Version: v0.1 (draft, pending Indian privacy lawyer review; v0.1 restructured to explicitly cover both Play Store applications)
Effective date: 2026-06-10 (v0 draft — not yet legally effective)
Last reviewed: 2026-06-10
This Privacy Policy explains how personal information is collected, used, shared, and protected when you use the CareFirst AI emergency-response platform, operated by CuraNova Global Med LLP ("CuraNova", "we", "us").
CareFirst AI is delivered through two distinct Google Play applications that share a single backend platform. This policy covers both. Where data practices differ between the two apps, the section names the app explicitly; where practices are common to both, the section applies to either.
| Application | Google Play package | Audience | Operated by |
|---|---|---|---|
| CareFirst (patient app) | almas.carefirst |
Members of the public who are patients of a partnered hospital and may need emergency-response services | CuraNova Global Med LLP, on behalf of the partnered hospital |
| CareFirst Driver (responder app) | ai.curanova.carefirst.driver |
Ambulance crew (drivers, paramedics) employed by or contracted to an onboarded ambulance organisation | CuraNova Global Med LLP, on behalf of the ambulance organisation |
The two apps have disjoint data scopes by design. The patient app collects information needed to request and receive emergency response (location during an emergency, health profile, contact information). The driver app collects information needed to dispatch and operate an ambulance shift (continuous on-shift location, mission acceptance and status logs, Workspace identity). Neither app collects the other's data category.
This policy is published in compliance with India's Digital Personal Data Protection Act, 2023 (DPDP Act) and the Information Technology Act, 2000, including the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.
It does not apply to: - The internal portals used by partnered hospitals' staff and dispatch operators (Care and Command Centre — separate policy applies) - Third-party services that may be linked from either CareFirst app but are not operated by CuraNova or the partnered hospital
CareFirst AI is a multi-tenant platform. The legal responsibility for your personal information depends on which partnered hospital you are registered with.
Under the DPDP Act, the Data Fiduciary is the entity that determines the purposes and means of processing personal data. For your information processed through CareFirst AI:
| Partnered hospital | Role | Contact |
|---|---|---|
| ALMAS Hospital, Kerala (launch partner) | Data Fiduciary for ALMAS-registered patients | info@almashospital.com |
| (additional partner hospitals onboarded later) | Data Fiduciary for their own registered patients | Listed in-app and on this page |
If you are registered with a partnered hospital, that hospital is the data fiduciary responsible for your information.
CuraNova operates the CareFirst AI platform on behalf of the partnered hospitals. Under the DPDP Act, CuraNova is a Data Processor — we process your personal data on the instructions of, and under contract with, the partnered hospital that is your data fiduciary.
CuraNova's responsibilities as data processor are governed by a Data Processing Agreement signed between CuraNova and each partnered hospital. These agreements ensure: - We process your data only for the purposes the hospital permits - We maintain reasonable security safeguards - We assist the hospital in responding to your data principal rights requests - We notify the hospital promptly of any personal data breach
This section is organised by which app collects which data. Common categories that apply to both apps come first, then patient-app-only, then driver-app-only.
The following categories are collected by both the CareFirst patient app and the CareFirst Driver app:
| Category | Examples | When collected |
|---|---|---|
| Device information | Device model, operating system version, app version | Each app session |
| Push-notification token | Firebase Cloud Messaging (FCM) token for delivering urgent notifications | App install and on refresh |
| Diagnostic and crash data | Crash stack traces, ANR reports, breadcrumbs | When the app crashes or encounters an error; via Firebase Crashlytics |
| In-app operational logs | Timestamps, sign-in events, navigation between screens | Each session |
The CareFirst patient app collects the following from members of the public registered with a partnered hospital.
| Category | Examples | Sensitivity (DPDP) |
|---|---|---|
| Identification | Full name, date of birth | Personal data |
| Contact | Phone number, email (optional) | Personal data |
| Government identification | National ID / Aadhaar number (optional) | Personal data |
| Address | Residential address | Personal data |
| Emergency contacts | Names, phone numbers, and relationships of people we should notify in an emergency | Personal data (third party) |
| Health information | Blood group, allergies, chronic medical conditions | Health data — sensitive under DPDP |
You may choose not to provide some of this information, but emergency-response services may be limited or delayed without a complete profile (for example, paramedics arriving on scene benefit from advance knowledge of blood group, allergies, and chronic conditions).
| Category | Examples | When collected |
|---|---|---|
| Live location (precise) | GPS coordinates of your device | Only when you press SOS, and during an active tracked emergency event |
| Live location (approximate) | Approximate device location | When precise is unavailable; same trigger as above |
| Authentication artefacts | One-time passwords (OTPs) sent to your phone for sign-in | At each sign-in |
| SOS event records | Time, location, hospital recommendation set, dispatch outcome | At each SOS event |
The patient app does not collect location outside of an active emergency event. It does not run a background location service.
The CareFirst Driver app collects the following from ambulance crew during their employment-related use of the app.
| Category | Examples | Source |
|---|---|---|
| Driver identity | Full name, work email address, Google account identifier | Google Workspace identity provider, on driver sign-in |
| Group membership confirmation | Membership in the ambulance@almashospital.com Workspace group |
Google Workspace identity provider, on each sign-in (used to gate access) |
The Driver app does not collect drivers' personal identification documents, residential addresses, government IDs, or health information about the driver themselves. The driver's profile is purely the Workspace identity issued by the employing organisation.
| Category | Examples | When collected |
|---|---|---|
| Continuous live location | GPS coordinates of the driver's device, including when the device screen is off or the app is backgrounded | Only while the driver is on an active shift. Collection begins when the driver signals shift start in-app and ends when they signal shift end. |
| Mission lifecycle events | Mission assignment, accept / decline, status transitions (en route, on scene, transporting, at hospital), completion | Each mission event |
| Route and navigation telemetry | Position samples used to compute ETA, off-route detection, hospital-approach signals | Throughout an active mission |
| Active ambulance identifier | The vehicle the driver has signed onto for the shift | At shift start; cleared at shift end |
The Driver app does not collect patient health records, patient profile data, or any information about persons other than the driver. The driver sees only operational dispatch information (incident address, patient phone for callback, dispatcher notes) for missions they have accepted.
Limited information may flow to us from:
We do not purchase or rent personal data from data brokers or unrelated third parties for either app.
We process personal information only for the following defined purposes, scoped per app.
We do not use information from either app for:
We rely on different lawful bases under Section 4 of the DPDP Act depending on which app and which processing activity. Each is identified explicitly below.
For most processing in the patient app: - Collection and storage of your health profile (blood group, allergies, chronic conditions, emergency contacts) - Sharing your medical profile with the responding emergency team when an SOS is active - Sending you informational SMS messages (e.g., post-emergency receipts)
You will be asked for granular consent at first launch, with separate toggles for distinct purposes. You may withdraw any consent at any time from in-app Settings. Withdrawal does not affect the lawfulness of processing performed before withdrawal.
When you press SOS, we process and share your live location and minimum-necessary health information without requiring a fresh consent gesture at the moment of crisis, on the basis that the processing is in your own interest in a medical emergency. This judgement is proportionate to the urgency and limited to information strictly necessary for the responding team. Lawyer review pending.
For technical processing strictly necessary to operate the patient app (authentication token issuance, push-notification delivery, crash diagnostics).
The Driver app is used by ambulance crew in the course of their employment or contract with the ambulance organisation. We process driver data — Workspace identity, on-shift location, mission events — on the basis that it is necessary to perform the employment-related arrangement under which the driver provides ambulance services through their employer.
This basis covers: - Workspace SSO authentication and group-membership verification - Continuous on-shift location collection - Mission acceptance, status transitions, route telemetry - Foreground-service notification while the app is tracking location during a shift
For any processing of driver data that is not strictly necessary for the employment arrangement (none currently, but reserved for future features such as voluntary driver wellness analytics), we will obtain separate granular consent before commencing the processing.
Processing required by applicable statutes — including audit logs, regulator-required retention, breach-notification obligations — is performed on the basis of legal compliance.
We share your personal information only with the parties below, only for the purposes described, and only to the minimum extent needed.
Your medical profile, current location, and emergency event details are shared with your partnered hospital's dispatch operators and the responding ambulance team when you initiate an emergency event. This is the core function of the service.
We use the following third-party service providers to operate CareFirst AI. Each is bound by data protection obligations consistent with this policy.
| Sub-processor | Service provided | Location of processing | What they receive |
|---|---|---|---|
| Google LLC (Firebase Authentication) | Phone OTP verification, identity service | Global Google infrastructure | Phone number, authentication tokens |
| Google LLC (Firebase Cloud Messaging) | Push notifications | Global Google infrastructure | Device push tokens, notification payloads |
| Google LLC (Cloud Run, Cloud SQL, Cloud Storage) | Backend application hosting and database | asia-south1 (Mumbai, India) | All application data |
| Google LLC (Crashlytics, planned) | Crash and error reporting | Global Google infrastructure | Anonymised stack traces and device metadata |
| MSG91 | SMS delivery (one-time passwords, urgent notifications) | India | Phone number, message content |
| Sentry, Inc. (planned) | Application error tracking | EU or US region (to be configured) | Anonymised stack traces |
We do not enable any analytics or advertising integrations that profile users for commercial purposes.
We may disclose your personal information when required by: - A valid order from an Indian court or competent authority - A statutory obligation (e.g., reporting under the Information Technology Rules) - A demonstrable need to prevent serious harm to a person
We will challenge requests that are excessive or unlawful, and inform you whenever the law permits us to do so.
Most of your personal information is stored and processed within India (Google Cloud's asia-south1 region in Mumbai). However, certain ancillary services unavoidably involve cross-border processing:
| Service | Why cross-border | Approximate region |
|---|---|---|
| Firebase Authentication | Google's phone-verification service operates from global infrastructure | Multiple regions |
| Firebase Cloud Messaging | Push notification delivery operates from global infrastructure | Multiple regions |
| Crashlytics (planned) | Crash diagnostics use Google's global infrastructure | Multiple regions |
The DPDP Act permits transfers to countries that the Central Government has not specifically restricted. Google's privacy program meets the standards required for these transfers.
You may at any time request a list of all current sub-processors and the regions in which they operate, by contacting the Grievance Officer.
| Category | Retention period |
|---|---|
| Active account information (name, phone, profile) | For as long as your account is active, plus 90 days after deletion |
| Emergency event records (case details, dispatch logs) | 7 years from case closure (aligned with medical record retention) |
| Location data (live GPS) | Retained as part of the emergency event record; deleted otherwise within 30 days |
| Audit logs (admin access to your data) | 3 years |
| SMS / push delivery logs | 90 days |
When retention periods expire, we securely delete or anonymise the data so it can no longer be linked to you. You can also request earlier deletion under Section 12.
Under Section 11 of the DPDP Act, you have the following rights regarding your personal information:
You can request a copy of all personal information we hold about you, in a portable electronic format.
You can request correction of any inaccurate or incomplete personal information.
You can request deletion of your personal information that is no longer necessary for the purposes for which it was collected.
You can withdraw consent for any purpose at any time, with effect from the time of withdrawal. Withdrawal does not affect processing done before withdrawal.
You can lodge a complaint with the Grievance Officer (Section 11 below) regarding any concern about how your data has been handled.
You can nominate another individual to exercise your rights on your behalf in the event of your incapacity or death.
If you are not satisfied with our response to a grievance, you may file a complaint with the Data Protection Board of India.
You can exercise any of the rights listed in Section 9 through:
We will respond within 30 days of receiving a verified request, in accordance with the timelines set by the DPDP Act and any rules notified under it. For complex requests, we may extend this period by an additional 30 days; we will tell you if we need that extension.
Exercising your rights is free. We may charge a reasonable fee only for repetitive or excessive requests.
In compliance with Section 10 of the DPDP Act and Rule 5(9) of the Information Technology Rules, 2011, the Grievance Officer responsible for handling your complaints is:
Name:
Haris AKDesignation:Director, CuraNova Global Med LLPEmail:it@curanova.aiPhone:(to be confirmed)Postal address:(to be confirmed — see CuraNova Global Med LLP registered address)Hours: Monday to Friday, 10:00–17:00 IST, excluding public holidays
The Grievance Officer will acknowledge receipt of your complaint within 48 hours and respond substantively within 30 days.
We use a combination of technical and organisational measures to protect your information. These are reviewed periodically and include:
No system is perfectly secure. If you have reason to believe your account or information has been compromised, please contact the Grievance Officer immediately.
The DPDP Act (Section 9) provides additional protections for personal data of children under 18.
CareFirst AI's current position: the app is intended for adults (18+). We do not knowingly collect personal information from individuals under 18 except where: - A parent or legal guardian has provided verifiable consent on the child's behalf, and - The processing is necessary for the child's health or safety in an emergency
If you believe a child's data has been collected without proper consent, contact the Grievance Officer and we will take steps to delete it.
We do not undertake behavioural monitoring or targeted advertising directed at children, in any case.
CuraNova CuraNova Global Med LLP
(to be confirmed)
General inquiries: it@curanova.ai
Privacy / grievance inquiries: see Section 11
We may update this policy from time to time. When we make material changes: - We will publish the updated version with a new "Effective date" at the top of the document - We will notify you via the app and (where we hold contact details) by email or SMS, with a summary of changes - For changes that materially expand the scope of processing or new purposes, we will obtain renewed consent before applying the changes to your data
You can review the version history of this policy at https://carefirst-legal.web.app/history/.
This appendix supports the Google Play Data Safety questionnaire for both apps. It is for completeness and does not form part of the legal policy text shown to users. The lawyer-reviewed version of the policy may move this content elsewhere.
The Source app column indicates which Play Store application collects the data. Patient = almas.carefirst. Driver = ai.curanova.carefirst.driver. Both = collected by either app's user under the conditions described.
| Data type | Source app | Collected | Shared with third parties | Processing purpose | Optional |
|---|---|---|---|---|---|
| Name | Patient | Yes | Hospital dispatch, responding paramedics (during emergency) | Account management, emergency response | No |
| Name | Driver | Yes (from Workspace SSO) | Hospital dispatch (for crew identification) | Workspace authentication, audit | No |
| Phone number | Patient | Yes | MSG91 (OTP delivery), Hospital dispatch | Authentication, emergency response callback | No |
| Phone number | Driver | No | — | — | — |
| Email address | Patient | Optional | None | Account communications | Yes |
| Email address | Driver | Yes (Workspace) | None | Workspace authentication | No |
| Date of birth | Patient | Yes | Hospital dispatch, paramedics | Emergency response | Yes |
| Date of birth | Driver | No | — | — | — |
| Government ID (Aadhaar) | Patient | Optional | Hospital dispatch | Identification | Yes |
| Government ID (Aadhaar) | Driver | No | — | — | — |
| Address | Patient | Yes | Hospital dispatch | Emergency response routing | Yes |
| Address | Driver | No (driver home address not collected) | — | — | — |
| Health info — blood group | Patient | Yes | Hospital dispatch, paramedics | Emergency response | Yes |
| Health info — allergies | Patient | Yes | Hospital dispatch, paramedics | Emergency response | Yes |
| Health info — chronic conditions | Patient | Yes | Hospital dispatch, paramedics | Emergency response | Yes |
| Health info (any) | Driver | No (driver health data not collected) | — | — | — |
| Emergency contacts | Patient | Yes | Hospital dispatch (in emergency) | Emergency notification | Yes |
| Emergency contacts | Driver | No | — | — | — |
| Location — precise | Patient | Yes, during active emergency event only | Hospital dispatch, responding paramedics | Emergency response routing | No during event |
| Location — precise | Driver | Yes, continuously during an active shift (including background, screen off) | Hospital dispatch, patient in active mission | Dispatch routing, real-time mission visibility | No (required for app function) |
| Location — approximate | Patient | Yes, as fallback for precise | Hospital dispatch | Emergency response | No during event |
| Location — approximate | Driver | Yes, as fallback for precise during shift | Hospital dispatch | Dispatch routing | No |
| Workspace group membership | Driver | Yes (verified on each sign-in) | None | Access gate | No |
| Mission lifecycle events | Driver | Yes | Hospital dispatch | Operational coordination, audit | No |
| Active ambulance ID | Driver | Yes (per shift) | Hospital dispatch | Vehicle-to-driver association | No |
| Device ID / FCM token | Both | Yes | Google FCM (sub-processor) | Push notification delivery | No |
| Crash logs / diagnostics | Both | Yes | Google Crashlytics (sub-processor) | Service stability | No (no in-app opt-out at v0; may add) |