Skip to main content

Privacy Policy

Your data. Your trust.

We value your privacy at Srav Health. This policy explains how we collect, use, and safeguard your personal information in compliance with global regulations.

By using our services, you consent to our privacy practices. Please read this policy carefully.

1) Who we are & contact

Data Controller: Srav Health Pte. Ltd., 2 Venture Drive, 608526, Singapore

Email (privacy/data rights): priyanka@sravhealth.com

Email (support): priyanka@sravhealth.com

If you are in the EEA/UK, Srav Health acts as a data controller for your personal data. We may appoint an EU/UK representative where required.

2) Scope

This Policy covers personal data processed when you:

  • browse our website or use the Srav Health app;
  • create an account, complete assessments, receive a Personalized Plan;
  • attend clinical consultations (video or in-person) with your care team, including any recordings or transcriptions made with your consent;
  • receive clinical notes, protocols, diagnostic recommendations, or supplement prescriptions from your practitioners;
  • have your health information shared between your care team members (lead practitioner, supporting practitioners, care coordinator, and reviewing GP) for the purpose of coordinated care;
  • join programs (self-paced, coach-supported, group circles);
  • attend events (webinars/workshops);
  • message or book practitioners;
  • track symptoms, habits, or cycle data through the app;
  • receive emails, nudges, reminders, or participate in research/feedback.

3) The data we collect

We collect personal data that you provide directly, data generated by your use, and limited data from third parties.

a) Data you provide

  • Account & identity: name, email, passwordless login details (magic link/OTP), profile photo (optional), timezone/language.
  • Assessment & plan inputs: symptoms, goals, wellness history, lifestyle info, preferences; files you upload including prior diagnostic results, lab reports, and medical records.
  • Program & event data: registrations, questions, chat submissions, feedback forms.
  • Messages & notes: in-app messages with practitioners, check-ins, journal entries.
  • Clinical data: consultation notes authored by your practitioners, session recordings and transcripts (with your consent), diagnostic test results (both prior results you share and new tests ordered through the programme), supplement and herb prescriptions, treatment protocols, and care team coordination notes shared between your practitioners.
  • Tracking data: daily symptom logs, habit check-ins, and menstrual cycle tracking data entered through the app.
  • Transactions: purchases, billing details (handled by payment processors), receipts.
  • Support requests: content of emails/chats with Support.

b) Data we generate/observe

  • Personalized outputs: your Personalized Letter, root-cause map, Daily Flow, recommendations, integrated care protocols, and Integrative Health Reports.
  • Engagement & usage: app/web interactions, reminders sent, feature usage, completion metrics.
  • Device & log data: IP address, device type, OS/browser, app version, crash/diagnostic logs, device or installation IDs (e.g., push token, analytics instance ID).
  • Cookies & similar tech: pixels, local storage, and SDK events (see Cookies section).

c) Data from third parties (limited)

  • Payments: status/metadata from payment providers (e.g., Stripe).
  • Scheduling/Video: meeting links/status from Calendly; video call connections via Metered (TURN servers).
  • Attribution/Deep links: referral source from Firebase/Branch (or similar).

We do not buy third-party marketing lists.

Sensitive data (health/wellbeing):

When you enter symptoms, wellness history, or receive clinical care through the platform, you provide sensitive health data. This includes assessment answers, consultation notes, diagnostic results, and tracking data. We process this only with your explicit consent to deliver your care programme and coordinated clinical services.

4) How we use your data (purposes & legal bases)

We process personal data for:

Service delivery

Create your account; generate your plan; run programs/events; bookings; reminders; in-app messaging; customer support.

Legal bases: Contract (to provide the service), Consent (for sensitive data/features), Legitimate Interests (to run a secure, reliable service).

Recommendations

Show recommended practitioners and programs using fuzzy-logic matching of your assessment patterns to provider/program metadata.

Legal bases: Consent (for health data), Legitimate Interests (feature relevance).

No ads profiling: We do not use your health data for advertising.

Analytics & improvement

Aggregate/anonymous analysis of usage and outcomes; A/B tests; crash diagnostics.

Legal bases: Legitimate Interests; Consent where required (e.g., non-essential cookies).

Communications

Transactional emails (confirmations, reminders, receipts), service notices, security alerts.

Legal bases: Contract, Legitimate Interests.

Marketing emails only with Consent (you can opt out anytime).

Payments & fraud prevention

Process payments; prevent misuse; enforce policies.

Legal bases: Contract, Legitimate Interests, Legal Obligation.

Legal compliance

Respond to lawful requests, regulatory requirements, enforce terms.

Legal bases: Legal Obligation.

5) Cookies, SDKs & pixels

We use cookies and SDKs to operate and improve the Platform. Categories:

  • Strictly necessary (login/session, security).
  • Functional (preferences, timezone).
  • Analytics (e.g., GA4, privacy-safe configuration).
  • Marketing/attribution (e.g., Meta Pixel, Firebase/Branch for deep links).

You can manage preferences via our Cookie Banner/Settings and your device settings. Some features require essential cookies.

6) Sharing your data

We share data only with:

  • Processors who help us deliver the service. Our current sub-processors are:
    ProcessorPurposeData accessedData location
    XanoBackend & databaseAll patient data — assessments, clinical notes, messages, protocolsUS (AWS)
    StripePaymentsEmail, name, payment metadataUS
    VimeoConsultation recording storageVideo/audio recordings of sessionsUS
    MeteredVideo call relay (TURN servers)Encrypted media streams, IP addresses only — no access to contentGlobal (nearest node)
    ResendTransactional email & OTPEmail addresses, namesUS
    CalendlySession schedulingName, email, appointment timesUS
    This list is updated when sub-processors change. You may request the current list at any time by contacting priyanka@sravhealth.com.
  • Your care team— your lead practitioner, supporting practitioners, care coordinator, and the reviewing GP all have access to your clinical notes, assessment data, and treatment protocol as part of coordinated care. You consent to this sharing during onboarding. Access is logged and role-based.
  • Event co-hosts where clearly disclosed at registration.
  • Legal authorities where required by law or to protect rights/safety.

We do not sell your personal data. We do not allow third parties to use your health data for ads.

7) International transfers

We may process/store data in Singapore and other countries where we or our processors operate. Where required, we use safeguards (e.g., SCCs under GDPR) to protect your data across borders.

8) Retention

We keep data only as long as needed to provide the service and for legitimate business/legal purposes, then delete or anonymize it. Typical guidelines:

  • Account & plan data: while account is active and for a reasonable period after closure (e.g., 12–24 months) unless you request earlier deletion where applicable.
  • Transactions: 7 years (tax/audit).
  • Support tickets: up to 24 months.
  • Events/program chat: per program/event lifecycle, then archived/anonymized.

9) Your rights

Depending on your location (PDPA/GDPR and similar), you may have rights to:

  • Access your data;
  • Correct inaccurate data;
  • Delete your data (subject to legal holds);
  • Restrict or object to certain processing;
  • Data portability;
  • Withdraw consent at any time (this doesn't affect prior processing).

To exercise rights, contact priyanka@sravhealth.com. We may need to verify your identity. We will respond within 30 days (or the statutory period). You can also contact your local data protection authority.

10) Children

The Platform is for users 18+. We do not knowingly collect personal data from children. If you believe a child has provided data, contact us to delete it.

11) Security

We use administrative, technical, and organizational safeguards, including encryption in transit, role-based access, audit logs, and least-privilege access. No method is 100% secure; please use strong, unique credentials and keep them confidential.

Incident response: If we detect a data breach that poses risk to you, we will notify you and/or authorities as required by law.

Biometric authentication:If you choose to use Face ID to sign in, this is handled entirely by your device's operating system. The app does not access, collect, store, or process any biometric or face data.

12) Account linkage: web & app

Your website and app access use one shared account. Actions on one surface (e.g., enrollment, bookings, plan updates) may be reflected on the other.

13) Practitioners & your data

If you engage a practitioner:

  • They may view your relevant information (with your explicit consent) to support care;
  • They are independent providers and must comply with Srav Health's policies and applicable law;
  • Messaging and notes should remain within Srav Health for privacy.

You can revoke practitioner access by ending your care relationship (subject to legal/clinical retention norms).

14) Events & recordings

Many events are recorded. If you register, you may receive access to a replay for a limited period. We ask participants not to share links publicly. Event chat/Q&A may be visible to co-hosts and used to improve content.

15) Third-party links

Our Platform may link to third-party sites. We are not responsible for their privacy practices. Please review their policies.

16) Changes to this Policy

We may update this Policy from time to time. We will change the "Last Updated" date and, where required, notify you of material changes. Continued use of the Platform means you accept the updated Policy.

17) Region-specific notices

Singapore (PDPA)

You may contact us to withdraw consent, access, or correct personal data. We will seek your consent for new purposes where required.

EEA/UK (GDPR)

Legal bases we rely on include Contract, Consent, Legitimate Interests, Legal Obligation. Where we rely on Legitimate Interests, we balance against your rights and expectations. You have the right to lodge a complaint with your supervisory authority.

California (CCPA/CPRA) – if applicable

We do not "sell" personal information as defined by CCPA. We may "share" limited data for measurement with your consent. You can submit access/deletion requests to priyanka@sravhealth.com and manage cookie preferences in our banner.

18) Contact us

Questions or requests about this Policy or your data:

Srav Health Pte. Ltd.
Email: priyanka@sravhealth.com
Address: 2 Venture Drive, 608526, Singapore

For support: priyanka@sravhealth.com

Questions About Your Privacy?

If you have any questions or concerns about how we handle your data, please don't hesitate to reach out.

Contact Us