Draft for review. This is the v0 working draft of the CareFirst AI privacy policy, published for the closed-testing programme while final legal review is completed. The substantive policies described below already apply to closed-testing users. Section-level wording may be refined before public launch.

CareFirst AI — Privacy Policy

Version: v0.1 (draft, pending Indian privacy lawyer review; v0.1 restructured to explicitly cover both Play Store applications) Effective date: 2026-06-10 (v0 draft — not yet legally effective) Last reviewed: 2026-06-10


1. Introduction and scope

This Privacy Policy explains how personal information is collected, used, shared, and protected when you use the CareFirst AI emergency-response platform, operated by CuraNova Global Med LLP ("CuraNova", "we", "us").

1.1 The two applications this policy covers

CareFirst AI is delivered through two distinct Google Play applications that share a single backend platform. This policy covers both. Where data practices differ between the two apps, the section names the app explicitly; where practices are common to both, the section applies to either.

Application Google Play package Audience Operated by
CareFirst (patient app) almas.carefirst Members of the public who are patients of a partnered hospital and may need emergency-response services CuraNova Global Med LLP, on behalf of the partnered hospital
CareFirst Driver (responder app) ai.curanova.carefirst.driver Ambulance crew (drivers, paramedics) employed by or contracted to an onboarded ambulance organisation CuraNova Global Med LLP, on behalf of the ambulance organisation

The two apps have disjoint data scopes by design. The patient app collects information needed to request and receive emergency response (location during an emergency, health profile, contact information). The driver app collects information needed to dispatch and operate an ambulance shift (continuous on-shift location, mission acceptance and status logs, Workspace identity). Neither app collects the other's data category.

1.2 Compliance baseline

This policy is published in compliance with India's Digital Personal Data Protection Act, 2023 (DPDP Act) and the Information Technology Act, 2000, including the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.

1.3 What this policy covers

It does not apply to: - The internal portals used by partnered hospitals' staff and dispatch operators (Care and Command Centre — separate policy applies) - Third-party services that may be linked from either CareFirst app but are not operated by CuraNova or the partnered hospital

2. Who is the data fiduciary?

CareFirst AI is a multi-tenant platform. The legal responsibility for your personal information depends on which partnered hospital you are registered with.

Your partnered hospital is the data fiduciary

Under the DPDP Act, the Data Fiduciary is the entity that determines the purposes and means of processing personal data. For your information processed through CareFirst AI:

Partnered hospital Role Contact
ALMAS Hospital, Kerala (launch partner) Data Fiduciary for ALMAS-registered patients info@almashospital.com
(additional partner hospitals onboarded later) Data Fiduciary for their own registered patients Listed in-app and on this page

If you are registered with a partnered hospital, that hospital is the data fiduciary responsible for your information.

CuraNova is the data processor

CuraNova operates the CareFirst AI platform on behalf of the partnered hospitals. Under the DPDP Act, CuraNova is a Data Processor — we process your personal data on the instructions of, and under contract with, the partnered hospital that is your data fiduciary.

CuraNova's responsibilities as data processor are governed by a Data Processing Agreement signed between CuraNova and each partnered hospital. These agreements ensure: - We process your data only for the purposes the hospital permits - We maintain reasonable security safeguards - We assist the hospital in responding to your data principal rights requests - We notify the hospital promptly of any personal data breach

3. What information we collect

This section is organised by which app collects which data. Common categories that apply to both apps come first, then patient-app-only, then driver-app-only.

3.1 Common to both apps (technical and operational)

The following categories are collected by both the CareFirst patient app and the CareFirst Driver app:

Category Examples When collected
Device information Device model, operating system version, app version Each app session
Push-notification token Firebase Cloud Messaging (FCM) token for delivering urgent notifications App install and on refresh
Diagnostic and crash data Crash stack traces, ANR reports, breadcrumbs When the app crashes or encounters an error; via Firebase Crashlytics
In-app operational logs Timestamps, sign-in events, navigation between screens Each session

3.2 Collected by the CareFirst patient app only

The CareFirst patient app collects the following from members of the public registered with a partnered hospital.

3.2.1 Information you provide directly when you register

Category Examples Sensitivity (DPDP)
Identification Full name, date of birth Personal data
Contact Phone number, email (optional) Personal data
Government identification National ID / Aadhaar number (optional) Personal data
Address Residential address Personal data
Emergency contacts Names, phone numbers, and relationships of people we should notify in an emergency Personal data (third party)
Health information Blood group, allergies, chronic medical conditions Health data — sensitive under DPDP

You may choose not to provide some of this information, but emergency-response services may be limited or delayed without a complete profile (for example, paramedics arriving on scene benefit from advance knowledge of blood group, allergies, and chronic conditions).

3.2.2 Collected automatically during patient app use

Category Examples When collected
Live location (precise) GPS coordinates of your device Only when you press SOS, and during an active tracked emergency event
Live location (approximate) Approximate device location When precise is unavailable; same trigger as above
Authentication artefacts One-time passwords (OTPs) sent to your phone for sign-in At each sign-in
SOS event records Time, location, hospital recommendation set, dispatch outcome At each SOS event

The patient app does not collect location outside of an active emergency event. It does not run a background location service.

3.3 Collected by the CareFirst Driver app only

The CareFirst Driver app collects the following from ambulance crew during their employment-related use of the app.

3.3.1 Information provided through Workspace single sign-on

Category Examples Source
Driver identity Full name, work email address, Google account identifier Google Workspace identity provider, on driver sign-in
Group membership confirmation Membership in the ambulance@almashospital.com Workspace group Google Workspace identity provider, on each sign-in (used to gate access)

The Driver app does not collect drivers' personal identification documents, residential addresses, government IDs, or health information about the driver themselves. The driver's profile is purely the Workspace identity issued by the employing organisation.

3.3.2 Collected automatically during a driver's active shift

Category Examples When collected
Continuous live location GPS coordinates of the driver's device, including when the device screen is off or the app is backgrounded Only while the driver is on an active shift. Collection begins when the driver signals shift start in-app and ends when they signal shift end.
Mission lifecycle events Mission assignment, accept / decline, status transitions (en route, on scene, transporting, at hospital), completion Each mission event
Route and navigation telemetry Position samples used to compute ETA, off-route detection, hospital-approach signals Throughout an active mission
Active ambulance identifier The vehicle the driver has signed onto for the shift At shift start; cleared at shift end

The Driver app does not collect patient health records, patient profile data, or any information about persons other than the driver. The driver sees only operational dispatch information (incident address, patient phone for callback, dispatcher notes) for missions they have accepted.

3.4 Information received from third parties (both apps)

Limited information may flow to us from:

We do not purchase or rent personal data from data brokers or unrelated third parties for either app.

4. How we use your information

We process personal information only for the following defined purposes, scoped per app.

4.1 Purposes specific to the CareFirst patient app

4.2 Purposes specific to the CareFirst Driver app

4.3 Purposes common to both apps

4.4 To comply with legal obligations (both apps)

4.5 What we do NOT use your information for

We do not use information from either app for:

5. Lawful basis for processing under DPDP

We rely on different lawful bases under Section 4 of the DPDP Act depending on which app and which processing activity. Each is identified explicitly below.

5.1 Lawful basis for the CareFirst patient app

5.1.1 Your consent (Section 6)

For most processing in the patient app: - Collection and storage of your health profile (blood group, allergies, chronic conditions, emergency contacts) - Sharing your medical profile with the responding emergency team when an SOS is active - Sending you informational SMS messages (e.g., post-emergency receipts)

You will be asked for granular consent at first launch, with separate toggles for distinct purposes. You may withdraw any consent at any time from in-app Settings. Withdrawal does not affect the lawfulness of processing performed before withdrawal.

5.1.2 Legitimate use under Section 7(g) — medical emergency

When you press SOS, we process and share your live location and minimum-necessary health information without requiring a fresh consent gesture at the moment of crisis, on the basis that the processing is in your own interest in a medical emergency. This judgement is proportionate to the urgency and limited to information strictly necessary for the responding team. Lawyer review pending.

5.1.3 Performance of the service

For technical processing strictly necessary to operate the patient app (authentication token issuance, push-notification delivery, crash diagnostics).

5.2 Lawful basis for the CareFirst Driver app

5.2.1 Performance of the employment-related arrangement (Section 7(a))

The Driver app is used by ambulance crew in the course of their employment or contract with the ambulance organisation. We process driver data — Workspace identity, on-shift location, mission events — on the basis that it is necessary to perform the employment-related arrangement under which the driver provides ambulance services through their employer.

This basis covers: - Workspace SSO authentication and group-membership verification - Continuous on-shift location collection - Mission acceptance, status transitions, route telemetry - Foreground-service notification while the app is tracking location during a shift

5.2.2 Driver's separate consent for non-employment processing

For any processing of driver data that is not strictly necessary for the employment arrangement (none currently, but reserved for future features such as voluntary driver wellness analytics), we will obtain separate granular consent before commencing the processing.

5.2.3 Compliance with law (both apps)

Processing required by applicable statutes — including audit logs, regulator-required retention, breach-notification obligations — is performed on the basis of legal compliance.

6. With whom we share your information

We share your personal information only with the parties below, only for the purposes described, and only to the minimum extent needed.

6.1 Your partnered hospital and its emergency response team

Your medical profile, current location, and emergency event details are shared with your partnered hospital's dispatch operators and the responding ambulance team when you initiate an emergency event. This is the core function of the service.

6.2 Service providers (sub-processors)

We use the following third-party service providers to operate CareFirst AI. Each is bound by data protection obligations consistent with this policy.

Sub-processor Service provided Location of processing What they receive
Google LLC (Firebase Authentication) Phone OTP verification, identity service Global Google infrastructure Phone number, authentication tokens
Google LLC (Firebase Cloud Messaging) Push notifications Global Google infrastructure Device push tokens, notification payloads
Google LLC (Cloud Run, Cloud SQL, Cloud Storage) Backend application hosting and database asia-south1 (Mumbai, India) All application data
Google LLC (Crashlytics, planned) Crash and error reporting Global Google infrastructure Anonymised stack traces and device metadata
MSG91 SMS delivery (one-time passwords, urgent notifications) India Phone number, message content
Sentry, Inc. (planned) Application error tracking EU or US region (to be configured) Anonymised stack traces

We do not enable any analytics or advertising integrations that profile users for commercial purposes.

6.3 Legal disclosure

We may disclose your personal information when required by: - A valid order from an Indian court or competent authority - A statutory obligation (e.g., reporting under the Information Technology Rules) - A demonstrable need to prevent serious harm to a person

We will challenge requests that are excessive or unlawful, and inform you whenever the law permits us to do so.

7. Cross-border transfers

Most of your personal information is stored and processed within India (Google Cloud's asia-south1 region in Mumbai). However, certain ancillary services unavoidably involve cross-border processing:

Service Why cross-border Approximate region
Firebase Authentication Google's phone-verification service operates from global infrastructure Multiple regions
Firebase Cloud Messaging Push notification delivery operates from global infrastructure Multiple regions
Crashlytics (planned) Crash diagnostics use Google's global infrastructure Multiple regions

The DPDP Act permits transfers to countries that the Central Government has not specifically restricted. Google's privacy program meets the standards required for these transfers.

You may at any time request a list of all current sub-processors and the regions in which they operate, by contacting the Grievance Officer.

8. How long we keep your information

Category Retention period
Active account information (name, phone, profile) For as long as your account is active, plus 90 days after deletion
Emergency event records (case details, dispatch logs) 7 years from case closure (aligned with medical record retention)
Location data (live GPS) Retained as part of the emergency event record; deleted otherwise within 30 days
Audit logs (admin access to your data) 3 years
SMS / push delivery logs 90 days

When retention periods expire, we securely delete or anonymise the data so it can no longer be linked to you. You can also request earlier deletion under Section 12.

9. Your rights as a data principal

Under Section 11 of the DPDP Act, you have the following rights regarding your personal information:

9.1 Right to access (Section 11(1))

You can request a copy of all personal information we hold about you, in a portable electronic format.

9.2 Right to correction (Section 12(1)(a))

You can request correction of any inaccurate or incomplete personal information.

9.3 Right to erasure (Section 12(1)(b))

You can request deletion of your personal information that is no longer necessary for the purposes for which it was collected.

9.4 Right to withdraw consent (Section 6(4))

You can withdraw consent for any purpose at any time, with effect from the time of withdrawal. Withdrawal does not affect processing done before withdrawal.

9.5 Right to grievance redressal (Section 13)

You can lodge a complaint with the Grievance Officer (Section 11 below) regarding any concern about how your data has been handled.

9.6 Right to nominate (Section 14)

You can nominate another individual to exercise your rights on your behalf in the event of your incapacity or death.

9.7 Right to complain to the Data Protection Board of India (Section 13(2))

If you are not satisfied with our response to a grievance, you may file a complaint with the Data Protection Board of India.

10. How to exercise your rights

You can exercise any of the rights listed in Section 9 through:

  1. In-app: open CareFirst AI → Settings → Privacy and rights → choose the right you want to exercise (recommended; fastest)
  2. Email: write to the Grievance Officer (see Section 11) with proof of identity
  3. Postal mail: write to CuraNova's registered address (see Section 14)

We will respond within 30 days of receiving a verified request, in accordance with the timelines set by the DPDP Act and any rules notified under it. For complex requests, we may extend this period by an additional 30 days; we will tell you if we need that extension.

Exercising your rights is free. We may charge a reasonable fee only for repetitive or excessive requests.

11. Grievance Officer

In compliance with Section 10 of the DPDP Act and Rule 5(9) of the Information Technology Rules, 2011, the Grievance Officer responsible for handling your complaints is:

Name: Haris AK Designation: Director, CuraNova Global Med LLP Email: it@curanova.ai Phone: (to be confirmed) Postal address: (to be confirmed — see CuraNova Global Med LLP registered address) Hours: Monday to Friday, 10:00–17:00 IST, excluding public holidays

The Grievance Officer will acknowledge receipt of your complaint within 48 hours and respond substantively within 30 days.

12. Security of your information

We use a combination of technical and organisational measures to protect your information. These are reviewed periodically and include:

No system is perfectly secure. If you have reason to believe your account or information has been compromised, please contact the Grievance Officer immediately.

13. Children's information

The DPDP Act (Section 9) provides additional protections for personal data of children under 18.

CareFirst AI's current position: the app is intended for adults (18+). We do not knowingly collect personal information from individuals under 18 except where: - A parent or legal guardian has provided verifiable consent on the child's behalf, and - The processing is necessary for the child's health or safety in an emergency

If you believe a child's data has been collected without proper consent, contact the Grievance Officer and we will take steps to delete it.

We do not undertake behavioural monitoring or targeted advertising directed at children, in any case.

14. Contact us

CuraNova CuraNova Global Med LLP (to be confirmed) General inquiries: it@curanova.ai Privacy / grievance inquiries: see Section 11

15. Changes to this policy

We may update this policy from time to time. When we make material changes: - We will publish the updated version with a new "Effective date" at the top of the document - We will notify you via the app and (where we hold contact details) by email or SMS, with a summary of changes - For changes that materially expand the scope of processing or new purposes, we will obtain renewed consent before applying the changes to your data

You can review the version history of this policy at https://carefirst-legal.web.app/history/.


Appendix A — Data inventory summary (for Play Store "Data Safety" form)

This appendix supports the Google Play Data Safety questionnaire for both apps. It is for completeness and does not form part of the legal policy text shown to users. The lawyer-reviewed version of the policy may move this content elsewhere.

The Source app column indicates which Play Store application collects the data. Patient = almas.carefirst. Driver = ai.curanova.carefirst.driver. Both = collected by either app's user under the conditions described.

Data type Source app Collected Shared with third parties Processing purpose Optional
Name Patient Yes Hospital dispatch, responding paramedics (during emergency) Account management, emergency response No
Name Driver Yes (from Workspace SSO) Hospital dispatch (for crew identification) Workspace authentication, audit No
Phone number Patient Yes MSG91 (OTP delivery), Hospital dispatch Authentication, emergency response callback No
Phone number Driver No
Email address Patient Optional None Account communications Yes
Email address Driver Yes (Workspace) None Workspace authentication No
Date of birth Patient Yes Hospital dispatch, paramedics Emergency response Yes
Date of birth Driver No
Government ID (Aadhaar) Patient Optional Hospital dispatch Identification Yes
Government ID (Aadhaar) Driver No
Address Patient Yes Hospital dispatch Emergency response routing Yes
Address Driver No (driver home address not collected)
Health info — blood group Patient Yes Hospital dispatch, paramedics Emergency response Yes
Health info — allergies Patient Yes Hospital dispatch, paramedics Emergency response Yes
Health info — chronic conditions Patient Yes Hospital dispatch, paramedics Emergency response Yes
Health info (any) Driver No (driver health data not collected)
Emergency contacts Patient Yes Hospital dispatch (in emergency) Emergency notification Yes
Emergency contacts Driver No
Location — precise Patient Yes, during active emergency event only Hospital dispatch, responding paramedics Emergency response routing No during event
Location — precise Driver Yes, continuously during an active shift (including background, screen off) Hospital dispatch, patient in active mission Dispatch routing, real-time mission visibility No (required for app function)
Location — approximate Patient Yes, as fallback for precise Hospital dispatch Emergency response No during event
Location — approximate Driver Yes, as fallback for precise during shift Hospital dispatch Dispatch routing No
Workspace group membership Driver Yes (verified on each sign-in) None Access gate No
Mission lifecycle events Driver Yes Hospital dispatch Operational coordination, audit No
Active ambulance ID Driver Yes (per shift) Hospital dispatch Vehicle-to-driver association No
Device ID / FCM token Both Yes Google FCM (sub-processor) Push notification delivery No
Crash logs / diagnostics Both Yes Google Crashlytics (sub-processor) Service stability No (no in-app opt-out at v0; may add)