Tech FAQs
What application architecture do you use?
1
The application is built as a multi-tenant web application using Django as the application framework and PostgreSQL as the relational database. The platform is hosted on AWS, with PostgreSQL running on Amazon RDS.
Is customer data logically separated in a multi-tenant environment?
2
Yes. The application is designed as a multi-tenant platform with logical separation of tenant data enforced at the application and database layers to ensure customers can only access their own data.
Where is customer data stored?
3
Customer data is stored in PostgreSQL hosted on Amazon RDS within AWS infrastructure.
Is data encrypted at rest?
4
Yes. Data stored within the platform, including data residing in Amazon RDS, is encrypted at rest.
Is data encrypted in transit?
5
What cloud provider hosts the application?
6
How is the database managed?
7
Yes. Communications between clients and the application, as well as communications with backend services, are encrypted in transit using industry-standard TLS encryption.
What database technology is used?
8
The application uses PostgreSQL as its primary relational database management system.
Access to customer data is controlled through application-level authentication and authorization mechanisms within the Django application, along with tenant-aware data access controls to ensure users can only access data belonging to their organization.
How is access to customer data controlled?
9
The application is hosted on Amazon Web Services (AWS), leveraging AWS-managed infrastructure and services.
The PostgreSQL database is hosted on Amazon RDS, AWS's managed relational database service. This reduces operational overhead and provides managed database infrastructure, monitoring, backup capabilities, and high availability options.
What security measures protect customer information?
10
Key security measures include:
Encryption of data at rest.
Encryption of data in transit using TLS.
Logical tenant isolation within the multi-tenant architecture.
AWS-hosted infrastructure utilizing Amazon RDS for managed database operations.
Application-level authentication and authorization controls.
Restore Enterprises LLC (Restore) collects your personal information to provide personalized wellness insights and planning tools through its Services. Data is gathered directly from you (e.g., email, sleep habits, demographic data), generated by your use of the application, and collected via authorized integrations like your calendar (for scheduling information) and wearable devices (for physiological signals like heart rate and sleep data). This information, which may include sensitive health-related data, is used to calculate personalized metrics like your Chronotype, Energy Blueprint, and Restore Score. These outputs are informational estimates for general wellness planning and are explicitly not medical advice or performance evaluations.
Restore shares your data only with third-party service providers necessary to operate the Services (such as cloud hosting and integration partners) and is committed to not selling your information or using it for advertising purposes. For users accessing Restore through an enterprise program, your individual data—including your personal scores, sleep information, and calendar details—remains strictly private and is never accessible to your employer or administrators. Sponsoring organizations only receive anonymized, aggregated reports that reflect overall workforce trends, ensuring no individual user can be identified from the shared data. Restore implements appropriate security measures, including encryption, to protect the personal information it processes.