- Encrypted at rest in Supabase storage
- Only YOU can access them
- Row-level security in Postgres means no one else can read your data even with a database query
- Passwords are hashed with industry-standard algorithms (never stored plain)
- OAuth via Google available for extra safety
- Session tokens rotate regularly
- When Hippo uses Anthropic's Claude to generate outputs, your data goes to Anthropic just long enough to generate a response
- Anthropic doesn't train on your data
- Results come back to Hippo — nothing is stored on Anthropic's servers
- Google Calendar: we can only see events Hippo created (no reading your other calendars)
- Google auth: we only get your email, not your Gmail contents
- Our background jobs (email sending, streak calculation) require a signed secret
- No anonymous access to internal endpoints
- Automated vulnerability scans on every deploy
- Google OAuth tokens locked down with proper access controls
- Payment info (when live) is handled by Stripe — Hippo never sees or stores card numbers
- Email kenna@hippo.study
- We take security reports seriously, respond within 24 hours, and credit you if it's a real issue
If we ever have a security incident affecting your data, we notify you within 72 hours.
We're transparent about what happened and what we're doing to fix it.
