Privacy Policy
This Privacy Policy describes how Medovix LLP (“Medovix”, “we”, “us”) collects, uses, stores, shares, and protects your personal data when you use the Medovix mobile application and related backend services (collectively, the “Services”). It supplements our Terms & Conditions. Defined terms not explained here have the meanings given in the Terms.
We are the “Data Fiduciary” under the Digital Personal Data Protection Act, 2023 (“DPDP Act”) in respect of personal data we process about Indian Users.
1. Data we collect
1.1 Information you provide
- Account data: full name, email address, phone number (optional), password.
- Profile data: date of birth, gender, blood group, height, weight, login method.
- Health profile (sensitive personal data): self-reported medical conditions, allergies.
- Medications: name, nickname, strength, form, stock, dosage, dose unit, expiry, notes.
- Reminders: schedule times, frequency, cadence, start/end dates, specific dates, status.
- Reminder logs: scheduled time, taken time, status (taken / late / skipped / missed / scheduled), notes.
- Appointments: title, doctor, type, date, time, location, status.
- Reports: uploaded files (PDFs, images), title, type, date, doctor name.
- Caregiver linking: access codes, relationship, link status.
- Vix AI: messages you send to the AI assistant and replies generated for you.
1.2 Information collected automatically
- Device tokens for push notifications (Firebase).
- App version, OS version, device locale, timezone.
- Last-seen timestamp (when you last opened the app).
- In-app interaction events with notifications (taken / skipped / opened).
- Trivia interaction (which cards were tapped).
- Product-usage analytics: which sections of the app you open and the general health topics you browse. This is kept private to your account, used only to improve Medovix, and is never shared with advertisers or ad networks.
1.3 Information from third parties
- Authentication providers (e.g., email confirmation via Supabase).
1.4 Health Connect (Android)
On Android, Medovix can connect to Health Connect if you choose to enable it. We request read-only access to your Sleep data (the android.permission.health.READ_SLEEP permission) and use it only as described below:
- What we read: your sleep sessions — bedtime, wake time, total duration, and sleep stages (deep, light, REM, awake) where available — which your smartwatch, band, or other health apps have written into the on-device Health Connect store. We do not read any other Health Connect data type, and we never write to Health Connect.
- How we use it: solely to show your own sleep in the app’s Sleep tracker and to include sleep as one signal in your personal Health Insights. The data is stored only in your own Medovix account.
- How we protect it: Health Connect data is treated as sensitive personal data. We do not sell it, share it with any third party for that party’s own purposes, or use it — or anything inferred from it — for advertising or ad targeting.
- Your control: access is granted only through the standard Health Connect consent dialog after you choose to connect it, and you can revoke it at any time from Health Connect settings; revoking stops any further reads. Sleep data already saved to your account is deleted when you remove it or delete your account (see Retention below).
Medovix’s access to and use of Health Connect data complies with the Google Play Health Connect permissions policy, including the requirement that Health Connect data is used only to provide features that benefit you and is never used for advertising.
2. Why we collect it (purposes)
We process personal data for these purposes only:
- To create and operate your account.
- To deliver medication reminders, schedule alarms, and track adherence.
- To enable the optional caregiver-sharing feature, where you authorise it.
- To generate personalised Health Trivia and Vix AI replies relevant to your profile.
- To provide customer support and respond to your requests.
- To send service-related communications (security notices, terms updates, transactional emails).
- To detect, prevent, and respond to fraud, abuse, and security incidents.
- To comply with applicable law and lawful requests from authorities.
- To improve the Services through aggregated, non-identifying analytics.
We do not use your personal data to:
- Sell or rent it to third parties.
- Target advertising using your health data. The free tier of Medovix may show ads, but we never feed your health information (conditions, medications, vitals, cycle data, lab results, or anything inferred from them) to any advertiser or ad network, and we do not build ad audiences from it. Any ad relevance is decided by us, on our own systems, from your non-health usage signals only. We category-block sensitive and deceptive ads (pharma, “miracle cures”, weight-loss and supplement scams, adult content, gambling, alcohol, and competing health apps). Medovix Pro removes ads entirely.
- Train artificial intelligence models (your data is sent to Anthropic for individual replies; Anthropic’s commercial terms state they do not train on customer data).
3. Lawful basis (DPDP Act)
We rely on your consent as the lawful basis for processing your personal data. You provide consent by accepting these terms at signup and by enabling specific features (e.g., caregiver linking). You may withdraw consent at any time; the consequence is that the Services will no longer be able to perform their core functions for you.
4. Children
Medovix is intended for Users aged 13 and over. A User aged 13–17 may register their own account, but we obtain verifiable consent from their parent or legal guardian before processing their health data. At sign-up the minor provides a parent/guardian email address, or the Medovix ID of a parent/guardian who already holds a Medovix account (from which we obtain their contact email), and we email that guardian a request to approve or decline. Until the guardian approves, the account stays in a limited, pending state and we process only the data necessary to obtain that consent. The guardian may approve, decline, or withdraw consent at any time — which grants or revokes the minor’s access — and may choose to have the minor added to their own account as a managed dependent. A parent or guardian may also add an under-18 directly as a dependent they manage. We do not knowingly permit registration or use by anyone under 13; if we learn that an under-13 has registered, we will suspend and delete the account. We do not process a minor’s data for behavioural monitoring or targeted advertising. Parents or guardians with questions about their child’s data should contact hi@medovix.com.
5. Who we share data with (sub-processors)
We use the following sub-processors. By accepting these terms, you consent to your data being shared with them under contractual data-protection commitments.
- Supabase Inc. (United States) — database, file storage, authentication, real-time channels. Hosts the bulk of your data including profile, medications, reminders, logs, appointments, reports. See supabase.com/privacy.
- Anthropic PBC (United States) — Vix AI replies and daily Health Trivia generation. We send a personalisation context with each request (a snapshot of your active medications, recent adherence, upcoming appointments). Anthropic stores requests for up to 30 days for trust-and-safety purposes and does not train models on our customers’ data. See anthropic.com/legal/privacy.
- Google LLC / Firebase (United States) — Cloud Messaging for push notifications. We send a “data-only” payload containing reminder IDs and medication labels; we do not include sensitive notes in the push body. See firebase.google.com/support/privacy.
- Payment processor (planned: Razorpay) — not yet active. Once paid plans launch, a PCI-DSS-compliant processor will handle payments; you enter card details directly with them and they never reach our servers.
We may also disclose data to law-enforcement, courts, or regulators when required by law, or to protect the rights, property, or safety of Medovix, Users, or the public.
6. International transfers
Your personal data may be transferred to, processed in, and stored in jurisdictions outside India, including the United States, where our sub-processors operate. By using the Services you consent to such transfers. We rely on the sub-processors’ contractual safeguards; where the DPDP Act issues formal cross-border restrictions, we will update our practices to comply.
7. Retention
- Active accounts: data is retained for as long as your account is active.
- Deleted accounts: data is permanently and irreversibly deleted within 14 days of account deletion, except where retention is required by law (e.g., tax records for paid subscriptions, fraud-prevention logs).
- Aggregated, non-identifying analytics may be retained indefinitely.
8. Your rights
Under the DPDP Act and other applicable laws, you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data (most fields are directly editable in-app; for the rest, write to hi@medovix.com).
- Delete your account and associated data via Profile → Settings → Delete my account.
- Nominate a person to exercise your rights in the event of your death or incapacity.
- Withdraw consent at any time. Withdrawal does not affect the lawfulness of processing prior to withdrawal.
- Lodge a complaint with the Data Protection Board of India. We ask you to contact us first so we can attempt to resolve the issue.
We will respond to a verifiable rights request within 30 days.
9. Security
We protect your data using:
- HTTPS / TLS encryption in transit.
- Encryption at rest in Supabase’s PostgreSQL database and Object Storage.
- Row-Level Security (RLS) policies that constrain access to your own data and any caregiver-linked patient data.
- Authentication via email + password (and Google OAuth where supported).
- Service-side rate limits and anomaly detection for high-risk endpoints.
You are responsible for keeping your password confidential, locking your device with a PIN, pattern, biometric, or equivalent, and not sharing your account credentials or access codes.
10. Breach notification
In the event of a personal-data breach, we will notify the Data Protection Board of India and the affected Users without undue delay and in accordance with the timelines set by the DPDP Act and its rules.
11. Changes to this policy
We may update this Privacy Policy. Material changes will be notified in-app and by email at least 14 days before they take effect. Continued use of the Services after the effective date constitutes acceptance.
12. Contact
Data Protection Officer / Privacy contact: hi@medovix.com
Grievance Officer (as required under Indian rules): hi@medovix.com
Postal: Medovix LLP, D-204, Abhimanyu, NL Complex, Dahisar East, Mumbai 400068, Maharashtra, India
