A complete technical record of every category of data we collect, store, and process
This Data Policy provides a precise, technical record of every category of data that Vigzar MedCare collects, processes, stores, and transmits. It is intended to complement the Privacy Policy with granular, developer-grade transparency. Last updated: June 7, 2025.
This Data Policy applies to:
Our guiding principle: Collect the minimum data necessary. Store health data exclusively on the user's device. Never monetise personal or health information.
Stored exclusively on-device. Never transmitted to Vigzar servers.
Stored exclusively on-device. Never transmitted to Vigzar servers.
Stored exclusively on-device. Never transmitted to Vigzar servers.
Stored exclusively on-device.
Collected and processed via Firebase Authentication.
We do not store passwords. Authentication is delegated entirely to Google.
Transmitted only when the user explicitly initiates or schedules a backup.
Collected anonymously via Firebase Crashlytics.
Health data is explicitly excluded from all crash reports via Crashlytics data scrubbing configuration.
Collected anonymously via Firebase Analytics (if enabled).
All analytics events are designed to contain zero health information. Event parameters are reviewed before implementation to ensure no PII or PHI leakage.
Processed via Razorpay (India) and Google Play Billing.
| Data Category | Classification | Storage Location | Encrypted | Transmitted |
|---|---|---|---|---|
| Medication data | Health / PHI | On-device only | Yes (AES-256) | Only in backup |
| Family profiles | Personal | On-device only | Yes (AES-256) | Only in backup |
| Health records | Health / PHI | On-device only | Yes (AES-256) | Only in backup |
| Doctor directory | Personal | On-device only | Yes (AES-256) | Only in backup |
| Google email / name | Personal (PII) | Firebase Auth | Firebase managed | Yes (to Firebase) |
| Crash reports | Diagnostic | Firebase Crashlytics | Yes (in transit) | Yes (to Firebase) |
| Analytics events | Anonymous | Firebase Analytics | Yes (in transit) | Yes (to Firebase) |
| Backup blob | Health / PHI | User's Google Drive | Yes (AES-256) | Yes (to Google Drive) |
| Payment tokens | Financial | Firebase + local | Yes | Yes (to Razorpay / Google) |
PHI = Protected Health Information (equivalent standard applied regardless of jurisdiction)
Data persists until:
We do not sell, rent, or share personal data with third parties for commercial purposes. Authorised processors:
We may disclose data if required by:
We will notify affected users of legal data requests to the extent permitted by law.
All your health data is accessible at any time within the app. There is no separate data access request needed — it is always visible to you.
All data can be edited directly within the app at any time.
We respond to formal data rights requests within 30 calendar days. Submit requests to privacy@vigzar.com.
The app is not directed at children under 13. We do not knowingly collect personal data from children under 13. Child medication profiles created by parents or guardians are stored on-device under the parent/guardian's account and are subject to the same protections as all health data.
If you believe a child under 13 has created an independent account, contact privacy@vigzar.com immediately.
In the event of a confirmed data breach that affects personal data:
Given our offline-first architecture — where health data never resides on our servers — the blast radius of any server-side breach is limited to authentication metadata only.
Vigzar MedCare is designed with the following frameworks in mind:
We are not a HIPAA-covered entity, but we voluntarily align with HIPAA's minimum necessary and safeguard principles.
Material changes to this Data Policy will be communicated via:
Last updated: June 7, 2025
Version: 1.0.0
This Data Policy is binding and forms part of the Vigzar MedCare Terms & Conditions.