Privacy Policy

Effective date: 14 July 2026  ·  Last updated: 14 July 2026

This policy explains, in plain language, what data VitalMaa collects, why, who it is shared with, and the choices you have. It is written to comply with India's Digital Personal Data Protection Act, 2023 (DPDP Act) and the Digital Personal Data Protection Rules.

1. Who we are

VitalMaa is a health and wellness mobile app made for Indian families. It is operated by Sai Rakshith Muda (individual developer, India).

For the purposes of the DPDP Act, 2023, we are the Data Fiduciary for the personal data you share with VitalMaa.

2. Summary

  • VitalMaa is a health-tracking and health-education app. It is not a medical device, it does not diagnose, and it does not prescribe medication. Always consult a qualified doctor.
  • We collect the data you choose to give us (profile, food logs, exercise logs, blood reports, chat with Vaidya, and more) plus a small amount of technical data needed to run the app (device type, crash logs, push token, IP address).
  • We do not sell your data. We do not use your health data for advertising, and we do not share identifiable health data with advertisers or data brokers.
  • This version of the app is free. We do not collect payment information.
  • Your data is stored on Supabase (hosted on AWS in Mumbai, India). The app's AI features — Vaidya chat, reading your blood-report and food photos, and the voice assistant — are processed by Sarvam AI in India. Crash logs and usage analytics are processed by Google Firebase.
  • You can view, export, and delete your data from Settings → Export My Data / Delete Account.
  • VitalMaa is intended for adults 18 and older. For users under 18, a parent or legal guardian must set up the profile and give verifiable consent.

3. What personal data we collect

3.1 Data you provide directly

CategoryExamplesWhen collected
IdentityFirst name, age, gender, phone number, email, stateOnboarding, profile setup
Body metricsHeight, weight, BMI, target weightOnboarding + edit profile
Medical historyMedical conditions, family roleOnboarding
Dietary preferencesDiet type, food allergiesOnboarding
Activity & fitnessFitness level, exercise preferences, injuries, weekly goalOnboarding
MedicationsDrug name, dosage, frequency, timingOptional — medications module
Blood reportsLab report PDFs / images, extracted biomarker valuesReport upload
Health diariesBlood pressure, blood sugar, mood, symptoms, sleep, women's-health cycle (all optional)When you use those trackers
Food logsMeal names, portion sizes, calories, macrosEach time you log food
Exercise logsActivity name, duration, calories burnedEach workout
Water logsGlasses consumedWater tracker
Chat messagesQuestions to Vaidya, Vaidya's repliesEvery chat turn
Family dataFamily member name, relationship, phoneFamily module (only if you invite)
Voice audioVoice clips for the voice assistantOnly while you use the mic. Sent to Sarvam AI for speech-to-text; the text transcript is kept with your Vaidya history and the spoken reply audio is stored privately (both are removed when you delete your account).
PhotosReport photos, food photosOnly the specific photo you upload. Sent to Sarvam AI to read the text/food in it.

3.2 Data collected automatically

CategoryExamplesPurpose
Device infoOS version, device model, language, timezone, app versionCompatibility + support
Crash dataStack traces, device state at crash timeDebugging via Firebase Crashlytics
Usage analyticsScreen views, feature-usage counts, session durationProduct improvement via Firebase Analytics. No advertising IDs, no cross-app tracking, and no health information is sent to analytics.
Push tokenFirebase Cloud Messaging tokenMedication reminders & insights
IP addressYour device's public IPSeen by our network proxy (Cloudflare) and backend in transit; used for security and rate limiting
Health ConnectSteps, heart rate, sleep, calories, SpO2, blood pressure, glucose, weight — only if you grant permissionPersonalising plans and insights

3.3 Device settings we check on your phone (and never send anywhere)

Android lets you switch off notifications, silence one reminder type, revoke exact alarms, or let the battery saver close VitalMaa in the background. Any of these stops a medicine reminder from arriving, and none of them tells the app it happened — so we check them on your device and tell you what we find.

What we readWhyWhere it goes
Whether notifications are enabled for VitalMaaTo warn you that nothing can reach youStays on your phone
Whether one reminder type is switched off (e.g. medicine alarms)To warn you that only that reminder is silentStays on your phone
Whether exact alarms are allowedTo warn you that doses may arrive lateStays on your phone
Whether VitalMaa is exempt from battery optimisationTo warn you that your phone may discard pending alarmsStays on your phone
Your phone's manufacturer and brandTo show the correct settings path for your brandStays on your phone

None of this is transmitted, stored on our servers, or shared. It is read when you open Settings → Notifications, when you add a medicine, and when you return to the app, and it is discarded immediately. We record two anonymous usage counts — that a reminder-health screen was opened, and that a test alarm was sent — under the same analytics consent as everything else in 3.2. Neither records which setting was switched off on your phone.

3.4 Data we do NOT collect

  • We do not use tracking cookies for advertising.
  • We do not collect precise background location (location is used only in the foreground, when you tap a feature that needs it).
  • We do not read your contacts.
  • We do not scan your photo library or any videos.
  • We do not collect payment information in this version.
  • We do not sell your data to data brokers, advertisers, or insurance companies.

3.5 Permissions we ask for, and what happens if you say no

Every permission is optional. Declining one disables the feature that needs it and nothing else — the app keeps working.

PermissionUsed forIf you decline
NotificationsMedicine reminders, family alerts, meal/water nudgesNo reminders arrive; everything else works
Alarms & reminders (exact alarms)Firing a dose reminder at the minute you setReminders still fire, but the system may delay them
Ignore battery optimisationKeeping medicine reminders alive when your phone tries to close VitalMaa in the backgroundReminders may be dropped by your phone. We warn you and show you where to change it
CameraFood photos, lab report photos, phone-camera heart-rate readingsType or upload instead
MicrophoneSpeaking to VaidyaType instead
PhotosUploading a report or food image you pickUse the camera instead
Coarse / fine location"Labs near me", seasonal tips, SOSSearch by pincode instead
Physical activityStep countingLog workouts manually
Health ConnectReading your watch/band dataLog manually; nothing else changes

Ignore battery optimisation deserves a specific note, because Google Play treats it as a restricted permission. We request it only from the medicine reminder flow, only after you ask us to, and never at first launch. We use it for exactly one purpose: keeping scheduled medication reminders alive. It grants no access to any data.

4. How we get your consent (lawful basis)

We process your personal data only on these lawful bases:

  1. Your consent (DPDP Act §6). You give consent by choosing to create your profile and use each feature. For sensitive access — camera, microphone, location, and Health Connect — your device shows a standard permission prompt that you must accept before that feature can work.
  2. Legitimate uses without consent (DPDP Act §7): §7(a) data you provide voluntarily, §7(b) a service you asked for, §7(f) medical emergency.

For health data specifically, we rely on your explicit, informed consent — given by your choice to enter that data and by accepting the relevant device permission prompts.

5. Purposes of processing

We use your data ONLY for: running the app, personalising recommendations, sending reminders, safety alerts, crash debugging, non-health usage analytics, and responding to support requests. We do not use your health data for advertising, insurance underwriting, employment decisions, credit scoring, or any third-party profiling.

6. Who we share data with (sub-processors)

To run VitalMaa we use the service providers below. Each receives only the data listed, and only to do its job for us.

Sub-processorWhat they doData they seeLocation
SupabasePrimary backend — database, file storage, sign-in, and server functionsAll your profile, logs, reports, chat, and health dataAWS ap-south-1 (Mumbai, India)
Sarvam AIThe main AI engine: powers Vaidya chat, reads your blood-report and food photos (text recognition), and runs the voice assistant (speech-to-text and text-to-speech)Voice audio and transcripts, medical-report images, food photos, your questions to Vaidya and the profile/health context sent with them, and inputs for exercise plans and health predictionsIndia
Google FirebaseCrash reporting (Crashlytics), usage analytics, and push notifications (Cloud Messaging)Crash logs, non-health usage events, and your notification tokenGoogle (US / EU)
Google Sign-InOptional Google loginEmail, name, Google account ID — only if you sign in with GoogleGoogle (US / EU)
MSG91Delivers the one-time password (OTP) SMS for phone sign-inYour phone numberIndia
CloudflareRoutes app traffic to our backend (a proxy that sits in front of Supabase)Request contents in transit and your IP addressGlobal edge network
Open Food FactsLooks up packaged foods when you scan a barcodeThe scanned barcode only — no personal dataEU
USDA FoodData CentralLooks up nutrition when you search the US food databaseThe food name you search — no personal dataUSA
Google MapsOpens Maps when you tap "labs near me" or share an SOS locationThe map search you start, by your own actionUSA

Your health data lives and is processed in India (Supabase and Sarvam AI). We do not share your data with advertisers or data brokers.

7. Cross-border data transfers

Your main data store and the main AI processing (Supabase and Sarvam AI) are in India. Some providers are outside India: Google Firebase and Google Sign-In (US / EU), USDA (USA, food lookups only), and Google Maps (USA, only when you start a map search). Data sent to any of them travels over encrypted (TLS) connections. These transfers are permitted under DPDP Act §16.

8. Your rights under the DPDP Act

  1. Access — get a copy/summary of your data from Settings → Export My Data, or by emailing us.
  2. Correction — correct inaccurate or incomplete data (edit your profile, or email us).
  3. Erasure — delete your data and account from Settings → Delete Account.
  4. Grievance redressal — raise a concern with our Grievance Officer.
  5. Nomination — nominate another person to exercise your rights on your behalf.
  6. Withdraw consent — at any time by deleting your account (Settings → Delete Account), by turning off a permission (camera, microphone, location, Health Connect) in your phone's settings, or by emailing us. Withdrawing consent stops future processing; it does not undo processing already carried out lawfully.

How to exercise your rights: Email vitalmaa.health@gmail.com. We acknowledge within 7 days and complete actions within 30 days unless a statutory exception applies.

9. Children's data

VitalMaa is intended for users 18 years and older. If a user is under 18, a parent or legal guardian must create the profile and give verifiable consent. We never use children's data for tracking or targeted advertising.

10. Data retention

  • Active accounts: kept while your account is active, and removed within 30 days of deletion (allowing for backup rotation).
  • Chat and voice transcripts: kept with your account while active; you can clear chat anytime from Settings, and everything is removed when you delete your account.
  • Voice reply audio: stored privately and removed when you delete your account.
  • Crash logs: up to 90 days.
  • Analytics events: non-health, aggregate usage only; identifiers are purged on account deletion.
  • Blood reports: kept as long as your account is active.

11. Security

  • In transit: TLS 1.2+ enforced; cleartext traffic blocked.
  • At rest (server): AES-256 on AWS ap-south-1. Row-Level Security on every table, so you can only ever access your own records. Report and voice-audio storage buckets are private.
  • At rest (device): local cache lives in the app's private OS sandbox.
  • Auth: Phone OTP (the SMS is delivered by MSG91) and Google Sign-In, with Supabase secure token refresh.
  • Secrets: API keys are build-time environment variables; never committed to source.
  • Breach notification: we will notify the Data Protection Board of India and affected users as required by the DPDP Rules.

12. Sensitive personal data

Health data and medical records are sensitive under Indian law. We collect the minimum necessary, never share it with advertisers, and protect it with row-level security. Before using your camera, microphone, location, or Health Connect data, the app asks for that permission through your device's standard permission prompt, and only when you use the related feature.

13. Changes to this policy

If we make a material change we will notify you in-app and by email (if we have it) at least 14 days before the change takes effect. The "Last updated" date at the top always reflects the current version.

14. How to contact us

MatterHow
Privacy / data rightsvitalmaa.health@gmail.com
Grievance Officervitalmaa.health@gmail.com
General supportvitalmaa.health@gmail.com

Data Protection Board of India (escalation): if you are unsatisfied with our response to a grievance, you may lodge a complaint with the Data Protection Board of India once it is operational. Details will be published on meity.gov.in.

This is the grievance contact until a formal company entity is established, at which point this policy will be updated with the entity's registered details.