Noova — Health App Assessment Evidence
For ORCHA and MindApps submission. Access restricted.
A. Data Security
- Encryption at rest: Supabase Pro plan — AES-256 encryption at rest
- Data transmission: All data over HTTPS/TLS 1.2+
- Authentication: Supabase Auth — email/password + Google OAuth + Cloudflare Turnstile bot protection
- GDPR compliance: /privacy
- Data residency: Supabase us-east-1 (AWS). EU region migration planned before institutional submission.
- Third-party processors:
- Anthropic — AI processing
- Supabase — database and auth
- RevenueCat — mobile payments
- Stripe — web payments
- Resend — transactional email
- Twilio — SMS and WhatsApp
- Cloudflare — bot protection and CDN
B. Clinical Safety
- Noova is not a medical device
- Clinical disclaimer: shown on onboarding ✅
- No diagnostic claims: app copy reviewed — no clinical diagnostic language used
- Data not used for insurance or clinical scoring ✅
C. Usability
- Languages: 7 (EN, FR, ES, DE, PT, NL, IT)
- Accessibility: standard web accessibility. Full audit pending.
- Reading level: target Grade 8 or lower
D. Developer
- Company: Noova LLC, Milwaukee, WI, USA
- Support: support@noova.app
- Privacy: https://noova.app/privacy
- App Store: Coming soon
- Google Play: Coming soon
ORCHA checklist
- ☐ App live in App Store + Google Play
- ☐ Privacy policy covers ORCHA requirements
- ☑ Clinical disclaimer visible on onboarding
- ☑ Account deletion flow working
- ☑ HTTPS on all endpoints
- ☐ No health claims in App Store description
- ☐ Contact ORCHA: orchahealth.com/contact