How We Protect Your Data

Your identity and your health story are kept apart — and only you bring them together

Most health platforms keep your name sitting next to your health record in one database. We built ours differently: who you are and your health story live in two separate encrypted stores, engineered so that neither one is useful without the other.

  Identity Vault

  • Your name
  • Your email
  • Your phone number
You are
the key

  Health Record

  • Your labs & scores
  • Your habits & goals
  • Your conversations

Two encrypted stores, held apart by design. Signing in with your passkey — typically your face or fingerprint — is what reunites them, for you.

Six ways your data is protected

Separation by design

Your contact identity is removed from the health database and sealed in its own vault. Someone looking at one store sees either a health story with no name on it, or a name with no health story — never both.

Your face is the key

You sign in with a passkey — Face ID or your device's biometrics — a phishing-resistant standard that never sends a password anywhere. Authenticating as you is what links your identity to your health record for the length of your session.

A separate key for every member

Each member's identity vault is sealed with its own AES-256 encryption key, and that key is itself locked by a hardware-backed master key in a dedicated key-management service. Reading the database alone reveals nothing.

Every access leaves a record

Identity data cannot be read silently. Every single access — who asked, why, and when — is written to an append-only audit log before the data is unsealed. No log entry, no access.

Corwin gets to know you. The AI companies behind him never do.

This is the fear, so here is exactly how it works. Corwin remembers your story so he can coach you well — that memory lives in our systems, never theirs. Our HIPAA-covered partners are contractually barred from using your data to train their models. Every other engine gets your questions with your identity already gone — name and contact details stripped and replaced with stand-ins before a request can leave our systems, and the request is refused outright if that scrub hasn't happened. Your health story travels namelessly; who you are never leaves the vault.

Deny by default

The identity vault and its audit log are unreachable from any app or browser — database rules deny all direct access, full stop. Only tightly-scoped server processes, running under least-privilege identities, can touch them.

The foundation underneath

HIPAA security program AES-256 encryption at rest TLS encryption in transit FIDO2 passkeys Zero Trust architecture U.S. data residency Daily encrypted backups

An honest note: no security system on earth is impenetrable, and we won't pretend ours is. What we can promise is architecture that assumes a breach could happen and is engineered to make any single point of failure as close to worthless as possible — plus a team that treats your trust as the product. For the full picture of what we collect and how it's handled, read our Privacy Policy.