1. Introduction
THRIVE Health Pvt. Ltd. ("THRIVE", "we", "our", or "us") is committed to protecting your personal and health information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the THRIVE™ platform, including our website, mobile applications, and related services (collectively, the "Services").
By using our Services, you consent to the practices described in this Privacy Policy. If you do not agree with the terms of this policy, please do not access our Services.
2. Information We Collect
2.1 Personal Information
- Full name, email address, phone number, and date of birth
- Gender, city, state, and country of residence
- Payment and billing information (processed securely via Cashfree)
- Profile photo (if provided)
2.2 Health Information
- Health assessment responses across 14 categories
- Biomarker test results (blood work, lab reports)
- Medical history, family history, and current medications
- Lifestyle information including diet, sleep, stress, and exercise habits
- Physician consultation notes and care plans
- Documents and medical reports uploaded to the platform
2.3 Usage Information
- Log data including IP address, browser type, pages visited, and time spent
- Device information including hardware model and operating system
- Interaction data with our AI health assistant
3. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve our Services
- Generate your personalised health assessment, risk scores, and biological age estimate
- Create and manage your care plans and quarterly health roadmaps
- Connect you with THRIVE physicians and partner clinicians
- Power the THRIVE AI Health Assistant with your personal health context
- Process payments and manage your membership
- Send you health reminders, review notifications, and programme updates
- Comply with applicable laws and regulations
- Detect and prevent fraud or security incidents
4. How We Share Your Information
We do not sell your personal or health information to third parties. We may share your information with:
- THRIVE Physicians: Your assigned physician will have access to your health data to provide consultations and care plans
- Partner Clinicians: If enrolled through a partner, they may view your membership status and progress (not your full health data)
- Service Providers: Supabase (database), Google AI (AI assistant), Cashfree (payments), and Resend (email) under strict data processing agreements
- Legal Requirements: When required by law, court order, or to protect the safety of our users
5. Data Security
We implement enterprise-grade security measures including:
- AES-256 encryption for all data at rest
- TLS 1.3 encryption for all data in transit
- Row-Level Security (RLS) ensuring you can only access your own data
- Role-based access controls limiting physician and staff access
- Regular security audits and penetration testing
- Secure cloud infrastructure on Supabase (SOC 2 Type II certified)
6. Data Retention
We retain your personal information for as long as your account is active or as needed to provide Services. Health data is retained for a minimum of 7 years as required by applicable Indian medical regulations. You may request deletion of your account and associated data by contacting us at privacy@thrivecore.app.
7. Your Rights
You have the right to:
- Access a copy of all personal data we hold about you
- Correct inaccurate or incomplete data
- Request deletion of your data (subject to legal retention requirements)
- Withdraw consent for data processing (this will affect your ability to use the Services)
- Lodge a complaint with the relevant data protection authority
8. Children's Privacy
Our Services are not directed to individuals under the age of 18. We do not knowingly collect personal information from minors. If you believe a minor has provided us with personal information, please contact us immediately.
9. Changes to This Policy
We may update this Privacy Policy periodically. We will notify you of significant changes via email or in-app notification. Your continued use of the Services after changes constitutes your acceptance of the updated policy.
10. Contact Us
For privacy-related questions or to exercise your rights, contact us at: