Your body's data
is not our
product.
It is yours - to hold, to leave with, to erase. This page names, in plain English, what is architecturally true today and what we are building next. No marketing softeners. No compliance we do not hold.
- I
You own it.
Every entry, upload, and reading stays yours. We take no ownership license over your data - not to train models, not to sell, not to sublicense.
- II
You can export it.
One click, full ZIP, machine-readable. Take your signals, journals, protocols, and history with you - no exit fees, no friction.
- III
You can erase it.
Irreversible deletion from Settings → Privacy. Primary stores wiped within 7 days of the grace period; encrypted backups rotated within 35.
- IV
You can audit it.
An append-only PHI access log records every internal read of your health data. You can request the log tied to your account.
- ·Encrypted at rest (AES-256) and in transit (TLS 1.2+).
- ·Row-level security in the database - no user can read another user's data, ever.
- ·AI training on your data is opt-in and off by default.
- ·HIPAA-readiness controls shipped: audit log, PHI redactor at the AI gateway, breach detection, auto-logoff, re-auth for sensitive ops, export, erasure.
- ·No sale to third parties. No ad networks. No data brokers.
We would rather name the gap than paper it over.
- ·We still hold the encryption keys. You are trusting us not to look.
- ·Data lives in our managed database, not in storage you control.
- ·Export is a ZIP snapshot, not a live portable identity.
- ·Exports are not yet signed by your wallet as cryptographic proof of ownership.
- in design
Wallet-signed export manifest
Every export ZIP includes a manifest signed by your connected wallet - cryptographic proof that the snapshot is yours and untampered.
- in design
Bring-your-own-storage
Pipe your data continuously to a storage bucket you control (S3, IPFS, or Arweave). We become a compute layer over your store, not its owner.
- researching
User-held encryption keys (end-to-end)
The most sensitive fields - blood work, journals - encrypted with a key derived from your wallet or passphrase, so even we cannot read them. Requires rebuilding AI flows around consent-scoped decryption.
Code can enforce controls. Only paperwork makes them legally binding. Business Associate Agreements with our infrastructure providers, a named Privacy Officer, and a signed Risk Analysis are in progress - we will not claim HIPAA compliance until each is in hand. Until then, we ship the technical safeguards and say so honestly.
Sovereignty is not a feature. It is the ground the platform stands on. If we ever break this posture, the Founder Pledge triggers a user-controlled export and open-sources the platform.