Guarding the quiet things.
You ask us to hold your most honest writing. Holding it well is a technical responsibility, so here is exactly how the walls are built.
Encrypted in transit & at rest
Every connection uses HTTPS with TLS 1.3. Journal photos and file storage are encrypted at rest. Passwords are never stored in plain text — they are hashed with a modern password hashing function and salted per user.
Row-Level Security
Every table in the database carries a Row-Level Security policy. Even if a query is malformed, the database itself refuses to return a row that does not belong to the requesting account. Isolation is enforced in the datastore, not only in application code.
Least-privilege access
Engineers access production data only when strictly necessary, through audited, time-boxed credentials. Production data is never copied to a local machine or a personal device.
No ad network, no tracker
We ship no advertising SDK, no third-party analytics, and no cross-app tracking identifiers. This is not only a policy — it removes an entire category of breach surface that most consumer apps carry by default.
Found a hole?
If you have discovered a vulnerability in Little Buddha or this website, please tell us privately. We will acknowledge your report within 72 hours, keep you updated as we fix it, and credit you in our changelog if you would like to be credited.
We ask that you give us a reasonable window to ship a fix before publicly disclosing the issue, and that you do not access, modify, or exfiltrate any user data while testing. We will not pursue legal action against good-faith research that follows these terms.
security@littlebuddha.appNo system is unbreakable. If you discover something we have missed, we would much rather hear it from you than from someone else.