Back to home

Security

Security & disclosure

Last updated 2 August 2026. Health logs are personal, so we keep the security model simple: your rows belong to you, and nothing else can read them.

Controls we have enabled

  • • Row-level database rules scope every meal, workout, metric and chat to its owner.
  • • No moderator, staff or admin screen reads your health logs.
  • • Traffic is served over HTTPS; data is encrypted in transit and at rest by our host.
  • • Whoop tokens and payment secrets live server-side only and are never sent to the browser.
  • • Sign-in supports email, Google and Apple; we never see your Google or Apple password.
  • • Third-party sharing happens only through anonymised views that strip identity by design.

These describe controls in place today. They are not a SOC 2, ISO 27001, HIPAA or PCI certification, and we don't claim one.

Report a vulnerability

Found a flaw? Email us with the steps to reproduce. We'll acknowledge within 3 working days and keep you updated until it's fixed.

security@myprivyhealth.com

Safe harbour

We won't pursue legal action against good-faith research that: uses only your own test account, stops at the first sign of access to someone else's data, avoids denial of service and spam, and gives us a reasonable window before going public. Please don't access, modify or download other people's health data.

If something goes wrong

If personal data is ever exposed, we will notify affected members by email without undue delay — and within 72 hours of becoming aware where the law requires it — telling you what happened, what data was involved, what we've done, and what you should do. We'll notify the relevant supervisory authorities and state attorneys general as required.