Security Statement
Last updated: October 1, 2026
Protecting N3W
N3W operates N3 Wellness, a native iOS wellness app, and the public N3W Network directory on n3w.io. We use technical and organizational measures designed to protect account data, conversations, and professional listing information. This statement describes those measures at a high level; it is not a warranty and does not describe every control in place.
Not end-to-end encrypted: Chat and account data are protected in transit and at the infrastructure layer, but N3W does not provide end-to-end encryption for messages or AI conversations. Do not use N3 for emergencies or for sharing information you would only entrust to a clinical record system.
For more detail on what we collect and how we use it, see our Privacy Policy.
Account & access security
- Authentication: Sign-in is handled through Supabase Auth. The N3 Wellness app supports Sign in with Apple and Google. We do not operate a separate password database for those sign-in methods.
- Sessions: The iOS app uses Supabase-issued session tokens. Marketing and admin web surfaces may use browser sessions or cookies where applicable.
- Access boundaries: Many database tables use Supabase Row Level Security (RLS) so authenticated users can access only their own rows (for example chats, profile fields, and uploads tied to their account). Some data—such as published professional directory profiles—is intentionally visible to the public or to other signed-in users as described in the Privacy Policy.
- Plans & entitlements: Consumer AI plans (for example N3 Plus and N3 Pro) and usage limits are enforced server-side. Professional Network access is governed separately from consumer subscriptions.
- Administrative access: Internal admin tools are restricted and should only be used for support, safety, and operations.
Data protection
In transit
- Connections to n3w.io and our APIs are served over HTTPS (TLS).
At rest
- Application data is stored in Supabase (PostgreSQL and Storage). Our hosting provider and Supabase apply encryption and access controls at the infrastructure layer consistent with their platform documentation.
AI & PII handling
- Before content is sent to external model providers, we run pattern-based PII redaction on many chat flows (for example email addresses and phone numbers). Redaction is not perfect; you should avoid sending highly sensitive identifiers in chat when possible.
- We use additional checks on some model outputs to reduce the risk of leaked secrets or obvious PII in responses.
- Optional stricter minimization (for example redacting certain patterns before messages are stored) may be enabled in configuration; by default, messages are stored to support history sync, with redaction focused on outbound AI calls.
Uploads
- Image uploads are validated for type and size (for example up to 10 MB in current configuration).
- Where supported, EXIF metadata (such as GPS tags) is stripped from images before storage.
- Uploaded files are stored in access-controlled storage buckets tied to user or professional application workflows.
Abuse prevention
- Selected API routes apply rate limiting and related controls to reduce automated abuse.
Infrastructure & third-party services
N3W relies on vetted service providers to operate the product. Depending on the feature, this may include:
- Supabase — authentication, database, and file storage
- Vercel — hosting for n3w.io and serverless APIs
- OpenRouter (and underlying model providers) — AI inference
- Apple In-App Purchase & RevenueCat — consumer subscription status and entitlements on iOS
- Stripe Identity — professional identity verification (not consumer subscription checkout)
- Sentry — error and crash diagnostics (with field scrubbing for sensitive professional-application data where configured)
- Resend — transactional email where enabled
- Mem0 — optional structured memory features described in the Privacy Policy
Consumer subscriptions for N3 AI features are billed through Apple, not by N3W charging your card directly. Stripe is used for identity verification and may apply to legacy or administrative billing records where still present.
Vendor compliance programs (for example SOC reports) apply to those vendors' services, not to N3W as your wellness app provider. N3W does not represent that it holds SOC 2 or HIPAA certification unless separately disclosed in a signed agreement.
Professional identity verification
Professionals applying to the Network may complete identity verification through Stripe Identity. Government ID and selfie images are processed by Stripe under their policies. N3W reviews application materials for directory listing purposes; we do not guarantee the accuracy of every credential or the conduct of any independent professional.
See the Verification Policy and Professional Terms for more detail.
Monitoring & incident response
- Error monitoring: We use Sentry (and platform logs) to investigate outages, crashes, and unexpected errors. Events are scoped to operational needs and scrubbed where feasible.
- Response: We prioritize containment, investigation, and remediation based on severity. If we determine that a security incident requires notice under applicable law, we will provide notifications consistent with those requirements.
Data retention & deletion
- Account deletion: Signed-in users can request account deletion through in-app settings flows and related APIs. Deletion is designed to remove or anonymize associated application data, subject to legal, fraud-prevention, and backup constraints described in the Privacy Policy.
- Chat messages: Server-side chat history may be purged automatically after a configurable retention window (default 180 days via scheduled cleanup unless changed in production configuration). Separate long-term archive jobs may exist for operational tables—see Privacy Policy for the user-facing summary.
- Backups: Database backups may retain deleted data for a limited period before rolling off, consistent with provider retention.
Report a security issue
If you believe you have found a security vulnerability affecting N3W services, please report it responsibly:
- Email: security@n3w.io
- Include steps to reproduce, the affected URL or app version, and your assessment of impact.
- Please do not publicly disclose issues until we have had a reasonable opportunity to investigate.
General support: support@n3w.io · Privacy questions: privacy@n3w.io · Help Center