Privacy Policy
Last updated: April 6, 2026
1. Information We Collect
Account information: Name, email address, and password when you create an account, or identity information from Google if you use OAuth sign-in.
Health profile data: Age, sex, height, weight, health conditions, medications, allergies, supplements, exercise routine, diet, sleep patterns, lifestyle factors, and health goals — all voluntarily provided during onboarding and profile updates.
Biomarker data: Lab values you manually enter or upload via PDF. Uploaded documents are stored securely and processed by AI for value extraction.
Usage data: Protocol check-ins, adherence history, protocol generation timestamps, and feature interactions.
Payment information: Processed by Stripe. We do not store credit card numbers. We receive Stripe customer IDs and subscription status.
2. How We Use Your Information
We use your information to: provide and personalize the Service, generate AI protocols and recommendations, display biomarker trends and trajectory projections, process payments, and improve the platform. We do not use your health data for advertising or sell it to third parties.
3. AI Processing
Your profile and biomarker data is sent to Anthropic's Claude API for protocol generation, lab analysis, and supplement recommendations. Data sent to Claude is used solely for generating your response and is not stored by Anthropic for training purposes (per Anthropic's commercial API terms). We use Claude's commercial API, not the consumer product.
4. Data Storage and Security
All data is stored in Supabase (hosted on AWS) with row-level security (RLS) enabled. Only you can access your own data through authenticated API calls. Uploaded lab PDFs are stored in Supabase Storage with user-scoped access policies. Data is encrypted in transit (TLS) and at rest.
5. Data Sharing
We do not sell, rent, or share your personal health data with third parties. We share data only with: Supabase (data hosting), Anthropic (AI processing), Stripe (payment processing), and Vercel (application hosting). Each provider operates under their own privacy policies and data processing agreements.
6. Cookies and Analytics
We use essential cookies for authentication and session management. We do not currently use third-party analytics or tracking cookies. If we add analytics in the future, we will update this policy.
7. Your Rights
You have the right to: access your data (via your dashboard and future export feature), correct inaccurate data (via your profile page), delete your account and all associated data (by contacting support), and withdraw consent at any time by ceasing use of the Service.
8. Data Retention
We retain your data for as long as your account is active. If you delete your account, we delete all associated data within 30 days, except where retention is required by law.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify users of material changes via the Service or email.
10. Contact
Questions about privacy? Contact us at privacy@farshore.ai.