Data handling commitments
How we handle your data
1. What we do with your data
- Generate your personalised risk scores and supplement protocol.
- Show your daily check-in trends and lab results back to you.
- Let your nominated clinician review and approve your monthly program.
- Send you transactional email — welcome, password reset, and program-delivery messages — via Resend.
2. What we never do
- We never train AI models on your personal data. Anthropic and any other LLM provider receive your data for inference only — never for training. We have a Zero Data Retention agreement in place where the vendor offers one.
- We never sell, rent, or share your personal data with third parties other than the named processors listed below.
- We never share your data with employers without your explicit written consent. Even when you opt into a corporate plan, identifiable data does not flow to your employer — only de-identified, aggregated cohort signals.
3. Named third-party processors
We use the following processors to run the service. Each is bound by a written data-processing arrangement (DPA) and named here so you have full visibility:
| Vendor | Purpose | Region | DPA |
|---|---|---|---|
| Anthropic | LLM inference (Claude) | US | anthropic.com/legal/aup |
| Resend | Transactional email | US/EU | resend.com/legal/dpa |
| Stripe | Payment processing | US | stripe.com/au/legal/dpa |
| Supabase | Database, storage, authentication | AU (ap-southeast-2) | supabase.com/dpa |
| Vercel | Application hosting | Global | vercel.com/legal/dpa |
4. Your rights
You can download a complete export of everything we hold about you at any time from your Account page.
You can permanently erase your data at any time from your Account page. Your identifiers are removed; de-identified clinical observations may be retained per AHPRA records-keeping requirements.