Skip to main content

Security at ClapDiet

The protections ClapDiet actually has, named specifically enough that you can hold us to them — and, at the end, the ones we do not claim.

What stands behind your account

Your health record is some of the most personal information you have. Here is what protects it, in terms you can check rather than adjectives you cannot.

1 year

Strict HTTPS policy

90 days

Access trail kept

0

Card details stored

How we keep you safe

Encrypted in transit

Every connection runs over HTTPS, and we send a strict-transport header covering every subdomain for a year — so your browser refuses a plain-HTTP connection to us even if something tries to force one.

Passwords are never stored

What we hold is a bcrypt hash: a one-way function slow enough that guessing through a stolen table is expensive rather than instant. Nobody here can read your password, including us.

Sign-in attempts lock out, progressively

Three failures lock the account for five minutes, five for fifteen, ten for an hour, twenty for a day. That turns thousands of guesses an hour into four.

Two-factor authentication

Optional TOTP — the rolling six-digit code from any authenticator app — with single-use backup codes that are hashed too, so the list we hold is not a list of usable codes.

Two independent access trails

The application records sign-ins, password changes and administrator actions; database triggers record changes to accounts, sessions, logins and lab panels underneath it. Both are kept 90 days.

Card details never reach us

Payments go through Stripe's own checkout page. There is no card number field anywhere in this product, which is the strongest form that promise can take.

Where your rights come from

Rights over your data are worth more than badges. These are implemented, not promised:

GDPR — download everything you have stored, correct anything, or delete your account and have the health record itself erased in one operation

HIPAA — ClapDiet is a consumer app, not a covered entity, so HIPAA does not bind us. Several of its Security Rule safeguards are in place anyway; our help centre lists which ones are not

HTTPS everywhere — with a one-year strict-transport policy and a content security policy that stops an injected script sending your data elsewhere

An access trail — including a record every time an administrator opens one person's profile or lab panel

What we do not claim

A security page is only worth reading if the absences are in it too. These are things this page used to claim and cannot support:

Encryption at rest — your data is encrypted in transit. The database itself is not separately encrypted, and saying otherwise would be the easiest sentence to write and the least true

A security certification — no SOC 2 report, no ISO 27001, and no independent audit to point you at

A bug bounty programme — there isn't one, and no penetration test has been published. Reports are still very welcome

Round-the-clock monitoring — nobody is watching a screen at 3am, and we publish no uptime figure because we do not measure one

Tips to stay safe

Here is what makes the most difference on your side:

  • Use a password you use nowhere else
  • Turn on two-factor authentication, and keep the backup codes somewhere other than your phone
  • Do not share your password with anyone
  • Log out when using a shared or public computer
  • Treat any email asking for your password as fake — we never ask
  • Keep your browser and devices updated

Found a Security Issue?

If you find a security problem, please tell us right away. We take all reports seriously and will work quickly to fix any issues.

Report a Security Issue
ClapDiet
PrivacyTermsContact

© 2026 ClapDiet. All rights reserved.