Back to feed
Security February 7, 2026

"Privacy is Architecture, Not Policy"

"Why we technically cannot see your data. An explanation of Row-Level Security."

"Trust Us" is Not Enough

In 2026, a "Privacy Policy" is just a piece of paper. Companies promise not to look at your data, but their admins have root access to everything. At SparkyMinis, we don't ask you to trust our *intentions*. We ask you to trust our *architecture*.

The "Zero-Access" Standard

We designed our database so that we physically cannot see your private data.

1. Row-Level Security (RLS)

We use a database technology called RLS. Think of it like a hotel vault. * Traditional App: The "Receptionist" (App Server) has a master key to all rooms. * SparkyMinis: The "Receptionist" only checks your ID card. The *Vault Door* (Database) checks if `User ID == Owner ID`. If they don't match, the door simply doesn't open. * Even if a developer runs a query to "Show all invoices," the database returns 0 rows.

2. Client-Side Encryption

For your Secure Vault (Passports, Contracts), we go a step further. * Files are encrypted *before* they leave your device. * We host the "blob" of encrypted data. * We do not have the decryption key. Only your login session holds that key.

What This Means for Support

It means our Support Team is effectively "blind." * We cannot "login as you" to debug an issue. * We cannot recover a lost invoice if you delete it. * We cannot read your travel diary. It makes our support job harder. But it makes your data safer. We think that's a fair trade.
S
SparkyMinis Team Editor
Follow: