Security at Olive

Effective Date: June 23, 2025

Last Updated: August 31, 2026

Olive protects personal and entrusted information through controls that are specific to the function, identity, authority, and record involved. This page describes controls currently established in the Olive architecture; it does not promise that any security system is infallible.

Important: Olive is not a medical, clinical, or emergency service. If you or someone you know is in immediate danger, call your local emergency number. See our Crisis Resources.

1. Governing security model

2. Data protection

Encryption reduces risk but does not eliminate it. Olive does not describe provider-managed encryption as end-to-end encryption unless a specific feature separately establishes that property.

3. Authentication and privileged access

Authentication is provided through Supabase Auth. Authorization remains separate from authentication.

Olive does not publicly claim that every provider console or administrative surface enforces SSO, device trust, or a particular MFA configuration unless that control has been independently verified for the stated surface.

4. Application and service controls

5. AI processing and safety

Olive's AI companion may generate supportive prompts or responses when an authorized product function invokes an AI provider.

Users should not rely on Olive or its AI for emergency monitoring or outreach.

6. Child and Teen protections

Before age 13, a Child does not independently operate Olive or independently submit personal information or content through the Child account. Authorized guardian or facilitator assistance does not transfer ownership, confer recipientship, or reveal future-undelivered matter.

Teen protections include privacy-protective defaults, data minimization, no sale of Teen personal information, no behavioral advertising to Teens, no monetization of Teen Vault contents, no unnecessary engagement surveillance, no unnecessary public discoverability, and restricted unsolicited contact from unknown adults.

Olive is not a public people directory or open social-discovery service. A relationship or connection does not itself grant administrative authority or Vault access.

7. Logging, audit, and monitoring scope

Olive preserves designated security, authority, provenance, delivery, recovery, and lifecycle events where the governing architecture requires them. Not every user interaction or provider-console action is represented as an Olive audit event.

Integrity checks are used for protected Vault matter and source-governance assertions. Olive does not claim universal real-time security monitoring, automated anomaly alerting, or periodic review of every privileged action unless a specific control is independently established.

8. Retention, deletion, and recovery

Retention and deletion depend on the record's authority and obligations. Ordinary personal content, Entrusted Originals, recipient-held matter, provenance, delivery history, shared rights, legal holds, minimum security records, and historical attribution may have different treatment.

Only an Adult may initiate permanent deletion of their own identity or account. Child or Teen withdrawal is not permanent deletion. Account deletion does not authorize falsifying another person's legitimate surviving history or altering an Entrusted Original.

Recovery mechanisms are intended to restore protected continuity after a verified failure; they are not a promise that every record can always be recovered from every failure.

9. Incident response and legal obligations

Olive investigates reported security issues and will make notifications required by applicable law. Legal constraints are applied as narrowly as practicable while preserving unaffected protections and provenance. Olive does not adjudicate family disputes.

10. Responsible disclosure

To report a suspected security vulnerability:

11. Contact

This document will be updated when validated controls or providers materially change. The OLIVE Trust Charter remains the governing public trust commitment.