Privacy Policy

Last updated Jul 07, 2026

Privacy Policy

Last updated: 07 July 2026

Health Pilot ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains what information we collect, why we collect it, how we use and share it, and the choices you have. It applies to the Health Pilot mobile application and related backend services (together, the "App").

Health Pilot is a personal health tracking tool. Because you can log health and medical information in the App, some of the data we handle is sensitive personal data. We treat all such data with care and only process it to provide the features you use. By creating an account and using the App, you consent to the practices described in this policy.

Quick Summary

Data Why We Collect It Shared With
Account (name, email, hashed password or Google sign-in, optional mobile)Create and secure your account; email OTP verification, or Sign in with GoogleEmail delivery provider (OTP only); Google (only if you use Sign in with Google)
Health profile (DOB, gender, height, weight, blood group, lifestyle, conditions, allergies, emergency contact)Personalise tracking and reports; your name and health profile are used to generate your emergency (SOS) card on our server (not sent to AI)AI provider (only for diet plans and AI health summaries)
Health & wellness logs (vitals, water, medicines, appointments, journal)Store your history and generate insights & remindersAI provider (only when you use an AI feature)
Uploaded documents & profile photoDocument Vault storage; report analysis; profile displayCloud storage provider; AI provider (only when you request analysis)
Device & technical dataDiagnostics, security, reliable deliveryNot shared for marketing

We do not collect your location, contacts, or advertising identifiers, and we do not use advertising or third-party analytics/tracking SDKs. We never sell your data.

1. Information We Collect

We only collect information that you choose to provide or that is needed to operate the App. We do not require access to your location, contacts, or advertising identifiers, and we do not use third-party advertising or analytics/tracking SDKs.

  • Account Information: Your name and email address, used to create and secure your account. If you sign up with a password, it is stored only in encrypted/hashed form, and we send a one-time password (OTP) to your email to verify your account and to reset your password. Optionally, a mobile number.
  • Sign in with Google: You may also create an account or log in using "Sign in with Google." In that case, Google shares your name, email address, and a unique Google account identifier with us, and your email is treated as already verified since Google has confirmed it. We do not receive your Google password, and no separate password is created for Google-based accounts.
  • Health Profile: Optional details you add to your profile — gender, date of birth, height, weight, blood group, activity level, smoking and alcohol status, known medical conditions/diseases, allergies, and emergency contact name, relationship, and phone number.
  • Health & Wellness Logs: Readings and records you enter, including blood sugar, blood pressure, weight, body temperature, blood oxygen (SpO2), water intake, medicines and dose/refill history, medical appointments, and free-text symptom & mood journal entries.
  • Documents: Files you upload to the Document Vault (e.g., prescriptions, lab reports, medical records) and any profile photo you add. These may be images or PDFs.
  • Content You Request From AI Features: When you use an AI feature, the relevant health data and/or documents are processed to generate health summaries, diet plans, and medical-report analysis.
  • Emergency (SOS) Health Card: Generated on our own server from your existing profile data (blood group, allergies, conditions, medicines, emergency contact) as a PDF. This does not use AI and is not sent to any third party.
  • Device & Technical Information: Basic technical data such as device type, operating system version, and app version, used for diagnostics, security, and to deliver the service reliably.

2. Device Permissions We Request

The App requests only the permissions needed for specific features. You can grant or deny most permissions at any time in your device settings.

  • Camera: To take a profile photo or capture/scan a medical document. We access the camera only when you actively use these features.
  • Photos & Media / Storage: To let you select images or files to upload, and to save reports you download from the App to your device.
  • Notifications, Alarms & Related (exact alarm, full-screen alert, foreground service, run at startup, vibrate, wake lock): To show medicine reminders and appointment alerts at the times you schedule, including a full-screen alarm and reminder sound. These reminders are generated and scheduled locally on your device — reminder times and medicine names are not transmitted to power the alarm.
  • Biometric (Fingerprint / Face) Unlock: Used only to lock and unlock the App if you enable App Lock. Biometric verification is handled entirely by your device operating system; we never receive, see, or store your fingerprint or face data.

3. How We Use Your Information

  • To create and secure your account and verify your identity via OTP or Sign in with Google.
  • To provide the core health-tracking features and store your logs so you can view your history and trends.
  • To generate AI-powered health summaries, diet plans, report analysis, and your emergency health card.
  • To deliver medicine reminders and appointment notifications.
  • To maintain, secure, troubleshoot, and improve the App.
  • To comply with legal obligations.

We do not sell your personal information, and we do not use your health data for advertising or to build advertising profiles.

4. Automated Processing & Reminders

To provide reminders and alerts, the App processes some of your data automatically:

  • Medicine & appointment reminders are scheduled and shown locally on your device at the times you set. The reminder alarm and sound run on-device.
  • Health alerts: Our servers periodically review your recent readings (for example, values outside typical ranges) so we can notify you in the App. These are informational only and are not a medical diagnosis.

We do not make any legal or similarly significant decisions about you based solely on automated processing.

5. How Your Data Is Shared

We do not sell, trade, or rent your personal or health data. We share data only with the following categories of service providers, and only as needed to run the App:

  • AI Processing (Google Gemini): When you use an AI feature, the relevant health data and/or uploaded documents are sent to Google's Gemini API to generate the requested output. This data is processed to fulfil your request and is not used by us to train models. Google's handling of API data is governed by its own terms and privacy commitments.
  • Cloud Hosting & Storage: Your account data, health logs, and uploaded files are stored on our secured servers and in reputable cloud object storage used to hold your documents and images.
  • Email Delivery: An email service provider is used to send OTP and account-related emails.
  • Legal & Safety: We may disclose information if required by law, regulation, legal process, or to protect the rights, safety, and security of our users or the public.

6. Sharing You Initiate

Some features let you share your own data. When you download or share a health report or your emergency (SOS) health card, the App generates a PDF that you can save or send through apps you choose (email, messaging, etc.). A shareable report link is accessible to anyone who has the link, so please share it only with people you trust. Once you share a file outside the App, we cannot control how the recipient uses or stores it.

7. Data Storage, Location & Security

Your data is stored on secured servers. All data transmitted between the App and our servers is encrypted in transit using industry-standard HTTPS/TLS. Passwords are stored in hashed form, and access to your data requires an authenticated session token. You can add an extra layer of protection by enabling biometric App Lock on your device.

No method of transmission or storage is 100% secure, but we take reasonable technical and organisational measures to protect your information.

8. International Data Transfers

Your information may be stored and processed on servers, and by service providers (including Google's Gemini API), that are located in countries other than your own. Where data is transferred across borders, we take reasonable steps to ensure it remains protected in line with this policy and applicable law.

9. Legal Basis & Your Consent

We process your personal and health data on the basis of your consent, which you give by creating an account and using the App's features, and to perform the service you request. Health data is sensitive, so we only process it to deliver features you actively use. You can withdraw consent at any time by discontinuing use and deleting your account; withdrawal does not affect processing already carried out.

10. Data Retention & Deletion

We retain your information for as long as your account is active or as needed to provide the App. You can delete your account and all associated data at any time from within the App:

  1. Go to More → App Settings → Account.
  2. Tap Delete Account and confirm.

You may also request deletion by emailing us from your registered email address. Upon a confirmed request, your personal profile, health logs, medicines, appointments, journal entries, AI-generated content, and uploaded documents are permanently removed within 30 days. Anonymised, aggregated data that cannot identify you may be retained for service improvement.

11. Your Rights

Subject to applicable law, you have the right to:

  • Access the personal and health data we hold about you.
  • Correct or update inaccurate information — most of this can be done directly in the App.
  • Export or share reports you generate.
  • Delete your account and data, or ask us to do so.
  • Withdraw consent and object to certain processing.

To exercise any of these rights, use the in-App controls or contact us at the address below. We will respond within the timeframe required by applicable law.

12. Data Breach

Despite our safeguards, no system is completely secure. In the event of a data breach that affects your personal data, we will take prompt remedial action and notify affected users and the relevant authorities where required by applicable law.

13. Children's Privacy

Health Pilot is not intended for children under the age of 13 (or the minimum age required in your country). We do not knowingly collect personal data from children. If you believe a child has provided us with data, please contact us and we will delete it.

14. Medical Disclaimer

Health Pilot is a personal health tracking tool and does not provide medical advice. AI-generated summaries, alerts, and insights are for informational purposes only and are not a substitute for professional medical advice, diagnosis, or treatment. Always consult a qualified healthcare provider for medical decisions.

15. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date above. Significant changes may be communicated in the App. Continued use of the App after changes take effect constitutes acceptance of the updated policy.

16. Contact & Grievance Officer

For privacy-related queries, to exercise your data rights, or to raise a grievance about how your data is handled, contact our Grievance Officer at: takshaktiwari@gmail.com. We aim to acknowledge grievances within a reasonable period and resolve them in accordance with applicable law.