Skip to main content

Security & privacy

Privacy is structural, not promised.

We cannot read your vault because the encryption happens on your device. Not because we are virtuous. Because the mathematics makes it impossible.

Zero-knowledge
We store ciphertext only
Client-side
Keys never leave your device
End-to-end
Encrypted in browser before sync
No recovery
We cannot reset your master password

How the vault works

  1. Your device
  2. Master password
  3. PBKDF2 key derivation (100,000 iterations)
  4. AES-256-GCM encryption
  5. Ciphertext to server

Plaintext never touches our infrastructure. We store salt + ciphertext + IV only.

What we can and cannot see

  • We see: account email, authentication session, vault salt, cohort pacing, pseudonym, check-ins, daily actions, learning goals, experience level, weekly rhythm, mission completion, confidence ratings, board posts, chat messages, reel metadata, partner access keys, billing tier, and product analytics events.

  • We cannot see: vault file contents, competency baselines, practice drafts, master password, derived encryption keys, or full vault ciphertext blobs (unless you explicitly export them yourself).

AI processing

When you opt in, Datum sends only the fields named in that tool's consent notice to a managed AI API. Passwords, encryption keys, and unrelated vault files never leave your device.

Every AI turn shows a compact Receipt: what left the device, what stayed local, and that you decide before anything is saved as proof.

Data residency & infrastructure

Metadata and community data are stored in Supabase. Short-form videos are stored in Netlify Blobs with transport TLS. Titles, captions, and metadata live in Supabase.

Billing is handled by Stripe. We store only Stripe customer metadata. We do not handle or store payment card numbers.

Data export & deletion

  • Full account data export and account deletion are available from Account settings.

  • GDPR/CCPA-style access and deletion requests are also handled via hello@martori.studio.

Important: we cannot recover a lost master password. There is no backdoor. If you lose your master password, your vault contents are irretrievable. Please store it in a password manager.

Responsible disclosure

If you discover a security vulnerability, email hello@martori.studio with “Security” in the subject. We prioritize these and aim to acknowledge within 24 hours.

Read the full legal text

For the complete policy language, see our Privacy Policy and Terms of Service.