optim8Back to home
Security & data protection

Your results concern only you

optim8 handles health data — the most sensitive category of personal data under EU law. Below is exactly, without vague claims, how it's protected and what you're entitled to do with your data at any time.

GDPR · EU Regulation 2016/679Art. 9 GDPR — special category dataStored and processed in the EU
12 guarantees

What actually protects your data

Every point below is a working mechanism in the system today, not a declaration.

01

EU-only storage

The database is physically hosted in a data center inside the EU. No byte of health data leaves EU jurisdiction without Standard Contractual Clauses in place.

02

Encryption at every step

AES-256 at rest, TLS 1.2+ in transit — the same standard banks use to protect transactions.

03

Explicit, revocable consent

Health data is only processed after explicit consent — not a pre-checked box. Email us to withdraw it at any time; we act on it without asking why.

Art. 9(2)(a) GDPR

04

Isolation at the database level

The rule "this account only sees its own data" is built into the database itself (Row Level Security) — not only checked by application code that could accidentally be bypassed.

05

Full deletion on request

On request, we delete all of your data, including uploaded lab files — not "archive", physically erase. Works at any time, not only when a program ends.

Art. 17 GDPR — right to erasure

06

Export your data anytime

A full, structured export of your labs, history and recommendations — on request, no need to wait for a program to finish.

Art. 20 GDPR — data portability

07

No hidden subprocessors

Every company that technically touches your data is named — full list below. None is ever added without being stated in the agreement.

08

AI never diagnoses

The model reads text out of an uploaded document — and nothing else. Diagnoses and recommendations come from a deterministic algorithm where every threshold cites a peer-reviewed source.

09

Minimal data, separate shelves

We collect only what's needed for the service. Prospective-client contacts are physically stored separately from health data, under their own separate consent.

10

Every access is logged

Any time an admin touches a client's data, it's recorded in a protected access log — not just the lab results themselves, but actions taken on them.

11

Your employer never sees your report

If a company pays for access, it only ever gets de-identified, aggregated group statistics — never one individual's results, diagnoses, or recommendations.

12

Right to stop processing

Email us to restrict or fully stop processing your data at any time — you keep the right to also request its export or deletion.

Art. 18 & 21 GDPR

Where AI fits in

Where AI is used — and where it isn't

Uses AI
  • Reading values out of an uploaded lab PDF or photo
  • Converting units of measurement to a single standard
Never uses AI
  • Making a diagnosis
  • Computing Health Score or biological age
  • Choosing clinical thresholds or recommendations

Nutrition, supplement, and fitness recommendations are generated by a deterministic algorithm, not an AI model — the same fixed set of rules applies to everyone, with no on-the-fly improvisation. But a rule without a basis is just an opinion, so every threshold behind a recommendation cites a specific, current source — not a vague "scientifically proven".

What recommendations are built on

Current medical and nutrition guidelines — not guesswork

Every marker group and recommendation traces back to recognized international sources — from peer-reviewed journals to clinical associations.

Medical evidence base

PubMedCochraneThe LancetNEJMJAMAWHO

Specialty clinical guidelines

KDIGO · kidneyEndocrine Society · hormonesACC / AHA / HFSA · heartIDSA / SHEA · infectionsNICECDC · DPDx

Nutrition

USDA FoodData CentralEFSA

Fitness & lab standards

NASMLOINC
Who else technically touches your data

Subprocessors

The full list — no company beyond this one ever gets access to your data.

CompanyRoleRegion
SupabaseDatabase and file storageEU
AnthropicDocument recognition (enterprise contract — data is never used to train models)Per DPA
VercelApplication hostingPer DPA
ResendEmail notificationsPer DPA
Your rights at a glance

Not a courtesy — the law

Every right below is a working feature, not a clause in a contract you'd have to email us about.

Access

See what we hold about you

Full view of your own data at any time, no request needed.

Export

Take your data with you

A structured export — your data belongs to you.

Delete

Erase everything, no trace

Full deletion, including files, within 30 days.

Question about your data?

Access, export, deletion, or restriction requests — answered by a person, not an autoresponder.

Email support@optim8.ai