Privacy Policy
Effective Date: 28 May 2026
Last Updated: 28 May 2026 · v1.0
Last Updated: May 28, 2026
1. Who We Are
JivaKosh, operated by JivaKosh Health Technologies Pvt. Ltd., is a health data management platform that enables individuals and families to securely store, organise, and manage personal health records.
We are a Data Fiduciary as defined under the Digital Personal Data Protection Act, 2023 (DPDP Act). This means we determine the purpose and means of processing your personal data and are responsible for ensuring that such processing is lawful, fair, and transparent.
Data Protection Officer
JivaKosh Health Technologies Pvt. Ltd.
Email: dpo@jivakosh.com
2. Scope of This Notice
This Privacy Notice applies to:
- The JivaKosh mobile application (iOS and Android)
- The JivaKosh web application at jivakosh.com
- All related services, APIs, and communications operated by JivaKosh Health Technologies Pvt. Ltd.
This notice is issued in compliance with Section 5 of the Digital Personal Data Protection Act, 2023 and describes the personal data we collect, why we collect it, how we use and protect it, and the rights you hold as a Data Principal.
3. What Personal Data We Collect
We collect personal data only to the extent necessary for the purposes described in this notice.
a) Account & Identity Data
- Full name
- Mobile number (used for OTP-based authentication)
- Email address (optional, for notifications)
- Date of birth
- Gender
- Profile photograph (optional)
b) Health & Medical Records
- Medical reports, prescriptions, discharge summaries, and lab results
- Diagnoses, conditions, medications, allergies, immunisation records, and vital signs
- Family health profiles (with explicit consent from the account holder acting as guardian for minors)
- Doctor names, hospital names, and dates of visits
- Any other health information you choose to add
c) Health & Fitness Data from Connected Devices
Where you grant permission, JivaKosh reads health and fitness data from Google Health Connect (Android) and Apple HealthKit (iOS). The complete list of data types and their specific use is set out in Section 6 below.
d) Documents & Files
- Image or PDF files of medical documents you upload
- Extracted text and structured health data derived from those documents through AI processing (only if you have consented to AI processing)
e) Device & Technical Data
- Device type, operating system, and app version
- IP address and approximate geographic location (country/state level, derived from IP)
- Session identifiers and authentication tokens
- App crash reports and error logs (anonymised)
f) Usage Data
- Features accessed, screens visited, and actions taken within the app
- Search queries within the platform
- Frequency and timing of app usage (aggregated)
We do not collect personal data from third-party data brokers, social media platforms, or government registries.
4. Why We Process Your Data — Purposes and Legal Basis
Under the DPDP Act, we process personal data only on the basis of your freely given, specific, informed, and unambiguous consent. The table below sets out each processing purpose and its consent basis.
| Purpose | Data Used | Consent Type |
|---|---|---|
| Account creation and authentication | Name, mobile number, OTP, email | Mandatory — required to use the service |
| Storing and organising health records | All health and medical data | Mandatory — core platform functionality |
| Reading vitals from Health Connect / HealthKit | Heart rate, blood pressure, blood glucose, steps, weight, SpO₂, sleep, distance, exercise (see Section 6) | Optional — granted per data type in the OS; revocable any time |
| AI-assisted document processing | Document content, extracted health data | Optional — you may opt out at any time |
| Sending OTP and transactional SMS | Mobile number | Mandatory — required for secure login |
| Email notifications and reminders | Email address | Optional — you may opt out at any time |
| Aggregate analytics to improve the platform | Usage data, crash reports (anonymised) | Optional — collected by default, can be withdrawn |
| Customer support and grievance resolution | Any data relevant to your query | Incidental to your consent to use the service |
| Compliance with legal obligations | As required by applicable law | Legal obligation — no separate consent required |
You may withdraw any optional consent at any time from Settings → Privacy & Consent in the app. Withdrawal of mandatory consents will result in account closure.
5. Who We Share Your Data With
We do not sell, rent, or trade your personal data. We share data only with trusted Data Processors who process data strictly on our instructions and are contractually bound to protect it.
| Processor | Purpose | Data Shared | Location |
|---|---|---|---|
| OpenAI, LLC | AI document classification and data extraction (GPT-4o) | Document content and extracted health information (PII-redacted before transmission). Health Connect / HealthKit vitals are never sent to OpenAI. | United States |
| TrustSignal (Trust Signal Internet Services Private Limited) | Sending OTP and transactional SMS messages | Mobile number, message content | India |
| SendGrid | Sending transactional and notification emails | Email address, message content | United States |
| Microsoft Azure | Cloud infrastructure, file storage (Blob Storage) | All platform data including documents | India (primary region) |
All processors are engaged under Data Processing Agreements that require them to process data only as instructed, implement appropriate security measures, and delete or return data upon termination.
We may also disclose personal data to government or regulatory authorities when required by law, or to our legal and financial advisors under confidentiality obligations. In the event of a merger or acquisition, you will be notified of any change in Data Fiduciary.
6. Health & Fitness Data from Connected Devices (Google Health Connect & Apple HealthKit)
JivaKosh offers an optional Vital Sync feature that reads health and fitness data from your device's health platform — Google Health Connect on Android and Apple HealthKit on iOS — so your wearable, scale, BP cuff, and glucose meter readings appear in your JivaKosh vitals dashboard alongside the medical documents you upload.
This feature is strictly opt-in. We do not read any data from Health Connect or HealthKit until you tap Connect in Settings → Vital Sync and grant each individual data type in the system permission screen. You can revoke any permission at any time from the system Health Connect / Health settings, or disconnect the feature entirely from inside JivaKosh.
6.1 Health Data Types We Access
The table below lists every Health Data type JivaKosh requests, the exact Health Connect permission, what we do with it, and our commitments around handling.
| # | Health Data Type | Health Connect Permission | What We Read | How We Use It (Intended Purpose) |
|---|---|---|---|---|
| 1 | Heart Rate | android.permission.health.READ_HEART_RATE | Heart-rate samples (beats per minute) with timestamp and source-device name | Display on the in-app Vitals dashboard; compute daily minimum, average, and maximum; surface trends in your personal health summary; flag values outside healthy ranges |
| 2 | Resting Heart Rate | android.permission.health.READ_RESTING_HEART_RATE | Daily resting heart-rate readings | Track your cardiovascular baseline over time; display in Vitals dashboard |
| 3 | Steps | android.permission.health.READ_STEPS | Step counts with start and end time | Display daily and weekly step totals; contribute to your wellness summary |
| 4 | Weight (Body Mass) | android.permission.health.READ_WEIGHT | Body-weight measurements in kilograms with timestamp | Display weight-trend chart; compute BMI when height is known; include in family member health profile |
| 5 | Blood Pressure | android.permission.health.READ_BLOOD_PRESSURE | Systolic and diastolic readings (mmHg) with timestamp | Display blood-pressure trend; flag readings outside the normal range; include in a health summary you choose to share with your doctor |
| 6 | Blood Glucose | android.permission.health.READ_BLOOD_GLUCOSE | Glucose readings (mg/dL) with timestamp | Display glucose trend; flag hypoglycaemic / hyperglycaemic events; include in diabetes-related health summary |
| 7 | Oxygen Saturation (SpO₂) | android.permission.health.READ_OXYGEN_SATURATION | SpO₂ percentage readings with timestamp | Display SpO₂ trend; flag low readings on the Vitals dashboard |
| 8 | Distance | android.permission.health.READ_DISTANCE | Walking and running distance in kilometres | Display activity totals alongside step counts on your Vitals dashboard |
| 9 | Sleep | android.permission.health.READ_SLEEP | Sleep-session start and end times, plus stages (awake, light, deep, REM) | Display nightly sleep duration and stage breakdown; contribute to your wellness summary |
| 10 | Exercise / Workouts | android.permission.health.READ_EXERCISE | Workout type (running, cycling, yoga, etc.) and duration | Display exercise log; contribute to your activity totals |
On iOS, the equivalent Apple HealthKit data types are read under the NSHealthShareUsageDescription entitlement. The categories and usage purposes are identical to the Health Connect table above.
6.2 How Health Connect / HealthKit Data Is Stored and Protected
- Aggregated daily summaries (e.g. min/avg/max heart-rate, step total, sleep duration) are uploaded to your encrypted JivaKosh vault on Microsoft Azure (India region).
- Storage uses AES-256 encryption at rest and TLS 1.3 in transit.
- Health Connect / HealthKit data is associated only with your JivaKosh account and is accessible only to you and the family members you explicitly grant access to.
6.3 What We Do Not Do With Health Connect / HealthKit Data
- We do not sell, rent, trade, or transfer this data to any third party for advertising, marketing, or any other commercial purpose.
- We do not share this data with insurers, employers, data brokers, or any other party without your explicit per-share consent.
- We do not send Health Connect / HealthKit data to OpenAI or any other AI provider.
- We do not use Health Connect / HealthKit data to train or fine-tune any machine-learning or AI model.
- We do not derive a credit score, insurance score, or any other financial scoring from your health data.
- We do not read any Health Connect data type beyond the ten listed in Section 6.1.
6.4 Retention and Deletion
- Health Connect / HealthKit summaries are retained for the lifetime of your active account so you can see long-term trends.
- When you disconnect Vital Sync, all further reads stop immediately. Previously synced summaries remain in your vault and you can delete them individually from the Vitals screen.
- When you delete your JivaKosh account, all Health Connect / HealthKit data in your vault is permanently deleted within 30 days from live systems and within 90 days from backups, as described in Section 9.
- JivaKosh does not modify, delete, or write back to Health Connect or HealthKit (we use read-only access on Android; on iOS, write access is only used when you manually log a vital inside JivaKosh).
6.5 Revoking Access
- Android: Open the Health Connect app → App permissions → JivaKosh, and toggle off any data type, or tap Remove all permissions.
- iOS: Open the Settings app → Privacy & Security → Health → JivaKosh, and toggle off any data category.
- Inside JivaKosh: Open Settings → Vital Sync → Disconnect. This stops the sync orchestrator from making any further reads.
7. Third-Party Account Connections (Google Gmail)
JivaKosh offers an optional Gmail connector that lets you import medical documents (lab reports, prescriptions, discharge summaries, and similar records) that have been emailed to you as attachments. You may connect your Google account from Account Settings → Connect Gmail in the JivaKosh mobile app at any time, and you may disconnect at any time.
Google API scopes we request
When you connect Gmail, we request the following scopes via Google OAuth:
| Scope | User-facing label | Why we need it |
|---|---|---|
| https://www.googleapis.com/auth/gmail.readonly | View your email messages and settings | To scan the last 90 days of your inbox for medical document attachments and show them to you for review before import |
| openid, userinfo.email, userinfo.profile | Associate your Google account with your JivaKosh account | To identify which Google account has been connected and display it in Settings |
What we do with your Gmail data
- We scan the last 90 days of your inbox for PDF, JPG, and PNG attachments that appear to be medical documents
- Matching attachments are presented to you in a dedicated review screen inside the JivaKosh app
- Only attachments you explicitly select and confirm are imported into your JivaKosh health vault
- Imported attachments are then processed by the same document pipeline as any other upload (with AI extraction applied only if you have separately consented to AI processing — see Section 4)
What we do not do
- We do not read non-medical emails or email bodies
- We do not send, modify, delete, or label any messages in your inbox
- We do not access your Google contacts
- We do not display your email inbox inside the JivaKosh app
- We do not share Gmail data with any third party for purposes other than the specific import you requested
- We do not use Gmail data to train or fine-tune machine-learning or AI models
How we store and protect Gmail credentials
Google OAuth refresh tokens are encrypted at rest using AES-256-GCM with an encryption key stored in Microsoft Azure Key Vault. Access tokens are short-lived and are also encrypted. Tokens are never logged, never included in client-side bundles, and never shared with any party outside JivaKosh.
Revoking access
You can disconnect Gmail at any time from Account Settings → Gmail in the JivaKosh mobile app. Disconnection:
- Immediately revokes JivaKosh's OAuth token at Google
- Deletes the encrypted refresh token and access token from our servers
- Does not delete medical documents you previously chose to import — those remain in your health vault and can be removed individually at any time
You can also revoke access directly from your Google account at myaccount.google.com/permissions.
Google API Services User Data Policy — Limited Use
JivaKosh's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
8. Cross-Border Data Transfers
Some of our Data Processors, notably OpenAI (AI processing), are located in the United States. TrustSignal (SMS/WhatsApp) processes data within India. When you consent to AI document processing or SMS/email communications, your data is transferred to these processors outside India.
We ensure that all cross-border transfers are made only to processors with adequate contractual protections in place, are subject to the conditions of the DPDP Act, and are limited to the minimum data necessary for the stated purpose.
If you do not consent to AI processing, your documents will not be transferred to OpenAI and will be stored without automated data extraction. Health Connect / HealthKit data is never transferred outside India — it is stored in our Microsoft Azure India region.
9. How Long We Keep Your Data
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable law.
| Data Category | Retention Period |
|---|---|
| OTP codes | 24 hours from generation |
| Authentication tokens (refresh tokens) | 7 days from issuance |
| Active health records and documents | For the lifetime of the active account |
| Health Connect / HealthKit summaries | For the lifetime of the active account; deleted on disconnect or account deletion |
| Records marked as deleted by the user | 30 days (to allow recovery), then permanently deleted |
| AI processing queue entries | Deleted after successful processing |
| Audit logs and access logs | 1 year from creation |
| Customer support and grievance records | 3 years from closure of the request |
| Anonymised, aggregated analytics data | Indefinitely (cannot be linked to an individual) |
After account deletion, personal data is purged from live systems within 30 days and from backups within 90 days, except where retention is required by law.
10. Your Rights as a Data Principal
Under the DPDP Act, you have the following rights. To exercise any right, contact dpo@jivakosh.com or use the in-app settings.
Right to Access Information (Section 11)
You have the right to request a summary of the personal data we hold about you, the processing activities carried out, and the processors with whom your data has been shared. You can download a copy of your health data from Settings → Export My Data.
Right to Correction and Erasure (Section 12)
You have the right to correct inaccurate or incomplete personal data, and to erase data that is no longer necessary for the purpose for which it was collected, or where you have withdrawn consent. You can edit most data directly in the app. For erasure requests, contact dpo@jivakosh.com.
Right to Grievance Redressal (Section 13)
If you believe your rights have been violated, you may file a grievance with our Data Protection Officer. We will acknowledge your grievance within 48 hours and provide a resolution within 30 days. File a grievance at dpo@jivakosh.com or via Settings → File a Grievance. If unsatisfied with our resolution, you may escalate to the Data Protection Board of India.
Right to Withdraw Consent (Section 6)
You may withdraw any consent at any time from Settings → Privacy & Consent. Withdrawal is effective immediately for future processing and does not affect processing already completed. Withdrawing mandatory consents will require account deletion.
Right to Nominate a Nominee (Section 14)
You may nominate another individual to exercise your data rights in the event of your death or incapacity. Contact dpo@jivakosh.com to register a nominee.
11. Children's Data
JivaKosh allows account holders to create family health profiles for minor dependants (persons below 18 years of age). When you add a minor to your family profile, you represent that:
- You are the parent or legal guardian of that minor
- You are providing consent on behalf of the minor for the storage and management of their health data
- You will remove the minor's profile if you are no longer their guardian
We do not knowingly allow minors to create independent accounts without parental consent. All rights described in Section 10 may be exercised by a parent or guardian on behalf of a minor.
12. Data Security
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, disclosure, alteration, or destruction. These measures include:
- End-to-end TLS encryption for all data in transit
- AES-256 encryption for documents and sensitive data at rest
- Role-based access controls limiting staff access to personal data
- Multi-factor authentication for administrative access
- Regular security assessments and vulnerability scanning
- Secure deletion procedures for data no longer required
In the event of a data breach that poses a risk to your rights, we will notify you and the Data Protection Board of India as required by the DPDP Act.
13. Changes to This Privacy Notice
We may update this Privacy Notice from time to time. When we make material changes, we will post the revised notice at jivakosh.com/privacy with the updated date, and notify you by email or in-app notification at least 7 days before the changes take effect. Where changes require fresh consent, we will prompt you to provide that consent before the changes apply to you.
14. Contact and Grievances
Data Protection Officer
JivaKosh Health Technologies Pvt. Ltd.
Email: dpo@jivakosh.com
Response time: Within 48 hours of receipt
General Support
Email: support@jivakosh.com
Website: jivakosh.com
File a Grievance
Visit our Grievance page to understand the process and submit a complaint.