What "encrypted at rest" means on Robin
What encryption at rest is, what kinds of content it covers on Robin, why we do it, and what it does and does not protect against.
Encrypted at rest means Robin scrambles your sensitive content while it sits in storage. If someone somehow obtained a copy of Robin's database, your conversations would not be readable from it. On Robin, that protection covers the sensitive content you write and say: your messages, your call transcripts, the notes you write, the details you save about contacts, and what people write in your forms.
You will see the phrase on our transcripts page, in our privacy policy, and on the your data page. This page explains what it means in plain language, and what it does not protect against.
What "encrypted at rest" means
At rest means data that sits in storage, as opposed to data that moves over the network. Data in transit is protected separately, by the same HTTPS encryption every serious website uses. For your most sensitive content, Robin encrypts the data before it is stored. Only Robin's application can turn it back into something readable, and it does that solely to show your content to you and the people you shared it with.
What is covered
Here is the rule of thumb. The sensitive content you write and say on Robin gets this protection: your messages, your call transcripts, the notes you write, the details you save about your contacts, and what people write in your forms.
Your profile, availability, and session-type settings are information you have chosen to show other coaches on Robin anyway. They are protected by the platform-level safeguards everything gets.
Why we do it
Coaching conversations are confidential by profession. A message to your practice partner, or a transcript of a practice session, can mention real coaching clients, health, and work situations. These are things people said in confidence. Notes you write for yourself can hold the same material.
Robin's promise is that this content is for you and the people you shared it with, and never for us. Encryption at rest backs that promise with something stronger than policy.
The honest limits
This is not end-to-end encryption. Robin's application decrypts your data to show it to you. That is how your messages appear on screen and your transcripts open. End-to-end encryption, where even the service cannot read the data, does not fit the things Robin does at your request, such as show a transcript to both coaches who were on the call.
Encryption at rest protects against a database leak. It does not protect against an attack on Robin itself while it runs. That is a separate problem with its own safeguards, and one form of protection does not stand in for the other.
No encryption scheme removes the need to run the platform carefully. It narrows what can go wrong. It does not eliminate it.
The formal versions
The privacy policy carries the legally binding description of how Robin stores and protects your data. Who controls your data on Robin explains who is responsible for what.
Questions
Message Jon directly in the app. He reads every message and answers personally.