Privacy policy
Last updated: ⚠ TO FILL: date
The whole policy in one line: your health records are encrypted on your own device with a key we never receive, so the only personal data we actually hold is your email address and whether you have paid.
Who we are
The Data Fiduciary under the Digital Personal Data Protection Act, 2023 is ⚠ TO FILL: registered business name and full postal address . Contact details are on the contact page.
What we collect
| Data | Why | When |
|---|---|---|
| Email address | To hold your subscription and send receipts | Only if you subscribe |
| Subscription state and plan | To know what your account is entitled to | Only if you subscribe |
| An encrypted blob, and its approximate size | So you can restore onto a new phone | Only if you turn on backup |
| Payment reference from Razorpay | To match a payment to your account | Only if you pay |
Free use collects nothing at all — no account, no email, no analytics. The app works with the network switched off.
What we cannot collect
Not "will not" — cannot. Your medicines, conditions, test results, doctors, attachments and the names of the people in your vault are encrypted before they are written to storage or sent anywhere. We never receive your PIN or your recovery codes, so we have no way to decrypt any of it. We do not store an exact blob size either, because an exact size is a proxy for how much illness someone has accumulated.
What we never do
- We never sell your data, to anyone, for any purpose.
- We never use your records to train anything.
- We never share with insurers, employers or advertisers.
- We run no third-party analytics or advertising trackers on your records.
Who else is involved
Supabase hosts the database and encrypted backups, in Mumbai, India (ap-south-1). Razorpay processes payments and receives your email and payment details directly — we never see your card or UPI credentials. Neither can read your records.
How long we keep things
Your encrypted backup stays until you delete it or ask us to. After an account is closed we erase it within ⚠ TO FILL: erasure window, e.g. 30 days . Payment records are kept as long as Indian tax law requires ( ⚠ TO FILL: retention period ).
Your rights under the DPDP Act 2023
You have the right to access, correct and erase your personal data, to withdraw consent, to nominate someone to act for you, and to complain to the Data Protection Board of India. Write to the grievance officer on the contact page; we respond within ⚠ TO FILL: response window .
One honest limit: we can erase what we hold — your email, subscription and encrypted blob. We cannot erase, correct or produce the contents of your records, because we cannot read them. That copy is on your device and under your control.
Children
Under-18s do not have accounts. A child's records are a profile inside a parent's or guardian's vault — no login, no seat, no separate row on our servers. At 18 the app offers to hand the record over to them.
If there is a breach
We will notify affected users and the Data Protection Board as the DPDP Act requires. What an attacker would obtain is email addresses, subscription states and blobs they cannot open — but we would tell you all the same, and say exactly what was taken.
Draft. Not yet reviewed by a lawyer, and several details above are still unfilled. Do not accept a payment against this policy until both are done.