Trust & legal

Trust center

How we protect health data, use AI responsibly, and stay on the educational side of regulation.

Key takeaway

One place for privacy, security, AI transparency, and regulatory framing — with a self-assessed compliance posture mapped to GDPR, US privacy law, ISO 27001, SOC 2, and HIPAA practices. Policies you can read or download; deeper diligence on request.

Read more
Trust and privacy at Findings

Findings. Compliance statements reflect internal assessments — not third-party certification unless separately attested.

Overview

We maintain a documented security and privacy program — mapped to GDPR, US state privacy law, ISO 27001, SOC 2, and HIPAA Security Rule practices — assessed internally and published here for diligence. Findings is educational health intelligence software — not a medical device.

UNIT01 d.o.o. operates Findings as software membership — users arrange laboratory draws independently. We do not sell or bundle blood tests, operate laboratories, or provide clinical services. Questions: hello@unit01.dev.

Encrypted health data

GDPR & privacy aligned

Self-assessed controls

Security

Findings processes sensitive health data. Security is a product requirement — not a marketing badge. We implement technical and organizational measures appropriate to the risk and assess them against common diligence frameworks (see Compliance posture below).

Data in transit and at rest

  • Health data is transmitted over TLS (HTTPS) between your devices and our services
  • Data at rest is stored in encrypted databases and object storage provided by our infrastructure vendors
  • Authentication credentials are managed by Supabase Auth — we do not store plaintext passwords
  • Row Level Security (RLS) in PostgreSQL restricts database access so users can only read their own records

Access control

  • Production access is limited to personnel who need it to operate the service
  • API endpoints require authenticated sessions for user health data
  • Gated features enforce subscription and preview tiers server-side — not only in the client

Application security

  • OCR and AI features run server-side; model API keys are not exposed to clients
  • Upload and chat flows include consent and disclaimer surfaces before processing health data
  • AI chat responses may be reviewed by automated safety checks before delivery
  • We minimize data in background job queues (metadata only where possible)

Compliance posture (self-assessed)

We map our controls to the frameworks below and review them on an internal cycle. This is our diligence posture — not a substitute for a customer-specific security questionnaire or independent audit report.

FrameworkOur postureAttestation
GDPRAligned — privacy notice, explicit consent for health data (Art. 9), transfer safeguards, and user rights in product (access, export, delete).Self-assessed
CCPA / CPRA & US state health privacyAligned — consumer health data notice, no sale of health data, rights and appeal workflows where required.Self-assessed
ISO 27001Security program mapped to ISO 27001 Annex A controls (encryption, access control, incident response).Self-assessed — not ISO 27001 certified
SOC 2Controls informed by SOC 2 Trust Services Criteria (security and availability) — subprocessors under contract, RLS, server-side gates.Self-assessed — no SOC 2 report
HIPAAHealth data safeguards informed by HIPAA Security Rule practices. Generally not a HIPAA covered entity for typical direct-to-consumer use.Self-assessed — BAA available for enterprise on request

Compliance statements on this page reflect our internal control assessments and documented practices. They are not independent third-party certifications. We will update this page if we obtain formal ISO 27001, SOC 2, or other external attestation.

Incident response

If you believe your account has been compromised, contact hello@unit01.dev immediately. UNIT01 d.o.o. maintains internal procedures for assessing and notifying breaches where required by applicable law (including GDPR Articles 33/34 and US state breach notification rules).

AI transparency

Findings uses artificial intelligence for specific features — not as a replacement for clinical judgment. You should know when AI is involved, what it receives, and what it cannot do reliably.

Where we use AI

  • OCR — extracting biomarker values from uploaded lab PDFs and images
  • Scoped overviews — short summaries on dashboard, biomarker detail, trackers, checkup plan, and related surfaces
  • AI chat — conversational explanations using your stored health context
  • Memory extraction — optional facts stated in chat, stored for future context (editable by you)
  • Memory search embeddings — semantic retrieval of relevant memories in chat (OpenAI embeddings)

Marketing demos on our public website use illustration-only AI copy — not your data.

What data AI features receive

When you use AI features, our servers may send subprocessors a bundle that can include:

  • Profile demographics (age, sex, country) and medications
  • Recent biomarker values and trends
  • Daily tracker readings (typically last 14 days)
  • Relevant conversation-derived memories
  • Your chat message and prior messages in the same thread
  • For OCR — the lab file or image you uploaded

Anthropic processes most AI features; OpenAI processes embeddings only. API terms with these providers prohibit using your data to train their general models.

Limitations

  • AI outputs may be incomplete, outdated, or incorrect — verify with your clinician
  • AI does not diagnose, prescribe, or perform emergency triage
  • OCR may misread values — you must confirm extractions before saving
  • Automated safety review may block or flag some chat responses

AI responses are not medical advice. In an emergency, call your local emergency number.

Your choices

  • You choose whether to upload labs, use chat, or open AI overviews
  • You can edit or delete conversation-derived memories in Profile
  • You can delete your account and associated AI history
  • Full AI chat send requires an active membership after preview tiers

Regulatory positioning

Findings is personal health data organisation and education software. It helps adults upload laboratory reports, track biomarkers over time, log optional daily readings, and follow a profile-based health plan informed by published screening guidance.

We are the intelligence layer — software membership. Users arrange blood draws at any lab; we do not sell or bundle laboratory services.

What Findings is not

  • Not a medical device — not FDA-cleared or CE-marked as a device
  • Not a substitute for a qualified healthcare professional
  • Not for emergency triage or acute care decisions
  • Not a laboratory or provider of diagnostic testing
  • Not a drug interaction checker or prescribing system
  • Not intended to diagnose, treat, cure, or prevent disease

United States

We position Findings as a general wellness and education tool for informed adults — not as Software as a Medical Device (SaMD) intended to diagnose or treat disease.

European Union and United Kingdom

UNIT01 d.o.o. is established in Serbia. For EEA/UK users, we process special category health data under GDPR Article 9 with explicit consent. We do not market Findings as a medical device under EU MDR.

Subprocessors

We use service providers ("subprocessors") who process personal data on our behalf under written terms. This list is also in our Privacy Policy (https://www.getfindings.com/privacy#sharing).

ProviderRoleData involvedLocation / notes
Supabase, Inc.Database, authentication, encrypted storage, Row Level SecurityAccount, profile, health records, chat, memories, embeddingsEU/US — DPA via Supabase dashboard (Org → Legal documents)
Fly.io, Inc.API application hosting (NestJS backend)Request metadata, operational logs; health payloads in transit to/from APIUS/EU regions — pre-signed DPA in Fly dashboard → Compliance
Vercel, Inc.Web application hosting (Next.js frontend)Access logs, IP addresses; may proxy /api/v1 to API when configuredGlobal edge — DPA incorporated in Vercel terms (vercel.com/legal/dpa)
Anthropic, PBCOCR, chat, summaries, memory extraction, titles, drug interaction textLab images/PDFs, chat content, assembled health contextUS — DPA in Anthropic Commercial Terms; no training on API customer data
OpenAI, LLCText embeddings for memory search onlyMemory text (category, key, value)US — DPA at openai.com/policies/data-processing-addendum
RevenueCat, Inc.Subscription management and webhook billing eventsUser ID, subscription status, product IDsUS — DPA at revenuecat.com/dpa
Apple Inc. / Google LLCIn-app purchases when you subscribe via App Store or Play StorePayment handled by platform; we receive entitlement status via RevenueCatPer platform policies
Resend, Inc.Transactional email (when enabled)Email address, notification contentUS — DPA at resend.com/legal/dpa
Expo (push infrastructure)Mobile push notificationsPush token, notification payloadUS
Upstash, Inc.Redis job queue (OCR and notification workers)Job metadata (upload IDs, user IDs); not full health records in queue payloads by designEU/US — DPA incorporated in Upstash terms (upstash.com/trust/dpa.pdf)
PostHog, Inc.Optional product analytics (when you opt in)Pseudonymous device ID, product event names, coarse usage metadata — not lab or health profile contentEU (eu.posthog.com) — DPA at posthog.com/dpa
Meta Platforms, Inc.Optional campaign measurement (Conversions API via server-side tags when enabled)Hashed email (SHA-256), pseudonymous event IDs, browser/click identifiers (fbp/fbc), coarse conversion events (e.g. signup, membership) — not lab values or health profile contentUS — Meta Business Tools Terms; only when you opt in to campaign measurement where required
Google LLCOptional Google Tag Manager, Google Ads, and Google Analytics measurement when enabledHashed contact info for enhanced conversions where used, gclid, pseudonymous analytics IDs, coarse conversion events — not lab values or health profile contentGlobal — Google Ads/Analytics terms; only when you opt in to campaign measurement where required
Stape.ioServer-side tag management hosting (routes measurement events when campaign measurement is enabled)Event payloads for measurement forwarding (hashed contact info, click IDs, coarse conversion metadata) — not lab values or health profile contentEU/US — DPA at stape.io; optional subprocessor for measurement only

Questions: hello@unit01.dev.

Responsible disclosure

UNIT01 d.o.o. ("Findings", "we", "us") welcomes good-faith security reports from researchers, customers, and partners. This policy describes how to report vulnerabilities in Findings-owned websites and applications.

Third-party services (payment processors, AI providers, hosting vendors) are out of scope unless the issue is introduced by Findings configuration on our domains.

2. In scope

  • https://www.getfindings.com and subdomains
  • Findings web application and authenticated API surfaces operated by us
  • Findings mobile applications distributed under our brand

3. Out of scope

  • Social engineering, phishing, or physical attacks
  • Denial-of-service or load tests against production
  • Issues in third-party services we do not control
  • Missing security headers without demonstrated exploitability
  • Reports from automated scanners without a verified, exploitable finding

4. Program rules

When testing, you must:

  • Use only accounts you own or our designated test accounts
  • Not access, modify, or exfiltrate other users' data
  • Not degrade the experience for other users
  • Stop immediately if you encounter personal health information (PHI) or payment data beyond your own account
  • Give us reasonable time to remediate before public disclosure

Do not perform destructive testing, ransomware simulations, or persistence on our systems.

5. How to report

Email hello@unit01.dev with subject line "Security vulnerability report". Include:

  • Affected URL, app version, or API endpoint
  • Vulnerability type and estimated impact
  • Step-by-step reproduction instructions
  • Suggested remediation if known
  • Your contact information for follow-up

We aim to acknowledge reports within three business days and will keep you informed of status on a reasonable basis.

6. Safe harbor

If you make a good-faith effort to comply with this policy, we will not recommend legal action related to your research. We reserve all legal rights if testing violates this policy or applicable law.

We do not offer a paid bug bounty at this time. We may recognize valuable reports at our discretion.

7. Confidentiality

Do not publicly disclose vulnerabilities until we have confirmed remediation or agreed on coordinated disclosure timing. By submitting a report, you grant us permission to use the information to improve our security.

8. Contact

Security reports: hello@unit01.dev. General privacy: hello@unit01.dev. Trust center: https://www.getfindings.com/trust.

Documents

Official PDF exports match the web versions below. Compliance posture is self-assessed unless we publish independent attestation.

  • Privacy Policy

    GDPR-aligned privacy notice — purposes, legal bases, rights, and international transfers.

    Get this document

  • Terms of Service

    Membership agreement, acceptable use, and product limitations.

    Get this document

  • Consumer health data privacy

    US state consumer health privacy rights and how to exercise them.

    Get this document

  • Delete your account

    How to permanently delete your Findings account and health data — in-app steps, email requests, and retention.

    Get this document

  • Delete your data

    How to remove specific health data without closing your account — uploads, profile, memories, trackers, and email requests.

    Get this document

  • Trust, security & subprocessors overview

    Security measures, AI transparency, regulatory positioning, subprocessors, and responsible disclosure — combined for diligence.

    Get this document

  • Responsible disclosure policy

    Scope, rules, and how to report security vulnerabilities.

    Get this document

Available on request

For employers, clinics, partners, or procurement teams — email hello@unit01.dev.

  • Data Processing Agreement (DPA)

    On request

    For employers, clinics, or partners where Findings processes personal data under your instructions.

    Procurement

  • Security questionnaire responses

    On request

    Completed vendor security questionnaires (SIG Lite, CAIQ, or custom) for procurement teams.

    Procurement

  • DPIA executive summary

    On request

    High-level summary of our data protection impact assessment for health and AI processing.

    Procurement

Diligence requests

Security questionnaires, DPAs, and executive summaries are available on request. We aim to respond within five business days.

Vulnerability reports: hello@unit01.dev (see Responsible disclosure above). Privacy rights: use in-app Settings or the same address.

Product methodology and citations live in our Methods guide. In-app regulatory notices are in Important information.

Findings is health intelligence software. We do not sell blood tests, order testing, or provide medical care. You arrange draws at any lab and upload your results when you are ready.