Privacy policy
Version 1.0 · updated 2026-08-26
What we store
Donors: name, mobile number (encrypted), blood group, gender, birth year, district/area, consent records, donation history (self-reported or centre-confirmed). Optional email for match messages.
Requesters: name, mobile number (encrypted), hospital, district, blood group, units, dates. Never patient names, diagnoses or medical records.
What we never collect: addresses, Aadhaar or other ID numbers, medical documents, bank details (until a donation gateway exists, then only what payments legally require).
How it's protected
- Phone numbers are encrypted (AES-256-GCM) with a separate blind index for lookup, even a database leak doesn't expose numbers.
- No passwords exist. Login is your phone + one-time code.
- Staff access requires a second factor (TOTP) and every sensitive action is written to an audit log.
- Nightly encrypted backups, access-limited.
Who sees what
- Your number is never public and never shown to requesters.
- A coordinator sees it only for a request you accepted, only for that request.
- Public pages show aggregate counts only (e.g. "1,200 active donors").
- We do not sell, rent or share personal data with advertisers or data brokers. Ever.
Your rights
From your donor profile, one tap: export your data (JSON), withdraw consent (anonymized within 72 hours), or delete your account (immediate and permanent). You may also ask us by phone/email via the contact page.
Grievance
Until our formal Data Protection grievance officer is appointed (post Section 8 registration), raise any privacy concern via the contact page, it reaches the founder directly and is answered within 72 hours.