Skip to content
Stories

Buyer's guide

Privacy-first web apps: a buyer's guide

Most apps that claim to be private are not. Here is how to tell the difference, what to look for in 2026, and which categories actually have honest options.

Devon ParkContributorTuesday, June 2, 20267 min read

Privacy is one of those words that has been used for so many different things by so many different companies that it has lost most of its useful meaning. Every app claims to take your privacy seriously. Almost none of them define what that means with the specificity that would let you check. The result is a market where the actually-private apps and the merely-marketing-themselves-as-private apps look identical from the outside, and the cost of confusing them is paid only by the people who picked the wrong one.

This guide is the version I wish I had had three years ago when I started taking these claims seriously. It is the set of questions I now ask, the words I have learned to look for and to ignore, and a small set of recommendations in the categories where the privacy-first option actually exists. It is not exhaustive. It is, I hope, useful.

What 'private' actually means

There is a useful spectrum here, and most marketing copy is engineered to keep you from noticing where on the spectrum the product actually sits.

Level one: 'We do not sell your data'

The weakest possible privacy claim, and the most common. It rules out one specific bad practice — direct sale of user data to third-party advertisers — while leaving every other possibility open. The company can still read your content, train models on it, share it with 'partners,' hand it to law enforcement on request, lose it in a breach, or change the policy in two years. This claim is not nothing, but it is not much.

Level two: 'Your data is encrypted at rest and in transit'

This is true of essentially every serious web app in 2026, because not doing it is malpractice. The encryption keys, however, are held by the company. The company can decrypt your data anytime they want or need to. The encryption protects against an outside attacker reading the database. It does not protect against the company itself, against a subpoena, or against a rogue insider with sufficient access.

When a company emphasizes this in marketing without saying anything stronger, the silence is the information. They have told you what they do. They have, by omission, told you what they do not do.

Level three: end-to-end encryption

Genuinely private, with caveats. The data is encrypted on your device before it leaves, the server stores only the ciphertext, and the company cannot read it without your key. Signal works this way. So does the well-implemented version of WhatsApp messages. So does Proton Mail. So does, importantly, Excalidraw's collaboration rooms.

The caveats: metadata is usually not end-to-end encrypted (the server knows who you are talking to, when, and how often, even if it does not know what about). The client itself is a piece of software the company controls and updates, so a compromised client can defeat the encryption invisibly. End-to-end is a strong property, but it is not a magical force field, and treating it as one is how people end up surprised.

Level four: local-first

The strongest privacy property an internet-connected app can offer, and the rarest. Your data lives on your device, syncs only through cryptographic channels you control, and the server (if there is one) holds only encrypted blobs or nothing at all. Obsidian's vault model is local-first. The local-first software movement, which has been gathering momentum since 2019 or so, is producing more of these every year.

Local-first has tradeoffs. The collaboration story is harder. The cross-device sync is harder. The 'just works on any laptop without a setup' experience is harder. These are real costs, and they are why local-first has not taken over yet. For data you care about, they are often costs worth paying.

The five questions that separate marketing from substance

When evaluating a privacy claim, these are the questions I have found most useful. Most companies will give you nonanswers to two or three of them. The companies that answer all five directly are usually the ones taking it seriously.

  1. 1Can the company read my content, in plaintext, if they wanted to? (If yes, the privacy claim is at best level two.)
  2. 2Do you train models on my content? (Default-on, default-off, or never.)
  3. 3Who has access internally? (A small named team, all engineers, or 'authorized personnel'?)
  4. 4What happens to my data if you receive a government request? (Do they fight it, comply silently, or notify me?)
  5. 5When I delete my account, what happens to the data? (Immediate purge, ninety-day retention, or 'we keep it in backups indefinitely'?)

Categories with honest options

Messaging

Signal is the obvious answer, and it is still correct in 2026. End-to-end encrypted by default, metadata-minimizing, open source, funded by a nonprofit that has no interest in monetizing your messages. The alternatives are increasingly marketing themselves with similar language. Signal is the one whose technical architecture actually holds up to inspection.

Email

Proton Mail and Tutanota are both reasonable end-to-end-encrypted options. The caveat is that email is fundamentally a federated, plain-text protocol — the moment you send to a Gmail user, the encryption ends at the boundary. Encrypted email is best understood as a way to make your half of the conversation private, not the conversation as a whole.

Notes and documents

This is the hardest category, because the popular tools (Notion, Google Docs, Apple Notes) all sit at level two — the company can read your data. For genuinely private notes, the choices in 2026 are: a local-first tool like Obsidian or Logseq, an end-to-end-encrypted hosted tool like Standard Notes or Cryptee, or a plaintext-file workflow with a sync tool you control. None of these are as smooth as Notion. All of them are dramatically more private.

Collaboration whiteboards

Excalidraw is the standout — the collaborative rooms are end-to-end encrypted, the open-source codebase is auditable, and the company has no business reason to read your boards. Most whiteboards in this category are at level two. Excalidraw is at level three, and it is not a marketing claim — the architecture is published and the implementation has been independently reviewed.

AI assistants

The hardest category in 2026, because the underlying model architecture inherently requires the company to process your input. There is no end-to-end-encrypted ChatGPT. The honest options here are: pick a provider that has committed to not training on your inputs by default (Anthropic and OpenAI both offer this for paid plans), and accept that the conversations are visible to the company at the time of processing. For genuinely sensitive content, the only safe answer is a model running locally on your own machine, which is now feasible for small models but still impractical for the largest ones.

The categories where there is no good option

It is worth naming, honestly, the categories where the privacy-first answer is currently 'do not use this kind of app':

  • Social media, with the partial exception of Mastodon and similar federated networks (whose privacy properties are interesting but mixed).
  • Search engines that retain query logs and personalize aggressively. (DuckDuckGo, Kagi, and a handful of others have made this category meaningfully better, but the dominant options remain bad.)
  • Any app where the value proposition is 'we analyze your data and give you insights.' The analysis cannot happen without the data being readable, by definition.

Words to be suspicious of

After enough years reading privacy policies, certain words have come to function as small warning signs. They do not always mean something bad is happening. They mean the company has chosen language that allows for something bad to be happening, which is enough.

  • 'Partners' — usually means third parties whose identities the company prefers not to enumerate.
  • 'Anonymized' or 'de-identified' — terms with weaker meanings than most readers assume. True anonymization is hard, and the techniques most companies use have been shown to be reversible in many real-world cases.
  • 'May share' — language that reserves a right without committing to exercise it, but also without committing not to.
  • 'We take your privacy seriously' — pure boilerplate, usually inversely correlated with the substance of the rest of the policy.
  • 'Industry-standard security' — true of almost everyone and meaningful as a claim from almost no one.

A small pragmatic note

Privacy purism is exhausting and usually counterproductive. The goal is not to use only end-to-end-encrypted, local-first software for every task. The goal is to know which level of privacy each tool you use is actually providing, and to put the genuinely sensitive content in the tools that are at level three or four, while accepting that the rest of your work probably lives at level two and that is fine, mostly.

The mistake people make in either direction is the same: a refusal to distinguish between levels, leading to either 'I trust nothing and use nothing' or 'I trust everything and use anything.' Neither is a workable position. The middle position — calibrated trust, with the calibration based on what each tool's architecture can actually deliver — is harder, slower, and considerably more useful.


We try to flag the apps in the catalog that have meaningful privacy properties beyond the table stakes — end-to-end encryption, local-first architecture, open-source implementation. The flag is not on every app, because the property is not on every app. It is on the ones where it has been verified, by the editorial team or by independent reviewers we trust. If you have a candidate we missed, send it in.

Tags

privacyencryptionguideevaluationsecurity

More from the catalog

Apps that come up in this story.

1

Excalidraw

Design

4.9·24K
Launch
2

Claude

AI

4.9·320K
Launch
3

Notion

Productivity

4.7·210K
Launch

Keep reading

More stories from dotstore.

See all