What Gender Diary protects, and what it does not
This is the long answer. The short one would have to leave out the parts that matter if you are deciding whether to trust this with your journal.
Where your journal is
Your journal is stored on your device. There is no Gender Diary account, no server with a copy of it on, and nothing syncing in the background. An entry you write goes into storage on the device you wrote it on and stays there until you export it or delete it.
There is no server, so there is no server to be breached, subpoenaed or sold. What you are trusting instead is your own device and whoever else can reach it.
App lock
App lock is off until you turn it on, like every control in Gender Diary that hides something. Keeping a journal about your own life is an ordinary thing to do. Some people's circumstances make it dangerous anyway, and only you know whether that is yours.
What it does. App lock puts a PIN in front of the app, so somebody who picks up your unlocked phone cannot read your journal by opening it.
What it is not. It is not encryption of what is stored. It is a gate in the interface, and the interface is not the only way to reach a file. Four digits will stop a glance over your shoulder. It will not stop somebody with your device, time and a reason.
If you forget the PIN, there is one way back in: an action on the lock screen that wipes the local journal and starts you over. There is no recovery that keeps your entries, because a PIN that could be recovered would not be protecting anything. Wrong attempts wait longer and longer before the next one is accepted, and nothing wipes your journal automatically after a set number of tries. A counter like that is one bored kid or one argument away from destroying a diary nobody decided to destroy.
Encryption at rest
The journal is not encrypted where it is stored, yet. App lock limits access through the app. It is not encryption of the database, and somebody who can copy the files off your device can read what is in them. Encrypting the stored journal is being built, and this page will say so, name what it covers and name what it does not, once a test can show a copy of the closed files giving nothing up.
Archives
Export packs your journal into a single Archive file, encrypted with a password you choose, before the file goes anywhere. That password is not your PIN and not your Journal passphrase. It protects that one file.
What an Archive gives away. The first six bytes of the file spell GDIARY in plain text, followed by the format version and the settings used to turn your password into a key. That part has to be readable without the password, so that a file from a newer version can say so instead of decrypting into nonsense. Everything from your journal is behind the password. Somebody who finds the file learns that you have a Gender Diary Archive, and nothing about what is in it.
If you lose an Archive password, that file is not readable again. Other Archives made with other passwords are unaffected.
What the web host can see
Opening the app in a browser means asking a web host for it, and that host can see an IP address, roughly when the request happened, and that the app was fetched. Checking for a new version is the same kind of request. This is true of every website you open, and it is true of this one.
What the host does not receive is your journal. Entries, photos, notes and lab values are not sent to it, because there is nowhere for them to be sent.
You will not read "Gender Diary makes no network requests" here, because it is not true. Fetching the app is a network request. Your journal going somewhere is not.
What none of this protects against
If somebody already controls your device, none of this is what stands between them and your journal. An unlocked phone in somebody else's hands, an operating system that has been compromised, or the app sitting open in front of them are all outside what encryption at rest can do. Gender Diary does not claim otherwise. Be wary of anything that does.