Trust & Data Protection

Your clients trust you.
You can verify us.

trophē processes nutrition and lifestyle data — special-category data under GDPR Article 9. We treat that as an engineering requirement, not a legal footnote. This page describes exactly how, in plain language.

Roles, plainly

Your nutrition practice (or clinic) is the data controller for client data; trophē is the processor acting on your documented instructions. A draft Article 28 Data Processing Agreement is available on request and is being finalised with counsel — email dpo@trophe.app.

Where data lives

Primary data is stored in Supabase (PostgreSQL), currently hosted on AWS in the United States (us-east-2); migration to an EU region is planned. Because this is a transfer outside the EEA, we rely on the EU Standard Contractual Clauses offered in our processors' data-processing agreements (Supabase, AWS); our own transfer-impact assessment and executed DPAs are in progress. Row-level security is enabled on every database table, so tenant access is enforced at the database layer, not only in application code — comprehensive cross-tenant policy tests are on our hardening roadmap. Automated backups and point-in-time recovery are being provisioned as part of our in-progress move to Supabase Pro, and are not yet enabled.

Encryption

TLS 1.2+ in transit everywhere; AES-256 encryption at rest (provided by our hosting platforms). Sessions are kept in cookies rather than browser localStorage; service credentials are never present in client code.

What our AI sees

AI is routed by task. Product generative text and meal-photo vision use OpenAI's GPT-5.6 Luna, and a short recorded microphone path uses OpenAI's Audio Transcriptions endpoint. OpenAI states that API inputs are not used to train models unless a customer opts in, and currently documents no abuse-monitoring or application-state retention for audio transcriptions. We have not yet independently verified regional routing or completed our own transfer-impact assessment and executed vendor DPA review. DeepSeek (China) is restricted by code and tests to synthetic evaluation-data generation, not consumer traffic. Search and memory features generate embeddings via Voyage (US) over text that may include personal data. Historical provider records remain auditable without enabling future Anthropic dispatch. We are actively minimising what each provider receives and building automated egress controls; we never send uploaded medical documents, because we don't accept them.

Medical documents

We deliberately do NOT accept uploads of blood panels or medical documents yet. Until our counsel finalises retention obligations for health records, the intake collects lifestyle answers only — the most privacy-preserving default.

Retention

Active account data is retained while the account exists. You can request deletion of your account and data via dpo@trophe.app; a fully-automated, audited erasure workflow (including backup handling) is in active development, and until it ships we process deletion requests manually and confirm scope and timing with you. AI run telemetry is pseudonymous; an automated retention/pruning policy for it is in development.

Breach notification

As processor, trophē notifies affected controllers of confirmed personal-data breaches without undue delay and provides the information they need to meet their own regulatory obligations (such as the 72-hour deadline a controller faces under GDPR Article 33). We maintain a documented incident runbook.

Sub-processors

SupabaseDatabase, authentication, file storageUnited States (AWS us-east-2) — EU migration planned; under SCCs
VercelApplication hosting & deliveryUnited States (functions in cle1) + global edge — under SCCs
OpenAIConsumer generative text, meal-photo vision, and short microphone transcriptionUS/global — API inputs are not used for training unless opted in; audio transcription documents no content retention; our TIA, executed DPA and regional configuration review remain in progress
DeepSeekSynthetic evaluation-data generation only; current routing prohibits consumer trafficChina — may use inputs to improve its services; synthetic data only under current policy
Voyage AIText embeddings over food text and memory/conversation/knowledge content (may include personal data)US — data-use/transfer basis under review
LangfuseAI observability (pseudonymous run telemetry)Self-hosted via Cloudflare Tunnel — hosting region not independently verified

Our current draft DPA proposes notifying controllers of sub-processor changes in advance, with the right to object.

Your rights (and your clients’)

Access & portabilityRequest a full export of your data in machine-readable format (Art. 15, 20).
RectificationCorrect any inaccurate personal data (Art. 16).
ErasureRequest deletion of your account and data (Art. 17) via dpo@trophe.app; automated erasure is in development, so requests are handled manually for now.
Restriction & objectionLimit or object to specific processing (Art. 18, 21).
Consent withdrawalWithdraw any consent without affecting the lawfulness of prior processing (Art. 7) — contact dpo@trophe.app.

Exercise any right by emailing dpo@trophe.app. Automated rights-fulfilment with SLA tracking is in development; for now requests are handled manually.

Running a clinic or multi-coach practice? We’ll walk your DPO through this page, share our current draft DPA and discuss your requirements, and answer your security questionnaire — dpo@trophe.app.

Data sources & licensing

Nutrition values are compiled from public food-composition databases: Open Food Facts (© its contributors, used under the Open Database License (ODbL)), USDA FoodData Central, CIQUAL (France), CoFID (UK), BEDCA (Spain) and CREA (Italy). Open Food Facts product data remains © its contributors; crowdsourced entries are treated as estimates, not lab-verified values.

Last updated 2026-08-12 · trophē — Precision Nutrition Coaching