Action: file_editor create /app/PRIVACY_POLICY.md --file-text "# Privacy Policy — Acidity Care
**Effective date:** February 1, 2026
**Last updated:** February 1, 2026
This Privacy Policy describes how **Acidity Care** (\"we\", \"us\", \"our\", or the \"App\") collects, uses, and protects information when you use our mobile application for tracking and managing acidity, GERD, and digestive health.
By using the App, you agree to the practices described below. If you do not agree, please do not use the App.
---
## 1. Information We Collect
### 1.1 Information you provide directly
- **Profile data:** name, age, weight, height, and self-reported medical conditions you enter during onboarding.
- **Health data:** self-reported symptom logs (heartburn, reflux, bloating, stress, sleep quality), medication names, dosages, and reminder times you add manually.
- **Assessment responses:** answers to the 10-question acidity assessment.
- **Chat messages:** questions you ask our AI Health Assistant.
### 1.2 Information collected automatically
- **Device & app data:** an anonymous local user identifier stored on your device (no email, phone number, or login required).
- **Usage events:** app screen visits, feature interactions (used only to improve the app — never sold).
### 1.3 Payment data
We do **not** collect or store your credit card, debit card, UPI, or bank account information. All payments are processed exclusively by **Razorpay** (https://razorpay.com), a PCI-DSS Level 1 certified payment processor. We only receive a confirmation that a payment succeeded and an opaque transaction ID.
---
## 2. How We Use Your Information
We use the information to:
- Calculate your acidity risk score and personalize health recommendations.
- Display your symptom history, weekly/monthly trends, and the 30-day heatmap.
- Schedule local medication reminders on your device.
- Personalize responses from the AI Health Assistant.
- Generate the PDF health report you can share with your doctor.
- Process subscription payments and trial activations.
- Maintain and improve the App.
We **do not**:
- Sell your data to third parties.
- Use your health data for advertising.
- Share individually identifiable health data with anyone outside the third parties listed below.
---
## 3. Third-Party Services We Use
The following providers process data on our behalf under strict contractual obligations:
| Provider | Purpose | Data Shared |
|---|---|---|
| **OpenAI (via Emergent)** | Powers the AI Health Assistant (GPT-5.2 model) | Chat messages, your profile context (name, age, conditions) for personalization |
| **Razorpay** | Subscription payment processing | Order amount, currency, your anonymous user ID. **No card or bank data passes through us.** |
| **Expo / Google Play Services** | App delivery, local push notifications | Device-level technical data only |
| **MongoDB Atlas** | Encrypted database hosting for your profile, assessments, and symptom logs | All data listed in Section 1 |
You can review their privacy policies at: openai.com/policies/privacy-policy, razorpay.com/privacy, expo.dev/privacy, mongodb.com/legal/privacy-policy.
---
## 4. Data Storage & Security
- Data is stored on encrypted servers (MongoDB Atlas) with industry-standard TLS 1.2+ encryption in transit.
- Your anonymous user ID is stored locally in your device's secure storage (AsyncStorage).
- We retain your data only as long as your account is active. If you uninstall the App, your local identifier is removed; you can request server-side deletion at any time (Section 6).
- No system is 100% secure. While we use commercially reasonable safeguards, we cannot guarantee absolute security.
---
## 5. Children's Privacy
Acidity Care is **not intended for children under 13**. We do not knowingly collect personal data from children under 13. If you believe we have inadvertently done so, please contact us and we will delete it promptly.
---
## 6. Your Rights
You have the right to:
- **Access** the data we hold about you.
- **Correct** any inaccurate information (Profile → Edit Profile).
- **Delete** your data. Email us at **support@aciditycare.app** with your in-app user ID (Profile → Settings) and we will remove your records within 30 days.
- **Opt out** of AI personalization by leaving the onboarding \"conditions\" blank or skipping the onboarding entirely.
- **Cancel** your subscription anytime via Razorpay's customer portal or by contacting us.
EU / UK / California / India users have additional rights under GDPR, UK GDPR, CCPA, and the Digital Personal Data Protection Act 2023. Contact us to exercise them.
---
## 7. Medical Disclaimer
Acidity Care is **not a medical device** and does **not provide medical advice, diagnosis, or treatment**. The recommendations, AI assistant responses, and risk scores are informational only and are not a substitute for the advice of a qualified healthcare professional. Always consult a doctor before making changes to your medication, diet, or treatment plan. If you experience severe symptoms (chest pain, difficulty swallowing, blood in vomit, unexplained weight loss), seek immediate medical attention.
---
## 8. Subscriptions, Refunds & Auto-Renewal
- The Premium subscription costs **₹199/month** or **₹1,499/year** (billed via Razorpay).
- The 7-day free trial does **not** require a payment method and **does not auto-renew** into a paid subscription. You must manually subscribe at the end of the trial to continue Premium access.
- Paid subscriptions purchased via Razorpay can be cancelled by contacting **support@aciditycare.app** at least 24 hours before the next billing date.
- Refund policy: We offer a **7-day no-questions-asked refund** on the first paid month or year. Email support@aciditycare.app to request one.
---
## 9. International Transfers
Your data may be transferred to and processed in countries other than your country of residence (including the United States and India, where our processors operate). By using the App, you consent to such transfers, subject to the safeguards described in this Policy.
---
## 10. Changes to This Policy
We may update this Policy from time to time. Material changes will be announced inside the App with at least 14 days' notice before they take effect. The \"Last updated\" date at the top reflects the most recent revision.
---
## 11. Contact Us
For any questions, requests, or concerns about this Privacy Policy or your data:
**Email:** support@aciditycare.app
**Address:** [Your registered business address — required for Play Store]
---
*By using Acidity Care, you acknowledge that you have read, understood, and agreed to this Privacy Policy.*
"
Observation: Create successful: /app/PRIVACY_POLICY.md
Fetching debug logs for expo
==> /var/log/supervisor/expo.err.log <==
The following packages should be updated for best compatibility with the installed expo version:
expo@54.0.34 - expected version: ~54.0.35
expo-font@14.0.11 - expected version: ~14.0.12
expo-router@6.0.23 - expected version: ~6.0.24
Your project may not work correctly until you install the expected versions of the packages.
The following packages should be updated for best compatibility with the installed expo version:
expo@54.0.34 - expected version: ~54.0.35
expo-font@14.0.11 - expected version: ~14.0.12
expo-router@6.0.23 - expected version: ~6.0.24
Your project may not work correctly until you install the expected versions of the packages.
The following packages should be updated for best compatibility with the installed expo version:
expo@54.0.34 - expected version: ~54.0.35
expo-font@14.0.11 - expected version: ~14.0.12
expo-router@6.0.23 - expected version: ~6.0.24
Your project may not work correctly until you install the expected versions of the packages.
The following packages should be updated for best compatibility with the installed expo version:
expo@54.0.34 - expected version: ~54.0.35
expo-font@14.0.11 - expected version: ~14.0.12
expo-router@6.0.23 - expected version: ~6.0.24
Your project may not work correctly until you install the expected versions of the packages.
==> /var/log/supervisor/expo.out.log <==
LOG [web] Logs will appear in the browser console
Web Bundled 42ms node_modules/expo-router/entry.js (1 module)
LOG [web] Logs will appear in the browser console
Web node_modules/expo-router/entry.js ░░░░░░░░░░░░░░░░ 0.0% (0/1)
Web Bundled 40ms node_modules/expo-router/entry.js (1 module)
LOG [web] Logs will appear in the browser console
Web node_modules/expo-router/entry.js ░░░░░░░░░░░░░░░░ 0.0% (0/1)
Web Bundled 43ms node_modules/expo-router/entry.js (1 module)
LOG [web] Logs will appear in the browser console
yarn run v1.22.22
$ /app/frontend/node_modules/.bin/expo start --port 3000
env: load .env
env: export EXPO_TUNNEL_SUBDOMAIN EXPO_PACKAGER_HOSTNAME EXPO_PUBLIC_BACKEND_URL EXPO_USE_FAST_RESOLVER METRO_CACHE_ROOT EXPO_PACKAGER_PROXY_URL
Starting project at /app/frontend
Fast resolver is enabled.
Starting Metro Bundler
Waiting on http://localhost:3000
Logs for your project will appear below.
Web node_modules/expo-router/entry.js ░░░░░░░░░░░░░░░░ 0.0% (0/1)
Web Bundled 837ms node_modules/expo-router/entry.js (1331 modules)
Fetching debug logs for backend
==> /var/log/supervisor/backend.err.log <==
INFO: Waiting for application shutdown.
INFO: Application shutdown complete.
INFO: Finished server process [1118]
/root/.venv/lib/python3.11/site-packages/razorpay/client.py:4: UserWarning: pkg_resources is deprecated as an API. See https://setuptools.pypa.io/en/latest/pkg_resources.html. The pkg_resources package is slated for removal as early as 2025-11-30. Refrain from using this package or pin to Setuptools<81.
import pkg_resources
INFO: Started server process [1607]
INFO: Waiting for application startup.
INFO: Application startup complete.
[92m16:57:58 - LiteLLM:INFO[0m: utils.py:3427 -
LiteLLM completion() model= gpt-5.2; provider = openai
2026-06-22 16:57:58,345 - LiteLLM - INFO -
LiteLLM completion() model= gpt-5.2; provider = openai
[92m16:58:10 - LiteLLM:INFO[0m: utils.py:3427 -
LiteLLM completion() model= gpt-5.2; provider = openai
2026-06-22 16:58:10,819 - LiteLLM - INFO -
LiteLLM completion() model= gpt-5.2; provider = openai
[92m16:58:20 - LiteLLM:INFO[0m: utils.py:3427 -
LiteLLM completion() model= gpt-5.2; provider = openai
2026-06-22 16:58:20,100 - LiteLLM - INFO -
LiteLLM completion() model= gpt-5.2; provider = openai
==> /var/log/supervisor/backend.out.log <==
INFO: 10.66.3.68:52834 - "GET /api/report/u_test_1782147575854 HTTP/1.1" 200 OK
INFO: 10.66.3.68:52834 - "GET /api/subscription/u_test_1782147575854 HTTP/1.1" 200 OK
INFO: 10.66.3.68:52834 - "GET /api/profile/u_test_1782147575854 HTTP/1.1" 200 OK
INFO: 10.66.3.68:52834 - "GET /api/medications/u_test_1782147575854 HTTP/1.1" 200 OK
INFO: 10.66.3.68:52834 - "POST /api/medication HTTP/1.1" 200 OK
INFO: 10.66.3.68:52834 - "GET /api/medications/u_test_1782147575854 HTTP/1.1" 200 OK
INFO: 10.66.1.194:59246 - "GET /api/profile/u_1782147608838_vfmxbz HTTP/1.1" 200 OK
INFO: 10.66.1.194:55720 - "POST /api/assessment HTTP/1.1" 200 OK
INFO: 10.66.3.68:52638 - "GET /api/recommendations/12 HTTP/1.1" 200 OK
INFO: 10.66.3.68:52638 - "GET /api/subscription/u_1782147608838_vfmxbz HTTP/1.1" 200 OK
INFO: 10.66.3.68:53280 - "GET /api/subscription/u_1782147608838_vfmxbz HTTP/1.1" 200 OK
INFO: 10.66.1.194:50566 - "GET /api/assessment/latest/u_1782147608838_vfmxbz HTTP/1.1" 200 OK
INFO: 10.66.1.194:50566 - "GET /api/symptom-stats/u_1782147608838_vfmxbz HTTP/1.1" 200 OK
INFO: 10.66.3.68:53702 - "GET /api/assessment/latest/u_1782147608838_vfmxbz HTTP/1.1" 200 OK
INFO: 10.66.1.194:39042 - "GET /api/subscription/u_1782147608838_vfmxbz HTTP/1.1" 200 OK
INFO: 10.66.1.194:39042 - "GET /api/symptom-stats/u_1782147608838_vfmxbz HTTP/1.1" 200 OK
INFO: 10.66.3.68:53702 - "GET /api/medications/u_1782147608838_vfmxbz HTTP/1.1" 200 OK
INFO: 10.66.3.68:53702 - "GET /api/symptom-stats/u_1782147608838_vfmxbz HTTP/1.1" 200 OK
INFO: 10.66.1.194:39042 - "GET /api/assessment/latest/u_1782147608838_vfmxbz HTTP/1.1" 200 OK
INFO: 10.66.1.194:39042 - "GET /api/subscription/u_1782147608838_vfmxbz HTTP/1.1" 200 OK
Fetching debug logs for mongodb
tail: cannot open '/var/log/supervisor/mongodb*.log' for reading: No such file or directory