Boring on purpose.
Mise is health-adjacent software. Health-adjacent earns scrutiny. Below is the plain-English version of how we earn the right to your phone.
We don't train on your data
Your meals, body metrics, and goals are not used to train any model. There's no advertising layer to feed.
Edge-only AI keys
Our OpenAI API key lives in Supabase Edge Functions. Apps call our endpoints, not OpenAI directly.
Health data under your control
With Health permission, selected observations can be saved to your Mise profile. Relevant summaries reach OpenAI only after separate AI-data-sharing approval.
Scoped access
Connections use TLS and infrastructure providers encrypt stored data. Row-level policies scope private account records to the signed-in user. Shared household and public catalogue data use separate access rules.
Sensible storage
Account data lives in Supabase-managed Postgres and private object storage. We verify production backup and recovery settings rather than publishing an unsupported region or recovery-window promise.
Bounded operational traces
AI traces record the feature, model, token counts, duration, and success or failure for reliability and cost controls. We do not store prompt text in that operational trace.
Named processors
Our Privacy Policy lists each processor and its purpose. Payments run through Apple or Google's stores, and AI transfers require the provider-specific permission described there.
Deletion controls
Delete your account from Settings after confirming the permanent action, or request access or deletion by email. Processor and backup handling is described in the Privacy Policy.
Claims tied to — shipped controls.
| Commitment | Control |
|---|---|
| Advertising tracking | None in the app; analytics are off until you opt in. |
| Third-party AI | Provider-specific permission is required before personal data is sent. |
| Account deletion | Available in Settings with a permanent-action confirmation. |
| Access and correction | Edit profile data in-app or request a data copy by email. |
| App-store disclosures | Maintained against the shipped data flows and public Privacy Policy. |
| Security reports | Send reproducible details privately to security@getmise.org. |
Accessibility
Mise targets WCAG 2.1 AA on the web and follows Apple HIG / Material accessibility guidance on native. Dynamic Type, VoiceOver, TalkBack, and high-contrast modes are supported. If something is broken for you, please email access@getmise.org and we'll fix it.
Reporting a vulnerability
Email security@getmise.org with details and steps to reproduce. We review reports privately and respond as quickly as practical.
Read our Privacy Policy for how we handle your data, or visit the Help center.