Dumper

Security

Last updated October 1, 2026.

Security by design

Dumper is local-first, and that is our first security decision: your tasks, notes, journals, habits and brain dumps live in the app's own database on your device. Data we can never see is data we cannot leak. The server only ever holds a copy of the content you choose to sync, on an account you choose to create.

In transit and at rest

  • Every request from the apps and the website travels over TLS (HTTPS). The HTTP endpoints accept no plaintext traffic.
  • Server-side data — account records, synced content, attachments — sits on managed storage operated by Cloudflare with at-rest encryption.
  • Attachment files are stored under keys derived from your account, inside private storage that is never publicly readable; they are served only to your authenticated sessions.

Accounts and sign-in

  • Sign-in is passwordless: a six-digit code is emailed to your verified address. Codes are single-use, expire within minutes, and requests are rate-limited per IP address.
  • Because no password exists, credential stuffing and password reuse cannot compromise your Dumper account. The keys to your account are your email account and your device.
  • Sessions are long random tokens stored server-side, so a session can be revoked; the website keeps its session cookie httpOnly and out of reach of scripts, and the apps send tokens only over TLS.

On our servers

  • Sync, attachments and AI requests are authenticated on every call and scoped to your account — one account's data is never readable or writable through another's session.
  • Premium features are gated server-side, not in the app, so entitlements cannot be forged by a client.
  • Sensitive endpoints send `Cache-Control: no-store`, so proxies and browsers do not cache account or sync responses.
  • Logging keeps the minimum needed to operate: no request or response bodies of your content in durable logs, and no analytics on your usage.
  • Secrets — API keys and signing material — live in Cloudflare's secret store, not in code or config files.

In the apps

  • The app asks for the minimum permissions it can: internet access for the features that need it, and notifications for the reminders you schedule — delivered locally, with no push infrastructure.
  • No third-party advertising, analytics or tracking SDKs are embedded.
  • AI composition is explicit: only text you deliberately send is forwarded to the model provider; nothing is read or uploaded in the background.

Payments

Premium bought through Google Play is billed by Google under its own security programme; we learn only that an active purchase exists. We never see or store your card details.

An honest limitation

No system is perfectly secure, and we will not pretend otherwise. What we can promise is that we collect as little as possible, expose as little as possible, and keep the attack surface small. Please do your part: keep your device and email account secure, because they are the keys to your Dumper data. If something looks wrong, tell us at hello@ibrahimturan.com and we will act on it.

Responsible disclosure

Found a vulnerability or a data-handling concern? Emailhello@ibrahimturan.comwith the details. We take reports seriously, respond quickly, and will not take action against good-faith research.

Related

What data we handle and how to delete it is described in thedata policy; the legal detail is in theprivacy policy.