Security & Data Protection

How we protect your data and ensure your privacy

Data Encryption

Encryption in Transit

All data is encrypted using TLS 1.3 when transmitted between your device and our servers

Encryption at Rest

All stored data is encrypted using AES-256 encryption in our secure databases

SMS Security

SMS messages are transmitted securely through Twilio's encrypted infrastructure

Data Storage & Access

Secure Infrastructure

Data is stored on Supabase's secure cloud infrastructure with enterprise-grade security

Access Controls

Strict access controls ensure only authorized personnel can access user data

Row-Level Security

Database-level security ensures users can only access their own data

Authentication & Session Management

Phone Number Verification

All users are verified through SMS OTP authentication

Secure Sessions

HTTP-only, secure cookies with automatic expiration

No Password Storage

We don't store passwords - authentication is handled by Supabase Auth

Data Minimization

Minimal Data Collection

We only collect data necessary for protein tracking: phone number, food descriptions, and preferences

No Sensitive Health Data

We don't collect medical information, diagnoses, or treatment data

Purpose-Limited Use

Data is used solely for protein tracking and service delivery

Third-Party Security

Service Providers

Supabase:SOC 2 Type II certified, GDPR compliant database
Twilio:SOC 2 Type II certified, HIPAA eligible SMS service
Anthropic (Claude):Enterprise-grade AI service with data protection

All third-party providers are contractually bound to protect your data and maintain security standards.

Compliance & Certifications

SMS Compliance

  • • TCPA (Telephone Consumer Protection Act)
  • • CAN-SPAM Act compliance
  • • Explicit opt-in consent required
  • • Easy opt-out mechanisms

Data Protection

  • • GDPR compliance ready
  • • CCPA compliance ready
  • • Data subject rights support
  • • Data deletion capabilities

Security Practices

Regular Security Audits

We conduct regular security assessments and vulnerability scans

Secure Development

All code follows security best practices and undergoes review

Incident Response

We have procedures in place to respond to security incidents

Your Security Rights

Data Access

Request a copy of all data we have about you

Contact: support@gramsin.com

Data Deletion

Request complete deletion of your account and data

Contact: support@gramsin.com

SMS Opt-out

Reply STOP to any SMS to unsubscribe immediately

Or contact: support@gramsin.com

Security Questions

Ask questions about our security practices

Contact: support@gramsin.com

Security Contact

GramsIn Security Team

For security-related questions, vulnerabilities, or incidents:

Email: support@gramsin.com

Response Time: Within 24 hours for security issues

Security Updates

We regularly update our security practices and will notify users of any material changes to our security policies. This page was last updated on September 19, 2025.