HIPAA compliant. End-to-end encrypted. Built with security as the foundation, not an afterthought.
Health data is the most sensitive data that exists. Here is exactly what we do to protect it.
All health data stored in Cureva's systems is encrypted using AES-256, the same standard used by banks and government agencies.
All data moving between your device and our servers is encrypted with TLS 1.3. Your health conversations with Eva are private and cannot be intercepted.
Staff access to health data is strictly limited, role-based, and logged. Only engineers directly responsible for operating the service can access any data, and only when required.
We implement all administrative, physical, and technical safeguards required by the HIPAA Security Rule for Protected Health Information.
We conduct regular security assessments and penetration testing. Vulnerabilities are triaged and resolved on a defined timeline based on severity.
We do not sell your personal data or health information to any third party, including advertisers, data brokers, or pharmaceutical companies. Ever.
At any time, you can export a copy of all your health data in a standard format. At any time, you can delete your account and all associated data permanently. Deletion from production systems is completed within 30 days; deletion from backup systems within 90 days.
Family alerts and data sharing are always opt-in. You choose who sees what. We never share data with another family member unless you explicitly authorize it in your account settings.
If you share a doctor report, we send it only to the healthcare provider you specify. That report is not stored on our servers after delivery.
Health Insurance Portability and Accountability Act (USA). All Protected Health Information is handled under HIPAA-compliant policies and technical safeguards.
Personal Information Protection and Electronic Documents Act (Canada). We comply with Canadian federal and BC provincial privacy requirements.
General Data Protection Regulation (EU/EEA). Users in Europe have full rights under GDPR including access, deletion, and portability.
California Consumer Privacy Act (USA). California users have additional rights including the right to know, delete, and opt out of data sales (we do not sell data).
We take security reports seriously. If you discover a security vulnerability in Cureva, please report it responsibly by emailing [email protected] with the subject line "Security Disclosure".
We will acknowledge your report within 48 hours, investigate promptly, and keep you informed of our progress. We do not pursue legal action against researchers who follow responsible disclosure principles.
Join families who trust Eva with what matters most. Beta launches August 13, 2026.
Join the Waitlist