Privacy Policy

Last updated: 24 September 2026  ·  Effective: 24 September 2026

MySafeCard is an information-sharing tool, not a medical device. It does not diagnose, treat, or advise on any medical condition. All health information on your card is entered by you and is displayed solely to assist emergency responders in identifying your medical profile. See Section 3 for the full medical disclaimer.

1. About This Policy

This Privacy Policy explains what personal data MySafeCard ("we", "us", "our") collects from users of the MySafeCard mobile application (Android and iOS) and website (mysafecard.in), how that data is used, stored, and protected, and what rights you have over your data.

MySafeCard is a product owned and operated by Artha Tech Solutions, a sole proprietorship based in Hyderabad, Telangana, India.

By using MySafeCard, you agree to the practices described in this policy. If you do not agree, please uninstall the app and discontinue use of the service.

2. Google Play Data Safety Summary

The following table summarises the data types MySafeCard collects, consistent with the Data Safety declaration in the Google Play Store listing.

Data typeCollected?Encrypted in transit?User can delete?Shared with third parties?
NameYesYes (TLS)YesAWS SES (email only)
Email addressYes — your own account email, and optionally a card's own contact email if you add one while creating a card for someone else (see Section 4)Yes (TLS)YesAWS SES (email only); Google (if Google Sign-In used)
Health & fitness — blood group, allergies, medical conditions, hypertension/blood pressure status and reading, diabetes/blood sugar status and reading, related medicationsYes (hypertension/diabetes status is required; the reading and medication are only collected if you answer "Yes")Yes (TLS)YesNo
Profile photo / card photoOptionalYes (TLS)YesNo
Emergency contact details (name, phone, relationship)YesYes (TLS)YesMSG91 (SMS delivery, only if you use automatic SMS to notify the contact — see Section 7)
Date of birth, gender, nationalityOptionalYes (TLS)YesNo
Insurance policy documentsOptional — uploaded by you and attached to a cardYes (TLS)YesNo
Support chat messages and imagesOnly if you contact us through in-app support chatYes (TLS)Images: yes (on account delete). Messages: kept as a support record — see Section 17No
Device push token (FCM)YesYes (TLS)Yes (on account delete)Google FCM (notifications only)
Location dataYes — but only the device location of someone scanning another person's card (see Section 11A). Never collected when you view your own card or use the app for your own account.Yes (TLS)Not directly by the scanner (no account is tied to it); auto-limited to the most recent scan and, for notifications, the most recent 20 scans per cardNo
Financial / payment dataYes — Razorpay payment ID and order amount stored for invoice/audit, for both one-time card orders and membership plan payments (each plan period is paid for separately; there is no automatic renewal). Card numbers and banking credentials are handled entirely by Razorpay; MySafeCard never sees or stores them.Yes (TLS)Invoices retained 7 yrs (tax law)Razorpay (payment processing)
Membership / subscription status (plan type, status, expiry, trial dates)Yes, if you hold a membership or subscriptionYes (TLS)Yes (on card/account delete)No
Linked hardware identifier (NFC tag / wearable)Yes, if you activate a physical card or hardware deviceYes (TLS)Yes (on card/account delete)No
Usage analyticsYes — screen views, key in-app actions (login, signup, card creation/update/deletion, NFC tag write, card sharing, order initiated/completed/cancelled, promo code usage/failure, emergency contact approval sent, code redemption, profile updates), where users enter and leave a form or checkout flow without completing it, which button led into a screen, emergency number/contact call button taps (call action only — phone numbers are never logged), map-link opens, and app session data. No health, medical, or personally identifiable data (e.g. phone numbers, names) is included in analytics events.Yes (TLS)Yes (on account delete)Google Firebase Analytics
Crash reportsYes (Android app) — technical details of an app crash or error (device model, OS and app version, the error and where it happened) and your Firebase user ID. No health or medical data is included.Yes (TLS)Not user-initiated; kept by Google for a limited periodGoogle Firebase Crashlytics
App performance dataYes — app start time, screen loading time, and network request timing (which endpoints were called and how long they took, not the data in those requests). No health, medical, or personally identifiable data is included.Yes (TLS)Not user-initiated; aggregated, not tied to a deletable per-user recordGoogle Firebase Performance Monitoring

We never sell, rent, or trade your data. No data is shared with advertisers, data brokers, analytics companies, or any third party except as explicitly listed above (infrastructure providers used solely to operate the service) and the courier partner who delivers a physical card you order (Section 16). MySafeCard's own administrator can also access your data to operate the service and help you — see Section 15A.

3. Medical Disclaimer — Not a Medical Device

MySafeCard is a personal information-sharing application. It is not a medical device, diagnostic tool, clinical decision support tool, or medical advice service. It has not been evaluated, cleared, or approved by the Central Drugs Standard Control Organisation (CDSCO), the US Food and Drug Administration (FDA), or any other regulatory body as a medical device.

The health information displayed on your emergency card is entered entirely by you. MySafeCard does not verify, validate, interpret, or endorse any health information you enter. You are solely responsible for ensuring the accuracy and completeness of your card information.

In any medical emergency, always call emergency services first (dial 112 in India). Do not delay calling emergency services because of this app.

4. Information We Collect

Account data: Your email address, used for authentication and for the email communications described in Section 14 (transactional emails, service/product update emails, legal/policy update notices, and — unless you opt out — newsletter emails). If you sign in with Google, we receive your email and display name — no other Google data is accessed.

Emergency card data (entered by you): Name, date of birth, gender, nationality, blood group, allergies, medical conditions, hypertension (high blood pressure) status and, if applicable, your current BP reading and medication, diabetes (blood sugar) status and, if applicable, your current blood sugar reading and medication, emergency contact name(s), phone number(s), and relationship(s). An optional profile photo. Answering the hypertension and diabetes status questions is required to save a card; the reading and medication fields are only required if you answer "Yes."

Cardholder contact email (optional, per card): Each card may separately carry its own email address, entered by whoever creates or edits that card — for a card you create for a family member, this may be their email address, not your own account login email. It is stored for your reference and is never shown to anyone who scans or opens the card. See Section 14 for the one specific, planned use of this address beyond storage, and for what we do not use it for.

Insurance policy documents (optional): You may upload insurance policy documents to attach to a card. These files are stored in Firebase Storage, not in the public card record, and are only ever accessible to you as the card owner — the card's public view page does not expose them. You can delete an uploaded document at any time.

Emergency contact approval data: When you send an emergency contact an approval request, a record is created containing: the contact's name, phone number, and relationship; your name as card owner; a unique approval token; request status (pending / approved / declined); and timestamps. This record expires after 30 days. If you choose to send the approval link by automatic SMS rather than sharing it manually, the contact's phone number and the message text are also sent to MSG91, our SMS delivery provider — see Section 7 and Section 16.

Membership, subscription, and hardware data: If you hold a paid membership or subscription, we store your plan type, membership/subscription status, expiry date, trial start date, and (for family plans) a shared family bundle identifier linking member cards together. If you activate a physical card or a linkable hardware device (such as an NFC tag or wearable), we store a hardware identifier and which card it currently points to, so the device can be re-linked to a different card by its owner. None of this data is shared with any third party beyond Razorpay for payment processing (see Section 16).

Physical card order data: Delivery name, address, phone number, email, Razorpay payment ID, and order amount — used for printing, shipping, payment verification, and GST invoicing. Cards are printed in-house by MySafeCard. The details printed on the card (such as name, blood group, photo, and emergency contact) are used only to produce your card and are not included in billing or invoice records. Your delivery name, address, and phone number are shared with our courier partner to deliver the card. Razorpay additionally collects payment instrument details (card numbers, UPI IDs, etc.) directly from you; MySafeCard never receives or stores these.

Consent record: When you create an account, we record your acceptance of our Terms of Service and Privacy Policy. The record includes: your user ID, email, date and time of acceptance, version of terms accepted, device platform, and sign-in method. See Section 18A for details.

Support chat: If you contact us through the in-app support chat, we store your messages, any images you attach, and the time of each message, so we can answer you and keep a record of the conversation. Images are stored in Firebase Storage.

Push notification token: A Firebase Cloud Messaging (FCM) device token, used to send you app notifications — see Section 13.

What we do NOT collect: device identifiers, browsing history, contacts, calendar, or any data not explicitly listed above. We never collect your own location while you use the app for your own account or view your own card — the one exception, when you scan someone else's card, is described in Section 11A.

5. How We Handle Sensitive Health Data

Your card contains sensitive personal health information (blood group, medical conditions, allergies, hypertension/blood pressure status and reading, diabetes/blood sugar status and reading, and related medications). This data is stored on Google Firebase (Firestore). It is used to display your emergency card to people who access it via your card's link, QR code, or NFC tag, to print a physical card you order, and — only when needed — by MySafeCard's administrator to support you and keep the service working (see Section 15A).

We do not use your health data for advertising, profiling, research, AI/ML training, or any purpose other than those listed above. No third-party service receives your health data, and we never sell or share it for anyone else's purposes.

By creating a card, you understand that the information you submit is publicly accessible to anyone who has your card URL (including emergency responders and bystanders). You are solely responsible for the accuracy and appropriateness of the information you choose to include.

6. Authentication and Sign-In Methods

MySafeCard supports three sign-in methods:

No authentication credentials (passwords or OTP codes) are stored by MySafeCard beyond the minimum retention period required for operation.

7. Emergency Contact Approvals

When you add an emergency contact to your card, you may send them an approval request so they can consent to being listed. This feature works as follows:

By sending an approval request, you confirm that you have the contact's permission to share their name and phone number with MySafeCard for this purpose, and that the phone number you provide belongs to them (or to you, if you are listing yourself).

8. Card Deletion — What Is Removed

When you delete a card, all personal and medical data associated with it — name, photo, blood group, allergies, medical conditions, emergency contacts, and all other fields — is permanently and immediately erased from Firestore. This deletion is irreversible.

What is retained after deletion: the card's unique document ID (a short random identifier that forms the card's URL), containing only status, deletion date, and your user ID — no medical data. This is retained solely to ensure your physical NFC tag continues to point to a valid URL (so a scanner sees "card not found" rather than an error). You may reuse the same physical tag for a new card at any time.

9. Local Device Storage (AsyncStorage)

MySafeCard stores small amounts of data locally on your device using React Native AsyncStorage. This data never leaves your device and is not transmitted to our servers. Local storage is used for:

Uninstalling the app removes all locally stored data.

10. Photos and Camera Access

You may optionally add a photo to your card and profile. Photos are compressed and stored as base64-encoded data directly in Firebase Firestore — they are not uploaded to any external image host or CDN. Card photos are reduced to approximately 400×400 pixels; profile photos to approximately 200×200 pixels before storage.

On Android, camera and photo library permissions are requested only at the moment you tap the photo button — not in the background. Only the specific photo you select is accessed; no bulk gallery scan occurs. You can deny these permissions at any time in device Settings; doing so only disables the photo feature.

11. Device Permissions

No permission is requested in the background or without a direct action by you. Denying any permission disables only the specific feature it relates to — all other app features continue to work.

11A. Location Data (Scan Reporting)

If you scan or open someone else's MySafeCard — via their QR code, shared link, or NFC tag — the app makes a one-time, best-effort request for your device's approximate location, using your device's or browser's own native location permission prompt. This request is never made when you view your own card, and no in-app copy is shown before the prompt — it is your device's or browser's standard system dialog.

Why we ask: if a card is lost or stolen and later found, this lets the card's owner see roughly where and when it was last scanned — for example, to help recover it.

What is stored: only the latitude/longitude and timestamp of the scan. This is kept as the card's "last scanned location" (each new scan overwrites the previous one — it is not a full location history), and, for the most recent 20 scans of a given card, also attached to the notification sent to the card's owner so they can tap through to a map without needing to reopen the card.

Who can see it: only the card's owner, within their own app. It is never shown to other scanners, never included in analytics, and is not linked to any identity of the scanning visitor — MySafeCard has no way to know who scanned the card.

Your control: the location prompt is entirely optional. Declining it, or having location services turned off, does not affect your ability to view the card in any way — all emergency information is shown immediately regardless. We never infer your location from your IP address or any other fallback if you decline.

12. NFC Usage

When you write your card to an NFC tag, only your card's web address (URL) is written to the physical chip — no personal or medical data is stored on the NFC tag itself. The URL simply directs a scanner's browser to our web page, where your card data is fetched from Firebase. Writing to an NFC tag is entirely optional.

13. Push Notifications

MySafeCard sends push notifications about your account and cards — for example, when your card is scanned, when an emergency contact responds, updates on a physical card order, reminders to finish setting up a card, and occasional service announcements. To deliver notifications, we store your Firebase Cloud Messaging (FCM) device token and device platform (Android or iOS). No personal or medical data is included in notification payloads. You can disable notifications at any time in device Settings; your FCM token is removed from our servers when you delete your account.

14. Email Communications

MySafeCard sends four categories of email. All are sent via Amazon Simple Email Service (AWS SES); your email address and name are shared with AWS SES solely for delivery, and AWS SES does not receive your medical or health data.

We do not sell, rent, or share your email address with any third party for their own marketing purposes.

Card invitation emails (planned, not yet active): if you enter another person's email address while creating or editing a card for them (see Section 4), we may in a future update send that person a single email inviting them to claim and manage their own card on MySafeCard. This would be a one-time, functional message tied directly to the card created for them — not a marketing or promotional email — and would always include a clear way to opt out of any further contact. We do not use a cardholder's email address for promotional or marketing purposes. If that person separately creates their own MySafeCard account, the choices and protections in this section apply to them from that point on, the same as any other registered user.

15. Data Storage and Security

All data we store is kept on Google Firebase (Firestore, Authentication, and Storage). Google encrypts this stored data at rest, and data is encrypted in transit between your device and our servers using TLS. Firebase is certified under ISO 27001, SOC 1, SOC 2, and SOC 3. Account passwords are managed by Firebase Authentication and are never stored in plain text by MySafeCard.

This is not end-to-end encryption: MySafeCard's systems can read the data in order to provide the service — for example, to show your card to a responder, print your physical card, and help you through support (see Section 15A).

Firestore Security Rules ensure that other users of the app can read and change only their own data (plus the emergency card pages they are given a link to). Access for MySafeCard's administrator is described in Section 15A.

15A. Who at MySafeCard Can Access Your Data

MySafeCard is run by its owner, who is currently the only person with administrator access. The owner uses an internal admin panel to manage the service. The admin panel does not keep its own copy of your data — it is a tool for viewing and managing the same data stored on Google Firebase described in Section 15.

Through the admin panel, the administrator can see account details, emergency card information (including medical details), emergency contact approvals, physical card orders, and support chat messages. The administrator can, when needed, edit or delete a card, mark an emergency contact as confirmed, manage orders and memberships, and delete an account.

This access is used only to:

The administrator does not use your data for advertising, does not sell it, and does not share it with anyone except as described in this policy. If we ever give administrator access to anyone else (for example, a support team member), they will be bound by confidentiality and the same limits, and we will update this section.

16. Third-Party Services

MySafeCard uses the following third-party services:

We do not sell, rent, trade, or share your personal information with any party beyond what is described above. No third-party service receives your health or medical data.

17. Data Retention

Your card data is retained for as long as your account is active. Deleted card data is immediately and permanently erased (only the URL shell is retained — see Section 8). When you delete your account, all cards, photos, profile data, push notification tokens, insurance documents, hardware links, membership/subscription status, and approval records are permanently deleted.

Physical card order data (delivery name, address, phone number, email, and order details) is retained for invoicing and legal compliance. GST invoices are kept for a minimum of 7 years as required under Indian tax law. Delivery details are kept with the order record for as long as needed for delivery, returns and replacements, customer support, and those tax records.

Support chat images are deleted when you delete your account. Support chat messages are kept as a record of the support you received; you can ask us to delete them by emailing support@mysafecard.in.

Emergency contact approval records expire after 30 days. OTP codes expire after 10 minutes.

18. Your Rights and Account Deletion

You have the right to access, correct, or delete your data at any time. You can edit or delete any card directly within the app.

To permanently delete your account, email us at support@mysafecard.in with the subject line "Account Deletion Request" from your registered email address. We will process the request within 7 business days and confirm once complete. Account deletion is irreversible and removes all cards, profile data, photos, push notification tokens, and approval records. GST invoice records are retained as required by law.

19. Children's Privacy

MySafeCard is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. Users between the ages of 13 and 18 must have parental or guardian consent before creating an account. If you believe a child under 13 has provided us with information without parental consent, contact support@mysafecard.in and we will delete it promptly.

18A. Consent Recording

When you create a MySafeCard account or sign in for the first time using Google Sign-In, we record your acceptance of our Terms of Service and Privacy Policy. For email registrations, we also record your acceptance of the medical data declaration.

The consent record contains: your Firebase user ID, email address, the date and time of acceptance (UTC), the version of the Terms and Privacy Policy you accepted (identified by their effective date), your device platform (web, Android, or iOS), and your sign-in method (email or Google). We do not record your IP address.

This record is stored securely in Firebase Firestore under your user account and is retained for the lifetime of your account plus a minimum of 7 years after account deletion, as required for legal compliance. You may request a copy of your consent record at any time by emailing support@mysafecard.in. The consent record is not deleted when you delete your MySafeCard account; it is retained solely for legal compliance.

20. Changes to This Policy

We may update this Privacy Policy from time to time. The "Last updated" date at the top reflects the most recent revision. We will notify you of material changes via in-app notification or email. Continued use of the app after changes constitutes acceptance of the updated policy.

21. Contact Us

For privacy-related questions, data deletion requests, or to exercise your data rights:

Email: support@mysafecard.in
Website: mysafecard.in
Artha Tech Solutions, Hyderabad, Telangana, India