Skip to content
  • Features
  • Pricing
  • Privacy
  • FAQ
  • Support
Join the waitlist
  1. Holimo
  2. Legal
  3. Security
Draft — to be reviewed by counsel before launchThis page is a working draft. It isn’t final legal text yet, and the highlighted placeholders still need details from the company or its lawyer.

Security and Responsible Disclosure

Last updated: 5 October 2026

The short version

  • Every table is locked to its owner and tested automatically. Secrets live only on our servers. Journal and cycle data are encrypted on your phone.
  • Found a vulnerability? Please tell us privately. We won’t take legal action against good-faith research.

On this page

  1. How we protect your data
  2. Report a vulnerability
  3. What we commit to
  4. Safe harbour
  5. Out of scope

How we protect your data

  • Access control: every database table has row-level security, so each person can only read and change their own rows. Automated tests try to read, change, delete and forge another user’s rows on every table, and every release must pass them.
  • No secrets in the app: API keys and the database service key live only in server functions, never in the app you download.
  • On-device encryption: journal text and all cycle data are encrypted on your phone with AES-256-GCM before they sync. A backup of your key is held in a secure vault and released only to you after sign-in, so a new phone can read your data. A leak of the database alone would expose only scrambled text for these fields. Because we hold a backup of the key, this is not “zero-knowledge” encryption, and we say so plainly.
  • In transit: all traffic between the app and our servers is encrypted with TLS.
  • Where: data is stored in the EU (Frankfurt).
  • Backups and incidents: daily backups, and a written breach plan that includes notifying authorities within 72 hours where the law requires.
  • Deletion: deleting your account erases your rows, files and escrowed key.

More detail in plain language on our Privacy by design page.

Report a vulnerability

Email To fill in security@getholimo.com (confirm the mailbox exists). Our contact details are also in /.well-known/security.txt. Please include:

  • what you found and where (app version, URL or endpoint);
  • steps to reproduce it;
  • the impact you think it has;
  • how to reach you.

What we commit to

  • We will acknowledge your report within To fill in number working days.
  • We will keep you updated while we fix it, and tell you when it’s fixed.
  • With your permission, we will thank you by name once it’s fixed.

We don’t run a paid bug bounty at launch.

Safe harbour

If you act in good faith and follow this policy, we will not take legal action against you or ask anyone else to. Please:

  • only test with accounts you own, and never access, change or keep other people’s data;
  • stop and tell us if you come across personal data;
  • give us reasonable time to fix the issue before telling anyone else;
  • not degrade the service for others.

Out of scope

  • Social engineering or phishing of our team or users.
  • Denial-of-service or load testing.
  • Physical attacks.
  • Issues in third-party services (Apple, Google, Supabase, RevenueCat) — please report those to them.
  • Reports from automated scanners without a demonstrated impact.

Back to top

One calm app for your whole health. No ads, a fair price, private by default.

Need help now? Crisis resources

Product

  • All features
  • Today
  • Food
  • GLP-1
  • Move
  • Focus
  • Sleep
  • Mind
  • Water
  • Habits
  • Cycle
  • Insights
  • Pro and AI coach
  • Family plan

Company

  • Pricing
  • Privacy by design
  • About
  • Press kit
  • What’s new
  • Support
  • FAQ
  • Contact

Legal

  • All legal pages
  • Privacy
  • Consumer health data
  • Terms
  • Subscription terms
  • Medical disclaimer
  • AI disclosure
  • Cookies
  • Account deletion
  • Affiliate disclosure
  • Accessibility
  • Imprint
  • Security
  • Licences
  • Sub-processors

© 2026 Holimo. All rights reserved.

Holimo is a general wellness app, not a medical device. It doesn’t diagnose or treat anything.