Skip to main content

Privacy Policy

How we handle your health data

Last updated: July 2026 · Applies to Vitaliq app, web dashboard, and WhatsApp bot

1. What we collect

Account data: Phone number (used for OTP authentication). We do not collect your name unless you choose to add it to your profile.

Health profile: Age, gender, conditions you declare (diabetes, hypertension, etc.), medications you enter. All optional — the app works without them, but grades become condition-specific when you add them.

Scan data: Product barcodes you scan, food photos you submit, restaurant menus you photograph. Photos are processed by our AI and not stored permanently unless you explicitly save a scan to history.

AI coach conversations: Messages you send and receive in the coach, stored to provide context in future sessions. You can delete all conversations at any time.

Usage signals: Scan timestamps, score data, streak counts. Used to compute your Vitaliq Score.

Payment data: For paid plans, Razorpay handles all card data. We store only the mandate reference ID and plan status — never raw card numbers.

Device data: FCM token for push notifications. No device fingerprinting.

2. How we use your data

We use your data to: compute food grades adjusted for your conditions, power the AI coach with relevant context, calculate your Vitaliq Score, surface medication-food interaction alerts, and generate health reports.

We do not use your health data for advertising targeting, profiling for third-party sale, or any purpose not described in this policy.

Affiliate links (Zepto, Blinkit, BigBasket, insurance, lab tests) are surfaced based on your scan results, not your demographic profile. We earn a commission when you transact — we have no financial interest in what you buy beyond that.

3. Sharing and disclosure

We share your data with: Neon PostgreSQL (our database provider), Upstash Redis (our cache provider), Cloudflare R2 (image storage), MSG91 (OTP delivery), Razorpay (payments), Firebase (push notifications), Meta (if you use our WhatsApp bot).

All providers are bound by data processing agreements. None of these providers receive your health profile — they receive only the minimum data required for the service they provide.

We do not sell your data. We do not share your data with food brands, insurers, or any third party for commercial use.

We may disclose data in response to a lawful order from an Indian court or government authority. We will notify you of any such order unless prohibited from doing so by law.

4. Data retention

Scan history is retained for a minimum of 90 days. AI coach conversations are retained for a minimum of 1 year. Score and wellness data is retained for the lifetime of your account. Higher-tier plans extend these limits; Elite provides unlimited retention.

On account deletion, all personal data is permanently deleted within 30 days. Anonymised aggregate statistics (used for product grading and research) may be retained indefinitely.

5. DPDP Act 2023

Vitaliq is compliant with India's Digital Personal Data Protection Act 2023. We are a Data Fiduciary as defined under the Act.

Consent: We collect explicit consent for health data processing at the time you first enter a condition or medication. You can withdraw consent at any time from Settings → Privacy.

Data localisation: All personal health data is stored in India (Neon PostgreSQL, Asia-Pacific region).

Data Principal rights: You have the right to access, correct, and erase your data. See Section 6 for how to exercise these rights.

Grievance officer: For DPDP Act complaints, contact our Grievance Officer at privacy@vitaliq.co.in with the subject line "DPDP Grievance". We will acknowledge within 48 hours and resolve within 30 days.

6. Your rights

You have the right to: access a copy of all data we hold about you, correct inaccurate data, delete your account and all associated data, export your data in machine-readable format, and withdraw consent for health data processing.

To exercise any of these rights, go to Settings → Privacy in the app, or email privacy@vitaliq.co.in.

We do not charge for data access requests. We respond within 30 days.

7. Security

All data is encrypted in transit (TLS 1.3) and at rest (AES-256). Our API requires JWT authentication on every request. OTP codes expire in 10 minutes and are single-use.

We conduct periodic security reviews. We do not store payment card numbers — Razorpay handles all card processing in their PCI-DSS certified environment.

In the event of a data breach affecting your personal data, we will notify you within 72 hours of becoming aware of it, as required under DPDP Act 2023.

8. Data export

You can export all your Vitaliq data at any time from Settings → Privacy → Export my data. The export includes your scan history, AI coach conversations, score history, and health profile in JSON format.

Exports are generated within 24 hours and sent to your email or available for download in the app for 7 days.

9. Contact

For privacy questions, data requests, or complaints:

Vitaliq Privacy Team

Email: privacy@vitaliq.co.in

Response time: 48 hours for acknowledgement · 30 days for resolution