Security

Developer Mode is off by default. When the user enables it, SuperAge exposes a local HTTPS API intended for paired clients on the user's current local network.

Trust Model

Read-Only Boundary

Allowed data methods:

GET
HEAD
OPTIONS

The v1 API does not create, update, delete, import, recalculate, or trigger app data. Pairing endpoints may use non-read methods because they create credential state, not app or HealthKit records.

Network Availability

iOS may suspend the app while it is not active. Developer Mode does not promise background server availability. If the local API is unreachable, open SuperAge and verify Developer Mode is still active.