Security

How we protect your health data

Health records are the most sensitive data most people ever put online. These are the protections we have built and the commitments we make about them.

  • Every record is bound to your account

    Row-level security policies run on the server for every read and write. A signed-in user can only ever reach rows that carry their own account ID — there is no shared or global view of health records.

  • Encrypted in transit, stored on managed infrastructure

    All traffic runs over HTTPS. Credentials are hashed and sessions use short-lived tokens that are refreshed rather than stored in plain form.

  • Doctor links expire and can be revoked

    Sharing your dashboard creates a read-only token with an expiry date. The recipient cannot edit anything, and revoking the link kills access immediately.

  • You can delete everything

    The Danger Zone on your history page permanently wipes your health records, family tree entries and saved scores. Deletion is immediate and cannot be undone.

  • We do not sell or share your health data

    Your records are not sold, rented or handed to advertisers. Support staff do not browse individual records.

Reporting a problem

If you believe you have found a security issue, please report it through the contact details in our Privacy Policy rather than disclosing it publicly, so we can fix it first.

These statements describe the protections currently in place in the product. They are not a certification, audit outcome or guarantee against every possible incident. See our Terms of Service for the full legal position.

Know your risk, take action

Create a free account and get your first risk assessment in under ten minutes. No card required.