Your data

Your health data
stays yours.

Encrypted. Isolated to your account. Never sold. What we built, in plain English.

  • Rules decide what is urgent
  • AI only explains
  • Never diagnoses
Isolated to your accountNEVER SOLDNEVER TRAINEDYOU WITHDRAW
Never sold. Never trained. You withdraw.

Minimum necessary

What we actually hold

Almost all of it is something you handed us on purpose. We do not buy data about you, and we do not go looking for your records.

Your account

Email and sign-in credentials, plus the plan you are on. Needed to give you an account at all.

What you tell us

Your health profile, goals, medications and supplements you enter, and the gut questionnaire. You type it; you can change it.

Labs you upload

The bloodwork PDFs you choose to add, and the markers read out of them. We never go and fetch records on your behalf.

Check-ins you log

Weight, sleep, energy and the other Progress entries you record yourself.

Device readings, later

If wearable sync launches and you connect a device, a short allow-list only: sleep duration, steps, activity minutes and weight.

How it is locked

Controls we built, described as controls

Every item here is something in the code, not an aspiration. None of it makes a system unbreakable, and we would not claim otherwise.

Encrypted in transit and at rest

Everything travels over TLS, and the database and platform storage are encrypted at rest.

A second seal on device readings

If wearable sync launches, each reading is encrypted in the application with AES-256-GCM before it is written, so the database row holds ciphertext. A reading that has been tampered with fails its check and is dropped rather than trusted.

Isolated to your account

Row-level security is on every table holding your data, so a query can only ever return your own rows. Device tables go further: they are readable by you alone, with staff and caregivers denied by default rather than filtered out afterwards.

Webhooks verified before they are read

Anything a device maker sends us has its signature checked against the raw body, and stale deliveries are rejected, before a single field is parsed. We do not keep the raw bodies, and our logs record a delivery id — never the readings.

Location is dropped on arrival

Activity payloads from device makers can carry GPS. We strip it in the adapter before anything is stored, and there is a test that fails if that ever stops being true.

Audited, least-privilege access

Sensitive actions are written to an audit log, and the keys that can bypass row-level security stay on the server and are used only where a human could not do the job instead. Secrets are never shipped to your browser.

Who can see what

Access is a short list

WhoSeesDevice readings
YouEverything in your account.Yes — you only.
A clinician or caregiverOnly what you have explicitly shared, and only while you leave that sharing on.No. Denied by default.
OLYRON staffAccess is limited to what a job actually needs, and sensitive actions are written to an audit log. It is not a browsing tool.No. Denied by default.
The AI coachYour labs and the check-ins you logged yourself — that is the whole context it gets.No. Not in the first version.
Your PDF reportYour labs, your check-ins, and — if wearable sync launches — a separate section clearly labelled as coming from your device.Display only, never merged into your lab markers, and never sent to the model that writes the summary.

Never

What we do not do

  • We do not sell your data. There is no advertising business here to feed it to.
  • We do not use your health data to train third-party models.
  • We do not store GPS or any location from a connected device.
  • We do not let a device write into your lab markers, your Body Repair Map, your RxGuard screening, or your gut score. Readings from a watch and results from a lab are not the same evidence and are never mixed.
  • We do not overwrite the weight or sleep you typed yourself with a number from a device.

Not live yet

Wearable sync is being built

It is not live, and you cannot connect a device today. We are describing it here because the protections were designed before the feature, not after it.

  • You will authorize the device maker directly. We never ask for your account password for another service.
  • Readings are encrypted in the application before they are stored.
  • Staff and caregivers cannot see them.
  • You can pause, disconnect, or delete readings.
  • Location is never stored, and readings do not touch your labs or your Body Repair Map.

Your controls

What you can do about it

Consent first

Sharing with a clinician, and connecting a device when that launches, both start with an explicit consent you give and can withdraw.

Turn it off

Revoke provider sharing whenever you want. When wearable sync launches you will be able to pause a connection, disconnect it, or delete the readings it brought in.

Take it or remove it

Email privacy@olyron.com to get a copy of your data or to have your account and data deleted. Doing both from Settings is being finished — until it ships, the inbox is the way.

The honest part

No system is perfectly secure

Anyone who tells you their product cannot be broken into is selling you something. What we can tell you is what we built, which is what this page is: encryption in transit and at rest, a second seal on the most sensitive readings, row-level isolation on every table, signature checks before we read anything a third party sends, audit logging, and least-privilege access. Our architecture is HIPAA-grade by design — consent, audit, isolation and minimum-necessary access are structural rather than bolted on. That is a description of how it is built, not a certification, and not a legal conclusion about our status.

The Privacy Policy is the binding document and says the same thing about absolute security. Trust & Safety covers the other half of this: why deterministic rules, not the model, decide what counts as urgent. If something here does not match what you see in the product, tell us at privacy@olyron.com.

Not medical advice

OLYRON Labs provides educational, wellness, and nutrition support with clinician-discussion guidance. It does not diagnose, treat, cure, or prevent disease, and it does not replace a physician, oncologist, registered dietitian, or emergency care. Always consult your clinician before changing medications, supplements, or treatment-related diets. For emergencies, seek urgent care immediately.

Know your body without giving it away.

Upload the bloodwork you already have. What it becomes is yours, encrypted, and never sold.