Trust & Security
How Labs Made Clear protects your health data
This page is maintained by the Labs Made Clear team to answer common security and privacy questions. It describes the controls that are enabled in the product today. It is not a third-party audit or certification.
Authentication
Accounts are protected by email and password sign-in with optional Google sign-in. Sessions are managed through our backend provider and stored securely in your browser.
Server endpoints that read or generate your personal health data require a valid authenticated session β they cannot be called anonymously.
Access controls
Every row of your health data β lab results, uploads, chats, logs, connection records β is tied to your user account and protected by row-level access rules. Other users cannot read or modify your data.
Administrative roles are granted manually and are never assigned based on email address alone.
Encryption
All traffic between your browser and Labs Made Clear is served over HTTPS. Health-record integration tokens (for example, FHIR access and refresh tokens) are encrypted with AES-256-GCM before being written to the database.
Data we store
We store the information you provide directly (profile, uploads, lab values, logs) and data you authorize us to import from connected health record providers. We do not sell your data.
You can delete your account and the associated records at any time from your profile.
AI processing
AI summaries and assistant features run on the model gateway we operate. Your lab values and questions are sent to the model only to produce the response you asked for, and are not used to train third-party models.
All AI-generated content is educational and is not medical advice.
Contact us
For security reports, privacy requests, or questions about how your data is handled, email security@onhealthos.com.
This page describes current product behavior and may evolve as we improve the service. It is not legal advice and does not replace our Privacy Policy or Terms of Service.
