Supplepedia

Loading…

Compliance & Commitments

Supplepedia supports GDPR and CCPA privacy rights, encrypts data in transit and at rest, and applies privacy-by-design principles including fail-closed vendor gates and audit logging.

Important: How Supplepedia handles health data depends on your practitioner relationship tier.

Tier 2 (default): Standard practitioner invites include clinical engagement. Defined clinical content (notes, context, messages, alerts, assessments) is PHI under HIPAA. Your practitioner is the Covered Entity; Supplepedia acts as their Business Associate. A Business Associate Agreement must be on file for their practice before Tier 2 invites can be sent or accepted, and the Service refuses those actions until it is.

Tier 1 (optional): Practitioners can downscale to protocol-only sharing. No Tier 2 clinical content is stored.

Self-directed supplement tracking outside a practitioner relationship is consumer wellness data. Supplepedia is not a full clinical EHR.

Security Controls

  • Authentication via Clerk or AWS Cognito with practitioner MFA support
  • Practitioner and admin sessions log out automatically after inactivity, recorded server-side so a timed-out session stays logged out and is not reset by a deployment
  • Disabling MFA or changing an account email requires a recent sign-in; changing a password signs out other devices
  • HTTPS/TLS in transit and AES-256-GCM encryption for sensitive fields at rest, under a key held separately from the database
  • Encrypted database backups, which cannot be switched off in production
  • Append-only audit trail for practitioner data access
  • Notifications use generic wording by default, so health details do not appear on a locked screen
  • Cookie consent gating for analytics and advertising on the website
  • No payment card data stored. Billing handled by Stripe, Apple, and Google

Subprocessors

We use third-party services including Clerk, AWS Cognito, Neon, Stripe, Loops, Sentry, Cloudflare, Fly.io, OpenAI, Expo, Google Analytics, and Meta. See our Privacy Policy for full disclosures.

Vendors we send data to are gated by signed-agreement flags, and those flows fail closed when an agreement is not in place. Neon and Fly.io are different: they are the database and the runtime, so no flag can hold data back from them and coverage has to come from the agreement itself. As of August 17, 2026 the main site and API are served directly by Fly.io and are no longer routed through Cloudflare, so no third-party proxy decrypts application traffic; Cloudflare now provides DNS and serves the www and payment subdomains only.

Contact

For security inquiries or data rights requests, contact kacey@thesupplepedia.com.