Launching soon  ยท  Free 7-day trial

Trust Center

Cureva's complete privacy, security, and compliance posture - built for individual families and institutional procurement teams alike.

Data Stored in Canada AES-256 Encrypted PIPEDA Compliant PHIPA-Aligned HIPAA-Aligned Zero Data Sales

Infrastructure certifications

Cureva's health data infrastructure runs on Supabase, which holds the following certifications. As a Supabase customer, Cureva operates within this certified environment - you do not need to take our word for it, you can verify Supabase's compliance posture directly at supabase.com/security.

Supabase certification

SOC 2 Type 2

Supabase is SOC 2 Type 2 certified - the gold standard for SaaS security controls covering availability, confidentiality, and security. Cureva's health data storage runs inside this certified environment.

Supabase certified
Supabase certification

ISO 27001

Supabase holds ISO 27001 certification - the international standard for information security management systems. Cureva inherits these controls as a Supabase customer.

Supabase certified
Supabase certification

HIPAA

Supabase is HIPAA compliant and supports Business Associate Agreements. Protected Health Information stored on Supabase benefits from HIPAA-compliant infrastructure controls.

Supabase certified
Supabase certification

GDPR + DPA

Supabase supports GDPR-compliant data processing with a formal Data Processing Agreement available. EU-region data residency is supported. Cureva's Canadian region (ca-central-1) falls under the same security controls.

Supabase certified

Data residency

๐Ÿ‡จ๐Ÿ‡ฆ
All health data is stored in Canada - AWS ca-central-1 (Montreal, Quebec)

Cureva's backend infrastructure runs on Supabase hosted in the AWS ca-central-1 region (Canada Central, Montreal). Your medication lists, health logs, vitals, and Eva conversation data never leave Canadian soil. This satisfies provincial requirements for health data residency in British Columbia, Ontario, and Alberta, and supports compliance with PIPEDA, PHIPA, and HIA.

Technical safeguards

Encryption at rest

AES-256

All stored health data - medications, vitals, Eva conversations, health notes - is encrypted using AES-256, the same standard used by Canadian financial institutions and federal government systems.

Active
Encryption in transit

TLS 1.3

All data moving between the Cureva app and our servers uses TLS 1.3. Connections using older protocol versions are rejected. Health conversations with Eva cannot be intercepted in transit.

Active
Authentication

JWT + Secure Storage

Session tokens are stored using the device's secure enclave (iOS Keychain / Android Keystore via expo-secure-store). Tokens are never stored in plain text or accessible by other apps.

Active
Access control

Least-privilege + Audit Log

Cureva staff access to health data is strictly limited to what is required for support. All administrative access is logged with timestamp, action, and identity. Access reviews are conducted on a regular basis.

Active
Data minimization

Collect Only What Is Needed

Cureva does not collect device contacts, location, payment card numbers (Stripe handles billing), or any data unrelated to health management. No advertising SDKs are embedded in the app.

Active
User control

Delete Your Account Anytime

Users can permanently delete their account and all associated health data at any time from within the app or via cureva.app/delete-account. Deletion is permanent and irreversible within 30 days.

Active

Compliance frameworks

Framework Jurisdiction Status Notes
PIPEDA Canada (federal) Compliant Personal Information Protection and Electronic Documents Act. Cureva is a Canadian company subject to PIPEDA for all personal health information it collects.
PIPA (BC) British Columbia Compliant Cureva Health is incorporated and operates in British Columbia. BC's Personal Information Protection Act applies as the primary provincial law.
PHIPA Ontario Aligned Personal Health Information Protection Act. Our practices are designed to align with PHIPA requirements for Ontario users. Cureva is not currently registered as a Health Information Custodian (HIC) in Ontario. A formal PHIPA compliance review is planned for 2026 Q4.
HIA Alberta Aligned Health Information Act. Our data handling practices align with HIA requirements for Alberta users, including Canadian data residency and consent-based collection. Formal HIA registration planned for 2026 Q4.
HIPAA United States Aligned Health Insurance Portability and Accountability Act. Cureva implements administrative, physical, and technical safeguards aligned with the HIPAA Security Rule. Cureva is a Canadian company and is not currently a HIPAA Covered Entity or Business Associate. US users' data is handled under HIPAA-aligned policies.
GDPR / UK GDPR EU / United Kingdom Aligned Canada's PIPEDA is recognized by the EU Commission as providing adequate protection (Decision 2002/2/EC), making data transfers from EU/EEA to Cureva lawful by default. EU representative appointment in progress under Article 27 GDPR.
CCPA California, USA Aligned California Consumer Privacy Act. California residents have rights to access, delete, and opt out of sale of personal information. Cureva does not sell personal data. See our Consumer Health Data notice.
HALO Canada (national) Roadmap 2027 Health Application Lightweight Protocol. Canada Health Infoway's standardized framework for approved digital health apps to integrate directly into clinic EMR systems - enabling secure, plug-and-play launch from a physician's existing terminal without separate login or manual data re-entry. Cureva is designing its API layer for HALO compatibility. Formal application to Canada Health Infoway planned for 2027.

"Aligned" means our technical and policy controls satisfy the requirements of that framework. "Compliant" means Cureva is directly subject to and in active compliance with the law. SOC 2 Type 2, ISO 27001, and HIPAA are held by Supabase - Cureva's infrastructure provider - and apply to the environment where all health data is stored. See the infrastructure certifications section above.

What we will never do

Sell your health data

Cureva's only revenue source is your subscription. We do not sell, license, or share health data with advertisers, pharmaceutical companies, insurers, data brokers, or any third party for commercial purposes.

Move your data outside Canada

Health data is stored in AWS ca-central-1 (Montreal). It does not transit through US servers. Eva's AI processing uses Anthropic's API - health conversation content is processed under Anthropic's zero-data-retention enterprise policy.

Lock your data hostage

You can export your health history as a PDF at any time. If Cureva were ever to shut down, we would provide a minimum 90-day export window and direct guidance for migrating your data.

Surprise paywall your caregiver alerts

Family caregiver alerts are included on all paid plans. We will not move core safety features behind an upsell tier without a minimum 60-day notice period and a free migration path.

Compliance documents

Security contact

Report a vulnerability or request compliance documentation

To report a security vulnerability, contact [email protected]. We will acknowledge within 24 hours and provide a resolution timeline within 72 hours for critical issues.

For procurement inquiries - Business Associate Agreements, institutional PIAs, or compliance questionnaires - contact [email protected]. We respond to all institutional privacy requests within 5 business days.

Questions about our compliance posture?

Our privacy team responds to procurement inquiries, compliance questionnaires, and BAA requests within 5 business days.

Contact Privacy Team โ†’