How HealNova Protects Your Data
HealNova is a general wellness platform, not a medical device, and does not provide medical diagnosis or treatment. Because we still handle sensitive personal health information, we hold ourselves to a high security bar. This page summarizes our practices, what data we keep and for how long, and how to report a security issue. For the full legal terms, see our Privacy Policy and Legal Center.
Security practices
- Data encrypted in transit (TLS) and at rest.
- Role-based access controls and audit logging for internal systems.
- Security practices informed by ISO/IEC 27001 and SOC 2 Type II principles, and by HIPAA-aligned safeguards for health-related data, though HealNova is not a HIPAA Covered Entity or Business Associate and does not hold FDA or CE medical device certification.
- Regular dependency and vulnerability scanning of our application stack.
Data handling & retention
Account & profile data
Name, email, and login credentials. Retained for the lifetime of your account and deleted within 30 days of account closure, unless a longer period is required by law.
Health & wellness inputs
Self-reported symptoms, vitals synced from Apple Health/Google Fit, and assessment responses. Retained while your account is active; you can request export or deletion at any time from Settings or by contacting us.
AI-generated insights
Wellness recommendations and pattern alerts produced from your inputs. These are informational only, are not a medical diagnosis, and are retained alongside your account data.
Uploaded images (skin/eye scans)
Processed for on-device or encrypted-in-transit analysis. Retained only as long as needed to generate your insight, or longer if you explicitly save a result to your history.
Payment & billing data
Handled by PCI-DSS-compliant third-party payment processors. HealNova does not store full card numbers.
Your rights
You can request access to, correction of, or deletion of your data, or ask us to export it, at any time by contacting [email protected]. See our Privacy Policy for full detail on regional rights (GDPR, CCPA/CPRA, DPDPA, and others).
Reporting a vulnerability
If you believe you've found a security vulnerability in HealNova, please report it responsibly. We ask that you do not publicly disclose the issue until we've had a reasonable opportunity to investigate and address it.
- Contact: [email protected]
- Machine-readable policy: /.well-known/security.txt
- Please include steps to reproduce, affected URLs, and any relevant logs or screenshots.