Privacy Policy for DawaSnap AI
Effective Date: October 3, 2026
Last Updated: October 3, 2026
Application Name: DawaSnap AI (Android Package: in.dawasnap.app)
Primary Domains: https://noorpos.in • https://dawasnap.vercel.app • https://dawalensai.onrender.com
Operator Legal Name: Noor Technologies (Developer: MD Hassan)
Data Privacy Contact: newluckypharmacy@gmail.com
DawaSnap AI is an informational medication tracker and clinical reference assistant. It is NOT a certified medical device, diagnostic system, or substitute for professional medical advice, clinical diagnosis, or prescription management. Always consult a licensed physician, clinical pharmacist, or certified healthcare provider before taking, modifying, or discontinuing any medication.
Data Sources: Drug reference monographs, safety warnings, and dosage parameters are compiled from public pharmacopeial databases including the Indian Pharmacopoeia (IP), Central Drugs Standard Control Organisation (CDSCO), and US FDA National Drug Code directory.
DawaSnap AI ("we", "our", "us", or "the Service") operates an intelligent medication management platform designed to help users track personal prescriptions, receive automated expiry notifications, and check general pharmacological references. This Privacy Policy details our transparent data governance practices in strict compliance with the Google Play Store Data Safety Policy, the Google API Services User Data Policy, and the Digital Personal Data Protection (DPDP) Act 2023.
1. Google API Services User Data & Limited Use Disclosure
Mandatory Limited Use Statement:
DawaSnap AI's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
When you choose to authenticate using Google Sign-In, we access and process your account details strictly according to these standards:
- OAuth Scopes Requested: We request only basic identity scopes:
openid,profile(display name, profile picture), andemail. We do not request access to Google Drive files, Gmail, Google Contacts, Google Photos, or Google Workspace data. - User-Facing Features Only: We use your Google profile solely to authenticate your identity, secure your private Firestore database partitions, and dispatch medication expiry alerts to your verified email address upon your configuration.
- No Advertising or Resale: We never sell, rent, commercialize, or transfer your Google profile information or health data to advertisers, data brokers, or marketing networks.
- Prohibition on Generic Model Training: Your private medication records, dosage logs, and inquiries are never used to train, fine-tune, or distill foundation artificial intelligence (AI) models.
- Human Access Safeguards: No personnel reads your personal Google or health data except where explicitly requested by you for technical troubleshooting, required for security fraud audits, or compelled by law.
2. Categories of Information We Collect
A. Information You Provide
- Account Profile: Display name, email address, profile picture URL, and Firebase Auth unique identifier (UID).
- Medication Vault Data: Medicine brand names, generic active ingredients, dosage strengths (e.g. 500mg), dosage forms (tablet, syrup, injection, drops), expiration dates, quantities on hand, schedule intervals (morning, afternoon, evening, night), and intake notes.
- Dose Administration Logs: Timestamps when you mark medications as taken.
- Pharmacist Inquiries: Medication inquiries or interaction questions submitted to Dr. DawaSnap.
B. Hardware & Device Permissions
| Permission | Type | Purpose & Data Handling |
|---|---|---|
| Camera | Optional | Used exclusively when you tap "Scan Package" to capture medicine boxes or prescription labels. Captured photos are processed locally in sandboxed IndexedDB storage and are never saved to cloud Firestore documents. |
| Notifications (POST_NOTIFICATIONS) | Optional | Used to alert you on-device when medications are nearing expiration or need refill. On Android 13+, permissions are requested with explicit rationale. You can toggle notifications off at any time. |
3. Camera, Packaging Photos & Image Storage Architecture
Local Sandboxed Storage: When you photograph medicine packaging, the image is stored locally in your device's sandboxed IndexedDB database (DawaSnapLocalImages). Packaging photos are never stored in Firebase Firestore documents. When you scan a medicine box using cloud AI, the photo is transmitted over encrypted HTTPS to Google Gemini solely to extract medicine text and expiration dates. In offline mode, text recognition is performed using on-device optical character recognition and rule-based heuristic classification without transmitting the image across the network. Deleting an entry or deleting your account permanently wipes the image from device storage.
4. AI Pharmacist Architecture: Cloud AI & Offline Reference Engine
DawaSnap AI provides dual-mode clinical assistance:
- Cloud AI (Google Gemini API): When online, complex multi-medication interaction screenings and queries can be processed via Google Gemini API. Only clinical medication names and user queries are transmitted; your personal name, email address, and authentication tokens are strictly stripped prior to API requests. Responses are labeled with ✨ Cloud AI (Gemini).
- Offline Reference Engine: When offline or when cloud API keys are absent, consultations are handled by an on-device, rule-based drug reference engine and heuristic packaging classifier running entirely in local device memory. Responses are labeled with 📖 Offline Reference Engine.
- Clinical Feedback & Incident Reporting: Each AI response includes a "Report" button allowing users to report inaccurate or potentially concerning answers anonymously without sending any personal health data.
5. Technical Subprocessors & Service Providers
We work exclusively with vetted infrastructure providers bound by rigorous data processing agreements:
| Provider | Service Purpose | Data Transferred | Privacy Link |
|---|---|---|---|
| Google LLC (Firebase Auth & Firestore) | User authentication and encrypted cloud database synchronization. | UID, email, display name, encrypted medicine records (excluding images). | Firebase Privacy |
| Google LLC (Firebase Cloud Messaging) | Device push notification routing for scheduled expiry alerts. | FCM push token, platform identifier. | FCM Overview |
| Google LLC (Crashlytics) | Native Android application crash detection and stability monitoring. | Anonymous stack traces, OS version, device model (no health data). | Crashlytics Safety |
| Google LLC (Google Analytics 4) | Aggregated platform usage metrics. Loaded only after explicit user consent. | Pageviews and generic navigation events (all medicine names, dosages, and PII are strictly stripped). | Google Analytics Terms |
| Google LLC (Gemini API) | Multimodal prescription label extraction and pharmacological interactions. | Query text, medicine names, packaging images during active scan. | Gemini API Terms |
| Resend Inc. | Transactional email dispatch for user-configured expiry reminders. | Recipient email address, medicine name, expiration date. | Resend Policy |
| Vercel Inc. | Frontend web application hosting, CDN distribution, and SSL edge termination. | HTTP request metadata and IP headers (purged within standard edge cycles). | Vercel Privacy |
| Render Services Inc. | Backend Express server hosting for secure proxy routes and cron jobs. | Encrypted HTTPS API payloads, server access logs. | Render Privacy |
6. Data Security Standards
- Encryption in Transit: All communications between clients, backend microservices, and Google Cloud APIs utilize Transport Layer Security (TLS / HTTPS).
- Encryption at Rest: Database records in Google Cloud Firestore are encrypted with enterprise AES-256 standards.
- Role-Based Access Control: Firestore Security Rules enforce strict ownership checks; users cannot read, list, modify, or delete medication records belonging to another account.
- Token-Based Authentication: All protected backend endpoints require verified Firebase Admin ID tokens passed via standard
Authorization: Bearerheaders. The user ID is cryptographically verified from the token payload, never accepted from untrusted request bodies.
7. Data Retention Table & Account Deletion
In adherence to Google Play Store Account Deletion requirements and the DPDP Act 2023, data is retained strictly as outlined below:
| Data Category | Items Included | Retention Period & Deletion Process |
|---|---|---|
| Account Credentials | Google UID, email address, profile picture | Deleted immediately upon account deletion request. |
| Medicine Vault | Medication names, dosages, forms, quantities, schedules | Deleted immediately upon item removal or account deletion. |
| Dose History | Historical timestamps of taken medicines | Deleted immediately upon account deletion. |
| Consultation Chats | Dr. DawaSnap chat transcripts and messages | Deleted immediately upon manual clear or account deletion. |
| Push Notification Tokens | FCM tokens and background cron schedules | Purged immediately from operational servers on account deletion. |
| Server Access Logs | Aggregated IP requests and routing logs (no health data) | Retained up to 14 days for security and rate-limiting, then automatically purged. |
| Disaster Recovery Backups | Automated Google Cloud infrastructure database snapshots | Rotated, overwritten, and permanently expired within 30 days. |
How to Delete Your Account and Data
- In-App Immediate Deletion: Open Settings → Account → click "Delete Account & Data". Re-authenticates with Google, calls server purge, deletes Firestore collections in batches, removes the Auth user, and wipes local device storage.
- Standalone Web Deletion Portal (No App Needed): Visit https://dawasnap.vercel.app/delete-account to either sign in with Google for automated deletion or submit an email deletion request for processing within 7 business days.
- Revoke Google Access: You can disconnect DawaSnap AI anytime via Google Account Permissions.
8. Compliance with Indian DPDP Act 2023 & Grievance Redressal
For users in India, processing of digital personal data is governed by the Digital Personal Data Protection Act, 2023. You have the right to access a summary of personal data, right to correction and erasure, right of grievance redressal, and right to nominate a representative.
Grievance Redressal Officer
Operator / Data Fiduciary: Noor Technologies
Grievance Officer: MD Hassan
Official Contact Email: newluckypharmacy@gmail.com
Physical Address / Location: India
Grievances and data requests are acknowledged within 24 hours and redressed within 30 days as mandated under Indian law.
9. Minimum Age & Children's Privacy Policy
DawaSnap AI is intended for adult users. You must be at least 18 years of age (or the legal age of majority in your jurisdiction) to use DawaSnap AI independently. Minors aged 13 to 17 may use the application only under active parental or legal guardian supervision. We do not knowingly collect personal data from children under 13 years of age. If we learn that an account was created by a child under 13, we immediately purge all associated records.
10. Consent Withdrawal & User Control
You may withdraw consent at any time:
- Analytics Tracking: Toggle analytics tracking off in App Settings. Google Analytics scripts will not load without explicit consent.
- Camera & Notification Permissions: Revoke permissions through your Android system settings (Settings → Apps → DawaSnap AI → Permissions).
- Email Expiry Alerts: Disable email reminders in Settings or delete scheduled reminders directly.
11. Contact Us
For questions or privacy requests regarding this Privacy Policy:
- Primary Email: newluckypharmacy@gmail.com
- Operator / Developer: Noor Technologies (MD Hassan)
- Location: India