Data Safety & Security
At Swasth, security and privacy are built into every feature. We maintain transparency about how your data is handled.
1. Security Practices
- Encryption in Transit: All data communication between the Swasth app and our cloud is protected by HTTPS/TLS 1.3.
- Encryption at Rest: Cloud databases (Supabase/PostgreSQL) are encrypted at rest.
- Data Isolation: Every user account uses Row-Level Security (RLS) policies, ensuring your data is only accessible to you.
- Secure Auth: We use industry-standard OAuth authentication with PKCE flow for Google and Apple Sign-In.
- Privacy by Design: Health features are designed to minimize data collection — we only ask for what's necessary for the app to function.
2. Data Collection Disclosure
We follow the Google Play Data Safety standards:
| Data Type | Usage |
|---|---|
| Account Info (Name, Email) | Personalization, Account Mgmt |
| Health Data (Cycles, Symptoms) | App Functionality, Insights |
| App Activity (Views, Features) | Analytics, Improvement |
3. Data Deletion
You have full control over your data. You can request permanent deletion at any time:
- In-app: Go to Settings > Account > Delete Account.
- Via Email: Send a request to support@swasth.health with "Data Deletion Request" as the subject.
All data is permanently purged within 30 days of the request.
4. Security Contact
For any security-related queries, please contact our team at security@swasth.health.