Founder's Note · By Blessing Platinum-Williams · 11 September 2026 · 6 mins

If I Can See Your Messages, They Can Too

I could have made Tonely smarter by keeping what you type. Here's why I didn't, and what recent headlines about cloud data requests confirmed for me.

One decision that has had conflicting responses has been my decision to make Tonely completely private and on-device. This decision wasn't made lightly. If Tonely stored the data, it would become smarter faster, plus I'd most likely be able to offer many other features that I'm currently unable to provide.

During an enterprise meeting, I was advised to store data to allow the user to have somewhat of a Spotify Wrapped, to help them see how they've progressed over time. My response? I considered this. In fact, I actually built it, then, before launch, removed it. Why? I feared who else might eventually request access to that information.

I wanted Tonely to support people in becoming more aware of the way they communicate. With the intentionality of Tonely, you must type and retype for Tonely to nudge you in the right direction. My users slowly but surely become better communicators on and offline, without being watched.

Do you know what was funny? The same person who advised me to store the data also asked me, rather sceptically, what my security and privacy measures were.

Nothing Leaves Your Device

Tonely doesn't have the same concerns as everyone else. A manager could ask me for your messages. A government could ask me for your messages. Someone could hack Tonely looking for them. It wouldn't matter, because the data doesn't exist. It's simply not there.

undefined

I had multiple reasons for this. One being that I wouldn't like someone spying on me, so I didn't want to spy on others. Two, I didn't want to have to cover the large expense usually associated with hoarding and protecting huge amounts of data. I just wanted to help people communicate. I didn't want to get myself into a debt hole that would be hard to escape.

And recently, I've been reminded why I made that decision.

Where Your Data Actually Goes

In 2025, the Scottish Police Authority was trying to establish the countries in which Microsoft could process data uploaded to Microsoft 365 by Police Scotland. Microsoft pointed to its general list of subprocessors, and subsequent correspondence reported by Computer Weekly showed that Microsoft declined to provide some information about its international data flows on the grounds of commercial confidentiality.

Think about that. An organisation handling incredibly sensitive policing information was having to ask its cloud provider where that information could actually go and be processed.

It gets even more interesting when you look at what happened in France. In 2025, Microsoft France was questioned by the French Senate and asked whether it could guarantee that French citizens' data, hosted in France, would never be transmitted to US authorities without French authorisation. It couldn't give that guarantee.

This wasn't necessarily a question of Microsoft's security being poor, because it isn't. It highlighted something completely different: where your data is physically stored and who may legally be able to request access to it are not necessarily the same question.

Microsoft's own transparency reporting makes this even less hypothetical. Between July and December 2025, Microsoft reported 190 law enforcement requests involving enterprise customers. It was compelled to provide responsive information in 94 cases and customer content was disclosed in 45. Three of those content disclosures related to non-US enterprise customers whose data was stored outside the United States.

Microsoft has safeguards around these requests and says it challenges requests where appropriate, but the point for me isn't that Microsoft did anything wrong. The point is that the information existed. Someone possessed it. Therefore, there was something that could potentially be requested.

The Netherlands Court of Audit found something else that caught my attention in 2025. It identified 1,588 cloud services being used across central government and found that, for 26% of them, ministries didn't even know whether they were using a public, private or hybrid cloud. Mandatory risk assessments also hadn't been completed for 67% of the important public cloud services it examined.

These are government departments with information security teams, lawyers, procurement teams and budgets far greater than mine. It reinforced something I already believed: the more data you collect and the more infrastructure you build around it, the more responsibility you create to understand where that data is, who can access it and how you are going to protect it.

The Questions I Didn't Want My Users Asking

If I was storing data, any employee of a company that adopts Tonely who is typing an emotionally charged message would rightfully have concerns. I would.

  • Is HR going to see this?
  • Can my manager see how often I've been flagged?
  • Is this going into my employee record?
  • Could this be used against me?

If Tonely stores employee communication data and gives an organisation access to it, a senior executive may legitimately have sufficient permissions to retrieve it. An investigation could result in someone requesting it. Legal could request it. HR could request it. Compliance could request it.

And suddenly, Tonely moves from communication awareness technology to employee monitoring technology.

People are always concerned about the hacker, and not the perfectly authorised person.

That person doesn't even have to have bad intentions. They might be doing their job. HR might be conducting an investigation. Legal might be responding to a legitimate request. Compliance might need to establish what happened. The problem is that once I decide to collect that information, I also have to accept that there may be circumstances where someone has a perfectly legitimate reason to ask me for it.

So Why Collect It At All?

There is a trade-off. I know Tonely could do more if I stored everything. I could give users beautiful yearly summaries. I could show organisations trends. I could train our models on an enormous stream of real-world communication. There are probably features I haven't even thought of yet that would become possible simply because I had all that data sitting there.

But every new reason I find to keep that data is potentially another reason someone else might find it valuable too.

I keep coming back to what Tonely is actually supposed to do. It is supposed to help you pause. It is supposed to make you aware that something you've written might not land the way you intended. Then it's supposed to let you decide what to do about it.

It doesn't need to remember what you said. And I don't need to know what you said.

That's the part I think we sometimes miss when talking about privacy. We talk about encryption, servers, permissions, retention policies and cybersecurity. All of those things matter when you have data to protect. But there's another question that should probably come before all of them: did you need to collect it in the first place?

For Tonely, my answer is no.

Maybe one day that decision will cost me a feature an enterprise customer really wants. Maybe it'll make parts of Tonely harder to build. It already has. I'm okay with that.

I would rather explain why Tonely can't show an employer everything their employees have been typing than have to explain to an employee why it can.

If I can't see your messages, neither can they.