Your body data is the most personal data there is
We built BodyClarityHub with privacy as a default, not an afterthought. Here is exactly how we protect your data — in plain language, without hand-waving.
Eight layers of protection
Security is not a single feature. It is a set of practices working together — from the database up to the user experience.
Row-Level Security
Every table in our database is protected by row-level security (RLS). This is enforced at the database level — not just in the app — meaning even a bug in our frontend cannot expose another user's data. Your queries can only ever return your own rows.
User Isolation
Your account is a sealed boundary. No other user — and no part of the application acting on their behalf — can read or write your data. There is no "see other users" feature, because the database itself prevents it.
Private Storage
Files you upload — progress photos, lab reports — are stored in private, access-controlled storage. They are not in a public bucket. No one can reach them without authenticated, authorized access tied to your account.
Signed URLs
When you view one of your own files, the system generates a short-lived signed URL that grants temporary access only to you, only for that file, only for a limited time. There are no permanent public links to your private data.
Data Export
Your data is yours. You can export everything you have ever logged — body metrics, nutrition, movement, sleep, biomarkers, and metadata — at any time, in a portable format. No support ticket required.
Data Deletion
You can delete your account and all associated data permanently. This is not a "deactivation" that keeps your data hidden — it is a real deletion that removes your information from our systems.
No Photo Sharing
BodyClarityHub has no social features. There is no feed, no friends list, no public profile, and no way to share, post, or expose your progress photos to anyone else. Your photos are visible only to you.
Encrypted in Transit and at Rest
All data is encrypted while traveling between your device and our servers (TLS) and while stored in our database. Your sensitive wellness information is never transmitted or stored in plaintext.
Row-level security, explained simply
Most apps protect data in the application code. That means a bug in the app can expose data it should not. We go further.
Our database enforces access rules on every single row. When your app asks for your weight history, the database checks that the request is coming from your authenticated account and only returns your rows.
This happens at the lowest level — before any application code runs. Even if a bug existed in our frontend, the database would still refuse to hand over another user's data.
Every policy is deny-by-default. Access is granted only when explicitly and verifiably allowed — never the other way around.
Your data rights
Export anytime
Download all your data in a portable format, whenever you want.
Delete permanently
Delete your account and all associated data — for real, not just hidden.
Never shared
No social features, no sharing, no public access to your photos or data.