Privacy Policy

Your privacy, our responsibility.

We handle your family's health data with the same care you would.

Updated July 6, 2026~9 min read12 sections
๐ŸŒธ

Who We Are

Day Zero ("Pushpa", "we", "our", "us") operates an AI-powered health assistant accessible via WhatsApp and our web and mobile platforms. We help individuals and families understand health documents, track medications, and stay on top of their family's wellbeing โ€” all in plain language.

This Privacy Policy explains what personal and health information we collect, how we use and protect it, and the rights you have over it. It applies to all users of Pushpa โ€” whether you access us through WhatsApp, our app, or our website.

By using Pushpa, you consent to the practices described here. If you use Pushpa to manage health data for family members, you confirm that you have their knowledge and consent to share their information with us on their behalf.

๐Ÿ“‹

Information We Collect

We collect only what is needed to provide and improve the service. Here is what that includes:

๐Ÿ‘ค

Personal Identity

Name, phone number, email, date of birth, gender, blood group, height, weight, city, and profile photo.

๐Ÿ“„

Health Documents

Photos and PDFs of lab reports, prescriptions, X-rays, ECGs, and other medical records you send us.

๐Ÿงฌ

AI-Extracted Health Data

Conditions, lab values, medications, vital signs, and dietary notes extracted from your documents by our AI.

๐ŸŽ™๏ธ

Voice, Audio & Camera

Voice notes you send via WhatsApp, live voice session audio, and camera frames you choose to share during live AI sessions. Live audio and video are processed in real time and not stored after the session ends.

๐Ÿ‘จโ€๐Ÿ‘ฉโ€๐Ÿ‘ง

Family & Caregiver Data

Profiles and health records of family members you add, with the role you assign (spouse, parent, child, etc.).

๐Ÿ””

Device & Notifications

Push notification tokens (Expo, web VAPID) and your WhatsApp opt-in preferences.

๐Ÿ“Š

Usage & Behavioural Data

Activity timeline, medicine adherence logs, daily health summaries, and stability scores.

๐Ÿ’ฌ

Communications

Messages you exchange with Pushpa via WhatsApp, OTP SMS records, and AI conversation history.

๐Ÿƒ

Activity & Fitness (optional)

If you connect Apple Health or Google Health Connect on the mobile app, we read steps, distance, calories burned, and heart rate to show your activity trends.

๐Ÿ“‡

Contacts (optional)

When you use the system contact picker to add a family member, we receive only the single contact you choose โ€” no Contacts permission is requested, and your contact list is never uploaded or stored.

What we do NOT collect

  • Payment card numbers or banking information (payments processed by third-party gateways)
  • Biometric identifiers like fingerprints or facial geometry
  • Location data beyond city/state you voluntarily provide
  • Social media profiles or browsing history outside Pushpa
๐ŸŽฏ

How We Use Your Information

Your data, your control

We are not in the business of selling health data. Your records stay within Pushpa's systems and the processors listed below, used only to provide the service you signed up for.

Every piece of data we collect has a specific, limited purpose:

  • Provide the core service โ€” reading reports, tracking medicines, answering health questions
  • Power AI analysis โ€” extracting structured health data from your documents using vision AI
  • Send timely reminders โ€” medicine alerts, follow-up notifications, daily health briefs
  • Support family health management โ€” linking records across family members you add
  • Enable doctor review โ€” when you request a doctor's review of your health summary and reports
  • Improve service quality โ€” aggregated, anonymised usage data to make Pushpa more accurate
  • Authenticate and secure your account โ€” OTP verification, JWT session management
  • Communicate essential service updates โ€” changes to terms, critical security notices

We will never use your health data to:

  • Sell or rent your information to third parties, advertisers, or data brokers
  • Train AI models on your personal health data without your explicit written consent
  • Target you with advertising, whether inside or outside Pushpa
  • Share information with insurance companies, employers, or government agencies (unless legally required)
๐Ÿค–

AI & Third-Party Processing

Cross-border data transfer

Some processors are based outside India. By using Pushpa, you consent to health data being processed in the USA, EU, and Singapore under the applicable safeguards described above.

Pushpa uses trusted AI platforms to analyse documents and power conversations. When you send a health document, relevant content is transmitted to these processors in an encrypted request. We do not share your name, phone number, or personal identifiers with AI processors โ€” only the document content and necessary medical context.

In the mobile app, we ask for your explicit consent before your first AI conversation. Your companion messages โ€” and, during live sessions, your voice and anything you show on camera โ€” are processed by the AI platforms below to generate responses. This can include health details you choose to share. It is used only to answer you, never for advertising or to train generalised models.

Our third-party processors

ServicePurposeCountry

Microsoft Azure OpenAI

Document vision analysis, AI conversations (GPT-4o)

USA / EU

Google AI (Gemini)

Live voice and video AI companion sessions (real-time processing)

USA

Google AI (Imagen 3)

Medical illustration generation for reports

USA

Amazon Web Services (S3)

Encrypted file storage for health documents

India / Singapore

Meta (WhatsApp Cloud API)

Messaging platform for all WhatsApp interactions

USA

Twilio

SMS OTP delivery, voice call infrastructure

USA

Expo

Push notifications for iOS and Android

USA

Each processor is bound by a Data Processing Agreement (DPA) and their own published privacy policies. Microsoft Azure OpenAI does not use customer data submitted through the API to train its models.

The mobile app also loads static decorative images and 3D visuals from content delivery networks (Pexels, icons8, unpkg/Spline). These requests contain no personal or health data.

Analytics & diagnostics

To keep the app stable and understand how it is used, we use PostHog for product analytics and session replay, and Google Firebase for crash reporting, performance monitoring, and push notification delivery. In session replays, text inputs and images are masked so recordings do not capture readable medical data, names, or document contents. These services receive usage events, a device push token, and diagnostic data โ€” not your health documents โ€” and process it in the United States. You can turn analytics off at any time in the mobile app under Profile โ†’ Settings โ†’ Share usage analytics.

ServicePurposeCountry

PostHog

Product analytics and masked session replay

USA

Google Firebase

Crash reporting, performance monitoring, push delivery

USA

๐Ÿƒ

Apple Health & Google Health Connect

You're in control

Connecting Apple Health or Health Connect is entirely optional. You can disconnect at any time from your device settings, and we stop reading new data immediately.

On our mobile app you can optionally connect Apple Health (iOS) or Google Health Connect (Android) so Pushpa can show your activity trends alongside your health summary. We access this data only after you explicitly grant permission, and you can use the rest of the app without ever connecting it.

What we read

  • Steps โ€” to display your daily activity and trends
  • Distance โ€” to display your daily activity and trends
  • Active and total calories burned โ€” to display your daily activity and trends
  • Heart rate โ€” to show heart-rate trends alongside your health summary

How we handle it

  • We read this data only after you grant permission through Apple Health or Health Connect, and you can revoke that access at any time in your device settings
  • Connected samples are transmitted to and stored on Pushpa's secure servers so we can display your trends and personalised summary
  • This data is used only to provide these in-app features โ€” it is never used for advertising, sold, or shared with third parties
  • We do not use Apple Health or Health Connect data to train generalised AI/ML models
  • Our use complies with the Apple HealthKit terms and the Google Health Connect permissions policy, including their restrictions on the use of health and fitness data
๐Ÿ‘จโ€๐Ÿ‘ฉโ€๐Ÿ‘งโ€๐Ÿ‘ฆ

Family Data & Access

Pushpa is built for families. When you add a family member, you become their health manager within the platform. Here is how access and privacy work:

  • The person who adds a family member can view, update, and manage their health records
  • Family members with their own accounts can control which records are visible to caregivers
  • Caregiver observations (private notes about a patient) are never shown to the patient โ€” this is a dignity protection built into the system
  • Doctors, when invited to review your case, can see only the relevant conversation and health context โ€” not your full record
  • You can remove a family member's data from your account at any time via account settings

Your responsibility as a health manager

By adding a family member, you confirm you have their consent to upload and manage their health data on Pushpa. You are responsible for ensuring the accuracy of the information you provide on their behalf.

๐Ÿ”’

Data Security

No perfect security

While we implement industry-standard protections, no system is 100% secure. We commit to notifying you within 72 hours if we discover a breach that affects your personal data.

We take the security of health data seriously. Here is what we do to protect your information:

  • All data is transmitted over HTTPS/TLS โ€” no unencrypted connections
  • Files are stored on AWS S3 with server-side encryption and accessed only via time-limited presigned URLs
  • Passwords are hashed using bcrypt with 12 salt rounds โ€” we never store plaintext passwords
  • Sessions are authenticated with signed JWTs; tokens expire and cannot be reused after logout
  • WhatsApp webhooks use HMAC-SHA256 signature verification to reject forged requests
  • Logs are structured and searchable, but sensitive headers (like Authorization tokens) are automatically redacted
  • Database access is scoped to each user's data โ€” no query can accidentally return another user's records

What you can do

  • Use a strong, unique password if you use email/password login
  • Do not share your WhatsApp OTP with anyone โ€” Pushpa staff will never ask for it
  • Log out from shared devices
  • Contact us immediately at system@dayzero.ai if you suspect unauthorised access
โš–๏ธ

Your Rights Under DPDP Act 2023

Under India's Digital Personal Data Protection Act 2023, you have the following rights with respect to your personal data:

  • Right to Access โ€” request a copy of the personal data we hold about you
  • Right to Correction โ€” ask us to correct inaccurate or incomplete data
  • Right to Erasure โ€” request deletion of your account and all associated data
  • Right to Withdraw Consent โ€” withdraw consent for any processing at any time (note: this may limit the service we can provide)
  • Right to Grievance Redressal โ€” raise a complaint and receive a response within 30 days
  • Right to Nominate โ€” nominate someone to exercise these rights on your behalf

How to exercise your rights

Email system@dayzero.ai with your registered phone number and the specific right you wish to exercise. We will respond within 7 business days and fulfill all requests within 30 days.

If you are not satisfied with our response, you may lodge a complaint with the Data Protection Board of India once it is constituted.

๐Ÿ’ฌ

WhatsApp & Messaging

Pushpa operates primarily over WhatsApp. When you message us on WhatsApp, your messages are received through the Meta WhatsApp Cloud API. Meta processes these messages in accordance with their own Privacy Policy.

  • Reminders, health nudges, and daily summaries are sent only if you have opted in
  • You can stop all WhatsApp messages at any time by sending the word STOP to our number
  • OTPs sent via SMS are single-use, expire in 10 minutes, and are never logged after verification
  • We do not use WhatsApp message metadata (read receipts, last seen) to build profiles

Managing your preferences

You can adjust your notification preferences, WhatsApp opt-in status, and reminder schedules from your Pushpa profile settings at any time.

๐Ÿ—‚๏ธ

Data Retention & Deletion

We retain your data for as long as your account is active or as needed to provide the service.

  • Active accounts โ€” all health records, documents, and conversation history retained
  • Deleted accounts โ€” data is purged within 30 days of account deletion request
  • AI conversation logs โ€” retained for 12 months, then anonymised or deleted
  • Push notification tokens โ€” deleted immediately upon opt-out or account deletion
  • Backup copies โ€” fully purged within 90 days of account deletion

Legal holds

In rare cases, we may be required by Indian law to retain certain records for up to 7 years (e.g., financial transaction records). In such cases, we retain only what the law requires and restrict all other processing.

๐Ÿ‘ถ

Children's Privacy

Pushpa requires users to be 18 years or older to create an account. We do not knowingly collect personal data directly from anyone under 18.

Children may be added as family members by a parent or legal guardian. In such cases, it is the parent's responsibility to ensure the child's health data is managed appropriately and with the child's best interests in mind.

If you believe a child under 13 has provided us personal data without parental consent, please contact system@dayzero.ai and we will promptly delete it.

๐Ÿ“

Changes & Contact

How we notify you of changes

If we make material changes to this Privacy Policy, we will notify you via WhatsApp message or email at least 7 days before the changes take effect. Continued use of Pushpa after the effective date constitutes acceptance of the updated policy.

Contact our Privacy Officer

  • Email: system@dayzero.ai
  • Response time: 2 business days for general queries, 7 business days for rights requests
  • Grievances resolved within 30 days as required by DPDP Act 2023

Registered address

Day Zero
New Delhi, India
dayzero.ai

Still have questions?

We wrote this in plain language for a reason. If something isn't clear, email us โ€” we'll explain it personally.

system@dayzero.ai