I think this might be a remnant of the time we did not delete media for graphs for cases we thought they might've just migrated to a new graph. For context, a semi-common pattern was for users to export their graph and restore to a new graph, so that they can change the name. Could you have gone through a similar process before deleting your account?
If you please contact support@roamresearch.com and provide the firebase links (even just a few should be okay to find the media), then we can proceed with the deletion for you. Sorry for the issue
I work at Roam on the engineering team.
I do not claim to know about this case, could you send me or support@roamresearch.com any more details you have re: this?
I can, however, tell you what the protocol has been since I've been working here at Roam (since 2021). No one can access user notes without an explicit written permission being granted. We have logs for when any graph is accessed via admins, and so, any member on the team accessing user notes without permission would be fired immediately. This was the operating policy and was made clear to me on my onboarding itself, along with the policy of immediate termination in the case of abuse.
Additionally, since Jan 2022, we have the ability for users to create End-to-end encrypted graphs. These graphs provide an extra level of protection - where your notes (& media) would be safe even in the worst case of Roam being hacked or compelled by law agencies to give info (to be clear, we haven't had either happen)
Roam actually DID NOT READ THEIR DATA (we have always had the policy of never accessing user data without explicit user permission). She just misunderstood what she was looking at.
More (verifiable) details in my comment here: https://news.ycombinator.com/item?id=44047945
I think I found your account and I don't see any access logs to your graph from anyone other than your account. If you can provide any more info or screenshots of we would be able to dig deeper into exactly what you saw. It could have been a console log or a hard coded employee email in the code.
We've always cared deeply about user's privacy and ownership over their notes. This is why we've had this policy from the start and focused heavily on local first features and data portability. We offer fully offline graphs, where the data never touches our server and is never able to be accessed by anyone on our team. We also offer fully encrypted graphs, which are stored on our servers but are not able to be read by anyone without the password (our team cannot read your data).
Emails: https://www.dropbox.com/scl/fi/s6ed1brrcvc0hncig7nm0/IMG_205...
https://www.dropbox.com/scl/fi/ohafavhr9nlqfedlbfxrd/IMG_206...
Roam actually DID NOT READ THEIR DATA (we have always had the policy of never accessing user data without explicit user permission). She just misunderstood what she was looking at.
More (verifiable) details in my comment here: https://news.ycombinator.com/item?id=44047945
But in the spirit of constructive criticism, your user had been carrying that belief for 5 years now because no one explained it when they originally reported the finding.
We followed up with our ex-employee to get the final (cutoff) message in this email thread https://firebasestorage.googleapis.com/v0/b/firescript-577a2...
In it he tries to explain that these are help graph transactions they are seeing. I do apologize if you didn't understand it at the time, but we did try to explain it to you. I Hope this clears up everything for anyone following along.
I understand what the screenshots are saying and this makes it clear that it was a misunderstanding and that NO ONE ACCESSED YOUR GRAPH(S). Please let me explain
Lets start with your first screenshot: https://www.dropbox.com/scl/fi/g9jv8eh1ugi5qda0c6azx/0811202...
If you take a look at this screenshot, it shows that the values you saw are in the indexeddb db "..._help-tx". The "help" bit denotes that those are the actions/txs taken in the "help" graph (which you can access via https://roamresearch.com/#/app/help). The reason you're seeing Bardia and Conor's emails there is because they wrote in the help graph (maybe they were writing guides there or adding stuff to the changelog). The reason the help graph data is in your indexedDB is because you probably opened the help graph at some point.
If someone had accessed your graphs, similar txs would have shown instead in the indexeddb dbs "..._DZ-tx" or "..._programming-with-categories-tx"
Everything I've said above can be verified if you say go to any Roam graph, and see what dbs are stored in IndexedDB in the devtools.
Hopefully this makes sense. Also, as Bardia replied in the email, we have never and will never edit user notes without explicit permission.
tl;dr: You thought you were looking at the logs for your graph but you were looking at the logs for the "help" graph. This is easily verifiable from your screenshots itself if you know where to look (details above).
Don’t do that. Things like this are an opportunity to overcommunicate. Explain in detail to the user, who’s smart enough to use the tools to reveal the information in the first place. Write up a FAQ entry explaining this for the next person so you can point them right to it. Don’t just reply to say basically “you didn’t actually see that” and leave it at that.
Yes, definitely a communication misstep on our part, and we could've handled it much better
I have a second comment there too, but got delayed in posting because HN rate-limited my account for too many comments
What is our fault that we did not clear up this misunderstanding immediately and I'm sorry for that dzink (I think this was during the time of Roam hypergrowth so maybe Bardia missed the later email reply?)
Hopefully, it is now clear that NO ONE accessed your graphs (and no graph is ever accessed without explicit user permission)
P.S. I took this video & wrote this message alongside my earlier one but could not post because HN said "You're posting too fast. Please slow down" XD. Hence the new account. Please do not block me because of this, mod
This can wait until tomorrow.
https://firebasestorage.googleapis.com/v0/b/firescript-577a2...
(looks like this will be my last reply in this thread)
Roam actually DID NOT READ THEIR DATA (we have always had the policy of never accessing user data without explicit user permission). She just misunderstood what she was looking at.
More (verifiable) details in my comment here: https://news.ycombinator.com/item?id=44047945
I've been an active user for a couple of years now and have substantial amount of information stored in Roam. I guess I should have known better than to have sensitive data stored in someone else's servers without encryption.
Time to explore Obsidian and see what the migration path looks like.
I want to clarify this (since you might not see the other replies in this thread)
Roam actually DID NOT READ THEIR DATA (we have always had the policy of never accessing user data without explicit user permission). She just misunderstood what she was looking at.
More (verifiable) details in my comment here: https://news.ycombinator.com/item?id=44047945
Have they clamped down on employee access? Was this "new employee" let go for accessing user data without any apparent reason?
Relevant reply here: https://news.ycombinator.com/item?id=44038085
Roam actually DID NOT READ THEIR DATA (we have always had the policy of never accessing user data without explicit user permission). She just misunderstood what she was looking at.
More (verifiable) details in my comment here: https://news.ycombinator.com/item?id=44047945