Security and privacy

How we handle your data.

You're trusting us with your sleep, your heart rate and your blood work. Here's exactly where it goes and who can see it, in plain language.

Where it lives

Your wearable data, weekly briefs and any lab results you share sit in a Supabase database. Every table has row-level security switched on with no public access rules, so nothing on the open internet can read client data. Only our own server-side code, holding a private key, can. Supabase encrypts stored data and every connection to it. Our backups are encrypted before they're stored.

How your devices connect

Whoop, Oura and Withings connect through each company's own official authorization screen. You approve exactly what we receive, and you can revoke that access at any time from your account with that company, without asking us. For other devices, we'll walk you through sharing an export, and nothing connects without your say-so.

Who reads it

Alex, and the Veda Health Terminal. The Terminal is code: it computes your personal baselines and flags what moved. No AI is involved in that detection, and every decision about your training is made by Alex. Your data isn't shared with anyone else, except service providers who help run the program under contract, as set out in our privacy policy.

Where AI is used, plainly

Arnold for clients. Enrolled clients get Arnold, a 24/7 assistant for training and logistics questions. It runs on xAI's Grok model, so when you ask Arnold something, the parts of your data needed to answer it are sent to xAI to generate the reply.

Arnold on this website is a separate assistant. It never sees any client's data. When it explains how the Terminal works, it uses a synthetic demo client, and its own data handling is covered in the privacy policy.

Payments

Checkout runs on Stripe. Your card details go straight to Stripe and never reach our servers.

Your controls

You can ask us at any time to export your data, correct it, or delete it and withdraw consent to processing. Disconnect a device yourself whenever you like. To make a request, email alex@getexpeditionready.com.

What we haven't done yet

We haven't had an outside security audit or penetration test. When we do, we'll name the firm and the date here, rather than imply one exists before it does.