Skip to main content
Mise private beta invitations are going out now.
Waitlist
Security

Boring on purpose.

Mise is health-adjacent software. Health-adjacent earns scrutiny. Below is the plain-English version of how we earn the right to your phone.

  • We don't train on your data

    Your meals, body metrics, and goals are not used to train any model. There's no advertising layer to feed.

  • Edge-only AI keys

    Our OpenAI API key lives in Supabase Edge Functions. Apps call our endpoints, not OpenAI directly.

  • Health data under your control

    With Health permission, selected observations can be saved to your Mise profile. Relevant summaries reach OpenAI only after separate AI-data-sharing approval.

  • Scoped access

    Connections use TLS and infrastructure providers encrypt stored data. Row-level policies scope private account records to the signed-in user. Shared household and public catalogue data use separate access rules.

  • Sensible storage

    Account data lives in Supabase-managed Postgres and private object storage. We verify production backup and recovery settings rather than publishing an unsupported region or recovery-window promise.

  • Bounded operational traces

    AI traces record the feature, model, token counts, duration, and success or failure for reliability and cost controls. We do not store prompt text in that operational trace.

  • Named processors

    Our Privacy Policy lists each processor and its purpose. Payments run through Apple or Google's stores, and AI transfers require the provider-specific permission described there.

  • Deletion controls

    Delete your account from Settings after confirming the permanent action, or request access or deletion by email. Processor and backup handling is described in the Privacy Policy.

Public commitments

Claims tied to — shipped controls.

CommitmentControl
Advertising trackingNone in the app; analytics are off until you opt in.
Third-party AIProvider-specific permission is required before personal data is sent.
Account deletionAvailable in Settings with a permanent-action confirmation.
Access and correctionEdit profile data in-app or request a data copy by email.
App-store disclosuresMaintained against the shipped data flows and public Privacy Policy.
Security reportsSend reproducible details privately to security@getmise.org.

Accessibility

Mise targets WCAG 2.1 AA on the web and follows Apple HIG / Material accessibility guidance on native. Dynamic Type, VoiceOver, TalkBack, and high-contrast modes are supported. If something is broken for you, please email access@getmise.org and we'll fix it.

Reporting a vulnerability

Email security@getmise.org with details and steps to reproduce. We review reports privately and respond as quickly as practical.

Read our Privacy Policy for how we handle your data, or visit the Help center.