Security & Privacy

Your research is private
and protected

HealthSageAI is built with security and privacy as foundational principles. Your data is isolated, encrypted, and under your control. We never sell your data.

How we protect your data

Security measures are enforced at the database, server, and application layers.

Row-level security

All user-scoped data is protected by database-level row-level security (RLS). Your research, workspaces, notes, and saved items are visible only to you. Access policies are enforced at the database layer, not just in the application code.

Data isolation

Each account has its own isolated scope for research, collections, and workspaces. There is no cross-account data access. Policies ensure that queries return only rows belonging to the authenticated user.

No personal medical records required

HealthSageAI does not require you to upload personal medical records. You may optionally share general context such as age range or goals, but the platform is designed around research and education, not personal health tracking.

Export your data

You can export your saved research, notes, collections, and workspace content at any time from Settings. Your data is yours.

Delete your data

You can permanently delete your account and associated data from Settings. Deletion removes your research, saved items, and workspace content.

Secrets managed server-side

API keys, service credentials, and other secrets are managed server-side and are never exposed to the browser. Sensitive operations are handled through server-side functions and edge functions, not client-side code.

Input validation

User input is validated on the server before being stored or processed. Quantity limits, format checks, and content constraints are enforced server-side to prevent abuse and data corruption.

Audit logs

Administrative actions are recorded in audit logs, providing a traceable history of changes to system configuration, user accounts, and content. Audit logs support accountability and incident review.

Admin role-based access control

Administrative interfaces are protected by role-based access control (RBAC). Only authorized admin roles can access admin routes, manage users, view billing data, or modify system configuration. Standard users cannot reach admin functionality.

Row-level security, explained

RLS is a database-level access control mechanism that restricts which rows a user can read or modify based on their identity.

Enforced at the database

Policies run on every query, not just in app code.

Per-user scoping

Each user sees only their own research and data.

Deny by default

Access is denied unless a policy explicitly allows it.

You control your data

Export everything. Delete everything. Your research, notes, collections, and workspace content belong to you and are accessible from Settings.

Export anytime

Download your saved research and notes from Settings.

Delete anytime

Permanently delete your account and all associated data.

No records required

No personal medical records are needed to use HealthSageAI.

Medical Disclaimer

HealthSageAI provides health education and research assistance for informational purposes only. It does not provide medical diagnosis or treatment and is not a substitute for professional medical advice.