Security & privacy
What we do with health information, in plain words
This page describes what is built today, not what we aspire to. The full terms are in the privacy policy.
Where your data lives
- Navwell runs on Google Cloud in the United States, under a Business Associate Agreement with Google that covers the services we use — the database, file storage, speech transcription and the AI platform.
- Data is encrypted in transit and at rest. Member uploads — meal photos, health records, voice notes — sit in private storage and are served only through short-lived signed links.
- Tokens for connected devices are encrypted at rest with a key the application holds separately from the database.
The AI coach
- The coach runs on Claude through Google Cloud's Vertex AI, inside the same boundary as the rest of Navwell — conversations are not sent to a consumer chatbot service.
- Google's terms say customer data is not used to train models; Anthropic's commercial terms say the same. We keep the vendor terms we rely on on file, with retrieval dates.
- What the coach remembers about a member is a list the member can read, edit and delete.
- It hands a conversation to the practitioner only with the member's consent, follows fixed safety scripts for crisis and eating-disorder signals, and can be switched off per practice or for everyone.
Signing in
- Two-step sign-in with a choice of methods: passkeys, an authenticator app, an emailed one-time code, and backup codes.
- Two-step is mandatory for practitioners and Navwell staff, and available to every member.
- Passwords must be at least 12 characters and are checked against known breaches; repeated failed sign-ins lock the account for 15 minutes.
- Sessions time out when idle — 60 minutes for practitioners and staff — and always expire after a fixed maximum.
Who sees what
- A practitioner sees the plan they assigned, completion, outcome scores, device trends, and the messages you send them. They do not see your coach conversations, meal photos or health records unless you share a specific item.
- Joining a practitioner's community from an existing account shows you exactly what becomes visible before you accept.
- Every sensitive action — who viewed or changed what, and when — is written to an append-only audit log that the application can add to but never edit or delete.
Your data, your choices
- Download your data as a file from your account at any time.
- Delete your account: everything private to you is deleted after a seven-day window in which you can change your mind. If you belonged to a practitioner's community, the practitioner keeps their own record of your care — the same way a clinic keeps a chart.
- Connected devices can be disconnected at any time, keeping or deleting the history.
- WhatsApp messages stop when you reply STOP; every email carries a one-click unsubscribe.
How we build and run it
- One Google Cloud project for production and a separate one for staging, both defined in code; secrets live in the cloud secret manager and never in the code; the application uses a database role that can read and write data but cannot change the database's structure.
- Error reports never carry personal data: an allow-list scrubber strips everything but opaque identifiers, and there is no session recording.
- No third-party analytics or advertising trackers — not in the app, and not on this website.
- One cost ledger meters every AI call, message, transcription and stored file; the AI, messaging, upload and device features each have a kill switch, so an incident can be contained in one action.
- The Google Health API integration passed an independent CASA application security assessment (Assurance Level 1) in September 2026.
What we do not claim
Navwell is built for practices that handle protected health information, and we intend to sign a Business Associate Agreement with every practice before it invites its first patient. We do not describe Navwell as “HIPAA compliant”: that is a statement about a whole organisation's programme, and ours is being completed with counsel. Ask us where it stands.
We do not hold a SOC 2 report or a HITRUST certification today. We will say so here the day that changes.
The AI coach is not a medical device and does not diagnose. Nothing on Navwell replaces the advice of your practitioner.
Questions about any of this: info@navwell.ai. Practices can also ask on the demo call.