Security
Your health data,
protected.
Whole handles sensitive health information: your movement, nutrition, sleep, mood, and soul check-ins. We take that responsibility seriously. Here's how we keep your data safe.
How we protect you
Security by design.
- 01
Encryption everywhere
All data is encrypted in transit using TLS 1.2+ and at rest using AES-256. Your health data never travels unprotected.
- 02
Data residency
Your data is hosted on Supabase infrastructure with region-based data residency. Database, auth, and storage are isolated per project.
- 03
Authentication & access
We use Supabase Auth with row-level security (RLS) policies. Your data is only accessible to you. No other user or employee can view it without explicit authorisation.
- 04
Minimal data collection
We only collect the data necessary to deliver your wellness insights. We never sell your personal information to third parties.
- 05
Compliance
Whole is built to comply with the UK General Data Protection Regulation (UK GDPR). Our infrastructure provider, Supabase, is SOC 2 Type II certified.
- 06
Responsible disclosure
If you discover a security vulnerability, please report it to security@joinwhole.app. We take every report seriously and will respond promptly.
Sub-processors
Who handles your data.
Every provider that processes personal data for us, what it sees, and where. The same list is in the security pack.
Supabase
Database, authentication, file storage
All application and health data
EU (Ireland)
Vercel
Application hosting and edge delivery
Request metadata, IP addresses
Global edge, EU primary
Stripe
Subscription billing
Billing contact and payment metadata. Card details never reach us.
EU and US
Resend
Transactional email
Name and email address
EU and US
Sentry
Error and performance monitoring
Error traces, user identifier. Health data is scrubbed before send.
US
Anthropic
Plan generation and reflective insight
De-identified wellbeing signals. No name, email or organisation identifier.
US
OpenAI
Plan generation and reflective insight
De-identified wellbeing signals. No name, email or organisation identifier.
US
Apple (APNs)
Push notifications
Device token and notification body
Global
Daily
Video sessions with coaches, where used
Session media, not recorded by default
Global
Certifications
Our compliance roadmap.
Active
SOC 2 Type II
Via our infrastructure provider, Supabase. Covers data security, availability, and confidentiality.
Active
UK GDPR
Compliant with the UK General Data Protection Regulation.
On roadmap
ISO 27001
Information security management system certification. Planned as we scale our enterprise offering.
Questions
about security?
We're happy to answer any questions about how we protect your data. Reviewing Whole for an organisation? The security pack has the DPA, the data-visibility table and the duty-of-care path.