๐ŸŒ

Units

Region & currency

๐ŸŒ

Appearance

Privacy & your health data

Last updated: June 27, 2026

We treat the information you give us โ€” including body metrics, health conditions, medications, and allergies โ€” as sensitive consumer health data and protect it accordingly. This summary explains what we collect, where it is stored and processed, how long we keep it, and the rights you have, including how to export or permanently delete it.

Where your data lives

When you use XyberHealth without an account, your profile and stacks are stored on your device (in your browser) and you can clear them anytime from your account. When you sign in, your data is stored on our servers so it can sync across your devices, protected by per-user database access controls keyed to your account. The sections below describe the data we hold on our servers once you sign in.

What we collect

  • Profile: sex, age, weight, height, body composition, activity, diet, goals.
  • Health inputs: conditions, medications (by class), allergies, pregnancy status.
  • Saved stacks and your current stack, cart and orders / auto-ship schedule.
  • Reminders and adherence, and notification / push-subscription settings.
  • Biomarker readings you log or import, and your cycle logs.
  • Sleep, readiness and biological-age snapshots derived from your inputs.
  • Fridge / nutrition data when you use the nutrition features.
  • Skin / hair photo analysis โ€” cosmetic, non-diagnostic results (consent-gated).
  • Messages, bookings and consult notes if you use the provider marketplace.
  • Account & security: email, sign-in credentials, two-factor settings, consent history.

Why we collect it

Solely to personalize and safety-check your supplement suggestions, fulfil orders, enable provider bookings and messaging you choose to use, and operate the service. We do not sell your health data and never use it for advertising, retargeting, or model training. The Ask XyberHealth assistant redacts personal details from your messages before they are processed and only draws on official public sources.

Third parties who process your data

We use a small set of vetted processors, bound by contract, only to operate the service:

  • Supabase โ€” database, authentication and file storage (our backend host).
  • Stripe โ€” payment processing for orders and provider bookings (incl. Stripe Connect). We never store full card numbers.
  • Resend โ€” transactional and (if you opt in) marketing email delivery.
  • A telehealth video provider (Whereby, with Daily.co as a configurable alternative) โ€” only if you join a video consult, and only for the duration of that call.
  • An AI language-model provider (configurable; the chat and vision models route through OpenRouter by default, with Anthropic / OpenAI / Google as alternatives) โ€” only for the Ask XyberHealth assistant and the cosmetic photo-analysis features, with personal details redacted first. By default the assistant runs an on-device, non-network model.
  • An image-generation provider (configurable) โ€” used only to render catalog product and ingredient illustrations. It is sent a short, catalog-derived prompt and never receives your account, profile, health, or photo data.

We do not claim any certification we do not hold. We apply strong technical and organizational safeguards (below), but we do not assert HIPAA, SOC 2, or similar attestations.

Retention

We keep your account data for as long as your account is active. When you delete your account (next section) we erase your personal data promptly. We retain a limited set of records only where the law requires: order, payment and booking records are kept for the period required by tax, accounting and consumer-protection law, and a minimal, non-identifying deletion record (a timestamp, with no name, email or health data) is kept so we can evidence that your erasure was honored.

Your rights โ€” access, export & deletion

Depending on where you live, you have rights to access, correct, delete, and port your data, and to withdraw consent. You can permanently delete your account and the data we hold on our servers at any time, directly:

We honor these rights under the EU/UK GDPR, Canada's PIPEDA and Quebec Law 25, the UAE PDPL (and ICT Health Law), the US CCPA/CPRA, and the Washington My Health My Data Act, as well as other GCC data-protection laws (Saudi PDPL, Qatar PDPPL). Where we cannot action a request instantly, we acknowledge and act on it within 30 days, except where retention is legally required.

Consent

We ask for your consent before collecting health data and record when you gave it, under which policy version and region. For US residents in states with consumer-health-data laws, collection and any sharing of health data is consent-based, and a separate authorization is required before any sale of such data (which we do not do). You can review and withdraw your consents anytime from your account.

Security

We apply defense-in-depth: per-user database access controls, encryption in transit, input validation, a strict content-security policy and security headers, PII redaction before logging, dependency and secret scanning, two-factor authentication, and least-privilege access.

Contact

Questions or requests: privacy@xyber.health.

This page is a plain-language summary and is not legal advice. Definitive terms are reviewed with qualified counsel for each jurisdiction we operate in.