Wellkept← Back to home

Wellkept Privacy Policy

Last updated: [DATE_OF_PUBLICATION]

Effective date: [DATE_OF_PUBLICATION]

This Privacy Policy explains how [COMPANY_LEGAL_NAME] ("Wellkept," "we," "us," or "our"), the entity that operates the Wellkept mobile application and website (together, the "Service"), collects, uses, discloses, stores, and protects your personal data, and what rights you have over it.

Wellkept is a health-records and AI health-insights application built primarily for users in India. We process sensitive personal health data, and this Policy is written to meet the heightened obligations that apply to that category of data under India's Digital Personal Data Protection Act, 2023 ("DPDP Act"). Where our user base includes individuals in jurisdictions covered by the EU/UK General Data Protection Regulation ("GDPR"), we also describe the corresponding GDPR concepts alongside the DPDP ones so this Policy is legible and enforceable under both frameworks.

Under the DPDP Act, [COMPANY_LEGAL_NAME] acts as the Data Fiduciary for the personal data you and your family members provide, and you (the account holder) are the Data Principal. Under the GDPR, the equivalent roles are "controller" and "data subject" respectively.

By creating a Wellkept account, you acknowledge that you have read this Privacy Policy and that you consent to the collection, use, and disclosure of your personal data as described here, including your explicit consent to the processing of sensitive health data as set out in Section 5.

If you do not agree with this Policy, please do not use the Service.


1. Who We Are

  • Data Fiduciary / Controller: [COMPANY_LEGAL_NAME]
  • Registered address: [REGISTERED_ADDRESS]
  • Grievance Officer (DPDP Act, Section 13) / Grievance Officer (IT Rules, 2021): [GRIEVANCE_OFFICER_NAME_AND_CONTACT]
  • Data protection / privacy contact: [DPO_CONTACT_EMAIL]

If you have any questions, complaints, or requests relating to this Policy or your personal data, contact the Grievance Officer at the details above. We aim to acknowledge grievances within 48 hours and resolve them within 30 days of receipt, in line with DPDP Act requirements.


2. Scope of This Policy

This Policy applies to personal data collected through:

  • The Wellkept mobile app (iOS and Android)
  • The Wellkept web application
  • Public, unauthenticated pages generated by Wellkept features on your behalf, such as doctor share-link pages

This Policy does not apply to third-party websites or services you may reach through links inside the Service (for example, an original Reddit post linked from a dermatology evidence card, or a pharmacy website referenced in an AI recommendation). Those services have their own privacy practices, which we do not control.


3. Data We Collect

3.1 Identity and account data

  • Phone number — your primary identifier, used for OTP (one-time password) login. Wellkept does not use passwords.
  • Email address (optional)
  • Name
  • Language preference (one of 11 supported Indian languages: English, Hindi, Tamil, Telugu, Kannada, Malayalam, Marathi, Gujarati, Bengali, Punjabi, Odia)
  • Profile details you provide: date of birth, gender, blood group, height, weight, known medical conditions, allergies

3.2 Health data you upload or enter

This is sensitive personal data under the DPDP Act. It includes:

  • Documents: lab reports, prescriptions, medical scans, and other health records you upload (images or PDFs), and the structured data our AI extracts from them (test names, values, dates, diagnoses, medication names, doctor/lab names, etc.)
  • Biomarker readings: lab values tracked over time (e.g., HbA1c, cholesterol, creatinine), extracted automatically from documents you upload
  • Medications: names, dosages, schedules, and your dose-taking logs
  • Manual vitals: blood pressure, blood glucose, weight, and heart rate readings you log yourself
  • Symptom logs: symptoms automatically identified from your chat conversations by our AI (see Section 5.3)
  • Voice notes: when you use voice input, transcription happens on your device; only the resulting text is sent to our servers — the audio recording itself is never uploaded or stored by us
  • Skin photos: images you upload to the dermatology AI feature, and the AI-generated description and differential analysis produced from them
  • Consultation audio and transcripts: if you use a feature that records or transcribes a consultation, both the audio and the transcript may be stored, depending on the specific feature
  • Chat messages: everything you type to the Wellkept AI assistant, and the AI's responses

3.3 Family Vault data

If you add a family member (spouse, child, parent, or other relation) to your account's Family Vault, we collect and store the health data you enter on their behalf, including documents, biomarkers, medications, and vitals attributed to that family member. Family members do not have their own login; you, as the account holder, are responsible for this data (see Section 8 and the Terms of Service).

3.4 Usage and device data

  • App usage patterns (features used, session activity) for product improvement and abuse prevention
  • Device push notification token (for medication reminders and health digests via Firebase Cloud Messaging)
  • IP address, device/browser type, and similar technical metadata, primarily for security, rate-limiting, and fraud prevention
  • Subscription/plan status (Free, Pro, or Family)

3.5 Payment data (once billing is live)

Razorpay-based billing for Pro and Family plans is planned but not yet live. When it ships, payment card/UPI/bank details will be collected and processed directly by Razorpay, our payment processor — Wellkept does not store your full payment instrument details. This Policy will be updated with the specifics before billing goes live, and you will be asked to accept updated terms at that time.


4. How We Use Your Data (Purpose Limitation)

We use your data only for the purposes for which it was collected, specifically:

PurposeData used
Extracting structured data from your uploaded documents and summarizing themDocuments, images/PDFs
Answering your questions in the AI chat, in your chosen languageChat messages, relevant document/biomarker context
Tracking lab values over time and flagging out-of-range trendsBiomarker readings
Computing your Health Vitality Score and wellness insightsBiomarkers, medication adherence, trend data, profile completeness
Reminding you to take medicationsMedication schedule, push token
Checking for dangerous drug combinationsMedication list
Skin condition triage via the dermatology AIUploaded skin photo, optional symptom text
Generating a doctor-facing summary when you create a share linkWhatever categories you select (medications/biomarkers/conditions/documents)
Operating and securing the ServiceAccount/device/usage data
Billing (once live)Subscription plan, payment status (via Razorpay)

We do not use your health data to serve you targeted advertising, and we do not sell your personal data to third parties, in any form.


5. Legal Basis and Consent

5.1 Consent as the primary basis

Under the DPDP Act, our primary lawful basis for processing your personal data — and in particular your sensitive health data — is your free, specific, informed, unconditional, and unambiguous consent, given through a clear affirmative action (not bundled into a blanket "I agree to Terms" checkbox alone).

Concretely, this means:

  • You are asked to separately and explicitly consent to health-data processing during account onboarding, described in plain language, before any document upload, biomarker extraction, or AI chat feature becomes available to you.
  • Consent for Family Vault members is given by you, the account holder, on their behalf where they cannot consent for themselves (e.g., minors) — see Section 8.
  • You may withdraw consent at any time by deleting your account (Section 10), which is as easy to do as it was to give consent.
  • New processing purposes not covered by this Policy (for example, a future feature that shares data with a new category of third party) will require fresh, specific consent before that feature is enabled for you — it will not be silently added under a generic "we may update our practices" clause.

5.2 Other lawful bases we rely on narrowly

Some processing is necessary to operate the Service and does not require separate consent under DPDP's "certain legitimate uses" and equivalent GDPR "contract" / "legitimate interest" bases — for example, storing your OTP session to keep you logged in, or processing rate-limit counters to enforce your plan's usage cap. We keep this category as narrow as possible and do not use it for anything beyond operating the core Service you signed up for.

5.3 Automatic extraction from your conversations

Our AI automatically identifies symptoms you mention in chat and logs them as structured symptom_logs so they can inform your Health Vitality Score and future chat context. This is part of the core AI chat feature you consent to when you use chat; you can review and delete these logs via data export/account deletion. We do not use this extraction to build an advertising profile.


6. Sensitive Health Data — Heightened Protections

Because nearly everything in Wellkept is health data, we apply the following baseline protections to all of it, consistent with DPDP's treatment of sensitive personal data and with good health-data practice generally:

  • No targeted advertising is built on your health data — Wellkept does not run third-party ad networks against your account data.
  • No sale of your personal or health data to any third party, ever.
  • Purpose-limited AI processing: your data is sent to AI processors (Section 7) strictly to generate the specific output you requested (a document summary, a chat answer, a skin analysis) — not to train those providers' general-purpose models, to the extent their terms allow us to opt out (see Section 7.1 for the specifics of our Gemini relationship).
  • Access controls: your health data is scoped to your account (and Family Vault members you manage) and is not visible to other users, except through a share link you deliberately create and distribute (Section 9).
  • Breach notification: in the event of a personal data breach that risks harm to you, we will notify the Data Protection Board of India and affected users as required under the DPDP Act, and, where legally required, notify you directly via the contact details on your account, describing the nature of the breach and the steps we are taking.

7. Who We Share Data With

We share data only with the following categories of recipients, each acting as our data processor for the specific, limited purpose described:

7.1 Google Gemini API (Google LLC)

What's sent: the content of documents you upload (for extraction/summarization), your chat messages and relevant health context (for AI chat responses), and skin photos you upload plus a text description derived from them and relevant health context (for dermatology analysis). Why: this is the AI engine that powers document extraction, multilingual chat, and dermatology differential analysis. Note: this processing happens on Google's infrastructure, which may be outside India — see Section 12 on cross-border transfer.

7.2 Tavily (web search grounding)

What's sent: a short search query built from your chat message (up to ~200 characters) and, where relevant, the "known conditions" line from your health profile (e.g., a chronic condition you've recorded) — sent so the AI assistant can ground its answer in authoritative medical sources (PubMed, Mayo Clinic, WHO, NIH, MedlinePlus, NHS, and similar). This only runs for chat messages that need external grounding; simple document or chit-chat queries never reach Tavily. Why: improves the accuracy and currency of AI chat answers.

7.3 Reddit (public search API) and YouTube Data API (Google) — chat grounding

In addition to the dermatology reference dataset described in 7.4, Wellkept's AI chat assistant also queries Reddit's public search API and, if configured, the YouTube Data API v3, using the same short query described in 7.2 (your chat message text plus any recorded known conditions), to surface patient-community discussion and educational videos alongside clinical sources. No account identifiers (phone number, name, email) are included in these queries — only the free-text symptom/condition query — but the query itself can contain health information you typed. Results returned are limited to publicly available Reddit posts and public YouTube videos; nothing you say is posted, and no Reddit/YouTube account is created or linked to you.

7.4 Reddit (dermatology reference dataset)

Separately from 7.3, Wellkept maintains a reference dataset of publicly posted Reddit images and text from dermatology-related subreddits (e.g., r/Dermatology, r/SkincareAddiction, r/eczema), collected via Reddit's API for the sole purpose of powering the dermatology AI's comparison feature. No data about your account or your uploaded photos is sent to Reddit as part of this collection — it is a one-way ingestion of already-public Reddit content into our own database, not a per-user data flow. When you use the dermatology feature, the app may show you an "evidence card" referencing a matched Reddit case, including a link to the original public post, so you can review the source yourself — no additional information about the original poster is exposed beyond what they themselves already made public on Reddit.

7.5 Firebase Cloud Messaging (Google/Firebase)

What's sent: push notification payloads for medication reminders, weekly health digests, and daily health nudges. These notifications include a title and short body text that can reference health information — for example, a medication reminder push includes the medication name ("Time to take Metformin"), and a weekly digest push includes a short excerpt of an AI-generated health insight title. Why: push notifications need Google's infrastructure to reach your device when the app is closed or backgrounded.

7.6 OpenFDA (U.S. FDA public API)

What's sent: drug/generic names you enter into the drug interaction checker (not tied to your identity in the request). Why: cross-referencing drug interaction data and generic-name lookups.

7.7 Razorpay (planned, not yet live)

Once billing is enabled, payment details will be processed directly by Razorpay for Pro/Family subscription payments. Wellkept will not itself store your card, UPI, or bank account details.

7.8 Legal and safety disclosures

We may disclose personal data if required by law, court order, or governmental request, or where we believe in good faith it is necessary to protect the rights, property, or safety of Wellkept, our users, or the public.

7.9 No other sharing

We do not share your data with data brokers, advertising networks, or any party not listed above.


8. Family Vault and Minors

  • Family Vault lets you (the account holder) manage health records for family members — including children — who do not have their own Wellkept login.
  • All data entered for a family member is entered, controlled, and attributable to you, the account holder. You are responsible for having the appropriate authority (as a parent, legal guardian, or the family member's own informed consent, as applicable) to enter and manage their health data in Wellkept.
  • Wellkept is not intended for anyone under 18 to create their own account. A parent or legal guardian may add a child as a Family Vault member under the parent's own account, with the parent providing consent on the child's behalf, consistent with DPDP Act requirements for processing a child's personal data.
  • Share links (Section 9) can be scoped to a specific family member. A share link for a minor is generated and distributed entirely at the account holder's discretion — Wellkept does not independently verify the recipient's identity or relationship to the minor. Account holders should treat a minor's share link with the same or greater care as their own, since the feature was built for adult self-service sharing with a doctor and does not include additional guardianship-specific safeguards beyond account-holder control.
  • If you become aware that a child has created their own Wellkept account in violation of this Policy, please contact us at [DPO_CONTACT_EMAIL] so we can take appropriate action, which may include deleting the account.

9. Share Links

Wellkept lets you generate a token-based public URL that shows a read-only summary of your (or a Family Vault member's) health data — typically to share with a doctor before an appointment. Key facts:

  • You control what's included: medications, biomarkers, conditions, and/or documents — you choose each category when creating the link.
  • No login is required to view a share link. Anyone with the link URL can view the summary until it expires or you revoke it.
  • You set the expiry (default 72 hours) and can revoke the link at any time from within the app.
  • We are not able to control who you share the link with, or what a recipient does with the information after viewing it. Treat a share link like you would a printed medical summary — only send it to people you trust, over a private channel.
  • View counts are logged so you can see whether a link has been accessed, but we do not log the identity of viewers (since no login is required).

10. Your Rights

10.1 Rights under the DPDP Act

As a Data Principal, you have the right to:

  • Access a summary of your personal data and the processing activities carried out on it
  • Correction and completion of inaccurate or incomplete personal data
  • Erasure of your personal data once it's no longer needed for the purpose it was collected for, or upon withdrawal of consent
  • Grievance redressal through our Grievance Officer (Section 1), with a right to escalate to the Data Protection Board of India if unresolved
  • Nominate another individual to exercise these rights on your behalf in the event of your death or incapacity — this can be configured from your account settings (or, until that UI ships, by writing to [DPO_CONTACT_EMAIL] with proof of identity)
  • Withdraw consent at any time, with the same ease with which it was given

10.2 Rights under GDPR (for users to whom it applies)

The same underlying data operations also satisfy GDPR's rights of access, rectification, erasure ("right to be forgotten"), restriction of processing, data portability, and objection to processing.

10.3 How to exercise these rights — self-service, in-app

Unlike many apps, Wellkept implements the two most consequential rights as real, working, self-service features — no support ticket required:

  • Export your data: from your account settings, you can download a complete JSON export of everything tied to your account — profile, family members, documents and their extracted data, medications, conversations, and subscription status — generated on demand and delivered as an immediate file download.
  • Delete your account: from your account settings, you can permanently delete your account. This immediately and irreversibly deletes your account record and cascades to delete all directly associated database rows (documents, medications, biomarkers, chat history, symptom logs, share links, and family member records). Uploaded files (documents, photos) are marked for deletion immediately and are purged from storage by an automated cleanup process shortly afterward. This action cannot be undone — there is no recovery window or "soft delete" available to you after confirming.

For any right not yet exposed as a self-service control (for example, correcting a specific extracted field inside a document rather than deleting the whole account, or nominating a successor), contact the Grievance Officer at the details in Section 1, and we will act on your request within the timelines required by applicable law.


11. Data Retention

  • Active accounts: we retain your data for as long as your account is active, to provide the Service.
  • After account deletion: as described in Section 10.3, deletion is immediate and cascading at the database level; underlying files are purged from storage shortly after via an automated job. We do not indefinitely retain "deleted" health data in cold storage.
  • Backups: routine encrypted database backups may retain deleted data for a limited operational window (typically no more than 30 days) purely for disaster-recovery purposes, after which they are rotated out and overwritten. Backups are not used to serve or restore an individual deleted account on request.
  • Reddit reference dataset: the dermatology reference dataset (Section 7.4) is retained as long as the feature operates, since it is not personal data about any Wellkept user; if you notice content there that should not be retained (e.g., a takedown by the original Reddit poster), contact us and we will remove it.

12. Where Your Data Is Stored and Cross-Border Transfer

Wellkept's infrastructure runs on Postgres (AWS Aurora) with the pgvector extension for AI search, S3-compatible object storage for uploaded files, and Redis for caching and rate-limiting. These services can be configured to run in the AWS ap-south-1 (Mumbai) region to keep primary storage within India; the specific region is an infrastructure configuration decision rather than a fixed guarantee stated in this Policy — [COMPANY_LEGAL_NAME] will state the actual production region here once finalized: [DATA_RESIDENCY_REGION_CONFIRMATION].

Regardless of where primary storage sits, certain processing necessarily leaves Indian infrastructure because it is performed by third-party processors headquartered abroad — most notably Google (Gemini AI processing, YouTube search, Firebase push) and Tavily. Where personal data is transferred outside India, we rely on our processors' own compliance obligations (e.g., Google's standard contractual protections) and, where DPDP Act rules on cross-border transfer restrictions come into force for specific countries, we will restrict transfers accordingly.

If we become a Significant Data Fiduciary under DPDP Act thresholds (based on the volume and sensitivity of data we process) as Wellkept scales, additional obligations apply, including a Data Protection Impact Assessment, an independent data auditor, and potentially data-localization requirements for specified categories of data. This determination and its implications require dedicated legal review as the company approaches that scale and is not something this Policy resolves in advance.


13. Data Security

We apply industry-standard technical and organizational measures appropriate to sensitive health data, including:

  • Encryption in transit (TLS) for all API traffic
  • Access to production data restricted to authorized personnel on a need-to-know basis
  • Distributed rate-limiting (Redis) to prevent abuse of AI/document endpoints
  • Phone-number-based OTP authentication with JWT session tokens (no passwords to be phished or leaked)
  • Ownership-scoped queries throughout the backend so one user's data (or a Family Vault member's data) cannot be returned in another user's request

No system is perfectly secure, and we cannot guarantee absolute security. If you believe your account has been compromised, contact us immediately at [DPO_CONTACT_EMAIL].


14. Cookies and Similar Technologies (Web)

The Wellkept web app uses minimal, functional cookies/local storage required for authentication session persistence. We do not use third-party advertising or cross-site tracking cookies.


15. Children's Privacy

The Service is not directed to, and we do not knowingly collect account-registration data directly from, anyone under 18. Health data about a minor may only enter the Service through a parent/guardian's Family Vault, as described in Section 8.


16. Changes to This Policy

We may update this Policy from time to time. Material changes — particularly any change that introduces a new purpose for processing your health data or a new third-party recipient — will require fresh, specific consent before that change applies to you, consistent with Section 5.1. We will notify you in-app and update the "Last updated" date above. Continuing to use non-materially-changed aspects of the Service after a routine update constitutes acknowledgment of the updated Policy.


17. Contact Us

  • Grievance Officer: [GRIEVANCE_OFFICER_NAME_AND_CONTACT]
  • Privacy/DPO contact: [DPO_CONTACT_EMAIL]
  • Registered address: [REGISTERED_ADDRESS]

This Privacy Policy is a first-pass, product-accurate draft prepared to reflect what the Wellkept application actually does as of the date above. It is not a substitute for review by a qualified data-protection lawyer, particularly regarding: (a) the Significant Data Fiduciary determination in Section 12, (b) finalizing the data-residency statement in Section 12 once infrastructure region is locked in, and (c) any jurisdiction-specific requirements beyond India and the EU/UK.