How we handle your data.
You're trusting us with your sleep, your heart rate and your blood work. Here's exactly where it goes and who can see it, in plain language.
- It's never sold and never used for advertising.
- It's read by Alex and by our own software, and no public part of the system can reach it.
- Devices connect through the official authorization each company provides, and you can cut them off at any time.
- You can export it or have it deleted whenever you ask.
- Coaching, not medicine. We never diagnose or prescribe. Anything medical goes to your physician.
Where it lives
Your wearable data, weekly briefs and any lab results you share sit in a Supabase database. Every table has row-level security switched on with no public access rules, so nothing on the open internet can read client data. Only our own server-side code, holding a private key, can. Supabase encrypts stored data and every connection to it. Our backups are encrypted before they're stored.
How your devices connect
Whoop, Oura and Withings connect through each company's own official authorization screen. You approve exactly what we receive, and you can revoke that access at any time from your account with that company, without asking us. For other devices, we'll walk you through sharing an export, and nothing connects without your say-so.
Who reads it
Alex, and the Veda Health Terminal. The Terminal is code: it computes your personal baselines and flags what moved. No AI is involved in that detection, and every decision about your training is made by Alex. Your data isn't shared with anyone else, except service providers who help run the program under contract, as set out in our privacy policy.
Where AI is used, plainly
Arnold for clients. Enrolled clients get Arnold, a 24/7 assistant for training and logistics questions. It runs on xAI's Grok model, so when you ask Arnold something, the parts of your data needed to answer it are sent to xAI to generate the reply.
Arnold on this website is a separate assistant. It never sees any client's data. When it explains how the Terminal works, it uses a synthetic demo client, and its own data handling is covered in the privacy policy.
Payments
Checkout runs on Stripe. Your card details go straight to Stripe and never reach our servers.
Your controls
You can ask us at any time to export your data, correct it, or delete it and withdraw consent to processing. Disconnect a device yourself whenever you like. To make a request, email alex@getexpeditionready.com.
What we haven't done yet
We haven't had an outside security audit or penetration test. When we do, we'll name the firm and the date here, rather than imply one exists before it does.