1Introduction & Who We Are
Momivara is a clinic management application for gynaecology, obstetric and paediatric practices in India. It is operated by Trivartha, based in Vadodara, Gujarat, India ("Trivartha", "we", "our", "us").
This Privacy Policy explains what information the Momivara mobile application and associated services (together, the "App" or "Services") collect, why we collect it, who it is shared with, how long it is kept, and what you can do about it.
1.1 Who Uses the App
- Moms / Patients — pregnant women, new mothers and parents attending a clinic that uses Momivara.
- Doctors — registered medical practitioners running a gynaecology or paediatric clinic on the platform.
- Clinic Staff — receptionists, nurses and administrative staff added by a doctor.
- Clinic Owners / Administrators — the account that owns a clinic workspace.
1.2 Scope of This Policy
The Services are offered to clinics and patients in India. This Policy is written primarily against India's Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Information Technology Act, 2000 with its rules, together with the Google Play User Data Policy.
We do not currently target, market to, or knowingly onboard clinics or patients in the European Economic Area, the United Kingdom, or the United States. If you access the App from outside India, you do so on your own initiative, and you are responsible for compliance with your local law. Section 19 explains where your data is stored.
1.3 Acceptance
By downloading, installing, registering for, or using the App, you confirm that you have read and understood this Policy. If you do not agree with it, please do not use the App and, if you already have an account, delete it as described in Section 21.
2Who Controls Your Data
This is the most important section in this Policy, because it determines who is answerable to you for what. Momivara is software supplied to clinics. Most of the medical information in the App is created, owned and controlled by your clinic, not by us.
2.1 Two Different Roles
| Category of data | Data Fiduciary (decides why & how) | Our role |
|---|---|---|
| Clinical records, prescriptions, vitals, diagnoses, lab reports, scan reports, visit history, invoices, vaccination records, growth measurements | Your clinic (the treating doctor / clinic entity) | Data Processor acting on the clinic's instructions |
| Your account, login credentials, profile, and app-level settings | Trivartha | Data Fiduciary |
| Personal wellness data you create for yourself — contraction timer, personal gallery, medicine reminders, personal notes, emergency contacts | Trivartha (on your instruction) | Data Fiduciary |
| Messages you send in chat and community groups | Shared — you author it, the clinic administers its groups | Data Fiduciary for delivery and storage |
2.2 What This Means in Practice
- If you want a clinical record corrected or erased — a wrong diagnosis, an incorrect vital, a note attributed to the wrong patient — that request goes to your clinic. The clinic decides, because the clinic is the treating provider and the keeper of the medical record. We will facilitate and pass on such requests, and we will act on the clinic's lawful instruction.
- If you want your account deleted, that request comes to us, and we handle it directly (Section 21).
- We do not read, review, verify, correct, second-guess, or clinically validate anything a doctor or staff member enters. We have no clinical staff and we make no clinical judgements.
- We do not decide who your doctor is, what treatment you receive, what you are charged, or what is written in your file.
2.3 Processing on Clinic Instruction
When acting as a processor for a clinic, we process personal data only to provide the Services, keep them secure and reliable, comply with law, and follow the clinic's lawful documented instructions. We do not use clinic-controlled clinical data for our own purposes, and we never use it to train machine learning models (Section 16).
3Information We Collect
3.1 Account & Identity Information
- Name, mobile number, email address
- Password (handled by Firebase Authentication — see Section 18.2; we never see or store your password)
- Google account identifier and basic profile, if you choose Google Sign-In
- Profile photograph, if you upload one
- Role (Mom, Doctor, Staff, Owner) and clinic association
- Date of birth and address, where provided
3.2 Health & Clinical Information
Health data is sensitive personal information and we treat it accordingly. Depending on your role and your clinic's use of the App, this may include:
- Maternity & gynaecology: last menstrual period, expected date of delivery, gestational week, obstetric history (gravida/para), blood group, weight, blood pressure, blood sugar, SpO₂, temperature, pulse, antenatal visit notes, prescriptions, scan and lab reports, delivery and postnatal details
- Paediatrics: the child's name, date of birth, sex, birth weight, growth measurements (weight, height, head circumference), vaccination schedule and administered doses, paediatric clinical notes and prescriptions
- Self-tracked wellness data: contraction timings, medicine reminders, kick counts, personal symptom notes and similar entries you record for yourself
- Documents you or your clinic upload: lab reports, ultrasound images and reports, discharge summaries, and similar files
3.3 Clinic & Operational Information
- Clinic name, code, address, logo, branding and clinic type (gynaecology or paediatric)
- Doctor profile, qualifications and specialisation as self-declared by the doctor
- Appointments, queue tokens, consultation slots, shifts, leave and staff attendance
- Invoices raised by the clinic, amounts, line items and payment status
3.4 Content You Create
- Chat messages between you and your clinic
- Community group messages, polls, reactions and voice notes
- Photographs and videos you add to your personal gallery
- Notes, feedback and support requests
3.5 Device & Technical Information
- Device model, operating system version, app version and language
- Firebase Cloud Messaging token, used to deliver push notifications to your device
- Anonymous installation identifier used by Firebase Analytics
- Crash reports, stack traces and diagnostic logs (Firebase Crashlytics)
- Approximate region inferred from network address by our infrastructure provider
3.6 Permissions the App Requests
Android will ask you before granting any of these. You may refuse or later revoke any of them in system settings; only the specific feature stops working.
| Permission | Why we ask | If you decline |
|---|---|---|
| Camera | Scanning clinic QR codes, capturing report photographs, and the Baby Position Monitor (Section 7) | QR check-in, photo capture and the monitor are unavailable |
| Photos & Media | Attaching existing reports, images and profile photographs | You cannot attach files from your device |
| Microphone | Recording voice notes in community groups only | You can still send text; voice notes are unavailable |
| Precise Location | Attaching your location to an Emergency SOS alert (Section 8) | SOS still sends, without location |
| Notifications | Appointment reminders, queue updates, messages, medicine reminders | You receive no push notifications |
| Phone (call) | Dialling your clinic or an emergency contact when you tap a call button | Numbers open in your dialler instead |
| Exact alarms | Firing medicine and appointment reminders at the correct time | Reminders may be delayed by the operating system |
| Biometric | Optional fingerprint or face unlock for the App | Password login only |
4How We Use Information
4.1 To Deliver the Service
- Create and authenticate your account, and keep you signed in
- Connect you to your clinic and show you the right workspace for your role
- Book, reschedule and cancel appointments; manage the live consultation queue and tokens
- Record and display clinical visits, prescriptions, vitals, reports, growth charts and vaccination schedules
- Raise and display invoices, and record the payment status your clinic or you mark
- Deliver messages between you and your clinic and within community groups
- Send reminders for appointments, medicines and vaccination due dates
4.2 To Keep the Service Working & Safe
- Diagnose crashes and errors, and fix defects
- Detect and prevent misuse, fraud, unauthorised access and abuse
- Enforce clinic isolation and role-based access rules
- Maintain backups and restore data after a failure
- Understand which features are used, in aggregate, to decide what to build next
4.3 To Communicate With You
- Service messages: appointment confirmations, queue status, invoices, security notices, policy changes
- Support responses when you contact us
4.4 To Comply With Law
- Respond to lawful requests from courts, regulators and law enforcement
- Retain records where a statute or the clinic's professional obligations require it
- Establish, exercise or defend legal claims
5Legal Basis & Consent
5.1 Consent Under the DPDP Act
Under the DPDP Act, we process your personal data on the basis of your consent, which must be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action. You give that consent when you register and when you enable a specific feature.
5.2 Granular Consent
Consent is requested feature by feature, not as one blanket approval:
- Registration and clinic linkage — required to use the App at all
- Camera, microphone, location and notifications — each requested separately, at the moment the feature is first used
- Baby Position Monitor — requires a distinct acknowledgement of its limits (Section 7)
- Emergency SOS — requires you to nominate contacts and accept that location will be shared
- Community participation — optional; you may use the App without joining any group
5.3 Certain Legitimate Uses
The DPDP Act permits processing without separate consent for certain legitimate uses. We rely on these in narrow circumstances: where you voluntarily provide data for a purpose you have asked us to fulfil; for compliance with law or a court order; and to respond to a medical emergency threatening your life or health, or to provide medical treatment during an epidemic or threat to public health.
5.4 Withdrawing Consent
You may withdraw consent at any time, with the same ease with which you gave it — by revoking a permission in system settings, disabling a feature in the App, or deleting your account. Withdrawal is not retroactive: it does not affect processing already lawfully carried out.
5.5 Consent Given by Your Clinic
Where a clinic enters your data into the App, the clinic is responsible for having obtained your consent, or for having another lawful basis, before doing so. That responsibility sits with the clinic as the treating provider (Section 28).
6Children's & Infant Data
6.1 Children Do Not Hold Accounts
Account holders must be 18 years or older. Children cannot register, log in, or use the App independently. There is no interface through which a child interacts with Momivara.
6.2 Data About Children, Provided by Adults
Where the App holds information about a child, that information is entered by an adult — the child's parent or lawful guardian, or a treating clinician at the clinic. Such information may include the child's name, date of birth, sex, birth weight, growth measurements (weight, height, head circumference), vaccination schedule and doses administered, clinical notes, prescriptions and reports.
6.3 Parental & Guardian Consent
Section 9 of the DPDP Act requires verifiable consent from a parent or lawful guardian before processing the personal data of a child. When you add a child in the App, you confirm that you are that child's parent or lawful guardian and that you consent, on the child's behalf, to the processing described in this Policy. Where a clinic enters child data, the clinic is responsible for having obtained guardian consent.
6.4 Protections Specific to Children's Data
Consistent with Section 9(3) of the DPDP Act, in respect of children's data we do not:
- Undertake tracking or behavioural monitoring of children
- Direct any advertising at children — the App carries no advertising at all
- Profile children, or use their data for any purpose beyond the clinical and record-keeping purposes described here
- Use children's data to train any model (Section 16)
6.5 Access to a Child's Record
A child's record is visible to: the parent or guardian account linked to that child; the treating paediatric clinic and its authorised staff; and no one else. A mother linked to both a gynaecology clinic and a paediatric clinic will see each record only within the corresponding clinic workspace — the two do not merge.
6.6 Withdrawing Consent or Deleting a Child's Data
A parent or guardian may withdraw consent and request deletion of a child's data at any time, using the contact details in Section 33. Deletion of the data we hold on your instruction is subject to the clinic's independent medical record-retention obligations (Section 17.3).
6.7 If a Child Registered Without Authorisation
If we learn that someone under 18 has created an account, we will disable it and delete the associated personal data promptly. If you believe this has happened, contact us at once (Section 33).
7Baby Position Monitor — Camera Feature
7.1 What the Feature Does
When you open the Baby Position Monitor and grant camera access, the App uses your device's camera to look at the sleeping area and applies on-device Google ML Kit face detection and pose detection to estimate whether the baby appears to have rolled into a face-down position. If it estimates that, it sounds an alarm on your device to draw your attention so that you can check on your baby.
7.2 Everything Stays on Your Device
The ML Kit models run entirely offline on your device. They do not learn from your baby, do not adapt, and send nothing anywhere.
7.3 It Will Sometimes Be Wrong
Computer vision on a consumer phone camera is inherently unreliable. The monitor may fail to detect a genuine face-down position, and may raise an alarm when nothing is wrong. Circumstances in which it will not work correctly include, without limitation:
- Poor, changing, or very low light; darkness
- The baby being covered by a blanket, swaddle, toy or bedding
- Camera angle, distance, obstruction, or a moved or knocked phone
- Phone battery depletion, overheating, or the operating system suspending or killing the App
- The camera being claimed by another app, an incoming call, or a system interruption
- Silent mode, muted volume, connected headphones, or Do Not Disturb suppressing the alarm
- Device crash, restart, or storage or memory pressure
7.4 Your Responsibilities When Using It
- Continue to follow safe-sleep guidance from your paediatrician and from recognised bodies such as the Indian Academy of Paediatrics — place babies on their back to sleep, on a firm flat surface, clear of soft bedding.
- Never leave an infant unattended in reliance on this feature.
- Never treat the absence of an alarm as confirmation that your baby is safe, breathing, or in a safe position.
- Ensure the device is placed safely, cannot fall into the cot, and that cords are out of reach.
- Seek immediate medical help for any concern about your baby's breathing or condition. Call your doctor or emergency services — do not consult this App.
8Emergency SOS & Location
8.1 What SOS Collects and Sends
When you trigger an SOS alert, and only then, the App:
- Requests a precise GPS location fix from your device
- Converts those coordinates into a readable street address using your device's platform geocoding service (provided by Google Play Services on Android)
- Sends an alert containing your name, your message if any, the timestamp, your coordinates, the resolved address and a map link to your linked clinic and to the emergency contacts you have nominated
8.2 Location Is Not Collected Otherwise
The App does not collect location in the background, does not track your movements, does not build a location history, and does not access location when the App is closed. Location is requested only at the moment you press SOS. If you decline the permission or no fix is available within roughly fifteen seconds, the alert is still sent — without location.
8.3 Third-Party Geocoding
Converting coordinates into an address requires sending those coordinates to the device's geocoding provider (Google). That transfer is governed by Google's privacy policy. If you prefer this not to happen, decline the location permission; SOS will still function without an address.
8.4 Delivery Is Not Guaranteed
An SOS alert depends on your network connectivity, your device, notification permissions, battery state, the recipient's device and connectivity, and the availability of third-party infrastructure. Alerts may be delayed, undelivered, unseen or unanswered. Your clinic is under no obligation to us, and may be under no obligation to you, to monitor alerts at any particular time, including outside clinic hours.
8.5 Retention of Alerts
SOS alerts, including the location attached, are retained in the clinic's records so that the clinic has a history of what was raised and how it was handled. You may request deletion under Section 20.
9Payments, Invoices & UPI
9.1 Clinic Invoices and UPI
Clinics may raise invoices in the App for consultations and services. Payment happens outside the App, directly between you and the clinic, typically by UPI to the clinic's own UPI ID or by cash at the counter.
- We store the clinic's UPI identifier as the clinic has entered it, and display it to you.
- We store invoice line items, amounts and a payment status flag.
- Marking an invoice "paid" is a record-keeping action taken by you or by clinic staff. It is an honour-system marker. The App does not verify with any bank or payment network that money actually moved, and marking an invoice paid is not proof of payment.
- We never collect, see or store your UPI PIN, bank credentials, card numbers, CVV, or any payment instrument details. They are never entered into the App.
9.2 Billing Disputes Are Between You and Your Clinic
Fees, refunds, receipts, tax invoices, GST treatment and any dispute about an amount charged are matters between you and your clinic. We have no visibility into your bank or UPI account, cannot reverse a transaction, cannot confirm or deny that a payment occurred, and cannot adjudicate a billing dispute. Please raise these with your clinic directly.
9.3 Momivara Subscriptions (Clinics)
Where a clinic subscribes to Momivara, that subscription is processed through Google Play Billing. Google collects and processes the payment; we receive only the subscription status, product identifier, purchase token and validity dates needed to activate the plan. We never receive card or bank details. Refunds for Play Store purchases follow Google Play's refund policy.
9.4 Records
Invoice and subscription records are retained as described in Section 17, including where retention is required for tax or accounting purposes.
10Messaging, Community & Your Content
10.1 Direct Chat With Your Clinic
Messages between you and your clinic are stored on our infrastructure so that both sides can see the conversation history and so it survives a device change. They are visible to you and to authorised personnel at your clinic, which may include clinic staff and not only the doctor (Section 24).
10.2 Community Groups
Clinics may run community groups for their patients. Content you post in a group — text, images, polls, reactions and voice notes — is visible to every other member of that group and to the group's administrators. Voice notes are recorded on your device and uploaded to our storage for playback by group members.
10.3 Your Responsibilities for Content
You must not post content that is unlawful, defamatory, obscene, harassing, infringing, misleading as to medical fact, or that discloses another person's personal or health data without their consent. You are responsible for what you post.
10.4 Moderation
Group administrators at your clinic may remove content, mute or remove members, and delete groups. We may also remove content or suspend accounts where we believe, in our reasonable judgement, that content is unlawful or violates this Policy or our terms. We are not obliged to pre-screen or monitor content, and we do not do so systematically. We are an intermediary in respect of user content and claim the protections available to intermediaries under Indian law.
10.5 Licence to Operate the Service
You retain ownership of the content you create. You grant Trivartha a limited, non-exclusive, royalty-free licence to host, store, back up, transmit and display that content solely for the purpose of operating the Services for you and the people you have shared it with. This licence ends when the content is deleted, except for copies in backups pending their expiry. We do not use your content for marketing, promotion or model training.
11Notifications
11.1 What We Send
- Appointments: confirmations, reminders, reschedules, cancellations, queue and token updates
- Clinical: vaccination doses due, follow-up reminders, report availability
- Personal reminders: medicine reminders you have set for yourself
- Messages: new chat and community activity
- Billing: new invoices and payment confirmations
- Emergency: SOS alerts to clinics and nominated contacts
- Service: security notices, policy changes, mandatory update notices
11.2 How They Work
Push notifications are delivered through Firebase Cloud Messaging. To do this we store a device messaging token against your account; it is deleted when you sign out or delete your account. Some reminders are scheduled locally on your device and are not sent over the network at all.
11.3 Content of Notifications
Notification payloads are kept minimal and are designed to avoid exposing clinical detail on a lock screen. However, a notification may reveal that you have an appointment or a message from a named clinic. If your lock screen is visible to others, consider hiding notification content in your device's system settings.
11.4 Delivery Is Not Guaranteed
11.5 Turning Them Off
You can disable notifications by category in the App's settings, or entirely in your device's system settings. Service and security notices may still be shown inside the App.
12Reports, Media & Documents
12.1 What Gets Uploaded
You and your clinic may upload lab reports, scan reports, discharge summaries, prescriptions, photographs and similar documents. These are stored in Firebase Cloud Storage under access rules that restrict them to your account and your clinic.
12.2 Image Handling
Images are resized and compressed on your device before upload to reduce data usage and storage cost. We do not strip or analyse image metadata for any purpose beyond what is needed to display the file, and we do not extract location metadata from your photographs for our own use.
12.3 Personal Gallery
Your personal pregnancy and baby gallery is yours. It is not shared with your clinic unless you explicitly share an item.
12.4 Accuracy of Documents
We store documents as supplied. We do not verify, interpret, transcribe or clinically validate their contents. If a report in the App looks wrong, incomplete or attributed to the wrong person, contact your clinic immediately — and rely on the original issued by the diagnostic centre or laboratory, not on the copy in the App.
13Sharing & Disclosure
13.1 Within Your Clinic
Your information is shared with the clinic you are linked to: your treating doctor, other doctors within that same clinic where the clinic has enabled shared access, and clinic staff whose role requires it (reception, billing, nursing). Section 24 sets out what each role can see.
13.2 Across Clinics
Clinic workspaces are isolated by default (Section 23). Your data crosses a clinic boundary only when:
- You link yourself to a second clinic — for example, a mother linked to both a gynaecology clinic and a paediatric clinic. Each clinic sees only its own records.
- Your record is formally transferred to another clinic through the App's transfer function, which is an explicit, logged action.
13.3 Service Providers
We share data with the infrastructure providers listed in Section 14, strictly to run the Service. They act on our instructions and are bound by their own contractual and security obligations.
13.4 Legal and Regulatory Disclosure
We may disclose information where we are required to by law, or where we believe in good faith that disclosure is necessary to comply with a legal obligation, a court order, or a lawful request from a government or law enforcement authority; to enforce our terms; to detect or prevent fraud or a security incident; or to protect the rights, safety or property of you, us, our users or the public. Where we are lawfully permitted to notify you of such a request, we will endeavour to do so.
13.5 Business Transfer
If Trivartha is involved in a merger, acquisition, restructuring, financing or sale of assets, personal data may be transferred as part of that transaction. Any acquirer will remain bound by this Policy in respect of data transferred, or you will be notified and given a choice before any materially different treatment applies.
13.6 We Do Not Sell Your Data
14Third Parties & Subprocessors
14.1 Our Subprocessors
| Provider | Service | What it handles | Location |
|---|---|---|---|
| Google — Firebase Authentication | Login & identity | Email, phone, password hashes, session tokens | India / Google global |
| Google — Cloud Firestore | Primary database | Accounts, clinical records, appointments, messages, invoices | asia-south1 (Mumbai) |
| Google — Cloud Storage | File storage | Reports, images, voice notes, documents | asia-south1 (Mumbai) |
| Google — Cloud Functions | Server-side logic | Notifications, invoice triggers, background jobs | asia-south1 (Mumbai) |
| Google — Cloud Messaging | Push notifications | Device tokens, notification payloads | Google global |
| Google — Analytics for Firebase | Usage analytics | Anonymous events and installation identifier | Google global |
| Google — Crashlytics | Crash reporting | Stack traces, device model, OS version | Google global |
| Google — Remote Config | Feature flags | App version, configuration fetches | Google global |
| Google — Play Billing | Subscriptions | Purchase tokens and subscription status | Google global |
| Google — ML Kit | Baby Position Monitor | Nothing — runs entirely on your device, transmits nothing | On device only |
| Google — Play Services geocoding | SOS address lookup | Coordinates, only when SOS is triggered | Google global |
14.2 Their Terms
These providers process data under Google's privacy terms and their own security commitments. Their handling of data is governed by their policies, available at policies.google.com/privacy and firebase.google.com/support/privacy.
14.3 Changes to Subprocessors
We may add or change subprocessors as the Service evolves. Material changes will be reflected in an updated version of this Policy.
14.4 External Links
The App may link to external sites and resources. We do not control them and are not responsible for their content or privacy practices.
15Analytics & Crash Reporting
15.1 What We Measure
We use Firebase Analytics to understand, in aggregate, which features are used and where users get stuck. Events are things like booking started, booking succeeded, booking failed with a generic reason code, or branding saved.
15.2 What We Deliberately Exclude
15.3 Crash Reporting
Firebase Crashlytics collects stack traces, device model, operating system version and app version when the App crashes or hits an error. Crash reports may incidentally contain technical identifiers. We do not deliberately send personal or health data into crash reports, and we treat any such data as confidential and delete it when identified.
15.4 No Advertising
The App contains no advertising of any kind. We do not use advertising SDKs, we do not build advertising profiles, we do not use your device advertising identifier for targeting, and we do not share data with ad networks.
15.5 Retention
Analytics data is retained according to Firebase's configured retention period, and crash data is retained for up to 90 days, after which it is deleted or aggregated.
16No AI Training, No Data Sale
16.1 The Only Machine Learning in the App
The single machine learning component in Momivara is Google ML Kit face and pose detection, used by the Baby Position Monitor. It runs entirely on your device, using pre-trained models shipped with the App. It does not learn, does not adapt to your baby, does not store anything and transmits nothing (Section 7.2).
16.2 No Automated Clinical Decisions
Momivara does not generate diagnoses, does not summarise or interpret medical reports, does not suggest treatment, and does not make any automated decision that produces a legal or similarly significant effect on you. Every clinical entry in the App was typed by a human clinician. Every clinical decision is made by your doctor.
16.3 If This Ever Changes
We would have to publish a revised Policy, describe the processing plainly, and obtain fresh consent before using your data in any such way. It will not happen silently.
17Data Retention
17.1 Principle
We keep personal data only as long as necessary for the purpose it was collected for, or as long as a law or a clinic's professional obligation requires.
17.2 Indicative Periods
| Data | Retention |
|---|---|
| Account and profile | While the account is active; deleted on account deletion |
| Clinical records, prescriptions, vitals, reports | Retained by the clinic per its record-keeping obligations — see 17.3 |
| Paediatric records, growth and immunisation history | Retained by the clinic; immunisation history has long-term clinical value |
| Appointments and queue history | Duration of the clinic relationship |
| Invoices and payment records | Up to 8 years, where required for tax and accounting |
| Chat and community messages | Until deleted by you, your clinic, or on account deletion |
| Uploaded reports and media | Until deleted, subject to clinical retention |
| Emergency SOS alerts | Retained in clinic records for incident history |
| Notification device tokens | Deleted on sign-out or account deletion |
| Crash reports | Up to 90 days |
| Backups | Rolling, overwritten in the ordinary cycle |
| Security and audit logs | Up to 12 months |
17.3 Medical Records Survive Your Account Deletion
17.4 Anonymised Data
We may retain data that has been irreversibly anonymised, and can no longer identify you or be re-linked to you, for statistical and product purposes. Anonymised data is not personal data.
18Security Measures
The following describes what we actually do. We have avoided listing controls we do not operate.
18.1 Encryption
- In transit: all communication between the App and our infrastructure uses TLS 1.2 or higher.
- At rest on the server: Firestore and Cloud Storage encrypt stored data using Google-managed AES-256 encryption.
- On your device: authentication tokens and encryption keys are held in Android Keystore-backed secure storage. Selected sensitive fields in the local database — your emergency contacts and your medicine reminders — are additionally encrypted with AES-256-GCM before being written to disk.
18.2 Credentials
Passwords are handled entirely by Firebase Authentication. We never see, receive, store or have any means of recovering your password. We cannot tell you what your password is, and any message purporting to be from us that asks for your password is fraudulent.
18.3 Access Control
- Server-enforced Firestore and Storage security rules — access is denied at the database, not merely hidden in the interface
- Clinic-level data isolation (Section 23) and role-based access (Section 24)
- Least privilege: each role is granted only what its function requires
- Re-authentication for sensitive operations such as changing credentials or deleting an account
- Optional biometric lock on the App
18.4 Operational Security
- Infrastructure hosted on Google Cloud, inheriting its physical, network and platform security controls
- Automated crash and error monitoring
- Dependency and platform updates applied as part of ongoing maintenance
- Security rules exercised by an automated test suite before deployment
18.5 What You Should Do
- Use a strong, unique password and do not reuse it elsewhere
- Keep a screen lock on your device and keep the operating system updated
- Do not share your login, and do not hand an unlocked, signed-in device to someone else
- Sign out on shared or borrowed devices
- Tell us immediately if you suspect unauthorised access
19Where Your Data Lives
19.1 Primary Storage in India
Our database, file storage and server-side functions are provisioned in Google Cloud's asia-south1 (Mumbai, India) region. Your clinical records, appointments, messages, invoices and uploaded documents are stored in India.
19.2 Services That Operate Globally
Some ancillary Google services are not region-pinned and may process limited data outside India: Cloud Messaging (notification tokens and payloads), Analytics (anonymous usage events), Crashlytics (crash diagnostics), Authentication (identity records), Remote Config and Play Billing. These handle operational metadata, not your clinical records.
19.3 Transfers
The DPDP Act permits transfer of personal data outside India except to countries restricted by the Central Government. We do not transfer data to any restricted territory. Where data is processed outside India by the services above, it remains subject to Google's contractual and security commitments.
19.4 Government Access
Data stored in India is subject to Indian law, including lawful access requests. We disclose data only where legally compelled, and we do not provide any government or third party with bulk, direct or unfettered access to our systems.
20Your Rights
20.1 Rights Under the DPDP Act
- Right to access information — a summary of the personal data we process about you, the processing activities, and the identities of others with whom it has been shared.
- Right to correction and erasure — to have inaccurate or misleading data corrected, incomplete data completed, data updated, and data erased where it is no longer needed for the purpose it was collected for.
- Right of grievance redressal — to a readily available means of raising a grievance with us, which we must respond to (Section 33).
- Right to nominate — to nominate another individual who may exercise your rights in the event of your death or incapacity.
- Right to withdraw consent — as easily as you gave it (Section 5.4).
20.2 How to Exercise Them
Most rights can be exercised directly in the App: edit your profile, delete your content, revoke a permission, change notification settings, or delete your account. For anything else, contact our Grievance Officer (Section 33). We will verify your identity before acting, because acting on an unverified request would itself be a privacy failure.
20.3 Timelines
- Acknowledgement of a request: within 7 days
- Substantive response: within 30 days, extendable where a request is complex, with reasons given
- Account deletion: within 30 days of a verified request
20.4 Requests We May Decline
We may decline or limit a request where: we cannot verify your identity; the request is manifestly unfounded, excessive or repetitive; complying would infringe another person's rights or privacy; the data is subject to a clinic's medical record-retention obligation (Section 17.3); or a law requires us to retain it. We will always tell you why.
20.5 Your Duties Under the DPDP Act
The DPDP Act also places duties on you: not to impersonate another person when providing data, not to suppress material information, not to register a false or frivolous grievance or complaint, and to furnish only authentic information when seeking correction or erasure.
20.6 Complaints
If you are not satisfied with our response, you may complain to the Data Protection Board of India once it is constituted and operational. We would appreciate the chance to resolve it with you first.
21Account Deletion
21.1 How to Delete Your Account
You can request deletion from within the App under Settings → Account → Delete Account, or through the web form at momivara.trivartha.com/delete-account.html, or by writing to our Grievance Officer (Section 33).
21.2 What Gets Deleted
- Your login credentials and authentication record
- Your profile, personal details and preferences
- Your personal wellness data — gallery, contraction logs, medicine reminders, emergency contacts, personal notes
- Your chat and community messages, subject to 21.4
- Your device notification tokens
- Your clinic linkage
21.3 What May Be Retained, and Why
- Clinic medical records — retained by the treating clinic under its professional and statutory obligations (Section 17.3)
- Invoices and financial records — retained where tax or accounting law requires
- Data under legal hold — where a claim, complaint, investigation or proceeding exists or is reasonably anticipated
- Backups — residual copies persist until the ordinary backup cycle overwrites them
- Anonymised aggregates — which can no longer identify you
21.4 Group Content
Messages you posted in community groups may remain visible to other members after your account is deleted, because they form part of a shared conversation. Ask a group administrator to remove specific posts before deleting your account if this matters to you. We cannot recall content that others have already seen, saved or copied.
21.5 Irreversibility
21.6 Deletion by a Clinic
If a clinic closes its Momivara workspace, patient access to that clinic's records through the App ends. Custody of the underlying medical record remains the clinic's responsibility and is a matter between you and the clinic.
22Data Export
22.1 What You Can Export
You can obtain a copy of your profile, appointment history, clinical records visible to you, growth and immunisation records for your children, uploaded reports, invoices and personal wellness data.
22.2 How
Individual reports and records can be downloaded or shared directly from the App. For a consolidated export, write to our Grievance Officer (Section 33) and we will provide it within 30 days of verifying your identity, in a structured, commonly used, machine-readable format such as JSON or CSV, with attached documents in their original formats.
22.3 Limits
Exports contain your own data. They do not include another person's data, a clinic's internal operational or commercial information, other members' community messages, or our proprietary system data.
23Multi-Tenant Isolation
23.1 The Model
Every clinic operates in its own logical workspace. A clinic can see only its own patients, appointments, records, invoices, staff and messages. This is enforced server-side by security rules, not merely by hiding things in the interface — a request for data outside your clinic scope is refused by the database itself.
23.2 How Isolation Works
- Every record carries a clinic identifier, validated on every read and write
- Access tokens carry role and clinic claims that the server checks
- Cross-clinic queries are structurally denied
- File storage paths are namespaced per clinic and enforced by storage rules
23.3 Dual-Clinic Patients
A mother may be linked to a gynaecology clinic and a paediatric clinic simultaneously. The two remain isolated: the paediatric clinic does not see her obstetric records, and the gynaecology clinic does not see the child's paediatric records, unless she is a patient of both for those specific records.
23.4 Transfers
Records move between clinics only through the App's explicit transfer function, initiated deliberately using the destination clinic's code, and logged.
24Role-Based Access
24.1 Who Sees What
| Role | Typical access |
|---|---|
| Mom / Patient | Own records, own children's records, own appointments, invoices and messages |
| Doctor | Full clinical access to patients of their clinic; can create and amend records, prescriptions, invoices; can manage staff and clinic settings |
| Clinic Staff | Patient demographics, appointments, queue, check-in, billing and invoicing, and clinical data entry where their duties require; cannot alter clinic ownership or subscription |
| Clinic Owner / Admin | Everything a doctor can do, plus staff management, subscription and clinic-level configuration |
24.2 The Clinic Controls Its Staff
Your clinic decides who works there, what role each person holds, and when access is revoked. Trivartha does not vet clinic staff, does not conduct background checks, and does not supervise how a clinic manages its personnel. A clinic must revoke access promptly when a staff member leaves (Section 28.2).
24.3 Auditability
Record creation and amendment are attributed to the user who performed them, with timestamps, so a clinic can see who entered or changed what.
24.4 Re-Authentication
Sensitive actions — changing your email or password, deleting your account, altering clinic ownership — require you to re-authenticate.
25Data Breach Response
25.1 If a Breach Occurs
On becoming aware of a personal data breach, we will contain it, investigate its cause and scope, assess the risk to affected individuals, remediate the vulnerability, and notify as required by law.
25.2 Notification
- Data Protection Board of India — notified as required under the DPDP Act, without undue delay
- CERT-In — reportable cyber security incidents notified within 6 hours of becoming aware, as required by the CERT-In Directions of 28 April 2022
- Affected users — notified without undue delay, in plain language, describing what happened, what data was involved, what we have done, and what you should do
- Affected clinics — notified so they can meet their own obligations as data fiduciaries
25.3 Reporting a Vulnerability
If you discover a security vulnerability, please report it to us privately using the contact details in Section 33 rather than disclosing it publicly. We will acknowledge your report and will not pursue action against good-faith security research that does not access, alter or exfiltrate other users' data, does not degrade the Service, and gives us reasonable time to fix the issue.
26Not a Medical Device, Not Medical Advice
26.1 No Medical Advice
Nothing in the App — no chart, no reminder, no vaccination schedule, no growth curve, no gestational week counter, no educational content — constitutes medical advice, diagnosis, prognosis, or treatment recommendation from Trivartha. Trivartha does not practise medicine and employs no clinicians in connection with the Services. Always consult a qualified registered medical practitioner.
26.2 Not a Regulated Medical Device
Momivara is not registered, approved, cleared or certified as a medical device under the Medical Devices Rules, 2017, by the Central Drugs Standard Control Organisation, or by any other regulator in any jurisdiction. It is not intended for diagnosis, prevention, monitoring, treatment or alleviation of disease within the meaning of those rules. Do not use it as if it were.
26.3 No Clinical Decision Support
The App performs no clinical reasoning. Vaccination schedules and gestational calculations are simple calendar arithmetic applied to dates entered by a human, presented for convenience. They are not tailored to a patient's clinical circumstances, and they may be wrong if the underlying dates are wrong. Your doctor's judgement governs, always.
26.4 Accuracy of Data
All health data in the App is entered manually by patients, doctors or staff. We do not verify it. Values may be mistyped, misattributed, out of date, incomplete or entered against the wrong patient. Do not make any medical decision on the basis of what the App displays without confirming it with your doctor and with the original source documents.
26.5 In an Emergency
27No Telemedicine
27.1 The App Does Not Provide Consultations
Momivara does not offer telemedicine. There is no video consultation, no audio consultation, no remote examination and no online prescribing feature in the App. It is a record-keeping, scheduling and communication tool supporting in-person care at a physical clinic.
27.2 Text Messaging Is Not a Consultation
The chat feature allows administrative and follow-up communication with your clinic. It is not a consultation channel, and a message from clinic personnel is not a teleconsultation, a diagnosis or a prescription.
27.3 If a Practitioner Uses It Otherwise
If a registered medical practitioner chooses to give clinical guidance through the App's messaging feature, that practitioner is solely responsible for complying with the Telemedicine Practice Guidelines and all applicable professional and regulatory obligations. Trivartha does not hold itself out as a telemedicine platform, does not facilitate teleconsultation, and accepts no responsibility for advice given by a practitioner through any channel.
28Clinic & Practitioner Responsibilities
This section applies to doctors, clinic owners and clinic staff using Momivara. It is a condition of your use of the Services.
28.1 Your Warranties
By using Momivara as a clinic or practitioner, you represent and warrant on a continuing basis that:
- You are a validly registered medical practitioner or a lawfully constituted clinic entity, holding all registrations, licences and permissions required to provide the services you provide, including under the Clinical Establishments Act and applicable State legislation.
- You have a lawful basis, including any patient consent required, for every item of personal and health data you enter, upload, store or process using the Services.
- You have obtained verifiable guardian consent before entering any child's data (Section 6.3).
- You will comply with the DPDP Act as a data fiduciary in respect of the data you control, with the National Medical Commission's professional conduct regulations, with medical record-keeping and retention requirements, and with all applicable rules on prescriptions and drugs.
- You will use the Services only for lawful clinical and administrative purposes, and not for marketing to patients without their consent.
28.2 Your Operational Duties
- Grant staff only the access their duties require, and revoke access immediately when a staff member leaves or changes role.
- Keep credentials confidential; do not share logins between people.
- Ensure the accuracy of what you and your staff enter, and correct errors promptly.
- Respond to your patients' access, correction and erasure requests as their data fiduciary.
- Notify us immediately of any suspected unauthorised access.
- Maintain your own independent records as your professional obligations require. Do not rely on Momivara as your only copy of a medical record.
28.3 What Trivartha Does Not Do
- We do not verify a practitioner's registration, qualifications, credentials or fitness to practise.
- We do not supervise, review or audit clinical practice, record quality, or fee levels.
- We do not vet, employ or supervise clinic staff.
- We do not act as your compliance function, your medical records officer, or your data protection officer.
- We make no representation to any patient about any clinic or practitioner on the platform.
28.4 Indemnity
28.5 Patients Contract With Their Clinic
Nothing in this Policy creates a doctor–patient relationship, a contract for medical services, or any duty of care in respect of clinical matters between a patient and Trivartha. The provision of healthcare is a matter between the patient and the clinic.
29Disclaimers & Limitation of Liability
29.1 Service Provided "As Is"
To the maximum extent permitted by applicable law, the Services are provided "as is" and "as available", without warranty of any kind, express or implied, including any implied warranty of merchantability, fitness for a particular purpose, accuracy, or non-infringement. We do not warrant that the Services will be uninterrupted, timely, secure, error-free, or that defects will be corrected.
29.2 Specific Exclusions
Without limiting the above, and to the maximum extent permitted by law, Trivartha is not liable for:
- Any clinical decision, diagnosis, prescription, treatment, omission or outcome — these are the practitioner's responsibility
- The accuracy, completeness, timeliness or clinical appropriateness of any data entered by any user
- Any failure, delay, false alarm, missed alarm or non-detection by the Baby Position Monitor (Section 7)
- Any delayed, undelivered, unseen or unanswered Emergency SOS alert (Section 8)
- Any missed, delayed or suppressed notification or reminder, including for appointments, medication and vaccinations (Section 11.4)
- Any payment dispute, non-payment, over-payment or billing error between a patient and a clinic (Section 9.2)
- Content posted by users in chat or community groups, or its consequences
- Unauthorised access resulting from your loss, sharing or weak protection of credentials, or from an unlocked device
- Outage, defect, data loss or security incident originating with a third-party provider, including Google, Firebase or the Play Store
- Loss of data where you have not maintained independent records
- Any event beyond our reasonable control, including network failure, power failure, natural disaster, epidemic, war, civil disturbance, government action, cyber attack or platform outage
29.3 No Indirect Loss
To the maximum extent permitted by law, Trivartha shall not be liable for any indirect, incidental, special, consequential, exemplary or punitive damages, nor for any loss of profit, revenue, goodwill, business, opportunity, anticipated saving, or data, however arising, whether in contract, tort (including negligence), statute or otherwise, even if advised of the possibility.
29.4 Aggregate Cap
29.5 What We Do Not Exclude
Nothing in this Policy excludes or limits liability that cannot lawfully be excluded or limited, including liability for fraud or fraudulent misrepresentation, for death or personal injury caused by our own gross negligence, or any liability that Indian law does not permit us to exclude. Where a limitation in this section is held unenforceable, it applies to the maximum extent that is enforceable, and the remainder of this Policy is unaffected.
29.6 Your Acknowledgement
You acknowledge that the allocation of risk in this section is a fundamental basis on which the Services are made available, that the fees charged (or the absence of fees) reflect that allocation, and that the Services would not be offered on different terms.
30Accessibility
We aim to make Momivara usable by as many people as possible, including support for system font scaling, sufficient colour contrast, and compatibility with Android screen readers such as TalkBack. The App is currently available in English only.
If you encounter an accessibility barrier, or need this Policy or your data in an alternative format, contact us (Section 33) and we will assist. We will not require you to disclose a disability in order to exercise a privacy right.
31Changes to This Policy
31.1 Updates
We may update this Policy as the App changes or the law changes. The version number and "Last Updated" date at the top of this page always reflect the current version.
31.2 Material Changes
Where a change materially affects how we handle your personal data, we will give notice through the App, and by email where we hold your address, before the change takes effect. Where the DPDP Act requires fresh consent, we will ask for it rather than assume it.
31.3 Continued Use
Continued use of the App after a change takes effect indicates acceptance of the revised Policy. If you do not accept it, stop using the App and delete your account.
31.4 Version History
- v2.0 — 19 July 2026: Comprehensive revision. Added paediatric and child data, Baby Position Monitor, Emergency SOS, UPI and invoicing, community and voice notes, and no-AI-training commitment. Clarified the clinic-as-fiduciary / Trivartha-as-processor split. Corrected security claims to match the shipped build. Removed HIPAA, COPPA, GDPR and CCPA compliance assertions and telemedicine provisions that did not reflect the Service as operated; re-based the Policy on India's DPDP Act 2023. Added grievance officer, governing law and liability provisions.
- v1.0 — 9 June 2026: Initial publication.
32Governing Law & Dispute Resolution
32.1 Governing Law
This Policy and any dispute or claim arising out of or in connection with it, its subject matter or formation (including non-contractual disputes or claims) are governed by and construed in accordance with the laws of India, without regard to conflict of law principles.
32.2 Jurisdiction
Subject to Section 32.3, the courts at Vadodara, Gujarat, India shall have exclusive jurisdiction over any dispute arising out of or in connection with this Policy or the Services, and you consent to that jurisdiction and venue.
32.3 Resolve It With Us First
Before commencing any proceeding, please contact our Grievance Officer (Section 33) and give us a genuine opportunity to resolve the matter. Most issues are resolved this way. We ask that you allow us 30 days from a written notice describing the issue and the outcome you seek.
32.4 Arbitration
Any dispute not resolved under Section 32.3 may, at either party's election, be referred to arbitration by a sole arbitrator under the Arbitration and Conciliation Act, 1996. The seat and venue of arbitration shall be Vadodara, Gujarat, and the language shall be English. This does not prevent either party from seeking urgent interim relief from a court.
32.5 Regulatory Recourse
Nothing here prevents you from complaining to the Data Protection Board of India or any other competent authority (Section 20.6).
32.6 Severability
If any provision of this Policy is held invalid, illegal or unenforceable, it shall be severed or read down to the minimum extent necessary, and the remaining provisions shall continue in full force.
32.7 No Waiver
Our failure to enforce any provision is not a waiver of it, and no waiver on one occasion operates as a waiver on any other.
32.8 Entire Agreement
This Policy, together with our Terms of Service and any clinic subscription agreement, constitutes the entire agreement between you and Trivartha regarding the processing of personal data, and supersedes all prior understandings on that subject, including version 1.0 of this Policy.
33Grievance Officer & Contact
33.1 Data Fiduciary
Trivartha
Vadodara, Gujarat, India
A 33 —Usha Kiran society Tarsali Vadodara Gujarat
Application: Momivara — Clinic Management for Gynaecology & Paediatrics
Website: momivara.trivartha.com
33.2 Grievance Officer
In accordance with the DPDP Act, 2023 and the Information Technology (Intermediary Guidelines) Rules, 2021, the Grievance Officer for Momivara is:
Meena Devi — Partner
Designation: Grievance Officer, Trivartha
Email: info@trivartha.com
Address: as at Section 33.1
Hours: Monday to Saturday, 10:00 to 18:00 IST, excluding public holidays
33.3 What to Contact Us About
- Exercising your rights of access, correction, erasure or nomination
- Withdrawing consent
- Requesting a data export
- Reporting a security vulnerability or suspected unauthorised access
- Raising a grievance about how we have handled your data
- Any question about this Policy
33.4 What to Take to Your Clinic Instead
Correction or erasure of a clinical record, a question about a diagnosis or prescription, a billing dispute, or a complaint about care or conduct — these are matters for your clinic, which is the data fiduciary for those records and the provider of your care (Section 2.2).
33.5 Response Times
- Acknowledgement: within 7 days
- Grievance resolution: within 30 days
- Security incident reports: acknowledged within 48 hours
34Definitions
- Personal Data — any data about an individual who is identifiable by or in relation to such data.
- Data Principal — the individual to whom the personal data relates. Where the individual is a child, this includes their parent or lawful guardian.
- Data Fiduciary — the person who, alone or with others, determines the purpose and means of processing personal data.
- Data Processor — a person who processes personal data on behalf of a Data Fiduciary.
- Child — an individual under the age of 18 years.
- Processing — any operation on personal data, including collection, storage, use, sharing, alteration, retention and erasure.
- Health Data — personal data relating to physical or mental health, medical history, clinical findings, treatment and care.
- Clinic — the medical practice, practitioner or clinical establishment operating a workspace on Momivara.
- Services — the Momivara mobile application and associated backend, website and support.
- DPDP Act — the Digital Personal Data Protection Act, 2023 (India).
- Consent Manager — a registered entity through which a Data Principal may give, manage and withdraw consent, as contemplated by the DPDP Act. Momivara does not currently operate through a Consent Manager.