Privacy Policy
This policy explains, in plain language, what data VitalMaa collects, why, who it is shared with, and the choices you have. It is written to comply with India's Digital Personal Data Protection Act, 2023 (DPDP Act) and the Digital Personal Data Protection Rules.
1. Who we are
VitalMaa is a health and wellness mobile app made for Indian families. It is operated by Sai Rakshith Muda (individual developer, India).
- Grievance Officer: Sai Rakshith Muda
- Email: vitalmaa.health@gmail.com
- Country of operation: India
For the purposes of the DPDP Act, 2023, we are the Data Fiduciary for the personal data you share with VitalMaa.
2. Summary
- VitalMaa is a health-tracking and health-education app. It is not a medical device, it does not diagnose, and it does not prescribe medication. Always consult a qualified doctor.
- We collect the data you choose to give us (profile, food logs, exercise logs, blood reports, chat with Vaidya, and more) plus a small amount of technical data needed to run the app (device type, crash logs, push token, IP address).
- We do not sell your data. We do not use your health data for advertising, and we do not share identifiable health data with advertisers or data brokers.
- This version of the app is free. We do not collect payment information.
- Your data is stored on Supabase (hosted on AWS in Mumbai, India). The app's AI features — Vaidya chat, reading your blood-report and food photos, and the voice assistant — are processed by Sarvam AI in India. Crash logs and usage analytics are processed by Google Firebase.
- You can view, export, and delete your data from Settings → Export My Data / Delete Account.
- VitalMaa is intended for adults 18 and older. For users under 18, a parent or legal guardian must set up the profile and give verifiable consent.
3. What personal data we collect
3.1 Data you provide directly
| Category | Examples | When collected |
|---|---|---|
| Identity | First name, age, gender, phone number, email, state | Onboarding, profile setup |
| Body metrics | Height, weight, BMI, target weight | Onboarding + edit profile |
| Medical history | Medical conditions, family role | Onboarding |
| Dietary preferences | Diet type, food allergies | Onboarding |
| Activity & fitness | Fitness level, exercise preferences, injuries, weekly goal | Onboarding |
| Medications | Drug name, dosage, frequency, timing | Optional — medications module |
| Blood reports | Lab report PDFs / images, extracted biomarker values | Report upload |
| Health diaries | Blood pressure, blood sugar, mood, symptoms, sleep, women's-health cycle (all optional) | When you use those trackers |
| Food logs | Meal names, portion sizes, calories, macros | Each time you log food |
| Exercise logs | Activity name, duration, calories burned | Each workout |
| Water logs | Glasses consumed | Water tracker |
| Chat messages | Questions to Vaidya, Vaidya's replies | Every chat turn |
| Family data | Family member name, relationship, phone | Family module (only if you invite) |
| Voice audio | Voice clips for the voice assistant | Only while you use the mic. Sent to Sarvam AI for speech-to-text; the text transcript is kept with your Vaidya history and the spoken reply audio is stored privately (both are removed when you delete your account). |
| Photos | Report photos, food photos | Only the specific photo you upload. Sent to Sarvam AI to read the text/food in it. |
3.2 Data collected automatically
| Category | Examples | Purpose |
|---|---|---|
| Device info | OS version, device model, language, timezone, app version | Compatibility + support |
| Crash data | Stack traces, device state at crash time | Debugging via Firebase Crashlytics |
| Usage analytics | Screen views, feature-usage counts, session duration | Product improvement via Firebase Analytics. No advertising IDs, no cross-app tracking, and no health information is sent to analytics. |
| Push token | Firebase Cloud Messaging token | Medication reminders & insights |
| IP address | Your device's public IP | Seen by our network proxy (Cloudflare) and backend in transit; used for security and rate limiting |
| Health Connect | Steps, heart rate, sleep, calories, SpO2, blood pressure, glucose, weight — only if you grant permission | Personalising plans and insights |
3.3 Device settings we check on your phone (and never send anywhere)
Android lets you switch off notifications, silence one reminder type, revoke exact alarms, or let the battery saver close VitalMaa in the background. Any of these stops a medicine reminder from arriving, and none of them tells the app it happened — so we check them on your device and tell you what we find.
| What we read | Why | Where it goes |
|---|---|---|
| Whether notifications are enabled for VitalMaa | To warn you that nothing can reach you | Stays on your phone |
| Whether one reminder type is switched off (e.g. medicine alarms) | To warn you that only that reminder is silent | Stays on your phone |
| Whether exact alarms are allowed | To warn you that doses may arrive late | Stays on your phone |
| Whether VitalMaa is exempt from battery optimisation | To warn you that your phone may discard pending alarms | Stays on your phone |
| Your phone's manufacturer and brand | To show the correct settings path for your brand | Stays on your phone |
None of this is transmitted, stored on our servers, or shared. It is read when you open Settings → Notifications, when you add a medicine, and when you return to the app, and it is discarded immediately. We record two anonymous usage counts — that a reminder-health screen was opened, and that a test alarm was sent — under the same analytics consent as everything else in 3.2. Neither records which setting was switched off on your phone.
3.4 Data we do NOT collect
- We do not use tracking cookies for advertising.
- We do not collect precise background location (location is used only in the foreground, when you tap a feature that needs it).
- We do not read your contacts.
- We do not scan your photo library or any videos.
- We do not collect payment information in this version.
- We do not sell your data to data brokers, advertisers, or insurance companies.
3.5 Permissions we ask for, and what happens if you say no
Every permission is optional. Declining one disables the feature that needs it and nothing else — the app keeps working.
| Permission | Used for | If you decline |
|---|---|---|
| Notifications | Medicine reminders, family alerts, meal/water nudges | No reminders arrive; everything else works |
| Alarms & reminders (exact alarms) | Firing a dose reminder at the minute you set | Reminders still fire, but the system may delay them |
| Ignore battery optimisation | Keeping medicine reminders alive when your phone tries to close VitalMaa in the background | Reminders may be dropped by your phone. We warn you and show you where to change it |
| Camera | Food photos, lab report photos, phone-camera heart-rate readings | Type or upload instead |
| Microphone | Speaking to Vaidya | Type instead |
| Photos | Uploading a report or food image you pick | Use the camera instead |
| Coarse / fine location | "Labs near me", seasonal tips, SOS | Search by pincode instead |
| Physical activity | Step counting | Log workouts manually |
| Health Connect | Reading your watch/band data | Log manually; nothing else changes |
Ignore battery optimisation deserves a specific note, because Google Play treats it as a restricted permission. We request it only from the medicine reminder flow, only after you ask us to, and never at first launch. We use it for exactly one purpose: keeping scheduled medication reminders alive. It grants no access to any data.
4. How we get your consent (lawful basis)
We process your personal data only on these lawful bases:
- Your consent (DPDP Act §6). You give consent by choosing to create your profile and use each feature. For sensitive access — camera, microphone, location, and Health Connect — your device shows a standard permission prompt that you must accept before that feature can work.
- Legitimate uses without consent (DPDP Act §7): §7(a) data you provide voluntarily, §7(b) a service you asked for, §7(f) medical emergency.
For health data specifically, we rely on your explicit, informed consent — given by your choice to enter that data and by accepting the relevant device permission prompts.
5. Purposes of processing
We use your data ONLY for: running the app, personalising recommendations, sending reminders, safety alerts, crash debugging, non-health usage analytics, and responding to support requests. We do not use your health data for advertising, insurance underwriting, employment decisions, credit scoring, or any third-party profiling.
6. Who we share data with (sub-processors)
To run VitalMaa we use the service providers below. Each receives only the data listed, and only to do its job for us.
| Sub-processor | What they do | Data they see | Location |
|---|---|---|---|
| Supabase | Primary backend — database, file storage, sign-in, and server functions | All your profile, logs, reports, chat, and health data | AWS ap-south-1 (Mumbai, India) |
| Sarvam AI | The main AI engine: powers Vaidya chat, reads your blood-report and food photos (text recognition), and runs the voice assistant (speech-to-text and text-to-speech) | Voice audio and transcripts, medical-report images, food photos, your questions to Vaidya and the profile/health context sent with them, and inputs for exercise plans and health predictions | India |
| Google Firebase | Crash reporting (Crashlytics), usage analytics, and push notifications (Cloud Messaging) | Crash logs, non-health usage events, and your notification token | Google (US / EU) |
| Google Sign-In | Optional Google login | Email, name, Google account ID — only if you sign in with Google | Google (US / EU) |
| MSG91 | Delivers the one-time password (OTP) SMS for phone sign-in | Your phone number | India |
| Cloudflare | Routes app traffic to our backend (a proxy that sits in front of Supabase) | Request contents in transit and your IP address | Global edge network |
| Open Food Facts | Looks up packaged foods when you scan a barcode | The scanned barcode only — no personal data | EU |
| USDA FoodData Central | Looks up nutrition when you search the US food database | The food name you search — no personal data | USA |
| Google Maps | Opens Maps when you tap "labs near me" or share an SOS location | The map search you start, by your own action | USA |
Your health data lives and is processed in India (Supabase and Sarvam AI). We do not share your data with advertisers or data brokers.
7. Cross-border data transfers
Your main data store and the main AI processing (Supabase and Sarvam AI) are in India. Some providers are outside India: Google Firebase and Google Sign-In (US / EU), USDA (USA, food lookups only), and Google Maps (USA, only when you start a map search). Data sent to any of them travels over encrypted (TLS) connections. These transfers are permitted under DPDP Act §16.
8. Your rights under the DPDP Act
- Access — get a copy/summary of your data from Settings → Export My Data, or by emailing us.
- Correction — correct inaccurate or incomplete data (edit your profile, or email us).
- Erasure — delete your data and account from Settings → Delete Account.
- Grievance redressal — raise a concern with our Grievance Officer.
- Nomination — nominate another person to exercise your rights on your behalf.
- Withdraw consent — at any time by deleting your account (Settings → Delete Account), by turning off a permission (camera, microphone, location, Health Connect) in your phone's settings, or by emailing us. Withdrawing consent stops future processing; it does not undo processing already carried out lawfully.
How to exercise your rights: Email vitalmaa.health@gmail.com. We acknowledge within 7 days and complete actions within 30 days unless a statutory exception applies.
9. Children's data
VitalMaa is intended for users 18 years and older. If a user is under 18, a parent or legal guardian must create the profile and give verifiable consent. We never use children's data for tracking or targeted advertising.
10. Data retention
- Active accounts: kept while your account is active, and removed within 30 days of deletion (allowing for backup rotation).
- Chat and voice transcripts: kept with your account while active; you can clear chat anytime from Settings, and everything is removed when you delete your account.
- Voice reply audio: stored privately and removed when you delete your account.
- Crash logs: up to 90 days.
- Analytics events: non-health, aggregate usage only; identifiers are purged on account deletion.
- Blood reports: kept as long as your account is active.
11. Security
- In transit: TLS 1.2+ enforced; cleartext traffic blocked.
- At rest (server): AES-256 on AWS ap-south-1. Row-Level Security on every table, so you can only ever access your own records. Report and voice-audio storage buckets are private.
- At rest (device): local cache lives in the app's private OS sandbox.
- Auth: Phone OTP (the SMS is delivered by MSG91) and Google Sign-In, with Supabase secure token refresh.
- Secrets: API keys are build-time environment variables; never committed to source.
- Breach notification: we will notify the Data Protection Board of India and affected users as required by the DPDP Rules.
12. Sensitive personal data
Health data and medical records are sensitive under Indian law. We collect the minimum necessary, never share it with advertisers, and protect it with row-level security. Before using your camera, microphone, location, or Health Connect data, the app asks for that permission through your device's standard permission prompt, and only when you use the related feature.
13. Changes to this policy
If we make a material change we will notify you in-app and by email (if we have it) at least 14 days before the change takes effect. The "Last updated" date at the top always reflects the current version.
14. How to contact us
| Matter | How |
|---|---|
| Privacy / data rights | vitalmaa.health@gmail.com |
| Grievance Officer | vitalmaa.health@gmail.com |
| General support | vitalmaa.health@gmail.com |
Data Protection Board of India (escalation): if you are unsatisfied with our response to a grievance, you may lodge a complaint with the Data Protection Board of India once it is operational. Details will be published on meity.gov.in.