Noova — Health App Assessment Evidence

For ORCHA and MindApps submission. Access restricted.

A. Data Security

  • Encryption at rest: Supabase Pro plan — AES-256 encryption at rest
  • Data transmission: All data over HTTPS/TLS 1.2+
  • Authentication: Supabase Auth — email/password + Google OAuth + Cloudflare Turnstile bot protection
  • GDPR compliance: /privacy
  • Data residency: Supabase us-east-1 (AWS). EU region migration planned before institutional submission.
  • Third-party processors:
    • Anthropic — AI processing
    • Supabase — database and auth
    • RevenueCat — mobile payments
    • Stripe — web payments
    • Resend — transactional email
    • Twilio — SMS and WhatsApp
    • Cloudflare — bot protection and CDN

B. Clinical Safety

  • Noova is not a medical device
  • Clinical disclaimer: shown on onboarding ✅
  • No diagnostic claims: app copy reviewed — no clinical diagnostic language used
  • Data not used for insurance or clinical scoring ✅

C. Usability

  • Languages: 7 (EN, FR, ES, DE, PT, NL, IT)
  • Accessibility: standard web accessibility. Full audit pending.
  • Reading level: target Grade 8 or lower

D. Developer

ORCHA checklist

  • ☐ App live in App Store + Google Play
  • ☐ Privacy policy covers ORCHA requirements
  • ☑ Clinical disclaimer visible on onboarding
  • ☑ Account deletion flow working
  • ☑ HTTPS on all endpoints
  • ☐ No health claims in App Store description
  • ☐ Contact ORCHA: orchahealth.com/contact