Security & Data Protection

Last Updated: January 2025
Version: 1.0
Legal Entity: QBod LLC

This document describes QBod's security practices and technical safeguards for protecting your data. It is provided for transparency and applies to employees, contractors, and service providers.

1. Policy Scope and Purpose

1.1 Purpose

This Security & Data Protection Policy establishes the technical and organizational measures QBod LLC implements to protect user data, ensure system integrity, and maintain regulatory compliance.

1.2 Applicability

This Policy applies to:

2. Data Classification

2.1 Sensitive Health Data

While QBod is not a HIPAA-covered entity, we treat the following as sensitive health data:

Protection Level: Highest (AES-256 encryption, strict access controls, audit logging)

2.2 Personal Identifiable Information (PII)

Protection Level: High (TLS 1.3 encryption, hashed passwords, role-based access)

3. Encryption Standards

3.1 Data in Transit

3.2 Data at Rest

3.3 End-to-End Encryption

4. Authentication and Access Control

4.1 User Authentication

4.2 Internal Access Control

5. Infrastructure Security

5.1 Cloud Infrastructure

5.2 Application Security

5.3 Mobile Application Security

6. Backup and Disaster Recovery

6.1 Backup Strategy

6.2 Disaster Recovery

7. Incident Response

7.1 Security Incident Types

7.2 Incident Response Process

7.3 Breach Notification

If a data breach affects user data, QBod will:

8. Compliance

8.1 Current Compliance

8.2 Regular Audits

9. Third-Party Service Providers

9.1 Vendor Security Requirements

All third-party vendors must:

9.2 Current Service Providers

Google Gemini (AI Processing):

Supabase (Database):

AWS (Infrastructure):

RevenueCat (Subscriptions):

10. Contact Information

For security-related questions, concerns, or vulnerability reports:

Email: support@qbod.fit
Mailing Address: QBod LLC

For specific security requests, use subject lines: