MinDrop

Security at MinDrop

Last updated September 27, 2026

The short version. Your notes are encrypted on our servers with a key that belongs only to your account. It isn't end-to-end encryption: our servers can open your notes so that Mia, text and email capture, Kindle sync and syncing between your devices can work. Our staff tools can't see what you write. There are no ads and no trackers, we don't sell your data, and you can delete everything whenever you like.

Encryption

Your board is encrypted when we store it. That includes your notes, lists, the photos and files on them, and your meeting transcripts. Notebooks synced from your Kindle are encrypted the same way. We use AES-256-GCM, and every account has its own key.

Your key is never stored as-is. We keep it locked with a master key that only our app server holds, outside the database. A copy of the database on its own doesn't reveal anyone's notes.

To be plain about it: this is encryption at rest, not end-to-end encryption. With end-to-end encryption only your devices could read your notes, and MinDrop couldn't do much for you. Our server has to read your notes to answer Mia's questions about your board, file the texts and emails you send in, sync your Kindle, and bring your changes to your other devices. So while it's working, the app server can decrypt your notes. It does that only to run the features you use.

Everything between your devices and MinDrop travels over HTTPS, and our servers reach the database over an encrypted connection.

Who can see your notes

Our staff tools run as a separate service with their own restricted database login. They show account details like your email address, sign-up date, plan, usage counts and any feedback you send us. They can't read your board or your Kindle notebooks, and they don't have the key that would decrypt them.

Signing in to the staff tools takes a password and an authenticator code, and every staff action is written to a log that can't be edited.

Signing in

On your devices

In the iPhone and Android apps you can turn on an app lock. MinDrop then asks for Face ID, Touch ID, your fingerprint or your phone's passcode before it opens. The lock is set on each device separately and is never synced.

The apps keep a copy of your board on the device so it works offline.

Meetings

We keep the transcript of a meeting, never the audio. The recording streams through our server to transcription without being saved there, and the phone deletes its copy once the upload finishes. As soon as your transcript comes back, we delete the transcription service's copy of the audio and transcript. If a transcript is never collected, our server deletes that copy after 7 days.

Photos

Photos you add in the apps, and pictures you text to MinDrop, are saved without their location and camera data. Images attached to emails you send in are saved as they arrive.

What we don't do

Where it lives

Your account and your encrypted board are stored in the United States. The companies that help run MinDrop, what each one receives and where, are listed on our Privacy page. If you turn on AI features, the content they need is sent to the AI provider named there, which may process it outside the United States.

Deleting your account

You can delete your account in Settings, after confirming your password or an emailed code. That removes your account, board, files, Kindle notebooks, meeting transcripts, phone numbers, connections and your encryption key from our database right away. Backups age out on their normal schedule. The details are in Retention and deletion.

Report a security issue

If you think you've found a security problem in MinDrop, please email [email protected] with the subject “Security”. Tell us what you found and how to reproduce it, and please give us a chance to fix it before sharing it publicly. We'll reply and keep you posted.