SECURITY

Your camera never leaves your phone.
Security is the architecture.

RightRep is a health companion that watches you exercise. That trust is earned with engineering, not promises — here is exactly how your data is protected, from the camera feed to the cloud.

How your data is protected

Our latest internal security audit found no leaked credentials, no privilege-escalation path and no cross-account reads — its one high finding, unbounded AI spend per account, was fixed with durable metering. The design below is what keeps it that way.

📱

On-device pose analysis

The camera feed is analyzed on your phone in real time and never uploaded. Media leaves the device only when you act on it: a meal photo to log calories, a machine picture to build a profile — or a post you explicitly publish to the community feed.

🎫

Scoped upload tickets

Every media upload goes through a short-lived signed ticket bound to your account and the exact object, with per-file type and size caps and a daily byte budget. Access expires in minutes, not months.

🔑

Verified API tokens

Every API request carries a Firebase ID token verified against Google's certificates with the issuer and audience pinned — unsigned, mis-issued or foreign tokens never get through.

🛡️

Server-enforced rules

Database and storage rules run on the server. Account tier, admin status and professional badges are never writable by any client — and care-circle access is granted by you and cut the moment you revoke it.

⚖️

Metered AI usage

Every AI call is metered per account with durable daily ceilings, so abuse of the shared infrastructure is capped hard — not just rate-damped — and every prompt is logged for review.

🇧🇷

LGPD-first health data

Health data is owner-only by default. Sharing is explicit, consent-based and revocable; deletion is available in-app, on the web, and cascades fully — account, media and logs.

Report a vulnerability

Found something that looks off? Tell us and a human will investigate.

How to report

Email [email protected] with the subject "Security report". Include the steps to reproduce, the impact you see, and any account you tested with — the more concrete, the faster we can fix it.

Email a security report

What we ask

Test only against accounts you own, avoid privacy violations and data destruction, and give us a reasonable head start before publishing anything. We don't run a paid bug bounty today — reports are credited on request.

Related

📜

Privacy Policy

Exactly what the app collects — account, location, photos, health metrics — and the choices you keep.

Read the policy

🗑️

Delete your account

Everything, gone — in-app or from the web, no email required.

How deletion works

✉️

Anything else

Security questions that aren't vulnerabilities? The contact page routes you to a human.

Contact us