Healthcare App iOS DPDP Act 2023

Privacy Policy

Swaniyam is a wellness and medicine-tracking app. Here's exactly how we collect, use, store, and protect your data — written in plain language.

Effective31 May 2026
Updated31 May 2026
Version1.1
EntityGalgotias University

This Privacy Policy applies to all users of the Swaniyam mobile app and related services. Swaniyam helps users manage medicine schedules, log symptom and intake records, and view insights from their own entries.

We are committed to handling your data responsibly, transparently, and in line with applicable law, including:

  • Information Technology Act, 2000 and applicable Rules
  • Digital Personal Data Protection Act, 2023 (DPDP Act), as applicable

For users in other regions, we also honour applicable local privacy requirements where relevant.

By using Swaniyam, you agree to this Privacy Policy. Please read it carefully before using the app.

For the purposes of this policy, the following terms are defined as:

  • Personal Data
    Any data about an identifiable individual.
  • Sensitive Personal Data
    Health-related and wellness-related data you submit in the app.
  • Processing
    Collection, storage, use, disclosure, deletion, or other handling of data.
  • Data Fiduciary
    The entity determining the purpose and means of processing (us).
  • Data Principal
    The individual to whom personal data relates (you).
  • Consent
    A free, specific, informed, and unambiguous indication of your agreement.
  • Third Party
    Any person or entity other than you and us, including service providers.

A. Information You Provide Directly

  • Name, email address, gender, date of birth, weight, height, blood group
  • Account credentials and login verification inputs (email/password, OTP)
  • Medicine entries, medicine schedules, planned and unplanned medicine logs
  • Symptom entries and severity information
  • Profile photo selection (if you choose to add one)

B. Information Collected Automatically

  • Authentication and session information required to keep you signed in
  • Standard technical metadata processed by backend and auth providers (e.g. timestamps, server logs, IP metadata)
  • Device and app context such as OS version and app behaviour during normal operation

C. Health & Sensitive Data

Health and wellness data is treated with a higher level of protection. Explicit consent is obtained before this data is collected or processed.

Swaniyam may process sensitive wellness and health-adjacent data such as:

  • Symptom logs and severity records
  • Medicine schedules and intake logs (planned and unplanned)
  • Weight, height, blood group, and related profile details

Legal basis: Explicit consent and service delivery necessity for the features you request.

D. Data from Third-Party Integrations

Based on current integrations, Swaniyam connects with:

Supabase
Authentication and cloud database infrastructure
Sign in with Apple
Optional Apple ID-based authentication
Google Sign-In
Optional Google account-based authentication
DailyMed API (U.S. National Library of Medicine)
Medicine information lookup initiated by you

Swaniyam currently does not include HealthKit or Google Fit integrations. If added in future, this policy will be updated before that release.

We use your data to:

  • Provide and personalise core app functionality
  • Maintain medicine tracking, symptom logging, and user insights
  • Support login, account management, and security
  • Improve product quality and reliability
  • Respond to support requests and legal requests

We do not: sell your personal data · share health data with advertisers · share data with insurers, employers, or pharmaceutical companies for marketing or profiling · use your data for cross-app ad tracking.

We do not sell personal data — ever. Sharing occurs only where strictly necessary for service delivery, legal compliance, or security.

We may share data with:

  • Supabase
    Backend infrastructure (authentication and database)
  • Google / Apple
    Social sign-in only when you choose those methods
  • DailyMed (NLM)
    Medicine search requests you actively initiate
  • Legal authorities
    When required by valid and lawful legal process
  • Business transfer
    Merger or acquisition with notice where legally required

Where we use aggregated or anonymised data, it is used in non-identifiable form only and cannot be traced back to any individual.

Current services and SDKs integrated in the app:

Supabase (supabase-swift)
Authentication and cloud data sync
supabase.com/privacy →
GoogleSignIn / GoogleSignInSwift
Optional Google login integration
policies.google.com/privacy →
Sign in with Apple
Optional Apple login integration
apple.com/legal/privacy →
DailyMed API (NLM)
Medicine information retrieval on user request
dailymed.nlm.nih.gov →

The current app includes no integrated ad SDK, no ATT tracking flow, and no dedicated analytics or crash reporting SDK. Each third-party service operates under its own privacy policy as linked above.

Swaniyam currently does not use Apple HealthKit in the reviewed codebase.

If HealthKit integration is added in a future release, this policy will be updated prior to release and will include all required Apple disclosures, specifically that:

  • HealthKit data will not be used for advertising or marketing purposes
  • HealthKit data will not be shared with third parties without explicit user permission
  • HealthKit data will not be sold under any circumstances
  • Data is stored using cloud infrastructure provided by our backend stack (currently Supabase) and on-device app storage for session continuity
  • We use encryption in transit (HTTPS/TLS) and apply access controls appropriate to service operations
  • We apply authentication controls and backend security measures and review our practices periodically
  • If processing occurs across borders, we apply reasonable contractual and organisational safeguards as required by applicable law

No system is 100% secure. While we continuously improve our security controls, we cannot guarantee absolute security of data transmitted over the internet.

We retain data only as long as necessary for service delivery and legal purposes:

  • Account data
    Retained while active, plus up to 90 days after closure, unless a legal retention obligation applies
  • Health and wellness logs
    Retained while active; deleted within 30 days of a valid deletion request unless a legal hold applies
  • Technical logs
    Retained for up to 12 months for security and troubleshooting
  • Backup data
    Rolling backups purged within 30–90 days

You can request deletion of your account and data by:

  • Using the in-app account deletion flow (if enabled), or
  • Emailing from your registered account email address

Timeline: We will acknowledge your request within 48 hours and complete deletion within 30 days, subject to legal exceptions.

We may retain minimal data where required by law, security, or dispute resolution. Otherwise, your profile and all health and wellness records are permanently deleted from active systems.

Subject to applicable law, you may exercise the following rights:

📋
Access
Request a copy of the personal data we hold about you.
✏️
Correction
Ask us to correct inaccurate or incomplete data.
🗑️
Erasure
Request permanent deletion of your personal information.
📦
Portability
Receive your data in a machine-readable format where feasible.
🚫
Withdraw
Withdraw consent at any time without penalty.
⚖️
Grievance
Raise a complaint with our Grievance Officer (Section 19).
👤
Nomination
Under DPDP Act, nominate someone to exercise rights on your behalf.

To exercise any right, contact . We may verify your identity before processing. Response target: within 30 days.

Swaniyam is intended for users aged 18 and above by default unless a separate child-compliant flow is implemented.

  • We do not knowingly collect personal data from individuals under 18 without verifiable parental or guardian consent
  • If minors are permitted in future, verifiable parental consent and additional protections will be implemented before processing any child data — in compliance with the DPDP Act, 2023
  • We do not conduct behavioural tracking or profiling of minors under any circumstances
  • Parents or guardians may contact to request deletion of a child's data
⚠ Not Medical Advice

Swaniyam is a wellness and medicine-management support tool, not a medical device. It does not diagnose, treat, cure, or prevent any disease or medical condition. All content, suggestions, and insights are for informational and personal tracking purposes only and are not a substitute for professional medical advice, diagnosis, or treatment. Always consult a qualified healthcare professional before making any medical decisions.

We maintain incident response processes to identify, contain, and remediate security incidents.

  • If a confirmed breach materially affects your personal data, we will notify affected users and relevant authorities as required by applicable law
  • This includes applicable CERT-In obligations under Indian law where relevant
  • For high-risk confirmed incidents, our target notification objective is within 72 hours where legally required and feasible
  • Notifications will describe what data was affected, what occurred, and what steps are being taken

The Swaniyam native iOS app does not rely on browser cookies in the native app context.

If we launch web-based components in the future, we may use essential and analytics cookies and will provide appropriate cookie controls and an updated cookie policy at that time.

  • The "Last Updated" date and version number at the top of this page will always reflect the current version
  • Material changes will be communicated via in-app notice, email, or other suitable channels before they take effect
  • Continued use of the app after the effective date constitutes acceptance of the revised policy where permitted by law

As required under the Information Technology Act, 2000 (Rule 5(9)) and the DPDP Act, 2023, we have appointed a Grievance Officer:

⚖ Grievance Officer
Name
Designation
Email
Postal Address
Greater Noida, Uttar Pradesh, India

Service levels:

  • Complaint acknowledgement within 48 hours of receipt
  • Resolution within 30 days, subject to complexity and applicable law

For all privacy-related queries, data requests, or concerns:

Data Fiduciary / Company
Galgotias University
Registered Address
Greater Noida, Uttar Pradesh, India
General Support
Privacy Contact