Security & Privacy
Your health data is yours
We built BetterHealthMap with privacy and security at the foundation. Here's how we protect your data.
How We Protect Your Data
Security built into every layer
From the database to the browser, we apply defense-in-depth principles to keep your information safe.
Row-Level Security (RLS)
Every database table is protected by Supabase Row-Level Security policies. These policies ensure that users can only read and write their own data — never anyone else's.
Strict User Isolation
Your health data is isolated to your account. Database queries are scoped to your user ID at the policy level, so even if a request is malformed, the database enforces the boundary.
Private File Storage
Uploaded documents (lab reports, health records) are stored in private buckets. Files are never publicly accessible by default.
Signed URLs
Access to private files is granted through time-limited signed URLs that are generated server-side and tied to your authenticated session.
Server-Side Authorization
Sensitive operations — like admin actions, subscription changes, and data exports — are authorized on the server, not in the browser. The client never has elevated privileges.
Secure Authentication
Authentication is handled through Supabase Auth with secure session management. Passwords are hashed, and sessions are validated server-side.
Input Validation
All user input is validated on the server before it reaches the database. This prevents malformed data and common injection attacks.
Upload Validation
File uploads are checked for allowed types and size limits. We do not execute or render uploaded files — they are stored as binary data only.
Audit Logging
Administrative actions are logged for accountability. Audit logs track who did what and when, supporting security reviews and incident response.
Role-Based Admin Access
Admin features are gated by server-side role checks. Only authorized admin accounts can access administrative tools, dashboards, and user management.
Service-role secrets never reach your browser
Administrative and service-level credentials are kept strictly on the server. The browser only ever receives an authenticated user session — never service-role keys or elevated credentials. This ensures that even a compromised client cannot bypass database-level security policies.
Your Data, Your Control
Export or delete your data anytime
You are always in control of your information. We never sell your data to third parties.
Export your data
Download a copy of your assessment results, health map, goals, habits, and tracked metrics at any time from your privacy settings.
Delete your account
Permanently delete your account and all associated data at any time. This action is irreversible and removes your information from our systems.