← Iron Sharpens Iron

ISI Alberta Inc · Updated October 5, 2026

Security & Data Protection Statement

1. Platform and accountability ISI Alberta Inc, trading as Iron Sharpens Iron (ISI), operates isi.fitness using Base44. The platform supplies hosting, authentication, storage and integrations. Its published provider directory lists infrastructure in the United States and Israel. The Privacy Policy explains categories, purposes, recipients and transfers. ISI remains responsible for its own configuration and use of these services.

2. Access controls The application source defines owner/admin access rules for several sensitive entities and limited team/partner response functions. These rules are designed to restrict access; they are not proof that every entity, file URL or service-role function is secure in production. Administrative and service-role capabilities can exceed ordinary member permissions. We require unique staff credentials, role-appropriate access, confidentiality, timely revocation and review of privileged accounts. MFA must be enabled wherever supported and verified before privileged production access. Consent records are restricted against ordinary update/delete in the application schema. Privileged server operations can still supersede them. We therefore do not describe them as universally immutable or inaccessible to administrators. Corrections, withdrawals and legally required deletion must remain possible through controlled procedures with an audit trail.

3. Encryption, providers and assurance We rely on the platform's documented transport and storage safeguards and validate their application to our database, files, backups and credentials. We do not publish specific encryption algorithms, certification coverage or audit dates without current supporting evidence. Provider certification does not certify this app or eliminate configuration risks. The Privacy Officer maintains the evidence and reviews meaningful provider changes.

4. AI and sensitive information AI integrations process the inputs needed for the selected feature, including health-related derived rules and selected meal photos. Omitting an email or raw condition does not necessarily anonymize a request. ISI does not itself train AI on identifiable member records. Provider retention, aggregated/anonymized uses and training restrictions depend on applicable terms and settings and require verification. We do not promise universal zero retention or that all providers only return an answer and do nothing else. Required provider permission for protected sensitive data must be resolved before enabling affected flows.

5. Devices and files The browser stores sign-in/working state and onboarding drafts that can contain health or other sensitive information. Protect your device, keep software current, avoid shared browser profiles and sign out when finished. A hidden story or deleted database pointer is not proof that a media object has been erased. File-access permissions, cache behavior, deletion propagation and backups require separate review. The app is not an encrypted medical-record vault or a HIPAA-compliance assurance.

6. Incidents and lawful requests We investigate suspected access or disclosure, preserve appropriate evidence and make notices when required under the law applicable to the incident. The legal test is not always Canada's real-risk-of-significant-harm test: applicable U.S. health-app and state rules may have different triggers. Lawful government demands are reviewed and handled according to the relevant law and provider arrangements. No system is perfectly secure.

7. Good-faith vulnerability reporting Email legal@isi.fitness with subject Security, the affected component and enough nonsensitive detail to reproduce the issue. We aim to acknowledge within three business days. Do not access, retain, change or delete other members' information, exploit a finding further, run denial-of-service/social-engineering tests or use stolen credentials. Seek permission before active testing beyond your own authorized account. We will not pursue action merely for a good-faith report within these limits; this does not grant access to third-party systems or bind third parties. Allow reasonable time for remediation and coordinate any publication without exposing personal information. There is no promised financial reward.

8. Review and contact The Privacy Officer reviews access and evidence on meaningful changes and at least annually. We correct inaccurate security representations when discovered. Contact: Jade Chiles, legal@isi.fitness. Operator: ISI Alberta Inc, Alberta, Canada; contact legal@isi.fitness.