AsistanApp Privacy Policy
Last updated: May 6, 2026
Scope
This policy explains how VitaGuard/AsistanApp processes personal data (identity, contact, health, and device data) in line with GDPR and applicable Turkish data protection law (KVKK).
Data We Collect
- Account Data: full name, email, phone number, date of birth.
- Health Data: blood pressure, glucose, pulse, and emergency-trigger measurements.
- Technical Data: session token, device identifier, and security/error logs.
- Location Data: only in emergency scenarios and within user-initiated flow.
Permissions and Device Access
- Location: requested only to share location during emergency assistance flow.
- Microphone: used only when voice command feature is started by the user.
- Camera: used only when the user initiates medication recognition.
Subscription and Payment Data
Subscription status and plan details are shown in-app. If payments are processed through Apple infrastructure, your card details are not stored by us.
Purposes and Legal Basis of Processing
- Emergency management and family notification.
- Health tracking and reporting.
- Account security (authentication, session management, abuse prevention).
- Compliance with legal obligations.
Data Security
- Passwords are not stored in plain text; strong hashing (PBKDF2) is used.
- All client-server traffic in production is encrypted via TLS/HTTPS.
- Access is authorization-controlled and data sharing is limited to necessary roles.
Data Sharing
Your data is shared only with parties required for service operation (e.g., notification/SMS providers) and with authorized authorities when legally required. We do not sell personal data.
Advertising and Data Use Commitment
SafeGuardian AI may display in-app ads through Google AdMob in selected screens.
Where legally required, Google User Messaging Platform asks for advertising consent. If consent is not available, only limited/non-personalized advertising requests are made.
Health data, emergency records, and family notifications are not sold and are not used to make medical decisions for advertising.
Retention Period
Account and health data is retained while the account is active. Security and SMS audit records are retained only as needed for abuse prevention and legal obligations. Account deletion removes account-linked data immediately; RevenueCat event identifiers may be retained in anonymized form to prevent duplicate billing events.
User Rights (GDPR/KVKK)
- Right of access, correction, restriction, and objection
- Right to request data portability
- Right to request permanent deletion of account and related data
Account Deletion (Data Deletion)
Account deletion requires password re-verification. After successful server confirmation, the account, linked sessions, device tokens, health records, medications, moods, alerts, tasks, family links, and local offline queues are deleted. Users can request a machine-readable copy of their data before deletion.
Contact
For privacy and data rights requests: privacy@safeguardian.app