Security Statement

What actually protects your account and your data in PHYSIOATHLETX — and, just as importantly, what we do not claim.

1. Accounts and passwords

Authentication is handled by Supabase Auth. Passwords are stored only as salted hashes by that service. We never see, log or store your password in plain text, and no one at TECHFORWARD SOLUTIONS LIMITED can read it. Password resets go through a one-time link sent to your registered email address.

2. Your rows are yours

Every table in our database is protected by row-level security. The database itself — not just the application code — enforces that a signed-in account can read and write only the rows belonging to that account. A request carrying one user's session cannot return another user's workouts, check-ins, nutrition logs, coach chats or subscription record, even if the application code asked it to.

We do not take that on trust. An automated adversarial probe runs against the live database, signing in as a real test account and deliberately attempting cross-account reads, writes, updates and deletes on every table. Any table that answers a request it should have refused fails the probe.

3. Keys and server-side access

There are two database keys and they are kept strictly apart. The public, restricted key is the only one that reaches the browser, and it is subject to row-level security like any other client. The privileged service key bypasses those policies, so it lives only in server-side environment variables, is used only inside server code for narrow tasks such as processing a payment webhook, and is never included in any bundle shipped to a browser.

4. Encryption

All traffic between your device and the service runs over HTTPS with TLS. Data at rest is encrypted by our infrastructure providers (Supabase for the database and authentication, Vercel for hosting).

5. Payments

Card details are handled entirely by Airwallex on their own hosted checkout. Airwallex is a PCI-DSS compliant payment processor. Card numbers, expiry dates and security codes are entered on their pages, never on ours — they do not pass through our servers and we never store them. What we receive back is a customer reference and a subscription status.

Details of what we charge and when are in the Payment Policy.

6. Webhooks

Payment events arrive as webhooks. Every incoming webhook is verified against its cryptographic signature before it is allowed to change anything. A request that fails signature verification is rejected, so a forged call cannot grant, extend or cancel access.

7. AI features

The coach chat and food-photo estimates send a deliberately narrow slice of context to Anthropic: the coach messages you write and the recent turns of that same conversation, your goal, the titles of your programs and sessions, recent workout feedback, your plan tier, and any photo you choose to submit. Your selected conditions, safety-screen answers, daily check-ins and nutrition history are never sent, and a message containing pain, injury or crisis wording is answered by a fixed pre-written response without any request leaving the app. Both features are rate limited per account, which caps how much can be requested if credentials are ever misused. See the Privacy Policy for the full processing detail.

8. Operator access

Access to production systems is limited to the people who need it to run the service, held under named individual accounts, and kept to the least privilege the job requires. We do not browse user content, and support requests are answered from what you tell us rather than by reading through your records.

9. What we do not claim

We hold no security certification and we will not imply one. We are not certified against SOC 2, ISO/IEC 27001 or any comparable scheme, and we have not been independently audited against one.

We are also not a HIPAA covered entity or business associate. Health-adjacent information you enter is protected by the measures on this page and by our Privacy Policy and Consumer Health Data Privacy notice — not by HIPAA.

And the plain truth: no online service can guarantee absolute security. We reduce risk with the controls described here and keep improving them, but we cannot promise that no incident will ever happen.

10. Reporting a vulnerability

If you find a security weakness, tell us before you tell anyone else. Email support@physioathletx.com with the affected area, clear steps to reproduce, and what an attacker could do with it. Proof-of-concept detail is welcome.

We aim to acknowledge your report within 5 business days and will keep you updated while we work on a fix.

We will not pursue legal action against researchers who act in good faith: report promptly and privately, use only your own test accounts, stop as soon as you have confirmed the issue, do not access, modify or exfiltrate anyone else's data, do not degrade or disrupt the service, and do not publish before we have had a reasonable chance to fix it. We do not currently run a paid bug bounty, so we cannot offer a reward — we can offer a fast fix and public credit if you want it.

11. What you can do

  • Use a strong password that you do not use on any other site, and keep it in a password manager.
  • Sign out when you finish on a shared or public device, and do not let anyone else use your account.
  • Assume any message asking for your password is a phishing attempt — we never ask for it.
  • If you see activity in your account that was not you, or a charge you do not recognize, email support@physioathletx.com straight away.

12. If something goes wrong

If a security incident affects your personal data, we will investigate, contain it, and notify affected users and the relevant regulators as required by applicable law, without undue delay. Our notice will say what happened, what data was involved, what we have done and what you should do.

13. Contact

TECHFORWARD SOLUTIONS LIMITED
Unit 2A, 17/F Glenealy Tower
No.1 Glenealy, Central
Hong Kong
Company number 76317223 (Hong Kong)

support@physioathletx.com