Security & Privacy

Your body data is the most personal data there is

We built BodyClarityHub with privacy as a default, not an afterthought. Here is exactly how we protect your data — in plain language, without hand-waving.

How We Protect You

Eight layers of protection

Security is not a single feature. It is a set of practices working together — from the database up to the user experience.

Row-Level Security

Every table in our database is protected by row-level security (RLS). This is enforced at the database level — not just in the app — meaning even a bug in our frontend cannot expose another user's data. Your queries can only ever return your own rows.

User Isolation

Your account is a sealed boundary. No other user — and no part of the application acting on their behalf — can read or write your data. There is no "see other users" feature, because the database itself prevents it.

Private Storage

Files you upload — progress photos, lab reports — are stored in private, access-controlled storage. They are not in a public bucket. No one can reach them without authenticated, authorized access tied to your account.

Signed URLs

When you view one of your own files, the system generates a short-lived signed URL that grants temporary access only to you, only for that file, only for a limited time. There are no permanent public links to your private data.

Data Export

Your data is yours. You can export everything you have ever logged — body metrics, nutrition, movement, sleep, biomarkers, and metadata — at any time, in a portable format. No support ticket required.

Data Deletion

You can delete your account and all associated data permanently. This is not a "deactivation" that keeps your data hidden — it is a real deletion that removes your information from our systems.

No Photo Sharing

BodyClarityHub has no social features. There is no feed, no friends list, no public profile, and no way to share, post, or expose your progress photos to anyone else. Your photos are visible only to you.

Encrypted in Transit and at Rest

All data is encrypted while traveling between your device and our servers (TLS) and while stored in our database. Your sensitive wellness information is never transmitted or stored in plaintext.

Under the Hood

Row-level security, explained simply

Most apps protect data in the application code. That means a bug in the app can expose data it should not. We go further.

Our database enforces access rules on every single row. When your app asks for your weight history, the database checks that the request is coming from your authenticated account and only returns your rows.

This happens at the lowest level — before any application code runs. Even if a bug existed in our frontend, the database would still refuse to hand over another user's data.

Every policy is deny-by-default. Access is granted only when explicitly and verifiably allowed — never the other way around.

Your data rights

Export anytime

Download all your data in a portable format, whenever you want.

Delete permanently

Delete your account and all associated data — for real, not just hidden.

Never shared

No social features, no sharing, no public access to your photos or data.

Track your body without sacrificing your privacy

Your data is protected at the database level, isolated to your account, and always under your control.