HAYAAT
Private End-to-End-Encrypted AI Journal
エンドツーエンド暗号化された、プライベートなAI日記
Overview
概要Journaling apps want your data. A private journal should be the opposite — unreadable to everyone, including the server it lives on. Hayaat (Arabic for 'life') is an AI journal where every entry is encrypted in your browser before it ever leaves your device, then helped along by a language model that only ever sees the decrypted text in your own session.
日記アプリはあなたのデータを欲しがります。プライベートな日記はその逆であるべきで、保存先のサーバーを含め、誰にも読めないものでなければなりません。Hayaat(アラビア語で「人生」)はAI日記です。すべての記述は端末を離れる前にブラウザで暗号化され、言語モデルが目にするのは、自分のセッション内で復号されたテキストだけです。
I built Hayaat for myself — somewhere to think in prose that nobody else, not even the host, could ever read. The constraint came first: if I could not guarantee the privacy, I did not want to build it.
Hayaatは自分のために作りました。他の誰にも、ホスト側にさえも決して読まれない場所で、文章を書きながら考えたかったのです。制約が先にありました。プライバシーを保証できないなら、作りたくありませんでした。
How it was built
開発The hard part was marrying real cryptography with a genuinely useful AI. Entries are encrypted client-side with a key derived from your passphrase; the structuring and reflection features run on plaintext only transiently, in your session, and the database never holds anything but ciphertext.
難しかったのは、本物の暗号技術と本当に役立つAIを両立させることです。記述はパスフレーズから導出した鍵でブラウザ側で暗号化されます。整理と振り返りの機能は、自分のセッション内で一時的に平文を扱うだけで、データベースには暗号文以外は保存されません。
What it does
機能Entries are encrypted in the browser with AES-GCM-256 and a PBKDF2-derived key (300,000 iterations). Firestore only ever stores ciphertext — the server cannot read a word.
記述はブラウザでAES-GCM-256と、PBKDF2(30万回反復)で導出した鍵によって暗号化されます。Firestoreに保存されるのは暗号文だけで、サーバーは一語も読めません。
Claude turns freeform prose into a navigable timeline and surfaced reflections, so a stream of consciousness becomes something you can actually revisit.
Claudeが自由に書いた文章をたどりやすいタイムラインと振り返りに変えるため、思いつくままの文章が、後から本当に読み返せるものになります。
An AI coach reflects your own patterns back to you over time — gentle, grounded in what you actually wrote, never prescriptive.
AIコーチが、時間の経過とともに自分の傾向を映し返します。穏やかで、実際に書いた内容に基づき、決して押し付けません。
Single-user by design, gated behind authentication and an optional static-encryption layer. It is your space and only yours.
設計上の一人用で、認証と任意の追加暗号化レイヤーで保護されています。あなただけの場所です。
Under the hood
技術の詳細Encryption the server can't undoサーバーには解けない暗号化
Entries are encrypted in the browser with AES-GCM-256 and a key derived via PBKDF2 at 300,000 iterations. Firestore only ever holds ciphertext, so the backend is genuinely zero-knowledge — the host cannot read a single word, by construction rather than by policy.
記述はブラウザでAES-GCM-256と、PBKDF2(30万回反復)で導出した鍵によって暗号化されます。Firestoreに保存されるのは暗号文だけなので、バックエンドは文字どおりゼロ知識です。ホストが一語も読めないのは、運用方針ではなく仕組みによるものです。
AI on plaintext, only in-session平文のAI処理はセッション内のみ
The structuring and reflection features operate on decrypted text transiently, in your session, via callable Cloud Functions — Claude Haiku 4.5 for fast structuring and Sonnet 4.6 for deeper reflection. Nothing decrypted is ever persisted.
整理と振り返りの機能は、呼び出し可能なCloud Functions経由で、セッション内で一時的に復号されたテキストを扱います。高速な整理にはClaude Haiku 4.5、より深い振り返りにはSonnet 4.6を使います。復号された内容が保存されることはありません。
A privacy stance, not just an appアプリである以上に、プライバシーの姿勢
Most products in this space take the data. Hayaat is built to be unable to — proof that you can have an AI that helps you reflect without surrendering the most private thing you own.
この分野の多くのプロダクトはデータを取ります。Hayaatは取ることができないように作っています。最も個人的なものを差し出さずに、振り返りを助けてくれるAIを持てることを示しています。
Stack
技術構成Hayaat is a Vite + React + TypeScript app styled with Tailwind, on Firebase Auth, Firestore, Functions and Hosting. The AI layer uses Anthropic Claude — Haiku 4.5 for fast structuring and Sonnet 4.6 for deeper reflection — via callable Cloud Functions. Encryption is Web Crypto AES-GCM-256 with a PBKDF2 key derivation (300k iterations); entries are encrypted before persistence, so the backend is genuinely zero-knowledge.
HayaatはVite、React、TypeScript、Tailwindで構築し、Firebase Auth、Firestore、Functions、Hostingを使用しています。AIにはAnthropicのClaudeを使い、高速な整理にはHaiku 4.5、より深い振り返りにはSonnet 4.6を、呼び出し可能なCloud Functions経由で利用します。暗号化はWeb CryptoのAES-GCM-256とPBKDF2による鍵導出(30万回反復)で、記述は保存前に暗号化されるため、バックエンドは文字どおりゼロ知識です。
Where it is now
現状と今後Hayaat is deployed and owner-locked, with zero-knowledge encryption holding from day one. That hard constraint — the server can never read your entries — shapes what comes next: encrypted multi-device sync and a mobile shell, both designed to preserve the guarantee.
Hayaatは所有者専用として公開中で、ゼロ知識暗号化は初日から維持しています。サーバーが記述を決して読めないという厳格な制約が、今後の方向を決めます。暗号化されたままの複数端末間の同期と、モバイル版の外枠を、どちらもこの保証を守る形で設計しています。
Hayaat is a privacy stance as much as an app: proof that you can have an AI that helps you reflect without surrendering the most private thing you own. Most products would have taken the data. This one refuses to be able to.
Hayaatはアプリであると同時に、プライバシーに対する姿勢の表明です。最も個人的なものを差し出さずに、振り返りを助けてくれるAIを持てることを示しています。多くのプロダクトはデータを取ったでしょう。このアプリは、取ることすらできないように作っています。