a voice journal loses something different than a text one
if a text journal app disappears with your phone, you lose sentences — a real loss, but a loss of something you could, in theory, try to reconstruct from memory. if a voice journal disappears, you lose the actual recording: the tone of your own voice on a specific night, the pause before you said the hard part, the sound of relief or exhaustion that a transcript never fully captures anyway.
that's not a reason to avoid voice journaling — it's a reason to take the backup question more seriously than you might for a text-only app, since what's actually at stake if you lose the file is bigger than words on a page.
local-first means the loss is real if it happens
archive keeps your journal on your device by default — no account, nothing synced anywhere unless you turn it on. the one exception is transcription: when you ask an entry to be transcribed, that audio is sent to a transcription service to do the work, then the result comes back to your device. that design choice — local storage by default, with backup and transcription as things you actively use rather than background syncing — is what makes phone loss a real risk rather than a hypothetical one.
this is the actual tradeoff of local-first storage, stated plainly rather than glossed over: maximum privacy and maximum vulnerability to a single point of failure are the same design decision, not two separate features. an app that's always backing up to its own servers by default is trading away some of that privacy specifically to remove that vulnerability — which is a legitimate choice for some people, and the reason archive offers backup as something you choose instead of assuming.
how the optional backup actually works
archive's backup, when you turn it on, copies your journal into a private, app-only folder inside your own google drive account. google does not see the contents of that folder — it's encrypted the same way any private drive folder is — and no one else can access it, including archive. it's your account, your folder, your copy, sitting in infrastructure you already trust with other things.
this is a meaningfully different arrangement than an app that backs up to its own company-run servers. with archive's approach, if the app disappeared entirely tomorrow, your backup would still be sitting in your own drive account, untouched — because it was never dependent on archive's own servers to begin with.
what backup does and doesn't protect you from
backup protects against losing, breaking or replacing your phone. it does not protect against forgetting your google account password with no recovery method set up, or against deliberately deleting the backup folder yourself. it's worth treating a journal backup with the same seriousness as any other backup — check occasionally that it's actually running, and make sure your google account itself has real account-recovery options set.
it also doesn't make your journal any less private by default — turning on backup is additive, not a switch that changes how the rest of the app handles your data. transcription still only touches audio you specifically ask to transcribe; the mood suggestions still stay local to the entry; nothing about backup changes any other privacy behavior in the app.
how this compares to a cloud-native journal
an app that syncs to its own servers by default (day one is the clearest example — full end-to-end encrypted cloud sync across every device, as a core feature, not an option) solves the phone-loss problem completely and automatically. you never have to think about backup, because there's no local-only state to lose in the first place.
that convenience has a real cost: your journal exists, encrypted or not, on a company's infrastructure by default, and staying private depends on trusting that company's encryption, policies and continued existence. archive's approach inverts that tradeoff — your journal stays on your device by default, storage and backup are decisions you make rather than defaults you inherit, and the only thing that routinely leaves your device is the audio for an entry you specifically ask to transcribe.
neither arrangement is strictly better. a cloud-first app removes a decision you might forget to make; a local-first app removes a dependency you might not want. which one fits depends entirely on which risk — losing a phone, or trusting a server — actually worries you more.
deciding whether to turn it on
if losing your phone tomorrow and losing your entire journal with it would genuinely bother you, turn backup on — it costs you nothing except trusting your own google account, which you likely already do for photos, email or other things that matter. if you'd rather keep the journal strictly local no matter what, and you're comfortable with the real risk that implies, that's also a legitimate choice, and archive doesn't make it for you either way.
the only wrong version of this decision is not making it at all — assuming a backup exists because it feels like it should, without ever having turned it on. check the setting once, decide deliberately, and then the rest of the tradeoff is exactly what you chose it to be.
