Your Health Data is Sacred
Privacy isn't a featureโit's the foundation of everything we build. Here's exactly how we protect your information.
How We Protect Your Data
Zero PII Storage
We delete your original lab reports immediately after extracting biomarker data.
- โSource documents never touch our database
- โOnly numerical biomarker values are stored
- โNo names, addresses, or identifying information
- โProcessing happens in isolated, ephemeral containers
End-to-End Encryption
All data is encrypted in transit and at rest using industry-standard protocols.
- โTLS 1.3 for all data transmission
- โAES-256 encryption for data at rest
- โEncryption keys managed by AWS KMS
- โZero-knowledge architecture where possible
Secure Authentication
We use Google OAuth for authenticationโwe never see or store your password.
- โOAuth 2.0 with Google as identity provider
- โNo passwords stored on our servers
- โSession tokens with automatic expiration
- โMulti-device support with secure token management
Infrastructure Security
Built on enterprise-grade infrastructure with multiple layers of protection.
- โHosted on AWS with SOC 2 Type II compliance
- โAutomatic security patching and updates
- โDDoS protection and rate limiting
- โRegular third-party security audits
Data Minimization
We only collect the absolute minimum data required for the service to function.
- โNo tracking cookies or analytics scripts
- โNo third-party advertising integrations
- โMinimal logging with automatic purging
- โYou can export or delete all data anytime
Compliance
We adhere to international privacy regulations and industry best practices.
- โHIPAA-grade security standards
- โGDPR compliant data handling
- โCCPA compliant for California residents
- โRegular compliance audits and certifications
The Journey of Your Lab Report
Transparency is critical. Here's exactly what happens to your data, step by step.
Upload
Your PDF is transmitted over TLS 1.3 to an isolated processing container.
Process
AI extracts biomarker values, units, and reference ranges from the document.
Delete
The original PDF is permanently deleted. Only extracted data is shown to you for verification.
Store
After you confirm, only the numerical biomarker values are saved to your account.
Your Data, Your Rights
๐ Right to Access
Export your entire health history as JSON or CSV at any time. No waiting, no approval needed.
๐๏ธ Right to Delete
Delete your account and all associated data instantly from your settings page. Permanent and irreversible.
โ๏ธ Right to Correct
Edit any biomarker value at any time. You own your dataโyou control its accuracy.
๐ซ Right to Opt-Out
We don't sell your data. We don't share it with third parties. But if we ever did, you'd have full opt-out rights.
Third-Party Services We Use
We're transparent about the services we rely on to deliver Toowit.
Google OAuth (Authentication)
We use Google's authentication service to verify your identity. Google knows you use Toowit, but we never share health data with them.
Google Privacy Policy โSupabase (Database & Auth Infrastructure)
Our database is hosted on Supabase, a SOC 2 Type II compliant platform. All data is encrypted at rest.
Supabase Privacy Policy โAI Provider (Biomarker Extraction)
We use a third-party LLM service to extract biomarker data from PDFs. Your original documents are never stored by us or the LLM providerโonly the extracted numerical values are returned.
Note: We configure our LLM provider with strict no-data-retention policies.
Questions or Concerns?
If you have questions about our security practices, discovered a vulnerability, or want to report a privacy concern, please contact us immediately.
Contact Security TeamWe respond to security inquiries within 24 hours.