HamroSwasthya

Privacy Policy

Version 1.1 | Effective 20 August 2026 | Operated by Tru-Path Labs

This Privacy Policy explains how Tru-Path Labs ("we", "us", "our") collects, uses, stores, and protects your personal data when you use the HamroSwasthya App ("App"). We are committed to handling your health data with care and transparency.

Contact: [email protected]

1. Data Controller

The data controller for your personal data is Tru-Path Labs, the operator of HamroSwasthya. Contact: [email protected].

We are primarily subject to the laws of Nepal. As we expand internationally, we will comply with applicable data protection laws in the markets where the App is made available.

2. Data We Collect

2.1 Account data

2.2 Health profile data

2.3 Medical Records

2.4 Technical and usage data

2.5 Data we do not collect

2.6 Website feedback messages

If you use a public HamroSwasthya contact or guide-feedback form, we collect the email address you provide, optional name, message, selected topic, and the page context of your message. Please do not include personal health information. We use Cloudflare Turnstile and a privacy-preserving rate-limit key to protect the form from abuse; we do not store your raw IP address for this purpose.

2.7 Symptom-checker voice and optional vocabulary feedback

If you choose to use voice, your recording is sent securely to the Google Gemini API to create a transcript. HamroSwasthya processes the recording for that request and does not save the audio in its database or file storage. You can use the symptom checker without voice by choosing symptoms manually.

After matching, the checker may show wording that did not match an approved symptom. You may separately opt in to share only that displayed unmatched wording. If you do, we store the wording, its normalised form, language, occurrence count, consent version, submission and expiry dates, and its editorial review status. For this feature we do not store your audio, full transcript, matched wording, raw IP address, account identity, or a session identifier.

The Google Gemini API may process opted-in unmatched wording to suggest an existing catalogue symptom or “no match” for clinical review. It cannot create symptom IDs, approve wording, change your current checker result, rank conditions, or make a clinical decision. A configured clinical reviewer must approve any wording before it can be used by the deterministic symptom matcher.

We reject feedback containing obvious contact details, URLs, emergency wording, or self-harm wording. Unmatched wording is deleted after approval or rejection, or automatically within 90 days. Sharing is optional and does not affect access to the checker.

२.७ लक्षण जाँचको आवाज र ऐच्छिक शब्दावली प्रतिक्रिया

आवाज प्रयोग गरेमा, तपाईंको अडियोलाई लेखमा बदल्न Google Gemini API मार्फत सुरक्षित रूपमा प्रशोधन गरिन्छ। HamroSwasthya ले अडियोलाई आफ्नो डाटाबेस वा फाइल भण्डारणमा सुरक्षित गर्दैन। आवाज प्रयोग नगरी पनि लक्षणहरू आफैँ छानेर जाँच गर्न सकिन्छ।

लक्षण मिलाइसकेपछि, स्वीकृत लक्षणसँग नमिलेको शब्द देखिन सक्छ। तपाईंले चाहेमा त्यही देखाइएको नमिलेको शब्द मात्र छुट्टै सहमतिमा साझा गर्न सक्नुहुन्छ। यस सुविधाका लागि अडियो, पूरा भनाइ, मिलेको शब्द, कच्चा IP ठेगाना, खाता पहिचान वा सेसन पहिचान सुरक्षित गरिँदैन। साझा गरिएको शब्द चिकित्सकीय समीक्षापछि स्वीकृत वा अस्वीकृत हुँदा, वा बढीमा ९० दिनभित्र, मेटाइन्छ। साझा गर्नु ऐच्छिक हो र यसले लक्षण जाँच प्रयोग गर्न असर गर्दैन।

3. Lawful Basis for Processing

By creating an account, accepting the in-App consent screens, uploading Medical Records, or entering health profile information, you voluntarily provide that data and give us permission to process it for the purposes described in this Policy. For health-related data, this includes your explicit consent to process special category or sensitive health data where such consent is required by law.

If you add a family or dependent profile, you confirm that you have the consent, parental responsibility, legal authority, or other lawful basis required to provide that person's personal and health-related information to us.

4. How We Use Your Data

We will never sell your data. We will never use your health data for advertising.

5. Data Storage and Security

5.1 Cloud storage

Your Account data, Medical Records, and health profile are stored on Google Firebase infrastructure, including Firebase Auth, Firestore, and Firebase Storage. Firebase uses encryption at rest and TLS encryption in transit. Data is stored in Google's cloud infrastructure under our Firebase project.

5.2 On-device security

Medical record images are also stored locally on your device in encrypted storage backed by the Android Keystore system. Encryption keys never leave your device.

5.3 Access controls

Your data is protected by Firebase Security Rules. Only you can access your own records. Shared records via QR are read-only and time-limited. No Tru-Path Labs employee has routine access to your Medical Records.

5.4 Your responsibility for access and sharing

You are responsible for keeping your login credentials, device passcode, biometric unlock, and QR Share links secure. If you choose to share records using a QR link, the recipient may view, copy, photograph, screenshot, or otherwise record information displayed to them. We cannot control the actions of recipients once you choose to share your data.

5.5 Website feedback

Public website feedback messages are stored in a private Cloudflare D1 database and can be accessed only by authorised HamroSwasthya administrators. Turnstile verification is provided by Cloudflare before a feedback message is accepted.

5.5 Biometric lock

The App supports biometric and passcode lock to prevent unauthorised local access.

6. Data Retention

Active account data and recordsRetained while account is active
After account deletion requestDeleted from active systems within 60 days
Backup copiesPurged within 60 days of deletion
Security and access logs180 days
Website feedback messagesUp to 12 months, unless deleted earlier
Opted-in unmatched symptom wordingUntil clinical approval or rejection, or no longer than 90 days
Inactivity warning sent12 months of inactivity
Account eligible for closure18 months of inactivity, with notice

7. Third-Party Processors

We use the following sub-processors, all operated by Google LLC:

Firebase AuthUser authentication
FirestoreAccount and metadata storage
Firebase StorageMedical record files
Firebase CrashlyticsCrash reporting
Firebase AnalyticsUsage analytics
CloudflarePublic website hosting, Turnstile verification, and feedback-message storage
Google Gemini APIVoice transcription and editorial vocabulary suggestions from wording you separately choose to share

Google Firebase, Google Gemini API, and Cloudflare process data only to provide the services described above. We do not use third-party human support tools that would expose your data to support agents.

8. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.

9. Data Breach Notification

In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify you without undue delay and in any event within 72 hours of becoming aware of the breach. Notification will be sent to your registered email address and, where required, to the relevant supervisory authority.

10. International Data Transfers

Your data is stored on Google Firebase infrastructure, which may involve transfers to servers outside Nepal or your country of residence. Google maintains appropriate safeguards for such transfers, including Standard Contractual Clauses where required. By using the App, you consent to these transfers where consent is a valid lawful basis.

11. Accuracy, Backups, and User Responsibility

We do not verify, clinically review, interpret, or guarantee the accuracy, completeness, authenticity, or medical usefulness of any Medical Records or profile information you provide. You are responsible for checking that uploaded records are correct and readable.

You should keep your own backup copies of important medical documents. HamroSwasthya is a convenience and storage tool, not an official medical record system, healthcare provider, insurer, hospital, government database, or emergency medical service.

12. Cookies and Tracking

The App does not use browser cookies. We use Firebase Analytics SDK for aggregate usage analytics. You can opt out of analytics collection in the App settings. The public website uses Cloudflare Turnstile on feedback forms to prevent abuse; its necessary technical processing is governed by Cloudflare. We do not track you across third-party websites or apps.

13. Children

The App is not intended for children under 16 to create or operate their own Account. If we become aware that a child under 16 has created an Account, we may delete the Account and associated data.

A parent, guardian, or legally authorised caregiver may create and manage a dependent profile for a child, provided they have the necessary consent or legal authority to do so.

If you believe a child has created an Account without appropriate authority, please contact us.

14. Changes to This Policy

We will notify you of any material changes to this Privacy Policy at least 30 days before they take effect, by email or in-App notification. The date of the latest update is shown at the top of this document.

15. Contact and Complaints

For privacy questions, data requests, or complaints, contact:

Email: [email protected]

If you are not satisfied with our response, you have the right to lodge a complaint with the relevant data protection supervisory authority in your country.