Legal

Privacy Policy

Last updated: 1 August 2026 · Applies to womezo.in and health.womezo.in

Draft for review. This draft is written to match Womezo's actual data model and India's DPDP Act, 2023 — it is not yet reviewed by qualified legal counsel and should not be relied on until that review is complete.

1. Overview

Womezo ("we," "us," "our") provides an AI-powered health platform for women, operated in India. This policy explains what personal and health information we collect, why, how it's protected, and the rights you have over it under India's Digital Personal Data Protection Act, 2023 ("DPDP Act").

Health data is the most sensitive category of information we handle. Every section below applies with that in mind.

2. Information we collect

Account information (name, email, phone, date of birth, locale); health information (uploaded reports, extracted lab values, medications, cycle logs, symptoms, nutrition and weight logs); AI interaction data (chat messages, model/prompt version used); billing information (plan and status — card details are handled directly by Stripe); and usage/device data.

We collect health information only when you choose to provide it — by uploading a report, logging a symptom, or answering an onboarding question.

3. How we use your information

To provide the core product; to power the AI assistant's answers using your own health history where you've consented to that; to process billing; to maintain security (fraud prevention, audit logging); and, only with separate opt-in consent, to communicate about product updates.

We do not use your health data for advertising, and we do not build advertising profiles from it.

4. How AI processing works

When you upload a report or ask the AI assistant a question, relevant data is sent to our AI processing layer to generate a response, running through enterprise AI infrastructure under agreements that prohibit using your data to train their models. Every AI-generated response is logged with the model and prompt version that produced it.

5. Sharing & third parties

We do not sell your personal or health data, under any circumstances. We share data only with service providers processing on our behalf under contract (authentication, payments, cloud infrastructure, AI/OCR processing), a doctor you explicitly choose to share with via a revocable link, and legal authorities only when required by valid Indian law.

6. Your rights under the DPDP Act

As a data principal, you have the right to access a summary of your data, correct inaccurate data, erase your data (Settings → Privacy → Delete my data), withdraw consent for any specific use, nominate another individual to act on your behalf, and file a grievance with our Grievance Officer, escalating to the Data Protection Board of India if unresolved.

7. Data retention

We retain health data for as long as your account is active, plus a limited retention window after closure to meet medical record-keeping norms and legal obligations, after which it is automatically deleted unless you request immediate erasure sooner.

8. Security

Encryption in transit and at rest, strict per-account data isolation, audit logging, and rate-limited access are described in full on our Security page.

9. Children's privacy

Womezo's teen-focused features are intended for use with verifiable consent from a parent or guardian, in line with the DPDP Act's requirements for processing children's data.

10. International data transfers

Your data is primarily stored and processed in India. Where a service provider processes data outside India, that transfer is governed by contractual safeguards consistent with DPDP Act requirements.

11. Changes to this policy

We'll notify you in-app and by email of material changes before they take effect.

12. Contact & Grievance Officer

For privacy questions or to exercise your rights: privacy@womezo.in

To file a formal grievance under the DPDP Act: grievance@womezo.in