Curevity — Privacy Policy

Effective date: 3 August 2026  ·  Applies to the Curevity mobile app for iOS and Android.

Curevity ("we", "us") is a personal health-tracking app operated by Jamali Web Tech. This policy explains, in plain words, what information the app handles, where it lives, and the choices you have. The short version: your complete health history lives on your own phone, encrypted. Our servers hold only the minimum needed for the features you switch on.

1. What stays on your phone

Everything you record in Curevity — medicines, dose schedules and history, health readings (blood pressure, sugar, weight, pulse, SpO2, temperature), symptoms, conditions, appointments, diet details and medical report files — is stored in an encrypted database on your device. We cannot read it. It is not uploaded, synced or backed up to our servers unless a specific feature below requires a specific part of it. Deleting the app deletes this data.

2. What our servers hold, and why

Curevity uses Supabase (a hosted database service) for the features that need a server. Each item below exists only if you use that feature:

Account. Your email address, a securely hashed password, and a display name. Email verification and password-reset codes are delivered by our email provider (Resend).

Caregiver sharing. If you invite a caregiver, we store a limited "care summary" so they can watch over you: your medicine names and schedules, recent dose events (about 30 days), recent readings, missed-dose alerts, appointments, and — if you fill it — your emergency card. Access is enforced row-by-row on the server: only caregivers you approved can see it, only the categories you allowed, and you can revoke access at any time. Reports you explicitly share with a caregiver are stored until you unshare them.

Subscriptions. Your plan tier, its expiry and store receipt identifiers, so paid features work across reinstalls. Payment itself is handled entirely by Apple's App Store or Google Play — we never see your card or bank details.

Push notifications. A device push token (Firebase Cloud Messaging), used to deliver caregiver alerts and care updates.

AI usage counters. How many AI chats and diet plans you used this month (numbers only, kept 12 months), to enforce plan quotas.

3. AI features

When you use Curevity AI (chat, diet plans, or report scanning), the text needed to answer you — your question, relevant tracked data you have chosen to discuss, or the text extracted from a report you scan — is processed by OpenAI as our processor, through our own server. Report scanning sends extracted text only, never the photo or PDF itself. Under OpenAI's API terms this data is not used to train their models. AI answers are informational and never a diagnosis (see our Terms).

4. Location

The doctor-search feature can use your current location, only when you tap "near me", only while the app is in use, and only to send a search request to Google Places. We do not store your location on our servers.

5. What we do NOT do

No ads, no ad networks, no analytics or tracking SDKs, no sale of data, no cross-app tracking, no use of your health data for marketing. Ever.

6. Sharing

We share data only with the service providers that make the app work — Supabase (database and authentication), OpenAI (AI text processing), Google (Places search, Firebase push delivery), Resend (account emails), and Apple/Google (subscription billing) — each bound to process it only for us. Beyond that, data leaves our systems only if you direct it (for example, sharing a doctor PDF from your phone) or if the law compels us.

7. Your controls

Delete my data in Settings erases the app's local health data on your phone and the caregiver-shared copies on our servers. Removing a caregiver, or unsharing a report, removes their access immediately. You can also email us to delete your account entirely. Data needed for an active paid subscription is kept while the subscription runs, then deleted on the same schedule.

8. Security

Local health data is encrypted at rest on your device; you can additionally require Face ID / Touch ID / your device credential to open the app. Server data is protected with row-level security, encrypted transport (TLS), and secrets kept in a managed vault. No system is perfectly secure, but the design principle throughout is that the sensitive whole never leaves your phone.

9. Children

Curevity is not directed at children under 13, and we do not knowingly collect their data. A caregiver account must be operated by an adult.

10. Changes and contact

If this policy changes materially we will tell you in the app before the change applies. Questions or requests: [email protected]. Curevity is operated from India; this policy is governed by the laws of India.