Great question. One of the things we're trying to do is encrypt everything in a way that requires multiple hacks to actually decrypt the content. We're keeping the encrypted content on our databases, but using multiple private keys (one tied to the user, one stored in a separate vault). Journal employees cannot decrypt a user's data without unlocking a vault on our end, and our auth store.