is done, and only the encrypted version is ever stored. The encryption protects against database breaches and backup leaks — not against the processing that makes a reply possible.

  • Can my therapist read everything I write?

    No. Nothing is shared by default. You share one conversation at a time from its header, and you can revoke any share instantly — they lose access to past and future messages alike. A trusted person only ever sees the conversations you've actively chosen to share, plus whatever else you deliberately turn on, like a mood trend or a single thought-record entry.

  • Is this a crisis service?

    No. tellmewhy is not a medical device and not a substitute for professional care or emergency services. If it detects a crisis signal it surfaces hotline resources — 988 in the US, findahelpline.com internationally — and crisis-flagged messages are surfaced to your trusted person's attention queue, in the conversations you've chosen to share with them, the next time they look. It doesn't push an alert. In an emergency, please contact your local emergency services.

  • What happens to my data if there's a breach?

    Message bodies, conversation titles, and folder names are all encrypted at rest, so a breach exposes no content. It would reveal metadata — when conversations happened, which messages were flagged as crisis-level, and who is linked to whom — but never a single word of what was said.

  • How does deleting my account work?

    It's self-serve from your account settings — password plus a clear acknowledgment — and it happens in one stroke, with no waiting period: your encryption key is destroyed, so nothing encrypted can ever be read again by anyone, including us, and every row you own is purged. A few things survive by design: an audit line of ids and timestamps (no content, ever), and, if you'd linked a therapist, the notes they wrote about you plus a name-only marker that you left — those are encrypted with their key, not yours, and were always their record. One honest caveat — a database backup taken before the key is destroyed still holds the wrapped key, so it stays readable until it ages out of backup retention or the master key is rotated.

  • What if I forget my password?

    Reset it by email. You'll get a link and nothing else — no name, no message content, nothing an inbox thief learns beyond the fact that this address has an account here — then you set a new password and every other session is signed out. A reset restores your access without losing any data: your conversations are still there, still yours to read. The reset itself never decrypts a thing — your key is wrapped by our server, not your password, so recovery is an inbox check, not a backdoor. That means it's only as strong as your inbox: whoever controls your email can complete a reset, and we don't verify email at sign-up, so use an address you actually control.

  • Does the AI provider train on my conversations?

    Every AI call routes through OpenRouter with per-request data collection denied, and the account's data policy must be configured to exclude logging and training providers before anything real runs on it. Your conversations are used to write you a reply and nothing else.

Whenever you're ready, this space is yours.

Start talking