Legal
Privacy Policy
TrueKin, by TrueKin Technologies Private Limited
By using TrueKin, you agree to the practices described here.
1. Who We Are
TrueKin Technologies Private Limited is the data controller and operator of TrueKin. We are incorporated in India and subject to Indian data protection law.
Registered Address
TrueKin Technologies Private Limited, India
Governing Laws
This policy is made in compliance with the:
- Information Technology Act, 2000 (IT Act)
- IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (SPDI Rules)
- Digital Personal Data Protection Act, 2023 (DPDP Act)
2. Grievance Officer
Under the IT Act 2000 and SPDI Rules 2011, we are required to appoint a Grievance Officer for privacy-related complaints. If you have any concern about how your data is handled, please contact:
Achyuth Jayagopal, Grievance Officer
grievance@truekin.co.in+91 94469 10814
34/812-H, Pynadath House, Amity Gardens, Beena Anjumana Road, Edappally, Ernakulam, Kerala 682024, India
We will acknowledge your complaint within 24 hours. General complaints about the app or service are resolved within 15 days (IT Rules 2021). Requests relating to your statutory data rights under the DPDP Act — access, correction, or erasure — are resolved within 90 days (DPDP Rules 2025).
For general support, visit the Support section in the TrueKin app.
3. What Information We Collect
3.1 Information You Provide Directly
Account Information
- Mobile number (for OTP login and identity verification)
- Email address (optional, for email-based login)
- Display name, gender, profile photo
Sensitive Personal Data (SPDI under SPDI Rules 2011)
The following information is classified as Sensitive Personal Data under Indian law. We collect it only with your explicit prior consent:
- Date of birth, height, weight
- Blood group
- Home address
- Health conditions you manage
- Food allergies and medicine allergies
- Medication names, dosages, schedules, doctor names, side effects, and notes
- Medical documents including lab reports, imaging reports, and prescriptions you upload
- Information extracted from documents by our AI system (only with your separate consent)
Family Care Information
- Names, relationships, and health details of family members you choose to add to your care circle
- Invitation details for people you invite to share care
3.2 Information Collected Automatically
- Device type, operating system, app version
- Feature usage and screen activity, associated with your account — used to understand how the app is used and improve it
- IP address (stored in irreversibly pseudonymised form; raw IP is never stored)
3.3 What We Do Not Collect
- Your GPS location or location history
- Your device contacts list
- Biometric identifiers (fingerprint, face scan)
- Payment or financial information
4. Why We Collect It (Purpose and Legal Basis)
| Purpose | Legal Basis Under DPDP Act 2023 |
|---|---|
| Account creation and OTP verification | Legitimate use (contract with you) |
| Displaying your health profile and medications | Legitimate use (contract with you) |
| Sending medication reminders | Legitimate use (contract with you) |
| Enabling family care sharing | Legitimate use (contract with you) |
| Processing uploaded documents with AI | Explicit consent (separate, specific) |
| Improving app reliability and performance | Legitimate interest (anonymised only) |
| Customer support and grievance resolution | Legal obligation / Legitimate interest |
| Complying with court orders or legal process | Legal obligation |
5. Sensitive Personal Data: Special Protections
Because TrueKin handles health information, the following additional protections apply under SPDI Rules 2011:
- We collect SPDI only after obtaining your free, informed, specific, and explicit consent
- You may withdraw consent at any time. See Section 12 (Your Rights)
- We do not share your SPDI with any third party without your consent, except as required by law
- All SPDI is encrypted at rest using AES-256-GCM encryption. See Section 8
6. WhatsApp Communications
When you register with TrueKin, you may receive communications via WhatsApp, including:
- OTP verification codes for login
- Medication reminders (if you enable this in Settings)
- Important account and service notifications
What We Share with Meta (WhatsApp)
Your phone number is shared with Meta Platforms, Inc. solely to deliver WhatsApp messages to your device. We do not share your health data, name, or any other personal information with Meta for this purpose.
Meta's own privacy policy governs how they process your phone number and message metadata on their platform. TrueKin has no control over Meta's data practices.
Opt-Out
You can stop WhatsApp communications from TrueKin at any time by:
- Replying STOP to any WhatsApp message from TrueKin
- Adjusting your notification preferences in Settings → Notifications
7. AI Document Processing
When you upload a medical document, TrueKin can use an AI language model to extract and structure the information in it.
This is entirely opt-in
- You must give separate, explicit consent for AI processing before any document is analysed
- This consent is distinct from general data processing consent
- You can give or withdraw this consent at any time from Settings → Privacy & Consent
- If you do not give consent, your documents are stored but not processed by AI
Who processes it
Document contents are sent to Sarvam AI, an Indian AI company, for extraction. Processing stays within India — no document content is sent outside the country for this purpose. They do not use your data to train their AI models.
Accuracy warning
AI-extracted information may contain errors. Always verify extracted data against your original document. Do not make medical decisions based on AI-extracted data without consulting a healthcare professional.
8. How We Protect Your Information
8.1 Encryption
All Sensitive Personal Data is encrypted before it is stored in our database, using AES-256-GCM encryption with keys managed through a secure key management system. This means the data in our database cannot be read even if someone gained unauthorised database access.
All data in transit is protected with TLS 1.2 or higher.
8.2 Access Controls
Your health data is accessible only to you and family members you explicitly authorise. Our team cannot read your health records in the normal course of operations. Access to production infrastructure is limited and logged.
8.3 Session Security
Each login is secured with a one-time password (OTP). Session tokens are stored as one-way hashes. The raw token is never stored. Logging out immediately invalidates your session.
8.4 Pseudonymisation of Analytics and Logs
We do not link app usage analytics to your name, phone number, or health data. IP addresses in logs are irreversibly pseudonymised using a cryptographic HMAC.
8.5 Data Breach Notification
Despite our safeguards, in the unlikely event that your personal data is compromised in a security incident, TrueKin is legally bound under Rule 7 of the DPDP Rules, 2025 to act with transparency and speed:
- We will notify the Data Protection Board of India (DPBI) and inform you, without delay, in clear and plain language
- A detailed report describing the nature of the breach, the data affected, and mitigation steps will be submitted to the DPBI within 72 hours of our becoming aware of it
- Where the incident qualifies as a cybersecurity incident, it will also be reported to the Indian Computer Emergency Response Team (CERT-In) within 6 hours of detection, as required under Section 70B(6) of the IT Act, 2000
This notification duty applies regardless of how many users are affected — a breach involving a single account triggers the same reporting obligation as one affecting many.
9. Where Your Data Is Stored
Your data is stored on servers located in India. We use Supabase (database infrastructure hosted in India) as our primary database provider. Encryption keys for data at rest are managed using AWS KMS, hosted in AWS's Mumbai (India) region.
When your documents are processed by AI (with your consent), data is sent to Sarvam AI, whose processing infrastructure for this service is also located in India. This means your data does not leave the country for AI document processing.
10. Who We Share Your Data With
We share your information only in these specific circumstances:
| Recipient | What Is Shared | Why |
|---|---|---|
| Family members you invite | Profile and health data (based on your permissions) | You control and authorise this |
| Anyone you send a profile share link to | Data you include in the link (set by you) | You create, control, and can revoke links |
| Sarvam AI (India) | Contents of uploaded documents | AI extraction (only with your explicit consent) |
| AWS KMS (India, Mumbai) | Encryption keys (not your data itself) | Managing encryption keys for data at rest |
| Supabase (India) | Encrypted data at rest | Database hosting |
| MSG91 (India) | Phone number | Sending OTP via SMS |
| Brevo (France/EU) | Email address | Sending OTP and transactional emails |
| Firebase (Google) | Device push token | Delivering in-app notifications |
| Meta (WhatsApp) | Phone number | Delivering WhatsApp OTPs and notifications (see Section 6) |
| Law enforcement / courts | As required by law | Legal obligation only |
11. Data Retention
We keep your data for as long as your account exists. Once you delete your account:
| Data Type | Retention After Deletion |
|---|---|
| Health profile, medications, documents | Deleted within 30 days |
| Medical document files | Deleted within 30 days |
| Session logs | Deleted within 90 days of session end |
| Anonymised usage analytics | Retained up to 2 years (no personal identifiers) |
| Account deletion record | Retained 5 years (pseudonymised, no health data, no name) |
| Support ticket history | Retained 2 years |
The 5-year deletion record contains only a pseudonymised identifier and deletion timestamp. No name, phone number, email, or health data is retained. This is retained solely for legal compliance purposes.
Automated erasure for inactive accounts
If your account is entirely inactive — no logins and no medication-tracking activity — for a continuous period of 36 months, TrueKin will automatically begin erasing your account and its data. We will notify you via your registered email, phone number, or WhatsApp at least 48 hours before erasure, giving you the chance to log in and keep your account active.
12. Your Rights
Under the DPDP Act 2023 and SPDI Rules 2011, you have the following rights:
Right to Access
Request a full copy of all data we hold about you. You can download it directly: Settings → Privacy & Consent → Download My Data
Right to Correction
Update your profile, medications, and health records at any time within the app.
Right to Withdraw Consent
Withdraw consent for any specific purpose at any time: Settings → Privacy & Consent. Withdrawing consent for AI processing stops new documents being sent to AI (existing extractions are retained). Withdrawing consent for marketing stops all promotional communications. Withdrawing consent for health data storage will disable core features and may require account deletion.
Right to Erasure (Right to be Forgotten)
Permanently delete your account and all associated data: Account Settings → Delete Account. Deletion is irreversible. We recommend downloading your data first.
Right to Grievance Redressal
Contact our Grievance Officer at grievance@truekin.co.in. We acknowledge complaints within 24 hours; general complaints are resolved within 15 days, and requests relating to your data rights (access, correction, erasure) within 90 days. If you are not satisfied with our response, you may approach the Data Protection Board of India once established under the DPDP Act 2023.
Make a data request by email
13. Children's Privacy
We do not knowingly collect personal data from anyone under 18. If we become aware that a user is under 18, we will delete their account. If you believe a minor has registered, please contact grievance@truekin.co.in.
You may add family members under 18 to your care circle. By doing so, you expressly represent and warrant, under penalty of law, that you are their lawful parent or legal guardian and are legally authorised to manage their health information. TrueKin relies on this representation, and may require additional verification of your relationship to the minor at any time. Providing a false representation of guardianship is a serious violation of this Policy and our Terms.
14. Cookies and Analytics
The TrueKin mobile app does not use browser cookies.
We use pseudonymised analytics (no name, no phone number, no health data) to understand how features are used and improve the app. Analytics data does not identify you personally.
The TrueKin website (truekin.co.in) may use cookies for basic functionality and analytics. Cookie preferences can be managed through the banner shown on first visit or through your browser settings.
15. Changes to This Policy
- We will notify you in the app before the change takes effect
- Changes that affect how we use your sensitive health data will require your acknowledgement
- The version number and effective date at the top of this page will be updated
- We will maintain the previous version for 12 months on request
Continued use of TrueKin after the effective date of changes constitutes acceptance of the updated policy.
16. Contact
Privacy complaints or data requests
Grievance Officer
grievance@truekin.co.inAcknowledged in 24 hours · resolved in 15–90 days depending on request type
Registered office
TrueKin Technologies Private Limited, India
This Privacy Policy is governed by the laws of India. Any disputes are subject to the jurisdiction of courts in India.
Applicable laws: Information Technology Act 2000 · IT (SPDI) Rules 2011 · Digital Personal Data Protection Act 2023
Questions? Contact our Grievance Officer: grievance@truekin.co.in
Acknowledged in 24 hours · resolved in 15–90 days depending on request type.