Encryption everywhere
All traffic between your browser and Bloodwise is encrypted with TLS, and your documents and results are encrypted at rest.
Row-level security
Every document, biomarker, and conversation is scoped to your account at the database level. Access rules are enforced by the database itself, not just application code.
Modern authentication
Sign in with Google, Facebook, or email and password, backed by Supabase Auth with secure session handling and password reset flows.
Opt-in sharing only
Nothing you upload is visible to anyone else by default. Family sharing is granular — you choose exactly which biomarkers or categories are shared, and you can revoke access at any time.
No training on your data
Documents are processed by AI providers through API services that are contractually prohibited from training models on your data. Your results are never sold or used for advertising.
Deletion that means it
Delete a document and its extracted data goes with it. Delete your account and your documents, results, conversations, and preferences are removed.
Responsible disclosure
If you believe you have found a security vulnerability in Bloodwise, please report it to security@bloodwise.app. We take every report seriously and will respond as quickly as we can. Please give us a reasonable opportunity to address the issue before any public disclosure.
Questions
For more detail on what data we collect and how it is used, read our privacy policy. Anything else, email security@bloodwise.app.