This Privacy Policy describes how BastionGuard Medical Technologies Pvt. Ltd. ("we", "us", "our") collects, uses, stores and discloses personal information when you use the Sva — Detox mobile application (the "App") and related services.
We are committed to handling your data in accordance with the Digital Personal Data Protection Act, 2023 (DPDP Act), the Information Technology Act, 2000 and its Rules, and applicable laws of India.
1. Who we are
Data Fiduciary: BastionGuard Medical Technologies Pvt. Ltd.
Registered Office: 372/E 1, Karunya Building, Podiyadi, Pathanamthitta – 689110, Kerala, India
GSTIN: 32AAOCB1809M1ZK
Grievance Officer / Contact: info@bastionguardhealthcare.in
2. Information we collect
2.1 Information you give us
- Account data — name, email address, password (stored only as a one-way bcrypt hash), optional Google account profile picture and name (if you sign in with Google).
- Recovery email — a separate email you provide to recover your account.
- Role — Parent or Child / Self.
- Privileged (Parent) Password and daily Passcode — stored only as bcrypt hashes.
- Onboarding answers — age range, audience, current daily screen-time estimate, top distractions, motivation, friction style preferences, daily goal.
- App-usage settings you configure — list of tracked apps, detox windows, habits, daily intention text, mood selections.
- AI conversations — messages you exchange with our in-app coach "Sva".
- Billing information you provide at checkout — billing state, optional GSTIN (for tax-invoice purposes only), optional phone number for UPI AutoPay.
2.2 Information collected automatically
- Activity events — focus sessions, multi-step challenges (success/failure), tap counts on tracked apps, achievements earned.
- Device data — operating system version, device model (collected only in aggregate, no advertising identifiers).
- Crash and error logs — used only to fix the app; do not contain content of your AI conversations or your passwords.
2.3 Information collected via device permissions (Android-only, opt-in)
If and when you grant the relevant Android permissions:
- Usage statistics (
PACKAGE_USAGE_STATS) — aggregate per-app foreground minutes, used to compute your daily screen-time and per-app statistics on-device. - Accessibility service — used solely to detect when a tracked app is opened so the App can launch the in-app challenge. We do not read screen contents, capture passwords or harvest data from other apps.
- Display over other apps — used to render the challenge UI above the target app; no screen capture or recording.
These permissions can be revoked any time from Android Settings.
2.4 Information we do NOT collect
- Contact lists, SMS messages, call logs, photos, files, location.
- Advertising identifiers — we do not run ads.
- Biometric data.
- Card or bank account numbers — all payments are processed by Razorpay; we never see the full card number or CVV.
3. Why we use your information (purposes)
- To create and operate your account and provide the App's features.
- To personalise your experience using your onboarding answers.
- To generate AI coach responses by sending your message and limited profile context (name, goal, today's screen-time, tracked apps) to our AI model provider (Anthropic Claude via Emergent integrations).
- To process subscription payments and issue GST-compliant tax invoices.
- To prevent abuse, secure accounts and respond to user-support requests.
- To comply with our legal, regulatory and tax obligations.
4. Legal basis (DPDP Act, 2023)
We process personal data on the following legal bases:
- Consent — given explicitly during signup and onboarding.
- Legitimate use — for fraud prevention, security, and compliance with court orders or law.
- Contractual necessity — to deliver the subscription you purchased.
5. Third parties who process data on our behalf
We share only the minimum data required with the following "Data Processors", each of whom is bound by appropriate contractual terms:
| Processor | Purpose | Data shared |
|---|---|---|
| Razorpay | Payment processing & subscription billing | Name, email, phone, billing state, optional GSTIN |
| Maileroo | Transactional email delivery | Email address, name, invoice PDF |
| Anthropic (via Emergent) | AI coach replies | Your message text + limited profile context |
| Google (optional) | Authentication | Google account name, email, profile picture URL |
| Cloud hosting | App backend hosting in India / SE-Asia | All of the above, encrypted in transit and at rest |
We do not sell your personal data and we do not share it for third-party advertising.
6. Data retention
- Active-account data: retained while your account exists.
- AI conversation history: retained until you delete it or your account.
- Tax invoices & payment records: retained for 8 years as required by Indian tax law.
- Crash / error logs: 90 days.
- On account deletion: we erase all personal data within 30 days, except where retention is required by law.
7. Your rights
Under the DPDP Act you have the right to:
- Access the data we hold about you.
- Correct or update any inaccurate information.
- Erase your data (delete your account from Profile → Sign out → "Delete account", or by emailing us).
- Withdraw consent — by uninstalling the App and deleting your account.
- Nominate another person to exercise these rights in the event of your death or incapacity.
- Grievance redressal — write to our Grievance Officer; we will acknowledge within 24 hours and respond within 15 days.
8. Children's privacy
The App is intended for users 18 years and older, and for parents to manage the phone usage of their children. If a parent registers a child under 18:
- The parent is the verifiable consenting adult and assumes full responsibility for the data of the child.
- We do not knowingly process personal data of any child without parental consent.
- No advertising of any kind is shown.
- The AI coach does not collect or store the child's identifying information beyond what is required for the App to function.
If you believe a child has provided personal data to us without parental consent, email info@bastionguardhealthcare.in and we will delete it.
9. Security
We use industry-standard safeguards including TLS 1.2+ encryption in transit, encryption at rest, bcrypt password hashing, HMAC-verified webhooks, and role-based access controls. While no system is perfectly secure, we promptly investigate and notify affected users of any breach in accordance with the IT Rules and DPDP Act.
10. International data transfers
Most of our processors store data in India or the European Union. Some (Anthropic, Maileroo) are based outside India; transfers to such jurisdictions are made under appropriate contractual safeguards.
11. Cookies and analytics
The mobile App does not use cookies. We do not currently run any third-party analytics SDKs.
12. Changes to this policy
We may update this policy from time to time. Material changes will be notified within the App and via email at least 7 days before they take effect.
13. Contact us
Grievance Officer:
BastionGuard Medical Technologies Pvt. Ltd.
372/E 1, Karunya Building, Podiyadi, Pathanamthitta – 689110, Kerala, India
Email: info@bastionguardhealthcare.in