Trust

    Where your data lives, who touches it, and how to reach us.

    This page is maintained by Myelina Health to answer the security and privacy questions we hear most. It describes app-visible controls and our current practices — not an independent certification.

    Data residency

    Your account, check-ins, reflections, and AI conversation history are stored in the United States (AWS us-east-1) on our managed Postgres backend. Backups stay in the same region.

    Subprocessors

    These are the third parties that touch your data so the product can work:

    • Supabase — managed Postgres, auth, and edge functions (us-east-1).
    • Lovable — application hosting and delivery.
    • Emailit — outbound email (account, care-team share, and transactional notifications).
    • Model providers used by Myelina — prompts and responses are sent under contracts that forbid retention for training. We send the minimum context required to answer.

    Retention & deletion

    You can delete your account from Settings. Deletion purges every related row — profile, check-ins, reflections, medications, wearable imports, AI conversations, buddy links, email logs, subscription records — within minutes, not days. Backups age out on a 30-day rolling window.

    What we never do

    • We never sell your data.
    • We never share identifiable data with insurers, employers, or advertisers.
    • We never use your check-ins to train public AI models.
    • We never track you across other sites with our cookies.

    Reporting a vulnerability

    Email security@myelina.health or read our security.txt. We respond within 48 hours and credit responsible disclosure in our changelog.

    Compliance posture

    Myelina Health is a wellness tool, not a medical device, and is not a HIPAA-covered entity. Our architecture aligns with GDPR (EU/UK) and CCPA (California) principles: data minimization, purpose limitation, row-level access control, and user-initiated deletion. For the full picture of encryption and row-level security, see Security & privacy.

    General contact

    For anything non-security, email hello@myelina.health.

    Public KPIs

    Updated quarterly. Last review: Q3 2026.

    0
    user rows sold or shared with advertisers
    Ever. See Trust.
    0
    medical claims made by the product
    Wellness tool, not a device.
    48h
    security-report response SLA
    security@myelina.health
    60d
    minimum data before we call a pattern real
    With 95% confidence bands.
    <1min
    typical account-deletion propagation
    Every table, purged.
    us-east-1
    single data residency region
    AWS. No cross-region shuffling.