Privacy Policy

Last updated: August 6, 2026.

Personalization and supplement lists

Only your My Supplements product list, daily labeled-serving values, and list update time are stored in versioned browser local storage. They are not saved to your Safmira account or an account database. You can view, change, or clear this list from My Supplements, and browser controls can also remove it.

For You answers such as concern, adult age band, life stage, diet, conditions, medicine or surgery status, avoided ingredients, and form preference remain in page-session memory only. They reset when For You is entered again or the page is refreshed. When older local data is migrated, Safmira keeps only valid supplement-list items and discards the older health-context fields.

When you request recommendations or a supplement check, the browser temporarily sends the information needed for that calculation in a POST request. Safmira reads repository data, returns a no-store response, and does not persist the request as a health profile. Selected concerns and conditions are not placed in page URLs, server-rendered HTML, or analytics events. Standard hosting and security request logs may still record request metadata, but the application does not log the request body.

Information we process

When you register, Safmira stores your email address, a normalized copy used for sign-in, account status, account timestamps, and recent sign-in time. We do not verify that the email address belongs to you, and accounts are not intended for sensitive information, payments, or administrative access.

Passwords and abuse prevention

Safmira never stores your plaintext password. We store a randomly salted, versioned scrypt password hash. Verification answers, session tokens, browser-binding values, and rate-limit keys are stored only as hashes or keyed hashes. Temporary failed-attempt records help prevent automated registration and sign-in abuse.

Sessions and cookies

A necessary session cookie connects your browser to a server-side session. Sessions expire after 30 days and may renew when an active session has less than 15 days remaining. Signing out revokes the current session; changing your password revokes every older session. A short-lived browser cookie binds each image verification code to the browser that requested it, and a separate cookie remembers the cookie notice choice.

Operational data

Hosting and security providers may process standard request data such as IP address, browser type, requested URL, timestamp, and error or security signals. Authentication logs are designed not to include passwords, password hashes, verification answers, session tokens, authentication secrets, or full email addresses. Safmira does not sell personal information and does not currently use advertising or analytics cookies.

Your choices

You may clear the local supplement list inside My Supplements, sign out, or delete site cookies and local storage through your browser. Blocking necessary cookies prevents registration and sign-in from working. Requests concerning personal information can be sent to privacy@safmira.com. Because email ownership is not verified and email recovery is not available, we may need additional information before acting on an account request.

Changes

We may update this policy when the service or applicable requirements change. The date above identifies the latest revision.