ZevsMaticZevsMatic
ZevsMaticPLUS
Apr 30, 2026

Q: Is user data truly private, or can the team access it internally or via third-party services?

Based on your security page, data is stored on Google Cloud (Firebase/Firestore) with AES-256 encryption at rest and TLS in transit. You also state you only access data with user permission or if legally required. However, I want clarification:

Since data is processed via Google Cloud, does this mean third-party providers have infrastructure-level access?
Do you offer end-to-end encryption, or can your team technically access readable user data?
Are internal access events logged and visible to users?
As you state you are not yet GDPR compliant, how should EU users interpret data protection guarantees?

I’m trying to understand the difference between “private by policy” vs “private by architecture” before storing sensitive data.

Founder Team
Arthur_ByDesign

Arthur_ByDesign

May 7, 2026

A: Hey, Arthur here, one of the cofounders of ByDesign. Great questions, happy to address them directly.

Third-party integrations (like calendar) have scoped, limited access only to what's needed for that feature. They don't have broad infrastructure access.

We don't offer full end-to-end encryption today. That's an honest tradeoff we've made because it would break collaboration features that are core to the app. Internal access to the database is tightly restricted and monitored.

On your "private by policy vs private by architecture" question: we're currently policy-based, not architecture-based. We don't sell or share your data, and we give you full data deletion on request. We're actively working toward stronger architectural privacy guarantees over time.

On GDPR: we're in active implementation. In the meantime, the core protections (no data selling, full deletion rights) are already in place.

More detail on our security page: https://www.bydesign.io/security

Happy to answer anything else!

Share
Helpful?
2
Log in to join the conversation

If you want me to place an order, I need feedback on this one?

Sorry for the delay! Please see response above :)

Thanks Arthur,
appreciate the honest answer.

My concern is that “policy-based privacy” still means the team could technically access readable user data, even if access is restricted and monitored.

For an app that may contain someone’s private life, professional plans, calendar, relationships, and sensitive notes, that feels like a meaningful risk. Until there is stronger architectural privacy!

Verified purchaser

Totally agree with ZevsMatic. Perhaps there could be an opt-in option or a choice in the future so we can choose it ourselves?
E.g.
1. Collaboration mode: normal privacy
2. Privacy-focused mode: E2EE, but with no collaboration features

For me, I don't care about collaboration and social on this app, I just want a place where I can store my info reliably + good task mgmt features for personal use

Exactly

Related questions
View product details