We have designed our system so that it shoudl be impossible for anyone
apart from the people you have explicitly shared your data with, to know
what you're doing, even if they gained access to our database.
This is called "end-to-end encryption", a process where your data is sent
and stored scrambled, with only specific keys able to unscramble it. You
are the only person with keys to unscramble your data. Even we don't have
a key.
Your name, activities, and invites are encrypted. Only you and people you
invite can see this information.
Email addresses are not encrypted. This is essential so
we can send notifications and verify accounts.
If somebody gained access to the database they could see that your email
address is registered and verified on offto. That you have created X
activities (but they can't see any meaningful data about the activities:
title, location, start/end times etc. are all encrypted). That you have Y
invites (but not from who, or to which activities), and Z people have
granted you access to their profile (but not who).