Trust & Security
Security and privacy at Faex
Faex is a digestive-wellness product built on your smartphone. This page explains where your data lives, how it is protected, the rights you have over it, and the compliance posture we can honestly stand behind.
How we use your data
How your data flows through Faex.
Select a stage to see what happens to a submitted photograph during core analysis, and what does not happen.
Submit from the app
Your photograph is uploaded from your device directly to Amazon S3 over TLS, and your analyzed results are stored in Amazon RDS.
Faex AWS
Faex runs on Amazon Web Services inside our own AWS organization.
Core analysis
Our proprietary computer-vision models run inside our AWS account. Your photograph is never sent to a third-party AI service for the core analysis.
Your result
Your photograph is uploaded from your device directly to Amazon S3 over TLS, and your analyzed results are stored in Amazon RDS.
You can view your entire history from inside the app.
- Encryption
- Your data is encrypted at rest using AWS-managed keys, and encrypted in transit using TLS. Your account is protected by industry-standard credential and session controls.
- Access control
- Access to production systems is limited to named Faex personnel on the principle of least privilege, and requires multi-factor authentication. Your stool image is scoped to your account and is accessible only through user-scoped signed URLs. No other Faex user can view your images or your history.
- Your rights
- You can view your entire history from inside the app. You can export it in a structured format to keep or to share with your own clinician. You can delete individual entries or your entire account, and we honor that deletion across our live and backup systems within a defined window. You can revoke consent to any specific data-sharing arrangement without losing access to the core wellness product.
Privacy, in plain language
The short version of how we handle your data
This is the plain-language overview. The full, binding detail lives in our formal policies, linked at the end of this section.
-
What we collect
Faex is a digestive-wellness app. We collect the information you give us to make the app work: your account details, the photograph you take of a stool sample, any symptom notes or context you choose to add, and the analyzed results Faex produces from your photograph. We also collect the technical information any modern app needs to run — device type, app version, and crash logs. We do not collect biometric identifiers, precise location, or third-party data broker profiles.
-
How consent works
You control what Faex can do with your data. When you sign up, you agree to the terms and privacy notice. When you take your first photograph, you grant camera permission. When you enroll in a specific program — like the GLP-1 companion journey — you consent to that program specifically. Every consent is separate, revocable, and versioned. You can view, export, and delete your data from inside the app at any time.
-
What we do not do
We do not sell your data. We do not use your data for advertising. We do not train third-party AI models on your photographs or your notes. We do not share your data with a data broker. Where we improve Faex's own models using user data, we do so only with your consent and only on de-identified content.
Read the full detail: Privacy Policy Consumer Health Data Privacy Policy
Compliance posture
The honest version
Faex is operated as a general wellness product under the U.S. FDA General Wellness policy. Where we work with a covered entity — for example, an employer health plan — we operate in a HIPAA-aligned manner as a Business Associate. We design our data-handling to meet state consumer health data laws, including Washington's My Health My Data Act, and to meet GDPR and UK GDPR requirements for users in the EU and UK. We do not claim SOC 2, HITRUST, or ISO 27001 certification because we have not undergone those audits; we are transparent about what we have and have not achieved.
Responsible disclosure
If you believe you have found a security issue, we want to hear from you. Contact our team and we will route it to the right people.