Tovelu
🛡️ GLOBAL DATA PROTECTION STANDARD

Global Privacy Policy

Effective Date: September 22, 2026 • Last Reviewed: Q3 2026 • Operating Entity: Tovelu Health Technologies Private Limited

🔒 Tovelu Core Privacy Commitments (At a Glance)

1. Introduction & Corporate Scope

This Global Privacy Policy ("Privacy Policy") governs the collection, processing, retention, transfer, and deletion of personal and sensitive physiological information through the software applications, web portals, APIs, and digital services operated by Tovelu Health Technologies Private Limited (together with our affiliates, successors, and assigns, "Tovelu", "we", "us", or "our").

Tovelu is engineered as a privacy-protective, local-first metabolic operating system. Our services are accessible across more than 230 sovereign territories and jurisdictions worldwide. This Policy is structured in strict conformance with leading global privacy and statutory benchmarks, including:

  • European Union & European Economic Area: General Data Protection Regulation (EU) 2016/679 ("GDPR"), with specific reference to Article 6 (Lawful Basis) and Article 9 (Special Categories of Data).
  • United Kingdom: Data Protection Act 2018 and UK GDPR.
  • United States: California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (collectively, "CCPA/CPRA"), the FTC Act Section 5, and state comprehensive privacy statutes (Virginia VCDPA, Colorado CPA, Texas TDPSA, etc.).
  • India: Digital Personal Data Protection Act, 2023 ("DPDP Act") and Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.
  • Global Alignments: Canadian PIPEDA, Australian Privacy Act 1988, Singapore PDPA, Brazilian LGPD, and Swiss FADP.

2. Local-First Architecture & Data Minimization

In contrast to conventional health tracking cloud platforms that continuously upload granular user meal photos, glucose metrics, and intimate physical routines to remote centralized databases, Tovelu employs a Local-First Privacy Architecture:

Device-Side State: Your meal entries, daily macro rings, water tallies, step logs, sleep intervals, and custom pantry grocery selections are stored client-side in your device’s HTML5 LocalStorage and IndexedDB partitions.

Camera & Plate Scanner Privacy: When you utilize our 1-Snap Sequencing Plate Scanner, image frames processed through HTML5 getUserMedia and canvas operations are evaluated locally in memory. We do not archive or index personal photographic reels of your dining table or kitchen on our remote infrastructure.

3. Categories of Information We Process

A. Information You Voluntarily Provide

Account & Subscription Data: Full name, primary email address, authentication credentials, and transactional identifier issued by our PCI-DSS Level 1 payment processors (e.g. Stripe, Dodo Payments, Brevo). We never store raw payment card numbers or CVV codes on our servers.

Metabolic & Lifestyle Assessment Data: Self-reported biological baseline metrics (approximate age, biological sex, current weight, target weight, activity tier, sleep patterns, dietary preferences, and metabolic challenges such as insulin resistance or dyslipidemia).

B. Technical & Telemetry Information

Basic anonymized operational telemetry (browser type, operating system version, screen resolution, localized time zone, and application crash reports) strictly necessary to ensure runtime stability and service worker asset caching.

4. Lawful Basis for Processing (GDPR & Global Standards)

We process your personal and health information under the following legal frameworks:

  • Performance of Contract (Art. 6(1)(b) GDPR): To generate your personalized 90-day metabolic roadmap, calculate daily macro quotas, and facilitate uninterrupted application access.
  • Explicit Consent (Art. 9(2)(a) GDPR & India DPDP Act): By voluntarily completing the Tovelu clinical survey and configuring health goals, you explicitly consent to the algorithmic calculation of food sequencing order and nutritional pacing. You maintain the absolute right to revoke consent at any moment by purging your local session.
  • Legitimate Interests (Art. 6(1)(f) GDPR): To defend our legal interests, protect the platform against bot-driven abuse, and ensure cryptographic platform integrity.

5. Third-Party Service Providers & Data Processors

Tovelu partners only with certified, SOC-2, and GDPR-compliant infrastructure vendors subject to strict Data Processing Agreements (DPAs):

Processor Purpose Compliance Guardrails
Stripe / Dodo Payments Payment gateway & subscription billing PCI-DSS Level 1, Standard Contractual Clauses (SCCs)
Brevo (Sendinblue) Transactional receipt & delivery confirmation ISO 27001, GDPR Art. 28 Compliant DPA
Cloudflare Edge CDN, SSL encryption, and DDoS mitigation SOC 2 Type II, Global Edge Shielding

6. Cross-Border & International Transfers

Because Tovelu serves users across 230+ countries, technical telemetry and billing identifiers may occasionally transit through secure cloud data centers located in the European Union, the United States, or India. Where cross-border data movements occur from the European Economic Area (EEA), United Kingdom, or Switzerland, Tovelu relies exclusively upon European Commission Standard Contractual Clauses (SCCs) and UK International Data Transfer Agreements (IDTA).

7. Data Retention & The Right to Erasure

We retain account billing records for statutory taxation and accounting periods (typically 7 years in accordance with applicable financial reporting laws).

Right to Immediate Deletion: You possess the unconditional right to delete your health profile at any time. Tapping "Reset Local Data" inside your device settings will permanently eradicate all local biometric history, food logs, and cache. To delete cloud account records or unsubscribe, email legal@tovelu.store.

8. Notice to California Residents (CCPA / CPRA)

Under the California Consumer Privacy Act ("CCPA") and California Privacy Rights Act ("CPRA"), California residents hold specific legal rights:

  • Right to Know & Access: The right to request disclosure of categories of personal information collected.
  • Right to Delete: The right to request deletion of personal information.
  • Right to Non-Discrimination: Tovelu does not discriminate against any user exercising statutory privacy protections.
  • "Do Not Sell or Share My Personal Information": Tovelu does NOT sell or share personal or health information with third parties for cross-context behavioral advertising.

9. Cryptographic & Security Safeguards

Tovelu enforces end-to-end Transport Layer Security (TLS 1.3) across all network exchanges. Internal systems follow strict access controls, principle of least privilege (PoLP), and automated vulnerability auditing. While no transmission channel is invulnerable, Tovelu implements state-of-the-art administrative, physical, and technical safeguards.

10. Children’s Online Privacy Protection (COPPA / GDPR)

Tovelu is engineered strictly for adults aged 18 and older. We do not knowingly solicit, collect, or process information from individuals under 18 years of age. If we become aware that an account has been established by a minor without verifiable parental consent, all corresponding records are terminated forthwith.

11. Grievance Officer & Official Regulatory Inquiries

Pursuant to the Information Technology Act 2000, India DPDP Act 2023, and GDPR statutory appointment requirements, Tovelu maintains a designated Data Protection & Grievance Redressal Officer:

Corporate Entity: Tovelu Health Technologies Private Limited

Designation: Data Protection & Grievance Redressal Officer

Official Legal Inquiries: legal@tovelu.store

General Support & Member Inquiries: contact@tovelu.store

Response SLA: Inquiries are acknowledged within 24–48 hours and resolved pursuant to statutory timelines.

© 2026 Tovelu Health Technologies Private Limited. All rights reserved.