Legal
PRIVACY POLICY
Valenox is built by an individual developer, Dippu Kumar, as a local-first health companion for Indian families. This policy explains, in plain language, what data the app touches, where it goes, and what stays only on your phone. If a sentence here is unclear, that's a bug in this document — write to kumardippu@gmail.com and it will be fixed.
On this page
1. Our approach
Valenox has no user account and no backend server. There is nothing to sign up for and nothing for us to host on your behalf. Your health data — profile, food diary, steps, water, medicines, heart-rate readings, lab reports, vaccination records and chat history — is stored in a database on your own device and is not synced to any cloud service we operate, because no such service exists.
Two things do leave your device: requests to the AI provider when you actively use an AI feature (Section 3), and anonymous usage analytics (Section 4). Nothing else is transmitted anywhere by this app.
2. Information we collect
2.1 Information you provide directly
- Onboarding profile: date of birth, sex, height, weight, activity level and goal. Used to calculate BMI, BMR, body-fat estimate and your daily targets — entirely on-device.
- Logged health data: food diary entries, water glasses, medicines and dose times, manually entered steps (if your phone has no step sensor), lab report values you confirm, vaccination and checkup dates, and diet-plan preferences (region, dietary type).
- Camera-derived data: photographs you take of meals or lab reports, and heart-rate readings measured via your camera and flash (see 2.2 and Section 3).
- Assistant conversations: messages you type to the in-app AI assistant.
2.2 Camera use
Valenox uses the camera in two different ways:
- Food scanning opens your phone's own camera app via a standard Android camera intent. Valenox does not hold direct camera access for this — the photo is handed back to the app once you've taken it, then optionally sent for AI analysis (Section 3).
- Heart-rate measurement uses direct camera and flash access: you cover the rear camera and flash with a fingertip, and the app reads the colour change over roughly twenty seconds to estimate your pulse. This reading, and the brief video frames used to calculate it, are processed and discarded on-device — they are not saved as a video file and are not sent anywhere.
2.3 Sensor and device data
- Step count comes from your phone's built-in step sensor (or Google Play Services' Recording API, on devices that support it), read locally to build your daily and historical step counts.
3. AI features and what they send
When you actively use one of the features below, the relevant content is sent over an encrypted connection to our AI service provider (currently Groq, an AI inference provider used via an OpenAI-compatible API) for processing, and a response is returned to the app. This only happens when you initiate the action — nothing is sent in the background.
| Feature | What is sent |
|---|---|
| Food scanner | The photo of your plate |
| Lab report reader | The photo or PDF of your report |
| AI health assistant | The message you type, plus a short summary of the active profile's last 30 days of logged activity (steps, water, meals, medicines, health score) so the assistant can answer questions about your own data |
| Diet planner | Your profile stats (region, dietary preference, calorie target) — no name or contact details |
Lab reports specifically: a report photo may contain your name, date of birth and lab ID printed on the page. Only upload reports you're comfortable sharing with the AI provider for this purpose. The original file stays on your phone and is never included in the export feature described in Section 6.
We do not control how long the AI provider retains request data on their infrastructure; we do not instruct them to train models on your data, and we do not receive or store a copy of what you send them beyond what's already saved in your local diary (e.g. the dish names and calories that come back from a food scan). Every AI response carries a "not medical advice" disclosure — see Section 11.
4. Analytics
Valenox uses Google Analytics for Firebase to understand which features are used and to fix problems. This is limited, by design, to behavioral signals:
- Screens viewed and features opened (e.g. "Scan" tab opened, "Trends" viewed)
- Coarse action events (e.g. a food item was logged, a reminder was scheduled or actioned, an AI call succeeded or failed) — logged as a category and a label, never as free text
- Standard app-analytics device signals: an app-instance identifier, device model, OS version, language, and approximate country/region (derived from IP address, not GPS)
- Basic diagnostic and performance data (e.g. app crashes)
What analytics never receives: lab values, medicine names, body-weight or other health numbers, food or dish names, chat messages, or any other free text you type. This boundary is enforced in the app's code, not just promised in this document.
You can limit ad-related and analytics identifiers at the device level via Settings → Google → Ads on your phone, which applies across apps that use Google's advertising or analytics identifiers.
5. App permissions
Valenox requests the following Android permissions, each tied to a specific feature:
| Permission | Why it's needed |
|---|---|
| Internet | To reach the AI provider when you use an AI feature, and to send analytics events |
| Camera | Heart-rate measurement only (see 2.2). Food scanning uses the system camera app instead and needs no direct camera permission. |
| Activity recognition | To read your phone's step counter |
| Post notifications | To show medicine, water and vaccination reminders |
| Schedule exact alarms | So medicine reminders fire at the exact time you set, not "around" it |
| Receive boot completed / wake lock | So reminders survive a phone restart and fire reliably |
| Ignore battery optimizations (optional prompt) | Some phone manufacturers kill background apps aggressively; this optional prompt helps reminders keep working on those devices |
6. Storage, retention and deletion
Your health data is stored in a local database on your device and is excluded
from Android's automatic cloud backup (allowBackup="false") — we
do not want a copy of your health data sitting in your Google account backup
without your explicit action.
- Your own backup: the in-app Export feature writes a JSON file you control, which you can store or transfer however you choose. Restoring a backup validates the entire file before writing anything, so a corrupt or partial file cannot damage your existing data.
- Deleting your data: uninstalling the app deletes the local database and everything in it. There is no server-side copy for us to delete, because none exists.
- Diagnostics snapshot: the in-app "Share diagnostics" feature lets you export a local crash/usage log through your phone's normal share sheet (e.g. to email it to support). This only happens if you tap it — it is not sent automatically.
7. Sharing and third parties
We do not sell your data, and we do not run ads in Valenox. Data reaches outside parties only as follows:
- Groq (or another AI inference provider we may switch to) — processes the content described in Section 3, only when you use an AI feature.
- Google (Firebase Analytics) — receives the behavioral signals described in Section 4.
- Anyone you choose — if you use the Export or Share Diagnostics features and then send the resulting file yourself.
We do not otherwise share, rent or sell any data to advertisers, data brokers or other third parties.
8. Family profiles and children
Valenox lets one adult set up additional profiles for family members, including children, under a shared family PIN. A child's logged data (growth, vaccination dates, notes) is stored locally on the same device as the adult's, under the same rules as Section 6. Child profiles are deliberately blocked from the AI assistant and from certain modules — nothing typed by or about a child profile is sent to the AI provider through the assistant feature. Valenox is not directed at children, is not designed for a child to use unsupervised, and does not knowingly collect data directly from a child without a parent or guardian operating the app.
9. Security
Network requests to the AI provider and to analytics use encrypted (HTTPS) connections. Because your health data lives locally rather than on a server we control, its security also depends on your device's own protections — we recommend using your phone's lock screen and keeping its OS updated. If you share your phone with family members, the in-app family PIN (Section 8) adds a layer of protection for shared-device use, but is not a substitute for securing the device itself.
10. Your choices
- Access and portability: everything the app knows about you is visible in the app itself, and exportable in full via the Export feature at any time.
- Deletion: uninstall the app, or delete individual entries/profiles from within the app.
- AI features are optional: every AI-powered feature (scan, assistant, lab reader, diet planner) has a manual, fully offline alternative — search-by-name food logging works without any network call.
- Analytics: see the device-level opt-out described in Section 4.
If you are in a jurisdiction with a statutory right to request details of, or deletion of, data held about you (for example under India's DPDP Act or the EU's GDPR), write to kumardippu@gmail.com — though in most cases the in-app Export and uninstall already give you full access to, and control over, your data without needing to ask us at all.
11. Medical disclaimer
Valenox is a wellness companion, not a medical device. BMI, BMR, body-fat, calorie targets, heart-rate readings and the AI assistant's answers are estimates for general awareness, not a diagnosis, prescription or medical advice. The assistant is built to refuse questions about diagnosis, dosing and drug interactions and to direct you to a qualified doctor instead. Always consult a healthcare professional for medical concerns.
12. Changes to this policy
If this policy changes in a way that materially affects what data is collected or how it's used, the "Effective date" above will be updated and, where practical, noted in the app's release notes. Continued use of the app after a change means you accept the updated policy.
13. Contact
Valenox is built and maintained by one person. For privacy questions, data requests, or anything else: kumardippu@gmail.com.