Chronicle  ·  Case Study Vol. I

Ibasho

Digital Sanctuary for Authentic Emotional Expression

居場所 — 'A place where one belongs' · Privacy-first journaling meets gentle connection

Role
Lead Designer & Developer
Duration
4 months
Industry
Digital Wellness
Status
Web App · PWA
Private
Privacy First
Consent
Based Connection
Gentle
Safe Interactions

Overview

A privacy-first digital sanctuary for authentic emotional expression. Ibasho (居場所 — "a place where one belongs") merges journaling with gentle connection, enabling users to process emotions safely while building meaningful consent-based relationships.

Challenge

Digital wellness platforms struggle with fundamental conflicts:

  • Privacy Paradox: Platforms monetize data while claiming privacy
  • Connection Anxiety: Social features breed comparison and validation-seeking
  • Emotional Safety: Users hesitate to be vulnerable in exposed environments
  • Consent Gaps: Data sharing is opaque and rarely truly consensual

Solution

Ibasho inverts platform incentives: journaling remains private by default, connection requires explicit consent, and the interface reflects emotional safety rather than engagement metrics.

Core Philosophy

Privacy is a feature, not a setting. Consent is active, not assumed. Emotional intelligence guides UX. Every decision prioritizes user agency over platform growth.

Core Features

🔒

End-to-End Encryption

All journals encrypted with user-held keys. Platform cannot read entries.

🤝

Consent-Based Sharing

Share specific entries with explicit, revocable permission tokens.

💭

Emotional Journaling

Prompts guide reflection without manipulating towards specific emotions.

🌱

Gentle Social

Asynchronous sharing, no feeds, no likes, no algorithmic ranking.

Tech Stack & Security

Frontend

  • Next.js 16
  • React 19
  • TweetNaCl.js (NaCl crypto)
  • TypeScript
  • Tailwind CSS

Encryption

  • libsodium.js for E2EE
  • XSalsa20-Poly1305
  • Curve25519 key exchange
  • Secure random generation

Backend

  • REST API
  • Minimal data retention
  • Audit logging
  • PostgreSQL

Privacy

  • Zero-knowledge architecture
  • GDPR compliant
  • No tracking
  • Data export on demand

Key Challenges Solved

Client-Side Encryption

Implement full E2EE with key derivation and secure storage

Zero server access to plaintext

Consent Tokens

Implement time-limited, revocable share tokens with granular permissions

Sharing without platform middleman

Emotional Safety UX

Remove engagement dark patterns, design for reflection not activation

Users report less anxiety after journaling

Privacy-First Monetization

Build sustainable model without surveillance data

User subscription, not ad-tech

Impact

100%
Journal privacy
Zero
Platform data sales
User
Held encryption keys

Key Insights

  • Privacy and wellness are inseparable
  • Dark patterns harm long-term user health
  • Consent-based design is both ethical and functional
  • Sustainable business models exist outside ad-tech