Cureva's complete privacy, security, and compliance posture - built for individual families and institutional procurement teams alike.
Cureva's health data infrastructure runs on Supabase, which holds the following certifications. As a Supabase customer, Cureva operates within this certified environment - you do not need to take our word for it, you can verify Supabase's compliance posture directly at supabase.com/security.
Supabase is SOC 2 Type 2 certified - the gold standard for SaaS security controls covering availability, confidentiality, and security. Cureva's health data storage runs inside this certified environment.
Supabase certifiedSupabase holds ISO 27001 certification - the international standard for information security management systems. Cureva inherits these controls as a Supabase customer.
Supabase certifiedSupabase is HIPAA compliant and supports Business Associate Agreements. Protected Health Information stored on Supabase benefits from HIPAA-compliant infrastructure controls.
Supabase certifiedSupabase supports GDPR-compliant data processing with a formal Data Processing Agreement available. EU-region data residency is supported. Cureva's Canadian region (ca-central-1) falls under the same security controls.
Supabase certifiedCureva's backend infrastructure runs on Supabase hosted in the AWS ca-central-1 region (Canada Central, Montreal). Your medication lists, health logs, vitals, and Eva conversation data never leave Canadian soil. This satisfies provincial requirements for health data residency in British Columbia, Ontario, and Alberta, and supports compliance with PIPEDA, PHIPA, and HIA.
All stored health data - medications, vitals, Eva conversations, health notes - is encrypted using AES-256, the same standard used by Canadian financial institutions and federal government systems.
ActiveAll data moving between the Cureva app and our servers uses TLS 1.3. Connections using older protocol versions are rejected. Health conversations with Eva cannot be intercepted in transit.
ActiveSession tokens are stored using the device's secure enclave (iOS Keychain / Android Keystore via expo-secure-store). Tokens are never stored in plain text or accessible by other apps.
ActiveCureva staff access to health data is strictly limited to what is required for support. All administrative access is logged with timestamp, action, and identity. Access reviews are conducted on a regular basis.
ActiveCureva does not collect device contacts, location, payment card numbers (Stripe handles billing), or any data unrelated to health management. No advertising SDKs are embedded in the app.
ActiveUsers can permanently delete their account and all associated health data at any time from within the app or via cureva.app/delete-account. Deletion is permanent and irreversible within 30 days.
Active| Framework | Jurisdiction | Status | Notes |
|---|---|---|---|
| PIPEDA | Canada (federal) | Compliant | Personal Information Protection and Electronic Documents Act. Cureva is a Canadian company subject to PIPEDA for all personal health information it collects. |
| PIPA (BC) | British Columbia | Compliant | Cureva Health is incorporated and operates in British Columbia. BC's Personal Information Protection Act applies as the primary provincial law. |
| PHIPA | Ontario | Aligned | Personal Health Information Protection Act. Our practices are designed to align with PHIPA requirements for Ontario users. Cureva is not currently registered as a Health Information Custodian (HIC) in Ontario. A formal PHIPA compliance review is planned for 2026 Q4. |
| HIA | Alberta | Aligned | Health Information Act. Our data handling practices align with HIA requirements for Alberta users, including Canadian data residency and consent-based collection. Formal HIA registration planned for 2026 Q4. |
| HIPAA | United States | Aligned | Health Insurance Portability and Accountability Act. Cureva implements administrative, physical, and technical safeguards aligned with the HIPAA Security Rule. Cureva is a Canadian company and is not currently a HIPAA Covered Entity or Business Associate. US users' data is handled under HIPAA-aligned policies. |
| GDPR / UK GDPR | EU / United Kingdom | Aligned | Canada's PIPEDA is recognized by the EU Commission as providing adequate protection (Decision 2002/2/EC), making data transfers from EU/EEA to Cureva lawful by default. EU representative appointment in progress under Article 27 GDPR. |
| CCPA | California, USA | Aligned | California Consumer Privacy Act. California residents have rights to access, delete, and opt out of sale of personal information. Cureva does not sell personal data. See our Consumer Health Data notice. |
| HALO | Canada (national) | Roadmap 2027 | Health Application Lightweight Protocol. Canada Health Infoway's standardized framework for approved digital health apps to integrate directly into clinic EMR systems - enabling secure, plug-and-play launch from a physician's existing terminal without separate login or manual data re-entry. Cureva is designing its API layer for HALO compatibility. Formal application to Canada Health Infoway planned for 2027. |
"Aligned" means our technical and policy controls satisfy the requirements of that framework. "Compliant" means Cureva is directly subject to and in active compliance with the law. SOC 2 Type 2, ISO 27001, and HIPAA are held by Supabase - Cureva's infrastructure provider - and apply to the environment where all health data is stored. See the infrastructure certifications section above.
Cureva's only revenue source is your subscription. We do not sell, license, or share health data with advertisers, pharmaceutical companies, insurers, data brokers, or any third party for commercial purposes.
Health data is stored in AWS ca-central-1 (Montreal). It does not transit through US servers. Eva's AI processing uses Anthropic's API - health conversation content is processed under Anthropic's zero-data-retention enterprise policy.
You can export your health history as a PDF at any time. If Cureva were ever to shut down, we would provide a minimum 90-day export window and direct guidance for migrating your data.
Family caregiver alerts are included on all paid plans. We will not move core safety features behind an upsell tier without a minimum 60-day notice period and a free migration path.
To report a security vulnerability, contact [email protected]. We will acknowledge within 24 hours and provide a resolution timeline within 72 hours for critical issues.
For procurement inquiries - Business Associate Agreements, institutional PIAs, or compliance questionnaires - contact [email protected]. We respond to all institutional privacy requests within 5 business days.
Our privacy team responds to procurement inquiries, compliance questionnaires, and BAA requests within 5 business days.
Contact Privacy Team โ