Security & privacy
This page is maintained by ALERAiQ to answer common security and privacy questions. It describes controls currently enabled in the app, it is not an independent certification.
Encrypted transport
All traffic between your browser and our backend uses TLS 1.2+.
Row-level security
Every table with user data enforces row-level security so users can only read their own records.
Role-based admin access
Admin capabilities are gated by a server-side role check backed by a dedicated roles table, never by client flags.
Merchant of Record
Payments are processed by Paddle as our Merchant of Record. We never store card numbers.
Data export
You can request a full export of your account data from Settings at any time.
Password protection
Sign-ups are checked against known breached-password lists to reduce credential-stuffing risk.
Shared responsibility
ALERAiQ operates the application and the controls above. Our infrastructure providers are responsible for physical security, network isolation, and platform-level patching. You are responsible for keeping your account credentials confidential and reviewing what data you choose to enter.
Reporting a vulnerability
If you believe you have found a security issue, please email security@aleraiq.app. We aim to acknowledge reports within two business days.
Medical disclaimer
ALERAiQ provides educational wellness information and self-tracking tools. It is not a medical device and does not diagnose, treat, cure, or prevent any disease. Always consult a qualified clinician for medical decisions.