Security
How your memoir is protected
The privacy page says what we will and won’t do with your story. This one says how the software keeps that promise.
Your account
Sign-in is handled by a dedicated authentication service rather than by code we wrote ourselves - passwords are stored only as salted hashes, never in a form we or anybody else could read back. You can sign in with an email link instead of a password if you prefer, which for many older storytellers is both easier and safer.
Registration is protected against automated abuse by a bot check that does not ask you to identify traffic lights, or anything else.
Access control at the database, not just the app
The most common way personal data leaks is a bug in application code that forgets to check who is asking. We do not rely on that check being remembered. Every row of every memoir table carries the account it belongs to, and the database itself refuses to return rows belonging to anybody else - even if the application asks it to. A mistake in our code cannot hand your chapters to another member.
Your files
Photographs, documents, videos and recordings are held in private storage. They are not served from public addresses; each request produces a short-lived signed link that expires. There is no URL to your grandmother’s photograph that can be guessed, shared by accident, or found by a search engine.
Connections
The site is served over HTTPS only, and browsers are instructed to refuse an unencrypted connection to us for a year at a time. A content security policy restricts what the pages are permitted to load and where they may send data, which is what stops an injected script from quietly shipping your transcript somewhere. The site may not be embedded in a frame by another website, and the browser is told not to leak the page you came from.
Payments
Card details are entered on Stripe’s own hosted checkout and never pass through our servers or our database. We store the fact that you have a membership and when it renews - not your card.
Deletion
When an account ends, an automated job removes that member’s memoir tables and uploaded files. It is deliberately narrow: it can only touch memoir data, it refuses to run destructively without an explicit instruction, and by default it reports what it would delete rather than deleting anything. Safeguards of that kind exist because the most dangerous code in any system is the code that deletes things.
What we do not claim
We are not going to tell you that we are unhackable, because nobody honest says that. We hold no formal certification such as SOC 2 today. What we can tell you is what the controls above are, that they are in place now, and that we will keep this page accurate as they change.
Reporting a problem
If you believe you have found a security issue, please write to info@seniorcareres.com with enough detail to reproduce it. We will acknowledge you, fix it, and credit you if you would like to be credited. Please do not test against another member’s account or data.
Keep reading
Your story is already there. Rosie just helps you tell it.
Start with one conversation.
30-day free trial. No credit card to begin.