Satvora AI logo
Satvora AIHealth & Nutrition Companion
Security & Engineering Posture

Privacy by Architecture, Not Just Policy

Satvora AI is designed with an offline-first storage model and verified database access controls, ensuring your health records remain private and under your direct control.

Offline-First Local Storage Architecture

All daily food diary logs, water entries, weight records, and biometric preference calculations are stored locally in an on-device Room database on your physical device.

  • Core app functions with zero internet connection
  • Local database remains on your device hardware
  • No continuous tracking or background telemetry

Supabase Row-Level Security (RLS)

When cloud synchronization is activated, data stored in Supabase PostgreSQL is isolated by PostgreSQL Row Level Security (RLS) policies.

  • Strict database policies restrict queries to auth.uid()
  • Zero unauthorized cross-tenant data leakage
  • Verified against automated RLS security test suites

Volatile Memory AI Inference

Meal photographs analyzed by our cloud AI vision gateway are processed in volatile memory to compute nutritional estimations.

  • No permanent remote image archiving on servers
  • Images are not sold or licensed to third-party data brokers
  • Strict per-session token validation and rate limiting

Self-Serve Data Sovereignty

You have complete, unconditional ownership over your dietary and biometric records at all times.

  • 1-tap JSON personal data archive export in Settings
  • Immediate full record eradication in Danger Zone
  • Separate controls for resetting preferences vs deleting all data

Responsible Security Disclosure

If you are a security researcher and believe you have discovered a security vulnerability in Satvora AI, please submit your findings to our engineering team via our Web Inquiry form (select Category: "Technical Bug / Scan Issue") or through in-app bug reports.

Submit Security Disclosure via Web Portal →