My Cancer Journey ยท How we protect your data
My Cancer Journey is built on enterprise-grade cloud infrastructure:
Your data can only be seen by you and people you explicitly invite. We enforce this at the database level using Supabase Row-Level Security (RLS) โ meaning every database query is automatically filtered to the authenticated user's data, even if a bug existed in the application layer.
Invited users (Contributors and Viewers) are scoped to the data of the account owner only, and their access level is enforced server-side. Access can be revoked by the account owner at any time.
Users sign in with email and password via Supabase Auth. Sessions use short-lived JWTs (JSON Web Tokens) with secure refresh token rotation. Password reset links use the PKCE (Proof Key for Code Exchange) flow to prevent interception attacks, and always require a new password to be set before granting access.
All personal data is stored within the EU/UK region (AWS EU West). Data is not transferred to or processed in countries outside this region except where explicitly noted (e.g. email delivery via Resend, which operates under Standard Contractual Clauses).
We do not sell, rent, or share your personal data with any third party for advertising, analytics, or commercial purposes. The only third parties who may process your data are the infrastructure providers listed above, each acting as a data processor under our instructions.
No data is shared with AI providers. The food recognition feature uses on-device processing or a direct API call where applicable โ your food photos and health information are never used to train AI models.
You can permanently delete your account and all associated data at any time from within the app under Settings โ Delete My Account. This removes all records from the database and storage immediately. Supabase infrastructure backups may retain data for up to 30 additional days before full purge.
For a full description of your rights under UK GDPR, see our Privacy Policy.
If you discover a security vulnerability or believe your data has been compromised, please contact us immediately. We take all reports seriously and aim to respond within 24 hours.