Global Privacy Policy
Effective Date: September 22, 2026 • Last Reviewed: Q3 2026 • Operating Entity: Tovelu Health Technologies Private Limited
🔒 Tovelu Core Privacy Commitments (At a Glance)
- ✓ Local-First Architecture: Your daily meals, biometric inputs, and habit trackers reside directly inside your browser storage (IndexedDB/LocalStorage).
- ✓ Zero Data Brokering: We never sell, rent, monetize, or disclose your biological data, diet history, or health goals to insurance providers or advertisers.
- ✓ GDPR Art. 9 Explicit Consent: Special Category Health Data is processed strictly upon your direct invocation and consent.
- ✓ Instant Right to be Forgotten: One click in Settings wipes all local states, cookies, and tokens immediately from your hardware.
1. Introduction & Corporate Scope
This Global Privacy Policy ("Privacy Policy") governs the collection, processing, retention, transfer, and deletion of personal and sensitive physiological information through the software applications, web portals, APIs, and digital services operated by Tovelu Health Technologies Private Limited (together with our affiliates, successors, and assigns, "Tovelu", "we", "us", or "our").
Tovelu is engineered as a privacy-protective, local-first metabolic operating system. Our services are accessible across more than 230 sovereign territories and jurisdictions worldwide. This Policy is structured in strict conformance with leading global privacy and statutory benchmarks, including:
- European Union & European Economic Area: General Data Protection Regulation (EU) 2016/679 ("GDPR"), with specific reference to Article 6 (Lawful Basis) and Article 9 (Special Categories of Data).
- United Kingdom: Data Protection Act 2018 and UK GDPR.
- United States: California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (collectively, "CCPA/CPRA"), the FTC Act Section 5, and state comprehensive privacy statutes (Virginia VCDPA, Colorado CPA, Texas TDPSA, etc.).
- India: Digital Personal Data Protection Act, 2023 ("DPDP Act") and Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.
- Global Alignments: Canadian PIPEDA, Australian Privacy Act 1988, Singapore PDPA, Brazilian LGPD, and Swiss FADP.
2. Local-First Architecture & Data Minimization
In contrast to conventional health tracking cloud platforms that continuously upload granular user meal photos, glucose metrics, and intimate physical routines to remote centralized databases, Tovelu employs a Local-First Privacy Architecture:
Device-Side State: Your meal entries, daily macro rings, water tallies, step logs, sleep intervals, and custom pantry grocery selections are stored client-side in your device’s HTML5 LocalStorage and IndexedDB partitions.
Camera & Plate Scanner Privacy: When you utilize our 1-Snap Sequencing Plate Scanner, image frames processed through HTML5 getUserMedia and canvas operations are evaluated locally in memory. We do not archive or index personal photographic reels of your dining table or kitchen on our remote infrastructure.
3. Categories of Information We Process
A. Information You Voluntarily Provide
Account & Subscription Data: Full name, primary email address, authentication credentials, and transactional identifier issued by our PCI-DSS Level 1 payment processors (e.g. Stripe, Dodo Payments, Brevo). We never store raw payment card numbers or CVV codes on our servers.
Metabolic & Lifestyle Assessment Data: Self-reported biological baseline metrics (approximate age, biological sex, current weight, target weight, activity tier, sleep patterns, dietary preferences, and metabolic challenges such as insulin resistance or dyslipidemia).
B. Technical & Telemetry Information
Basic anonymized operational telemetry (browser type, operating system version, screen resolution, localized time zone, and application crash reports) strictly necessary to ensure runtime stability and service worker asset caching.
4. Lawful Basis for Processing (GDPR & Global Standards)
We process your personal and health information under the following legal frameworks:
- Performance of Contract (Art. 6(1)(b) GDPR): To generate your personalized 90-day metabolic roadmap, calculate daily macro quotas, and facilitate uninterrupted application access.
- Explicit Consent (Art. 9(2)(a) GDPR & India DPDP Act): By voluntarily completing the Tovelu clinical survey and configuring health goals, you explicitly consent to the algorithmic calculation of food sequencing order and nutritional pacing. You maintain the absolute right to revoke consent at any moment by purging your local session.
- Legitimate Interests (Art. 6(1)(f) GDPR): To defend our legal interests, protect the platform against bot-driven abuse, and ensure cryptographic platform integrity.
5. Third-Party Service Providers & Data Processors
Tovelu partners only with certified, SOC-2, and GDPR-compliant infrastructure vendors subject to strict Data Processing Agreements (DPAs):
| Processor | Purpose | Compliance Guardrails |
|---|---|---|
| Stripe / Dodo Payments | Payment gateway & subscription billing | PCI-DSS Level 1, Standard Contractual Clauses (SCCs) |
| Brevo (Sendinblue) | Transactional receipt & delivery confirmation | ISO 27001, GDPR Art. 28 Compliant DPA |
| Cloudflare | Edge CDN, SSL encryption, and DDoS mitigation | SOC 2 Type II, Global Edge Shielding |
6. Cross-Border & International Transfers
Because Tovelu serves users across 230+ countries, technical telemetry and billing identifiers may occasionally transit through secure cloud data centers located in the European Union, the United States, or India. Where cross-border data movements occur from the European Economic Area (EEA), United Kingdom, or Switzerland, Tovelu relies exclusively upon European Commission Standard Contractual Clauses (SCCs) and UK International Data Transfer Agreements (IDTA).
7. Data Retention & The Right to Erasure
We retain account billing records for statutory taxation and accounting periods (typically 7 years in accordance with applicable financial reporting laws).
Right to Immediate Deletion: You possess the unconditional right to delete your health profile at any time. Tapping "Reset Local Data" inside your device settings will permanently eradicate all local biometric history, food logs, and cache. To delete cloud account records or unsubscribe, email legal@tovelu.store.
8. Notice to California Residents (CCPA / CPRA)
Under the California Consumer Privacy Act ("CCPA") and California Privacy Rights Act ("CPRA"), California residents hold specific legal rights:
- Right to Know & Access: The right to request disclosure of categories of personal information collected.
- Right to Delete: The right to request deletion of personal information.
- Right to Non-Discrimination: Tovelu does not discriminate against any user exercising statutory privacy protections.
- "Do Not Sell or Share My Personal Information": Tovelu does NOT sell or share personal or health information with third parties for cross-context behavioral advertising.
9. Cryptographic & Security Safeguards
Tovelu enforces end-to-end Transport Layer Security (TLS 1.3) across all network exchanges. Internal systems follow strict access controls, principle of least privilege (PoLP), and automated vulnerability auditing. While no transmission channel is invulnerable, Tovelu implements state-of-the-art administrative, physical, and technical safeguards.
10. Children’s Online Privacy Protection (COPPA / GDPR)
Tovelu is engineered strictly for adults aged 18 and older. We do not knowingly solicit, collect, or process information from individuals under 18 years of age. If we become aware that an account has been established by a minor without verifiable parental consent, all corresponding records are terminated forthwith.
11. Grievance Officer & Official Regulatory Inquiries
Pursuant to the Information Technology Act 2000, India DPDP Act 2023, and GDPR statutory appointment requirements, Tovelu maintains a designated Data Protection & Grievance Redressal Officer:
Corporate Entity: Tovelu Health Technologies Private Limited
Designation: Data Protection & Grievance Redressal Officer
Official Legal Inquiries: legal@tovelu.store
General Support & Member Inquiries: contact@tovelu.store
Response SLA: Inquiries are acknowledged within 24–48 hours and resolved pursuant to statutory timelines.