In plain terms: your phone number and the contact details tenants leave for you are scrambled before they are saved, so they cannot be read straight out of our database. Your password is stored in a form that even we cannot turn back into your password. Your ID documents are not on the public internet. The specifics, if you want them:
- Phones, WhatsApp, alt phone, and tenant lead PII are encrypted at the column level using Fernet with a key we never log.
- We also keep a one-way HMAC-SHA256 lookup hash of phone numbers so operators can find a record without us decrypting the live data.
- Passwords are argon2id-hashed. We can never see or recover your password. We only verify it.
- Verification documents live in a private object-storage bucket gated by short-lived signed URLs. Public listing photos live in a separate public-read bucket with EXIF stripped.