Voke

How Voke protects your data

The technical version of how your data is protected, and how to tell us about a problem.

How your data is encrypted

Each account has its own data key. Your health data is stored in small blocks, one per day and per kind of reading, each sealed with AES-256-GCM. Account keys are wrapped by AWS Key Management Service in Canada and are never stored unencrypted. Health data, chats, morning summaries and Google tokens each use their own key derived from your account’s key.

What the server can do

Voke’s server decrypts your data to work out scores and serve it, so Voke isn’t end-to-end encrypted. Every read by another person or an AI is checked against the sharing levels you set before anything is decrypted, and it’s logged.

Your devices

Each iPhone holds a key in its Secure Enclave, and Apple Health uploads are signed with it. Deleting your account, removing a member, deleting a circle and signing out other devices each need a fresh signature from the device. Sessions last 15 minutes.

Sign-in

You sign in with Apple only. Voke has no passwords.

AI connections

AI apps connect over OAuth with PKCE. Tokens are bound to Voke’s MCP address, access tokens last one hour, and refresh tokens rotate. The tools are read-only, and you approve each connection on your phone with a switch per category.

Deletion

Deleting your account destroys its key. Within 7 days the encrypted copies left in backups can’t be read.

Infrastructure

Voke runs on AWS in Montréal, with backups in Calgary. There are no long-lived cloud keys; deploys use short-lived credentials. Server logs don’t contain health values.

What we haven’t done yet

Voke hasn’t had an outside audit or certification yet.

Report a vulnerability

Email [email protected]. Tell us what you found and how to reproduce it. We’ll reply within 3 business days. Please don’t access other people’s data or disrupt the service while testing.