Legal
DATA & SECURITY
Last updated: May 14, 2026
Veris handles sensitive health and fitness data. We take that responsibility seriously. This page explains the technical and organizational measures we use to protect your information.
🔒
Encryption in Transit
All data transmitted between your device and Veris is encrypted using TLS 1.2 or higher.
🗄️
Encryption at Rest
All data stored in our database and file storage is encrypted at rest using industry-standard AES-256.
🔑
Password Security
Passwords are stored as salted bcrypt hashes. We never store plaintext passwords under any circumstances.
🛡️
Row-Level Security
Your data is isolated from other users at the database level. No user can access another user's data.
📋
Access Controls
Only authorized personnel at Artemyx Labs can access production systems, with full audit logs on all access.
✍️
Agent Write Audits
Every write the AI agent makes to your profile is logged and can be reviewed or reverted by you at any time.
Infrastructure
Veris is built on trusted, enterprise-grade infrastructure providers:
Database & Auth — Supabase (AWS us-west-1)
Active
File Storage — Amazon S3 (us-west-2)
Active
Frontend CDN — Cloudflare
Active
AI Model API — Anthropic Claude
Active
Wearable Data — Terra API
Active
Payments — Stripe
Active
Your Data Rights
You have full control over your data at all times:
- Export: Download a complete JSON archive of your data from Settings → Data → Export.
- Delete: Permanently delete your account and data from Settings → Data → Delete Account. PII is purged within 24 hours; all linked data within 30 days.
- Revoke connections: Disconnect any wearable or third-party integration at any time from Settings → Connections.
- Consent management: Adjust your four data consent scopes at any time from Settings → Privacy.
What We Don't Do
- We do not sell your data to any third party.
- We do not use advertising pixels or trackers in any health-context flows.
- We do not share your individual data with advertisers, marketers, or data brokers.
- We do not allow our AI provider (Anthropic) to train on your data per their commercial terms.
- We do not store plaintext passwords or full credit card numbers.
Incident Response
In the event of a security incident that affects your data, we will notify you in accordance with applicable law. For incidents requiring urgent notification, we will contact you via email within the timeframes required by applicable regulations.
Reporting a Security Issue
If you discover a potential security vulnerability in Veris, please report it to us immediately and privately. Do not publicly disclose the vulnerability before we have had a chance to address it.
Security contact: security@artemyxlabs.com
We appreciate responsible disclosure and will work with you to address any valid security issues promptly.
Questions
For questions about how we handle your data, review our full Privacy Policy or contact us at privacy@artemyxlabs.com.