Your Health Data is Sacred
Privacy isn't a featureβit's the foundation of everything we build. Here's exactly how we protect your information.
How We Protect Your Data
Zero PII Storage
We delete your original lab reports immediately after extracting biomarker data.
- βSource documents never touch our database
- βOnly numerical biomarker values are stored
- βNo names, addresses, or identifying information
- βProcessing happens in isolated, ephemeral containers
End-to-End Encryption
All data is encrypted in transit and at rest using industry-standard protocols.
- βTLS 1.3 for all data transmission
- βAES-256 encryption for data at rest
- βEncryption keys managed by AWS KMS
- βZero-knowledge architecture where possible
Secure Authentication
We use Google OAuth for authenticationβwe never see or store your password.
- βOAuth 2.0 with Google as identity provider
- βNo passwords stored on our servers
- βSession tokens with automatic expiration
- βMulti-device support with secure token management
Infrastructure Security
Built on enterprise-grade infrastructure with multiple layers of protection.
- βHosted on AWS with SOC 2 Type II compliance
- βAutomatic security patching and updates
- βDDoS protection and rate limiting
- βRegular third-party security audits
Data Minimization
We only collect the absolute minimum data required for the service to function.
- βNo tracking cookies or analytics scripts
- βNo third-party advertising integrations
- βMinimal logging with automatic purging
- βYou can export or delete all data anytime
Compliance
We adhere to international privacy regulations and industry best practices.
- βHIPAA-grade security standards
- βGDPR compliant data handling
- βCCPA compliant for California residents
- βRegular compliance audits and certifications
The Journey of Your Lab Report
Transparency is critical. Here's exactly what happens to your data, step by step.
Upload
Your PDF is transmitted over TLS 1.3 to an isolated processing container.
Process
AI extracts biomarker values, units, and reference ranges from the document.
Delete
The original PDF is permanently deleted. Only extracted data is shown to you for verification.
Store
After you confirm, only the numerical biomarker values are saved to your account.
Your Data, Your Rights
π Right to Access
Export your entire health history as JSON or CSV at any time. No waiting, no approval needed.
ποΈ Right to Delete
Delete your account and all associated data instantly from your settings page. Permanent and irreversible.
βοΈ Right to Correct
Edit any biomarker value at any time. You own your dataβyou control its accuracy.
π« Right to Opt-Out
We don't sell your data. We don't share it with third parties. But if we ever did, you'd have full opt-out rights.
Third-Party Services We Use
We're transparent about the services we rely on to deliver Toowit.
Google OAuth (Authentication)
We use Google's authentication service to verify your identity. Google knows you use Toowit, but we never share health data with them.
Google Privacy Policy βSupabase (Database & Auth Infrastructure)
Our database is hosted on Supabase, a SOC 2 Type II compliant platform. All data is encrypted at rest.
Supabase Privacy Policy βAI Provider (Biomarker Extraction)
We use a third-party LLM service to extract biomarker data from PDFs. Your original documents are never stored by us or the LLM providerβonly the extracted numerical values are returned.
Note: We configure our LLM provider with strict no-data-retention policies.
Questions or Concerns?
If you have questions about our security practices, discovered a vulnerability, or want to report a privacy concern, please contact us immediately.
Contact Security TeamWe respond to security inquiries within 24 hours.