CureWise+ Privacy Policy

PRIVACY POLICY

CureWise+

Effective Date: August 17, 2026

DRAFT TEMPLATE — This document is a starting point prepared for attorney review. It is not legal advice. Before publishing, have a qualified lawyer review and localize it for every jurisdiction in which you operate, and fill in every bracketed [placeholder]. This template assumes an India-headquartered company serving users globally and references DPDP (India), GDPR (EU/UK), and CCPA/CPRA (California) — verify current requirements before relying on it.


1. Introduction

Parthiv Vanani ("CureWise+", "we", "us", or "our") provides a mobile application that helps users identify medicines, understand symptoms, and receive general health information using artificial intelligence ("the Service"). This Privacy Policy explains what personal data and health-related data we collect, why we collect it, how we use and protect it, and the rights you have over it.

By creating an account or using the Service, you agree to the collection and use of information as described in this Privacy Policy. If you do not agree, please do not use the Service.

This Policy applies to all users worldwide. Certain sections apply additional rights or obligations depending on your location, as noted below (e.g., EU/UK, California, India).

2. Important Notice About Health Information

CureWise+ is an informational and triage tool. It is NOT a substitute for professional medical advice, diagnosis, or treatment. AI-generated outputs (including medicine identification, symptom analysis, and condition suggestions) may be inaccurate or incomplete. Always seek the advice of a qualified physician or healthcare provider with any questions regarding a medical condition. Never disregard professional medical advice or delay seeking it because of something generated by this app. See our Terms & Conditions for the full medical disclaimer.

Because the Service may process images or descriptions of symptoms, medicines, or health reports, some of the data you provide may qualify as "special category data" (under GDPR), "sensitive personal data" (under India's DPDP Act and its rules), or "protected health information-like data" under other regimes. We treat this data with heightened protection as described in Section 6.

3. Information We Collect

3.1 Information you provide directly

  • Account information: name, email address, phone number, password (hashed), date of birth/age range.
  • Health-related content you submit: photos of medicines, medicine packaging, health/lab reports, and descriptions of symptoms you type or speak.
  • Communications: messages you send to support or feedback you provide.
  • Optional profile details: if you choose to add them (e.g., allergies, existing conditions) to improve recommendations.

3.2 Information collected automatically

  • Device information: device model, operating system, unique device identifiers, app version, and IP address.
  • Usage data: screens/pages visited within the app, time and date of visits, time spent on each screen, features used, and session length.
  • Crash & diagnostic data: automatically collected via Firebase Crashlytics to identify and fix bugs.
  • Approximate location: derived from IP address, only if used for localized results (e.g., nearby pharmacies), and only with your permission where required by law. We do not collect precise GPS location unless a specific feature requires it and you separately consent.

3.3 Information from third parties

  • If you sign in using Google, Apple, or another identity provider, we receive basic profile information (name, email) as permitted by your settings with that provider.
  • Data returned by our AI processing partners (see Section 6) as part of generating results for you.

4. How We Use Your Information

Purpose What we use Legal basis (GDPR) / basis (DPDP)
Provide core features (medicine scan, symptom check, report analysis) Images, text, account data Performance of contract / your explicit consent for health data
Improve accuracy of AI results De-identified or aggregated usage data Legitimate interest / consent
Account creation & authentication Name, email, password Performance of contract
Customer support Communications, account data Legitimate interest / contract
Legal compliance & fraud prevention Account & usage data Legal obligation / legitimate interest
Marketing (optional, opt-in only) Email, usage preferences Consent (withdrawable anytime)

We do not use your health-related images or reports to train third-party public AI models unless you explicitly opt in. See Section 6 for details on how AI providers process your data.

5. How We Share Your Information

We do not sell your personal or health data. We share data only in the following circumstances:

  • AI Processing Partners: To generate results, images/text you submit are sent to our AI infrastructure providers (see Section 6) strictly to process your request.
  • Service Providers: Cloud hosting, analytics, crash-reporting, and customer-support tool providers, under contractual confidentiality and data-processing terms.
  • Legal Requirements: If required by law, court order, or government request, or to protect rights, safety, or property.
  • Business Transfers: In connection with a merger, acquisition, or sale of assets, with notice to you and continued protection of your data.
  • With Your Consent: Any other sharing will be disclosed to you and requires your affirmative consent.

6. Third-Party AI Data Processing & Sharing

CureWise+ utilizes trusted third-party artificial intelligence service providers — specifically Google Gemini API (Google LLC) and NVIDIA AI Cloud Services (NVIDIA Corporation) — to analyze uploaded medicine packaging images, laboratory test documents, and user-submitted symptom queries.

  • Data transmitted: Uploaded photos of medicine labels, document scans of laboratory reports, and symptom descriptions entered by the user.
  • Purpose: Strictly to extract text, identify ingredients, and generate automated informational health and medication summaries.
  • Security & privacy: All data transmissions are encrypted using standard SSL/TLS protocols. User data is not used for advertising, tracking, or user profiling, nor is it sold or shared with any other third parties.
  • User consent: Users are prompted to explicitly consent to third-party AI processing prior to utilizing AI-powered scan and query features.
  • Training use: We select providers that offer contractual data-protection commitments (e.g., not using submitted data to train their general-purpose models, or data deletion after processing) — verify and document each provider's current data-use terms before launch, and update this section to match.
  • Infrastructure: We do not control these providers' infrastructure directly; our contracts with them govern how your data may be used and retained on their end.
  • Opting out: If you object to third-party AI processing of your data, you may not be able to use image-based or AI-based features of the Service.

Action required: confirm the exact data-retention and training-use terms with Google and NVIDIA (or any provider you use) under your specific API agreement, and reflect the accurate terms here before publishing.

7. Other Third-Party SDKs & Services

In addition to the AI processing providers above, the Application uses the following third-party SDKs for advertising, analytics, and stability monitoring. Each operates under its own privacy policy, linked below:

  • Google AdMob (advertising) — https://policies.google.com/privacy
  • Google Analytics for Firebase (usage analytics) — https://firebase.google.com/support/privacy
  • Firebase Crashlytics (crash reporting) — https://firebase.google.com/support/privacy

Only aggregated, anonymized usage data is shared with these services to help us improve the Application; we do not knowingly pass health-related content (photos, symptoms, reports) to advertising SDKs.

IMPORTANT — Ads and health data: Because this Application processes sensitive health information, advertising is run in non-personalized mode only, and no ad SDK receives symptom, medicine, or health-report content, or any inference drawn from it. We do not permit ad partners to build health-related interest profiles from your use of this Application.

8. Data Retention

Data type Retention period
Account data Until account deletion, plus a limited period for legal/audit purposes
Medicine scan / symptom images [Specify — recommended: deleted after processing unless user saves to history; otherwise auto-deleted after 30 days]
Health report images [Specify — recommended: deleted after processing unless user opts to retain in-app history]
Support communications Up to 3 years or as required by law
Usage/analytics data Up to 24 months, then aggregated/anonymized

You may request deletion of your data at any time (see Section 10). We will delete data within the timeframe required by applicable law after a verified request, except where retention is legally required.

9. Data Security

  • Encryption of data in transit (TLS) and at rest for stored health-related content.
  • Access controls limiting internal access to health data on a need-to-know basis.
  • Regular security review of third-party processors.

No method of transmission or storage is 100% secure. We cannot guarantee absolute security, but we work to protect your information using industry-standard measures and will notify affected users and relevant authorities of any data breach as required by applicable law (e.g., within 72 hours under GDPR where feasible).

10. Your Rights

10.1 All users

  • Access the personal data we hold about you.
  • Correct inaccurate data.
  • Request deletion of your account and associated data.
  • Withdraw consent for optional processing (e.g., marketing) at any time.
  • Export your data in a portable format.

10.2 Additional rights for EU/UK users (GDPR/UK GDPR)

  • Right to restrict or object to processing, including profiling.
  • Right to lodge a complaint with your local supervisory authority.
  • Right to be informed of automated decision-making logic where it produces legal or similarly significant effects (our AI outputs are advisory/informational and do not make automated decisions about you without human recourse).

10.3 Additional rights for California users (CCPA/CPRA)

  • Right to know categories of data collected, used, and disclosed.
  • Right to opt out of "sale" or "sharing" of personal information (we do not sell data).
  • Right to limit use of sensitive personal information.
  • Right to non-discrimination for exercising these rights.

10.4 Additional rights for India users (DPDP Act 2023)

  • Right to access a summary of personal data processed and processing activities.
  • Right to correction, completion, updating, and erasure of personal data.
  • Right to grievance redressal via our Grievance Officer (below).
  • Right to nominate another individual to exercise your rights in the event of death or incapacity.

To exercise any of these rights, contact us at [dedicated business email recommended — e.g. privacy@yourapp.com] (currently: parthivvanani51@gmail.com). We will respond within the time required by applicable law (e.g., generally 30 days under GDPR, and as prescribed under DPDP rules).

11. Children's Privacy

Given that this Service processes health-related data, the Service is not directed at and should not be used by children under 18, regardless of the lower general digital-consent age (e.g., 13) that may apply to non-health apps under COPPA (US) or DPDP (India). We do not knowingly collect personal data, including health data, from children under 18 without verified parental/guardian consent. If we learn we have collected such data without appropriate consent, we will delete it immediately. Parents/guardians who believe their child has provided data to us should contact us immediately.

The original generic template used age 13 (standard for non-health apps under COPPA). Given this app processes health/medical data, we've raised the threshold to 18 as a more defensible position — confirm the right age with counsel for each jurisdiction you launch in.

Opt-Out & Account Deletion

You can stop all data collection at any time by uninstalling the Application through your device's standard uninstall process, or by deleting your account in-app. Uninstalling stops future collection but does not automatically erase data already stored on our servers — to request deletion of existing data, contact us using the details in Section 16.

12. International Data Transfers

Your data may be processed in countries other than your own, including India, the United States, and other locations where our service providers and AI partners operate. Where we transfer personal data internationally, we rely on appropriate safeguards such as Standard Contractual Clauses (for GDPR transfers), or other lawful transfer mechanisms as required by applicable law.

13. Cookies & Tracking Technologies

Our app and any associated website may use cookies, SDKs, or similar technologies for authentication, analytics, and performance monitoring. Where required by law, we will request your consent before using non-essential tracking technologies, and provide a way to manage your preferences.

14. Grievance Officer / Data Protection Contact (India — DPDP Act)

In accordance with the Digital Personal Data Protection Act, 2023, the details of our Grievance Officer are:

  • Name: Parthiv Vanani
  • Email: [dedicated business email recommended — e.g. privacy@yourapp.com] (currently: parthivvanani51@gmail.com)
  • Address: [Company Registered Address, City, State, India]

15. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via in-app notice or email before they take effect, and update the "Effective Date" above. Continued use of the Service after changes take effect constitutes acceptance.

16. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or your data, contact us at:

  • Parthiv Vanani
  • Email: [dedicated business email recommended — e.g. privacy@yourapp.com] (currently: parthivvanani51@gmail.com)
  • Address: [Company Registered Address, City, State, India]

Comments