Support
Security
How we protect the data you trust us with, and how to tell us if you find a weakness.
By design
- Less data, less risk: calendar, location and DNA files stay on your iPhone. Raw readings from Apple Health and connected devices reach our server only with your consent and are deleted 90 days after each was taken. The server gets only what you switch on.
- Encryption: TLS for everything in transit; databases and storage encrypted at rest. Your settings are sealed on your device before upload, so we cannot read them.
- Device access keys: the keys that Oura, WHOOP and other device makers issue to Horavi are stored encrypted, used only to fetch your data, and deleted when you disconnect the device.
- A key per person: each person’s documents are sealed with their own key; deleting the account destroys the key.
- Every opening logged: each time a document is opened, by you, a person you trust or the assistant, it is written to a log you can see.
- Least access: only the people who run Horavi can reach production, and that access is logged.
- Minimum to the AI: the model receives only what one answer needs, without your name, email or identifiers. It never receives raw readings from Apple Health or your devices; from those it sees only the daily numbers our server works out without AI.
Responsible disclosure
Found a vulnerability in Horavi, horavi.app, app.horavi.app or api.horavi.app? Write to ab@digitalflow.agency with the subject “Security”: what you found, how to reproduce it, and what it could expose.
- We confirm receipt within 3 working days and keep you posted until it is fixed.
- Test only with accounts you own. Do not access, change or delete other people’s data, do not degrade the service, and do not use social engineering or physical attacks.
- Give us reasonable time to fix before you publish. We will credit you if you wish.
- If you follow these rules in good faith, we will not take legal action against you.
Machine-readable: /.well-known/security.txt.