FAQ · Data and privacy
Passwords are stored as salted hashes, sessions are carried by a token that is validated server-side, and the connection is HTTPS end to end. Administrative views mask phone numbers and require a second password check before a record can be edited, so support staff cannot browse accounts at will.