Trust & Security

How we protect your data

You share real things with us — health details, caregiving situations, family circumstances. Here's exactly what we do to protect that, and just as importantly, what we don't claim to do.

What's actually in place

lock

Encrypted in transit and at rest

Your data lives on Supabase's managed Postgres infrastructure and is served through Vercel — both encrypt data in transit and at rest as part of their own infrastructure.

database

Row-level database security

Access to sensitive tables is restricted at the database level with Postgres Row Level Security, not left to application code alone to enforce.

https

HTTPS everywhere, hardened headers

Every page is served over HTTPS, with security headers — X-Frame-Options, HSTS, Referrer-Policy and more — to reduce common web attacks.

admin_panel_settings

Hardened admin access

Our admin panel requires a properly generated signing secret. The app refuses to run with a missing or weak one rather than falling back to a guessable default.

speed

Rate limiting on sensitive actions

Sign-up, provider enquiries, and provider applications are rate-limited to reduce automated abuse.

file_download

You control your data

Request a copy of your data, correct it, or delete your account at any time. We do not sell your personal data to anyone.

public

Safeguards on cross-border transfer

Supabase and Vercel apply Standard Contractual Clauses to data that leaves Singapore — Supabase DPA Clause 12.1, and Vercel DPA Schedule 3 (Cross Border Data Transfer Mechanism) together with Schedule 5 (UK IDTA).

credit_card

Payments handled by Stripe

We never see or store your card details. Payments are processed by Stripe, a PCI-DSS Level 1 certified payment processor.

How Smart Plans uses AI

Smart Intake — the matching on our Find Help page — runs on REFRAME's own rule-based logic and does not call a third-party AI provider.

Smart Plans (“reFrame My Life” and “reFrame Care”) is different: the situation text you type is sent to Anthropic, the maker of Claude, to generate your plan. We do not have a Zero Data Retention agreement with Anthropic in place today. Anthropic's standard commercial terms state they do not train models on API customer data, but may retain request data for a limited period for safety and abuse-monitoring purposes. We're reviewing whether to pursue a Zero Data Retention agreement.

Full detail is in our Privacy Policy, Section 7.

Where we draw the line

It's easy for a security page to list impressive-sounding certifications that don't actually apply to the company. We'd rather be precise about what's true today than borrow the language of standards we haven't met.

remove_circle_outline

Not HIPAA compliant

HIPAA is a US healthcare law that doesn't apply to REFRAME, a Singapore platform. We don't use HIPAA language to describe our practices, and we haven't sought HIPAA certification.

remove_circle_outline

No biometric authentication

REFRAME is a web platform, not a native app — there's no Face ID or Touch ID to offer, so we don't claim it.

remove_circle_outline

No Business Associate Agreements (BAAs)

A BAA is a HIPAA-specific contract. Since HIPAA doesn't govern us, we don't sign them, and a vendor offering one wouldn't change our own compliance posture.

remove_circle_outline

No independent security audit yet

We haven't undergone a formal third-party penetration test or a SOC 2 / ISO 27001 audit. If that changes, we'll update this page rather than implying it's already done.

remove_circle_outline

No Zero Data Retention agreement with our AI provider

Smart Plans sends situation text to Anthropic to generate a plan. We don't have a Zero Data Retention agreement with them today — see below.

Questions we get asked

Do you sell my data?

No. We do not sell personal data, and we do not share it with advertisers. See our Privacy Policy for exactly who we do share it with, and why.

Is my payment information safe?

Yes — payments are handled entirely by Stripe. REFRAME never sees or stores your card number.

Can I delete my data?

Yes, at any time — from Account Settings, or by emailing our Data Protection Officer at dpo@reframeasia.com. Your profile is deleted; community contributions are anonymised rather than removed, since other members may be relying on that thread.

Do you use AI on my information?

Only if you use Smart Plans ("reFrame My Life" or "reFrame Care"), and only the situation text you choose to type. See "How Smart Plans uses AI" below for the detail, including what we don’t yet have in place.

Where is my data stored?

With Supabase and Vercel, which may store or process data outside Singapore under the contractual safeguards described above. Full detail is in our Privacy Policy.

Want the full detail?

Our Privacy Policy covers exactly what we collect, why, who we share it with, and how long we keep it — including the parts we're still working on.