Home  ·  Privacy Policy

Your readings stay yours.

This policy explains exactly what CareAvatar collects, why, who can see it, how long we keep it, and how to make us delete it. Heart and voice recordings are the most personal thing in the app, so they get their own section.

Last updated 18 August 2026 Effective 18 August 2026 Version 1.0

Who we are

CareAvatar is a wellness app for medication reminders, daily heart and voice check-ins, and support modes for Alzheimer's and autism. This policy covers the app and this website.

CareAvatar is operated by Asyscraft Technologies Private Limited, a company incorporated in India , with its registered office at [Registered office address]. Where this policy says "we", it means that company. Where it says "you", it means whoever is using the app — the person doing the check-ins, or a carer using it on their behalf.

In the language of India's Digital Personal Data Protection Act, 2023, we are the Data Fiduciary and you are the Data Principal. If you are in the UK or EEA, we are the controller and you are the data subject.

The short version

We collect what the app needs to work and nothing extra. We do not sell your data, we do not run ads, and we do not share your readings with insurers, employers or data brokers. Nobody sees a reading unless you added them yourself.

What we collect

Grouped by why it exists, rather than by how our database happens to be laid out.

CategoryWhat it includesWhere it comes from
Account Name or nickname, email address or phone number, password hash, language and accessibility settings. You, at sign-up.
Medication Medicine names, doses, schedules, refill counts, and which doses were taken, snoozed or missed. You, as you set up and use reminders.
Check-ins Heart audio and voice audio, the measurements derived from them, and the personal baseline built from your first ten check-ins. The recordings you choose to save.
Prescriptions Photographs of prescriptions you upload, and the medicine names, doses and frequencies read out of them. You, if you use prescription scanning.
Daily life Meals logged, foods you have flagged as avoided, activity and exercise entries. You, if you use the diet or fitness sections.
Care circle Names and contact details of the people you add as family or carers, and what each of them is allowed to see. You, when you invite someone.
Community Your display name in groups, posts and replies, and reports you submit to moderators. You, if you join a group.
Technical Device model, operating system version, app version, crash reports, and notification tokens so reminders can reach the device. Your device, automatically.

What we deliberately do not collect

  • Continuous location. The app never asks for background location and does not track where you are.
  • Your contacts list. Care circle members are added one at a time, by you typing their details.
  • Advertising identifiers. There is no ad SDK in the app, so there is nothing to build an ad profile from.
  • Microphone access outside a check-in. Recording starts when you press record and stops when the check-in ends.

Heart and voice recordings

These are the most sensitive thing in the app, so they are handled differently from everything else.

  • Recording is always deliberate. A 45-second heart check or a 30-second voice check only runs when you start it. There is no passive or ambient listening.
  • Analysis is the point, not the audio. What the app actually uses is the derived measurements — heart rate, beat-to-beat variability, and the twelve voice measures covering pitch, clarity, pace, steadiness and pauses.
  • You control whether the audio itself is kept. In Settings you can choose to keep recordings so you can play them back or show a doctor, or to discard the audio as soon as the measurements are extracted. If you discard it, the audio is deleted from our servers and cannot be recovered.
  • A bad recording is refused, not saved. If a check-in is too short, too quiet or too noisy, the app asks you to try again rather than storing a reading it does not trust.
  • Recordings are never used to train models for anyone else without separate, explicit, opt-in consent that you can withdraw. Opting out does not reduce anything in the app.

Not a medical measurement

Check-in results are compared to your own history, not to a clinical reference range. They are not a diagnosis, and they are not a substitute for an ECG, a stethoscope or a clinician. If a reading worries you, speak to a doctor.

Why we use it

Under data protection law we need a lawful reason for each use. Ours are:

  • To provide the app you asked for — sending reminders on schedule, saving check-ins, building your baseline, showing your history. This is performance of our contract with you.
  • With your consent — processing health data such as heart audio, voice audio and prescriptions, and sharing anything with the people in your care circle. You can withdraw this at any time in Settings, and processing stops.
  • To keep the service working and safe — crash reports, abuse and spam handling, and community moderation. This is our legitimate interest in running a service that stays up and is not hostile to use.
  • To meet legal obligations — retaining records where a law requires it, and responding to lawful requests we are obliged to answer.

We do not use your data for automated decisions that produce legal or similarly significant effects on you. The app compares today to your own past readings; it does not score you, rank you, or pass a judgement on to anybody.

Who can see it

Four groups of people, and no others.

  • You. Everything, always, exportable.
  • The people you added to your care circle, limited to exactly what you allowed them to see. See the next section.
  • Service providers who run parts of the infrastructure — cloud hosting, push notification delivery, crash reporting, email delivery. They act on our written instructions only, may not use your data for their own purposes, and are bound by confidentiality terms.
  • Authorities, where the law compels it — a valid court order or an equivalent legal requirement. We check that a request is valid before answering it and, unless we are legally barred from doing so, we tell you.

We do not sell personal data. We do not share it with advertisers, data brokers, insurers or employers. If ownership of CareAvatar ever changes, your data moves under this same policy and you will be told before anything about it changes.

Family and carer access

Sharing is off until you turn it on, one person at a time.

  • You invite a specific person and choose what they can see — for example missed doses only, or missed doses plus check-in trends.
  • Permissions are per-person, not all-or-nothing. Two people can have two different views of your day.
  • You can see who currently has access, and remove anyone, at any time. Access ends immediately.
  • When someone is removed, they lose access to your history — including anything they could see before, not just what comes after.
  • Being in someone's care circle does not let a person change medication schedules unless the account is set up as a carer-managed account with that permission.

Where it is stored

Data is held on servers in India, operated for us by our hosting provider. Some service providers — for example crash reporting or email delivery — may process limited data outside that country. Where that happens we rely on appropriate safeguards, such as standard contractual clauses, and we limit what leaves.

  • Traffic between the app and our servers is encrypted in transit using TLS.
  • Recordings and prescription images are encrypted at rest.
  • Access by our staff is restricted to the few people who need it to run the service, and is logged.

No system is perfectly secure, and we will not claim otherwise. If a breach affects your personal data and is likely to put you at risk, we will tell you and the relevant regulator within the time the law requires.

How long we keep it

DataKept for
Account detailsWhile your account is open.
Medication and check-in historyWhile your account is open — the history is the point of the app.
Raw heart and voice audioUntil you delete it, or immediately after analysis if you turned off keeping recordings.
Prescription imagesUntil you delete them.
Crash and diagnostic logsUp to 90 days.
Everything, after you delete your accountErased within 30 days, except anything a law requires us to keep.

Backups roll off on their own cycle, so deleted data can persist in encrypted backups for a short period after deletion before those backups are overwritten.

Your rights

Wherever you live, you can ask us to do all of the following, and we will not charge you for it or make the app worse for asking:

  • See what we hold — a copy of your data.
  • Export it — a machine-readable file of your medication history and check-ins, from Settings or on request.
  • Correct it — fix anything wrong.
  • Delete it — your account and its contents, from Settings › Account › Delete account, or by writing to us.
  • Withdraw consent — stop health-data processing or care circle sharing, without affecting what was lawful before you withdrew.
  • Object or restrict — tell us to stop or pause a particular use.
  • Complain — to us first, we would prefer, but you can go straight to your data protection authority if you want to.

Write to privacy@careavatar.com and we will respond within 30 days. We may ask you to confirm your identity first, so that we are not handing your health history to somebody who is not you.

Children and supported adults

CareAvatar is not intended for children under 13, and we do not knowingly create accounts for them. Where a child or a supported adult uses the app, it should be set up and managed by a parent, guardian or authorised carer, who is responsible for the consents in this policy on their behalf.

If you believe a child's data has reached us without proper consent, write to privacy@careavatar.com and we will delete it.

Community groups

Groups are organised by what people are managing day to day, not by diagnosis label. They are moderated, but they are still a space where other people can read what you write.

  • Anything you post is visible to other members of that group. Treat it as public.
  • Your check-in readings and medication list are never posted automatically. Nothing from your health record goes into a group unless you type it there yourself.
  • You can delete your own posts. Copies other members have already seen or saved are outside our control.
  • Moderators can remove content and suspend accounts that break the community rules.

Changes to this policy

When we change something meaningful — a new category of data, a new recipient, a different retention period — we will tell you in the app before it takes effect, and update the date at the top of this page. Continuing to use CareAvatar after that means you accept the updated policy. If a change requires fresh consent, we will ask for it rather than assume it.

Contacting us

If you are not satisfied with our response, you may complain to the Data Protection Board of India, or — if you are in the UK or EEA — to your local supervisory authority.

Privacy questions, access requests and deletion requests: privacy@careavatar.com.

Grievance Officer (as required under Indian law): [Grievance officer name], grievance@careavatar.com, [Registered office address]. We acknowledge complaints within 48 hours and resolve them within 30 days.

For anything else, the contact page lists the right address for each kind of question.

Still have a question

Ask us before you sign up.

We would rather answer a privacy question now than have you wondering about it later.