Skip to main content

Security & Privacy

Formulate is designed from the ground up to protect clinical data. Here's how we keep your practice and your clients safe.

Last reviewed: July 2026

Encryption & Infrastructure

All data is encrypted at rest using AES-256 and in transit using TLS 1.2+. Our database is hosted on Supabase (AWS eu-west-2, London region), so clinical data is stored in the UK. Some sub-processors operate outside the UK — see the table below.

Access Control

Row-level security (RLS) is enforced at the database level. Every query is scoped to the authenticated therapist — one practitioner can never access another's client data, even through direct API calls.

GDPR Rights & Data Protection

Use pseudonymous client labels (initials or codes). Label checks reject obvious identifiers, but free-text answers can still contain personal information. Every client has a secure data portal where they can track their homework, request deletion under GDPR Article 17, and — where their therapist has enabled response sharing — view their submitted responses. The privacy policy lists the clinical records covered by the 90-day soft-deletion purge. Permanent erasure actions have no recovery window.

AI Data Handling

Before text is sent to our AI for worksheet generation, it passes through an automated PII-stripping step that detects and replaces email addresses, phone numbers, NHS and NI numbers, postcodes, dates, and names with safe placeholders. This is a safeguard, not a guarantee, so therapists are also asked not to enter identifiable client information. Your data is never used to train AI models.

Content Security Policy

HTML pages are served with a Content Security Policy that uses per-request nonces, so inline scripts run only when signed with a valid nonce — mitigating cross-site scripting (XSS) attacks.

Backups & security testing

Automated database backups with point-in-time recovery are being enabled with our database platform (Supabase, AWS London), and restore procedures are documented internally. Penetration testing is planned as part of DSPT registration. Current status for both is published in our DTAC self-assessment (business continuity and penetration testing rows).

Subprocessors

Third-party services that process data on our behalf.

ServicePurposeData Location
SupabaseDatabase, authentication & file storageUK (London, AWS eu-west-2)
VercelApplication hosting & CDNGlobal edge (US/EU)
StripePayment processingUS / EU
ResendTransactional emailUS
AnthropicAI worksheet generation (PII-stripped input only)US
SentryError monitoring (no clinical data)US
Meta (Facebook) PixelAdvertising-performance measurement — loaded only with your cookie consentUS
Vercel Web Analytics & Speed InsightsAggregate usage analytics and page-performance measurement — loaded only with your cookie consentUS / EU
PostHogProduct analytics, to see which features are used — loaded only with your cookie consent (not yet in use)EU
AyrsharePublishing our own marketing/blog posts to social media (no client or personal data)US

Have a security concern?

Contact us at formulatetools@outlook.com

Need a Data Processing Agreement? View our DPA · DTAC self-assessment · Clinical Safety Case