Meet NAVO. Blog. Guides. Listen. Get Started. Stay Connected. Log in.
Security & Trust

Your family's information
is safe with us.

We know you're trusting us with something deeply personal. Here's exactly how we protect it – in plain English, no jargon.

Encrypted at rest & in transit
SOC 2 Type II certified infrastructure
Row-level access controls
We never sell your data
Australian Privacy Act compliant
GDPR aware

No watered-down promises.

NAVO stores medications, allergies, legal documents, financial details. We designed the security of this product from the ground up with that in mind. This page explains what we do to protect your family's data, who can see it, and what happens if something goes wrong.

01 — Encryption

Your data is unreadable
to anyone without your key.

Your data is stored on encrypted infrastructure. Strict access controls and authentication mean that only authorised connections can ever read your information – and we keep those keys tightly secured.

✓ Active

Encrypted at rest

All data in our database is encrypted using AES-256 – the same standard used by banks and governments worldwide.

✓ Active

Encrypted in transit

Every connection between your device and NAVO is protected by TLS (HTTPS). The padlock in your browser is real and enforced.

✓ Active

Passwords never stored

We never store your password. It's converted into a one-way hash using bcrypt. Not even we can read it.

02 — Access controls

Your data is yours.
Nobody else's.

Encryption protects against external attackers. Access controls protect you from within – making sure no other NAVO user can ever see your data unless you've explicitly invited them.

We use Row-Level Security (RLS) enforced at the database level. This isn't just app logic that could be bypassed – it's a rule enforced by the database itself. Jane's data is Jane's data. Full stop.
✓ Active

Your profile, your control

Only you can access your account and the profiles you manage. No other user can see your data without an explicit invitation from you.

✓ Active

Family sharing is opt-in

You decide which family members to invite and exactly which sections they can see. Revoke access at any time.

✓ Active

Financial sections locked by default

Financial and digital accounts sections are hidden from all family members unless you explicitly choose to share them.

✓ Active

NAVO staff access

Our team does not access your profile data. We only do so if you specifically ask for technical support, and all access is logged.

03 — Infrastructure

Where your data lives.

We use best-in-class infrastructure with full-time security teams, independent audits, and enterprise-grade reliability.

Provider What they do Certification
Supabase Database, authentication & storage SOC 2 Type II
Vercel Application hosting & delivery SOC 2 Type II
Stripe Payment processing PCI DSS Level 1
Resend Transactional email delivery SOC 2 Type II
Honest note about data location: Our infrastructure providers are based in the United States, which means your data may be stored on US servers. Each provider we use offers formal Data Processing Agreements – we are executing these before public launch. Australian law governs how we handle your information, and we are implementing GDPR compliance for European and UK users.
04 — Your controls

You're always in charge.

Security isn't just something we do to protect you – it's something you have direct control over.

05 — What we will never do

Some things are simply
not for sale.

✗ Never

Sell your data

We will never sell your personal or health information to any third party. Not now, not if we grow, not if we're acquired.

✗ Never

Use your data for advertising

NAVO is ad-free. We do not use your data to serve ads, and we do not share data with advertising platforms.

✗ Never – without consent or legal obligation

Share medical info without authorisation

Your health data is yours. We do not share it with insurers, employers, or healthcare providers without your explicit request. The only exception is a lawful legal obligation such as a court order – which we'd notify you about wherever we legally can.

✗ Never

Use your data for commercial gain

We will never use your medical, health, or personal information for marketing, advertising, personalisation, or any other commercial purpose. Your data funds nothing except the service itself.

06 — Legal & compliance

Built to meet the law,
wherever you are.

✓ Compliant

Australian Privacy Act 1988

We comply with Australia's federal privacy law and all 13 Australian Privacy Principles, including specific rules for sensitive health information.

✓ In progress

GDPR (Europe & UK)

Our lawyer is adding GDPR-compliant clauses to our Privacy Policy, and we are executing Data Processing Agreements with each of our providers before public launch.

✓ Compliant

Not a medical device

NAVO is a personal information organiser. We are not regulated by the TGA. We store what you tell us – we don't diagnose, prescribe, or advise.

✓ Active

Complaints pathway

Unresolved privacy concerns can be escalated to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

On My Health Record: NAVO is not connected to the Australian Government's My Health Record system. Information you enter in NAVO is stored on our platform only and is not visible to or shared with My Health Record, any hospital system, any GP software, or any clinical database.
07 — Why free?

We're not free because you're the product.
We're free because that's the right place to start.

NAVO offers a free account because cost shouldn't be a barrier to keeping your family prepared. The basics – emergency info, medications, allergies, your parent's GP details – are free to store, free to access, and free to keep. No credit card. No time limit. That never changes.
✓ How it works

Free account, always

Sign up and add the details that matter most in an emergency – completely free. This isn't a trial. It's just how NAVO works.

✓ How we earn

Optional subscription

A low monthly subscription unlocks family sharing, document storage, and the full profile. You pay for features – not for access to your own information.

✓ Our commitment

Your data is never the revenue

We make money through subscriptions, not by selling, analysing, or monetising your personal information. That's a deliberate choice, not a default – and it won't change. If it ever did, we'd tell you, and you could leave and take your data with you.

"No system connected to the internet is 100% immune."

We take every reasonable precaution – encryption, access controls, trusted infrastructure, ongoing monitoring. But we believe in being straight with you. What we can promise is that we'll tell you promptly if something goes wrong, and we'll do everything in our power to protect you if it does.

Questions about
security?

Our privacy officer responds within 5 business days. We take every inquiry seriously.

Email privacy@meetnavo.com
Last updated: 6 June 2026 · Privacy Policy · Terms of Use