Privacy Policy

Last updated: April 1, 2026

The short version

Your health data belongs to you. We store it securely, never sell it, never share it with third parties for advertising, and you can export or delete it at any time.

What we collect

  • Account information: email address and password (hashed, never stored in plaintext).
  • Health journal data: symptom logs, severity scores, notes, and any other information you choose to enter.
  • Usage data: anonymous analytics via Plausible (no cookies, no cross-site tracking, no health data).

How we use your data

  • To provide the Notem service - journal, pattern detection, briefs, research.
  • Your symptom data is sent to the Anthropic Claude API (server-side only) to generate AI insights. Anthropic does not use your data to train models by default.
  • Your symptom terms (not your identity) are sent to the PubMed API to find relevant research.
  • We never sell your data. Ever.

Data security

All data is stored in Supabase with row-level security policies - your data is only accessible to you. All connections are encrypted via TLS. Sensitive fields (date of birth, sex) are encrypted at rest.

Your rights

  • Export: Download all your data as JSON from Account Settings at any time.
  • Deletion: Delete your account from Account Settings. Your data is permanently removed after a 30-day grace period.
  • GDPR / CCPA: If you are in the EU or California, you have additional rights including access, rectification, and portability. Contact us at privacy@odysseyai.app.

Age requirement

Notem is not intended for users under 13. Users under 18 require parent or guardian acknowledgment during signup.

Contact

Questions? Email us at privacy@odysseyai.app.