DPDP Act 2023 · Version v2-20260921

Privacy Policy

Effective 21 September 2026 · Last updated 21 September 2026

Legal review required. This document is a product-specific draft prepared for Vital Sense. It must be reviewed by qualified legal counsel to confirm compliance with the Digital Personal Data Protection Act, 2023 (as its Rules become operative) and with any other laws applicable to your operations before final publication.

Your health information is deeply personal. This Privacy Policy explains what data we collect when you use Vital Sense, why we collect it, who we share it with, how long we keep it, and what rights you have.

We operate under the Digital Personal Data Protection Act, 2023 (“DPDP Act”). Where applicable, we also honour rights granted by the EU General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).

1. Who we are

Vital Sense is operated by [VITAL SENSE ENTITY NAME], a company incorporated in India (CIN [TO FILL]), with its registered office at [REGISTERED OFFICE ADDRESS].

We act as a Data Fiduciary under the DPDP Act with respect to the personal data of individuals who use the Service directly. Where we process personal data on behalf of a hospital, employer, or other institutional customer, we act as a Data Processor and additional terms are set out in the applicable Data Processing Agreement.

Contact: privacy@vital-sense.in
Grievance Officer (DPDP §10): Dhawal Bargir, grievance@vital-sense.in. Full contact and complaint process at /grievance.

2. Data we collect

We only collect data that is necessary to provide the Service.

2.1 Account and identity data

  • Email address, name, and (if you sign in via Google) profile picture URL.
  • Preferred language.
  • Authentication tokens and session cookies.

2.2 Family profile data

  • Name, date of birth, gender, relationship to you, ABHA number (optional).
  • Chronic conditions, allergies, family history, emergency contact name and phone, lifestyle information (smoking / alcohol / exercise), pregnancy or menopause status (only for female profiles).

2.3 Health records (sensitive personal data under DPDP)

  • Uploaded lab reports, prescriptions, discharge summaries, imaging, vaccination records, device-display photographs, and PDFs.
  • AI-extracted lab values, reference ranges, test names, dates, referring doctor names, facility names, summaries, and plain-language explanations.
  • Symptom-checker conversations, urgency classifications, and red-flag alerts.
  • Medication names, doses, schedules, adherence logs, and notes.
  • Device readings entered manually (BP, glucose, SpO₂, weight, height, temperature).

2.4 Optional integrations

  • If you connect Gmail, we access only messages that match our allow-list of known Indian labs and hospitals, in order to identify lab reports and prescriptions. We do not read your general email. You can disconnect at any time from Account → Connections.
  • If you use “Sign in with Google”, Google shares your email, name, and profile picture with us in accordance with your Google account settings.

2.5 Technical data

  • IP address, user agent (browser + OS), device type, approximate location derived from IP (country-level only).
  • Referrer URL, timestamps, and pages visited.
  • Error logs (which may contain path fragments but no health data).

2.6 Analytics

  • Product-usage events (e.g., “record uploaded”, “symptom session started”, “language switched”). Only your Vital Sense user ID is sent — never your email, name, date of birth, or any medical value.

2.7 Support and feedback

  • Free-text feedback you submit through the in-app “Send feedback” flow, plus its sentiment, the URL you sent it from, your browser user-agent, and your chosen language.

3. Why we process your data

We collect explicit, per-purpose consent at sign-up and every consent is stored in an append-only audit log (consent_events) with the exact policy version you consented to. You can view and change your consent at any time in Account Settings → Consent & Privacy.

PurposeWhat we doRequired?Legal basis
core_serviceStore and display your uploaded reports, extracted lab values, medications, and family profilesRequiredConsent + necessary for performance
ai_processingSend your report contents to Google Gemini to extract values, categorise records, write summaries, and answer your Ask questionsRequiredExplicit consent
cross_borderRoute data to service providers located outside India for the two purposes above (see §5)RequiredExplicit consent
product_analyticsSend anonymised usage events (screens visited, feature counts) to PostHog EUOptional (opt-in)Explicit consent, freely revocable
email_updatesNon-essential email — product tips, health-literacy content, product updatesOptional (opt-in)Explicit consent, freely revocable
parental_consentProcess health data of a minor family profile you manage (per DPDP §9)Required per minor profileVerifiable parental / guardian consent

Withdrawing the three required consents means we can no longer lawfully hold your data — the app treats that as a request to delete your account, with the 30-day grace window described in §6.

We also process personal data — without needing separate consent — to comply with legal obligations (court orders, statutory requests), prevent fraud/abuse, and send security-relevant transactional email (sign-in codes, family invites, red-flag alerts to admins).

We do not sell your personal data. We do not carry any third-party advertising trackers.

4. Who we share your data with

4.1 Sub-processors

Sub-processorPurposeLocation
Supabase (Supabase Inc.)Managed Postgres, Auth, StorageMumbai, India (ap-south-1)
Google Gemini API (Google LLC)AI extraction, summarisation, symptom triageUnited States (Vertex AI Mumbai migration on roadmap)
Vercel (Vercel Inc.)Application hosting and CDNUnited States, edge regions
PostHog Cloud EU (PostHog Inc.)Product analytics (opt-in only)European Union
Resend (Resend, Inc.)Transactional and alert emailsUnited States
Cloudflare, Inc.Turnstile CAPTCHA on sign-upGlobal CDN
Google LLC (Gmail API)Optional Gmail auto-syncUnited States

We have contractual arrangements with each sub-processor that prohibit use of your personal data for their own purposes. Where AI is involved (Gemini), we have contracted for no training on your inputs.

4.2 Family members you invite

When you send a family invite, the invitee sees the profile(s) you shared with them and their associated records.

4.3 Legal disclosures

We may disclose personal data to comply with a court order, subpoena, or lawful request from a government authority. We will notify you unless prohibited by law.

5. Cross-border transfer

Some sub-processors are located outside India. At sign-up we ask for your explicit cross_border consent for this. You can see the current state at any time in Account Settings → Consent & Privacy.

Primary database and file storage remain in Supabase Mumbai (ap-south-1). AI inference (Google Gemini), transactional email (Resend), and application hosting (Vercel) are routed via United States infrastructure today; opt-in product analytics (PostHog) is hosted in the European Union. Migration of AI inference to Vertex AI in asia-south1 (Mumbai) is on our public roadmap.

6. How long we keep your data

The 30-day hard-delete of a deleted account is enforced by a nightly cron (/api/cron/purge-deletions) that runs at 03:30 IST. When the cron runs, all storage files, database rows, and the auth-user row are permanently erased in one transaction.

  • Account, profile, family data: until you delete your account → 30-day grace → permanent hard-delete
  • Medical records & extracted values: until you delete the record or your account
  • Symptom-checker conversations: 12 months from session end, then anonymised
  • Red-flag alert metadata: 24 months (safety-audit)
  • Consent audit log: lifetime of the account + 3 years after deletion (regulatory audit)
  • PostHog analytics: 12 months
  • Feedback: 24 months
  • Server logs: 30 days
  • Backups: up to 30 days after the source record is deleted

7. Your rights

Under the DPDP Act you have the right to:

  • Access — obtain a summary of the personal data we hold about you.
  • Correction and erasure — correct inaccurate data and request deletion of data no longer needed.
  • Grievance redressal — raise a complaint with our Grievance Officer and, if not resolved within 30 days, escalate to the Data Protection Board of India.
  • Nomination — nominate another individual who may exercise your rights in the event of your death or incapacity.
  • Withdraw consent — where processing is based on your consent, you may withdraw at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.

To exercise any of these rights, use the tools in Account Settings (Export data, Delete account, Consent preferences) or email privacy@vital-sense.in. We respond within 30 days.

8. Security

  • Row-Level Security (RLS) in the database so users can only read their own data.
  • Encryption in transit (TLS 1.2+) and at rest (managed by Supabase / Vercel / Google).
  • Strict access controls; administrator access to production requires MFA and is limited to a small team.
  • Rate limiting on AI endpoints (Upstash Redis).
  • CAPTCHA on sign-up (Cloudflare Turnstile).
  • Content Security Policy limiting third-party connections.
  • Regular dependency updates and vulnerability scanning.

No system is 100% secure. If you suspect a security incident, please contact security@vital-sense.in.

9. Children (DPDP §9)

The Service is not intended for children under 18 to use directly. A parent or legal guardian may add and maintain a family profile for a minor within their own account.

Verifiable parental consent. When you add a family profile whose date of birth makes the person a minor, we ask you to confirm — via a required checkbox in the Family form — that you are the parent or legal guardian of that person and that you consent to Vital Sense processing their health data. Every such confirmation is recorded as an event in consent_events, tagged with the policy version and timestamped.

Enforcement. Every AI route (record extraction, Ask, cross-report insights, prescription parsing) checks for a valid parental-consent event before processing a minor’s data. If the consent is missing or has been withdrawn, the request is refused server-side with a clear error pointing you back to the Family form.

10. Cookies and local storage

We use strictly necessary cookies for authentication and preferences (language, active profile). Analytics is opt-in; you can decline at first sign-in and toggle later from Settings.

11. Automated decision-making and AI

AI is used throughout Vital Sense to extract and interpret your health data. No automated decision produces legal or similarly significant effects on you. AI outputs are informational and are subject to your review before you act on them. You have the right to obtain a human review of any AI output by contacting privacy@vital-sense.in.

12. Changes to this Policy

Every material change to this Policy — a new sub-processor, a widened processing scope, a change in retention — bumps the policy version at the top of this page (currently v2-20260921). When we bump the version we will notify you both by email and by an in-app banner at least 14 days before the change takes effect, and we will ask you to re-confirm your required consents the next time you sign in. Until you re-confirm, AI features are paused; your existing data remains intact and downloadable.

13. Contact us

  • Privacy questions: privacy@vital-sense.in
  • Security issues: security@vital-sense.in
  • Grievance Officer: grievance@vital-sense.in

This page is the authoritative published version of our Privacy Policy. A .docx export is available on request. Last review: 21 September 2026.