The resume button that doesn't show your words
Why the recovery cues for an unfinished journal entry show no content, and why the exit popup gives people a real way to discard and leave.
Duskglow now brings your writing back if your phone locks or the tab dies mid-entry. The hard part wasn't saving the draft. It was deciding how much of it to put back on the screen, and how honest to be about leaving.
The screen you see most is the wrong place for your words
The home screen is the one people glance at most, often in places I don't control. On a train, in a waiting room, with the phone face-up on a desk. It's also the screen the operating system grabs a snapshot of when you switch apps, the little card you see in the app switcher. So when I added a cue to pick up an unfinished entry, the easy version would have shown a preview of what you'd written. A line or two, so you'd remember where you were.
I didn't. The home cue shows that a draft exists and nothing about what's in it. "Resume tonight's reflection," not "resume: I've been feeling."
Let me be clear about what this is and isn't. Once you're signed in, your own session can already read your writing, so this isn't a security wall. Nobody's breaking anything by glancing at your phone. It's a different risk, the ordinary one of a private thing being visible over your shoulder or frozen into a screenshot the system took without asking. For a gratitude journal, where the whole point is writing things you might not say out loud, that ordinary risk is the one that counts. So the most-seen screen holds the least content. That fit what this app is supposed to be.
Showing the draft where it's already in the open
There's a second place the draft turns up, and there I made the opposite call. In the history view, where you read back through past entries, the in-progress draft sits at the top as a card you can tap to continue, and that one does show a preview.
The difference is context. History is already the reading surface. To show you your past entries at all, the app has already unlocked and decrypted them in that view. A draft preview there isn't exposing anything the screen around it isn't already showing. You came here to read your own writing. So the preview lives where reading already happens, and stays off the screen you pass through on your way to everything else. Same draft, opposite calls, because the two surfaces aren't the same.
An exit that doesn't trap you
The third piece is the moment you try to leave the writing screen with an unfinished entry on it. What happens then is a values question wearing a popup.
The dark-pattern version is well-worn. Make leaving feel like losing. Offer "keep writing" in bright colors and bury the way out. Or quietly hold the draft and never tell the person it's still there. Plenty of apps run a soft version of this, and it does move the numbers.
I went with three honest buttons. Keep the draft and leave. Discard it and leave. Or keep writing. The discard path is the one I want to point at, because it's the one a retention-tuned version drops. If someone wants their unfinished words gone, they get a clean, obvious way to make that happen, not a maze.
I did turn down one option that looked friendly: a "finish and save" button right there in the popup. It sounds helpful. The catch is that finishing an entry properly runs through a few more steps, including marking how the night felt, and a true finish from a popup would have meant shortcutting that flow. A button that says "finish" but doesn't really finish is a small lie. I'd rather the popup do less and mean exactly what it says.
Saying what's true, not what sounds safest
One last thing, and it's a single word choice. When you keep a draft and leave, the popup tells you "your draft is saved." Not "saved and encrypted." Not "private." Just the plain fact of what happened.
The stronger-sounding words would be making a promise in a place that doesn't need one. The rule I hold is that the copy says what's true and stops. Reassuring is not the same as accurate, and on anything that touches privacy I'd rather be accurate and quiet than warm and loose.
Mental models
Put the least content on the screen people see most. A recovery cue doesn't need to show the writing to do its job. On the surface most exposed to shoulders and app-switcher snapshots, show that something exists, not what it says.
Match the surface to what it already reveals. The same draft can earn a content preview in one place and none in another. Reading views already decrypt; pass-through screens don't have to.
Give people a real way out. An honest exit includes a clean discard, even though a retention-tuned design would hide it. Making leaving hard moves the numbers and quietly costs you the trust the product runs on.
Don't ship a control that lies. A button labeled "finish" should actually finish. If doing it right needs more flow than the moment allows, make the control do less and say less, rather than pretend.