Through Their Eyes

Data & Security

Reflections are personal. So is how we protect them.

You're trusting us with words that people you love shared about you. Here's what we do to earn that.

Secure authentication

Sign-in uses established, industry-standard authentication with hashed passwords and support for trusted OAuth providers. Sessions are protected with signed tokens and automatic expiry.

Encryption

  • In transit: everything moves over HTTPS.
  • At rest: data is stored on managed infrastructure with disk-level encryption.

Secure storage

Your data lives on managed cloud infrastructure. Access to it is scoped by row-level security policies — meaning even our own systems can only reach the data they're explicitly allowed to reach. Anonymous responses stay anonymous even to us.

Account deletion

You can delete individual reflections at any time. You can also delete your account — which removes your profile and everything tied to it. Residual backup copies naturally expire within a short retention window.

Data export

A downloadable export of your reflections and Reflection Letters is on the way in a future chapter. In the meantime, write to us and we'll prepare one for you personally.

Privacy protections built in

  • Reflection Letters never reveal a respondent's email — only the names people chose to share.
  • Response counts stay hidden from your circle so no one feels compared.
  • Invitations use signed, expiring links.
  • We keep audit logs of privileged actions.

Responsible disclosure

If you find a security issue, please get in touch before sharing it publicly. We'll acknowledge quickly, work with you in good faith, and credit you where you'd like.