Privacy Policy
Version 2026-08-08
This policy describes how Alera handles account and health-related data. Alera is educational software, not a covered clinical product.
What we collect
- Account email, name, and authentication metadata
- Labs, wearable readings, journal entries, and settings you submit
- Technical logs needed to operate and secure the service
- Billing details processed by Stripe when you pay (Alera never stores full card numbers)
How we protect it
- Passwords are hashed by the identity provider (Supabase Auth). Alera never stores plaintext passwords.
- Wearable OAuth tokens are encrypted at rest with AES-256-GCM using a server-only key.
- Production requires a strong encryption key and HTTPS on the public origin.
- Admin access is fail-closed: only emails listed in server configuration can use /admin.
Sharing
We do not sell your health data. Processors (hosting, database, auth) only receive what is needed to run Alera. Optional AI chat is server-side and is not used unless configured.
Your choices
You can export your data or delete your account from Settings. Deletion removes Alera application records we control; identity-provider backups follow that provider’s retention.
Contact
Privacy questions: use the email on your account Settings page or the operator contact for this deployment.