All articles

What "encrypted at rest" means on Robin

What encryption at rest is, what kinds of content it covers on Robin, why we do it, and honestly, what it does and doesn't protect against.

Encrypted at rest means your sensitive content is scrambled while it sits in storage — so if someone somehow obtained a copy of Robin's database, your conversations wouldn't be readable from it. On Robin, that protection covers the sensitive content you write and say: your messages, your call transcripts, the notes you write, the details you save about contacts, and what people write in your forms.

You'll see the phrase on our transcripts page, in our privacy policy, and on the your data page. This page explains what it means in plain language — including what it does not protect against. We'd rather you understand the real protection than trust a vague reassurance.

What "encrypted at rest" means

At rest just means data sitting in storage — as opposed to data moving over the network (which is protected separately, by the same HTTPS encryption every serious website uses). For your most sensitive content, Robin encrypts the data before it's stored, and only Robin's application can turn it back into something readable — which it does solely to show your content to you and the people you shared it with.

What's covered

The rule of thumb: the sensitive content you write and say on Robin gets this protection — your messages, your call transcripts, the notes you write, the details you save about your contacts, and what people write in your forms.

Things like your profile, availability, and session-type settings are information you've chosen to show other coaches on Robin anyway — they're protected by the platform-level safeguards everything gets.

Why we do it

Coaching conversations are confidential by profession. A message to your practice partner or a transcript of a practice session can mention real coaching clients, health, work situations — things that were said in confidence. Notes you write for yourself can too.

Robin's promise is that this content is for you and the people you shared it with — never for us. Encrypting it at rest backs that promise with something stronger than policy.

What it is not — the honest limits

It is not end-to-end encryption. Robin's application decrypts your data in order to show it to you — that's how your messages appear on screen and your transcripts open. End-to-end encryption (where even the service can't read the data) isn't compatible with things Robin does at your request, like showing a transcript to both coaches who were on the call. What encryption at rest protects against is a database leak; it does not protect against Robin itself being compromised while running. That's a separate problem with its own safeguards — one form of protection doesn't stand in for the other.

No encryption scheme removes the need to run the platform carefully — it narrows what can go wrong, it doesn't eliminate it.

The formal versions

The privacy policy carries the legally binding description of how your data is stored and protected, and Who controls your data on Robin explains who is responsible for what.

Questions

Message Jon directly in the app — he reads every message and answers personally.

Still have questions? Get in touch and we'll help you out.