Privacy policy

Last updated: ⚠ TO FILL: date

The whole policy in one line: your health records are encrypted on your own device with a key we never receive, so the only personal data we actually hold is your email address and whether you have paid.

Who we are

The Data Fiduciary under the Digital Personal Data Protection Act, 2023 is ⚠ TO FILL: registered business name and full postal address . Contact details are on the contact page.

What we collect

DataWhyWhen
Email addressTo hold your subscription and send receiptsOnly if you subscribe
Subscription state and planTo know what your account is entitled toOnly if you subscribe
An encrypted blob, and its approximate sizeSo you can restore onto a new phoneOnly if you turn on backup
Payment reference from RazorpayTo match a payment to your accountOnly if you pay

Free use collects nothing at all — no account, no email, no analytics. The app works with the network switched off.

What we cannot collect

Not "will not" — cannot. Your medicines, conditions, test results, doctors, attachments and the names of the people in your vault are encrypted before they are written to storage or sent anywhere. We never receive your PIN or your recovery codes, so we have no way to decrypt any of it. We do not store an exact blob size either, because an exact size is a proxy for how much illness someone has accumulated.

What we never do

  • We never sell your data, to anyone, for any purpose.
  • We never use your records to train anything.
  • We never share with insurers, employers or advertisers.
  • We run no third-party analytics or advertising trackers on your records.

Who else is involved

Supabase hosts the database and encrypted backups, in Mumbai, India (ap-south-1). Razorpay processes payments and receives your email and payment details directly — we never see your card or UPI credentials. Neither can read your records.

How long we keep things

Your encrypted backup stays until you delete it or ask us to. After an account is closed we erase it within ⚠ TO FILL: erasure window, e.g. 30 days . Payment records are kept as long as Indian tax law requires ( ⚠ TO FILL: retention period ).

Your rights under the DPDP Act 2023

You have the right to access, correct and erase your personal data, to withdraw consent, to nominate someone to act for you, and to complain to the Data Protection Board of India. Write to the grievance officer on the contact page; we respond within ⚠ TO FILL: response window .

One honest limit: we can erase what we hold — your email, subscription and encrypted blob. We cannot erase, correct or produce the contents of your records, because we cannot read them. That copy is on your device and under your control.

Children

Under-18s do not have accounts. A child's records are a profile inside a parent's or guardian's vault — no login, no seat, no separate row on our servers. At 18 the app offers to hand the record over to them.

If there is a breach

We will notify affected users and the Data Protection Board as the DPDP Act requires. What an attacker would obtain is email addresses, subscription states and blobs they cannot open — but we would tell you all the same, and say exactly what was taken.

Draft. Not yet reviewed by a lawyer, and several details above are still unfilled. Do not accept a payment against this policy until both are done.