What we collect
We collect three categories of information. The first is account data — your email address, the password you set, and any profile details you choose to add. The second is health data you give us — symptoms, medications, vitals, photos of prescriptions, and anything you write in a free-text log. The third is data from devices and services you connect — wearable readings, fitness app exports, and lab reports you upload.
We do not collect health data from third-party sources you have not explicitly connected. We do not buy data from data brokers.
Why we collect it
Health data is collected to make Pivotical work for you. The agents read it to build your plan, surface patterns, check medication interactions, and prepare a record you can hand to a clinician. Account data is collected to keep your data tied to you and nobody else.
We do not use your health data to train public AI models. We do not use it to target advertising. We do not sell it.
Where it is stored
Data is stored on Supabase infrastructure, encrypted at rest and in transit. Photos and PDFs are stored in object storage with private ACLs and signed-URL access.
When AI agents process your data, the inference call is sent to our model providers (currently Mistral). Those calls do not include your name or email — they include only the data the agent needs and a synthetic identifier.
How long we keep it
Active account data is kept for as long as your account exists. When you delete your account, we delete your data within 30 days from primary storage and within 90 days from backups.
We keep a minimal audit trail of access events (who looked at what, when) for two years for security and compliance reasons.
Your rights
You can access, correct, export, and delete your data at any time from inside the app. You can also write to security@pivotical.in and we will respond within 30 days.
Specific regional rights — DPDP, GDPR, CCPA — are described in the regional notice for your jurisdiction. Those notices sit alongside this document in the legal pack.
Sharing & sub-processors
Pivotical uses a small number of sub-processors to operate the service. The current list, and the data each one handles, lives at the Sub-processors document in the pack. We update that page within 30 days of any change.
We do not share your health data with anyone outside that list — not advertisers, not data brokers, not employers, not insurers.
Children
Pivotical is not designed for and not directed at children under 13. We do not knowingly collect data from anyone under 13. If you become aware that a child has signed up, write to security@pivotical.in and we will delete the account.
Changes to this policy
When we change this policy, we update the 'last updated' date at the top and notify you in-app the next time you open Pivotical. Material changes get an email as well.
Contact
Privacy questions: security@pivotical.in. Grievance officer (India / DPDP): admin@pivotical.in. Data Protection Officer (EU / GDPR): admin@pivotical.in.