Security

We hold your test results and health information. This page explains how we protect it.

Who can see your information

You, Wellth's CEO and the person at Wellth working with you. No one else.

We do not sell your information, and we do not pass it on for anything other than delivering your care.

How your information is protected

  • Everything sent between you and the site is encrypted in transit.
  • Personal identity numbers and clinical notes are encrypted individually in the database with AES-256. They are never stored in plain text, and never sent to payment providers.
  • Passwords are stored as one-way hashes. We cannot see your password and we cannot recover it. We can only help you set a new one.
  • Repeated failed sign-ins lock the account, and sign-in attempts are rate limited.
  • We back up every day, and we test that the backups restore.

Proving who you are

You sign in with an email address and a password. You have to confirm the address before the account works, so no one can open an account in your name using an address they do not own.

Before you reach clinical content — results, reports, records — you confirm your identity with BankID.

Where your information is held

Our servers are in Finland, inside the EU. Sampling and analysis take place in Sweden.

The full list is in our privacy policy.

If something goes wrong

If your information is caught up in an incident, we will contact you. We will notify the Swedish Authority for Privacy Protection (IMY) within 72 hours.

We will tell you what happened, what was affected, and what it means for you.

If you find a vulnerability

Email [email protected] before you tell anyone else. We will acknowledge your report within three working days and keep you informed until it is resolved.

If you follow this policy, Wellth will not bring or support civil legal action against you. We cannot make promises about criminal liability or about third parties' rights — accessing someone else's data without authorisation is an offence under the Swedish Criminal Code, prosecuted by the state and not by us.

We hold health data, so the boundaries are narrow. Test only against your own account. Do not test against other people's accounts, do not download information that is not yours, and do not use denial-of-service attacks or social engineering against our staff, our practitioners or our laboratories.

Describing the problem is enough. Do not include anyone else's personal data in your report. If you think you need to show an example, contact us first and we will arrange an encrypted way to send it.

We do not currently pay bounties for reports, though we are glad to credit you publicly if you would like that.

What you can do

  • Use a password you do not use anywhere else.
  • Sign out on shared computers.
  • We will never ask for your password by email or over the phone. If someone does, it is not us.

Page last reviewed: August 2026. Next review: August 2027.
Questions about how we handle your information: [email protected]