That is a great point.
As you can see, the site is fully HTTPS secured. The Stripe endpoint is also cryptographically secure.
Naturally the server has to deal with your entries in plaintext form to print the book, but everything is totally automated. No human will every see anything you print.
I use Firebase as a database. The database can't be read from or written to by ANYONE OR ANYTHING but our authenticated servers. (For Firebase users, there is a blanket {.read:false, .write:false} on all locations).
Thanks for voicing your concerns. I'll be sure to include this information somewhere on the site ASAP.
I've added an FAQ (journaljerk.com/faq.html) that addresses your point. Thanks for your comment.
Colin