About this draft
This draft describes the Android app Dialysis Saathi V0.13.3 and this website. This draft was updated on 14 September 2026. The app is being developed independently by Vikas Tiwari, based in New Zealand. The legal publisher for public release is still being confirmed.
Privacy questions: dialysissaathi.support@gmail.com. This is a review draft, not a declaration of regulatory certification or store approval.
Information the app handles
| Information | Purpose |
|---|---|
| Patient profile, dialysis sessions, entered vitals, medicine details, schedules, appointments and lab results | Maintain the records, history, trends and reminders you use. |
| Medical PDFs, images and document details you import | Keep and retrieve your medical documents. |
| Google account identity and authorisation information, if you connect Drive | Identify your selected account and authorise the optional backup and sync functions. |
| App settings, reminder settings and security configuration | Operate local reminders and device-specific app access protection. |
| Support emails you choose to send | Respond to your question or investigate a reported problem. |
Core record keeping does not require a Dialysis Saathi account or a Google account. You choose what records to enter or import. If you maintain another person’s information, make sure you have the appropriate permission or authority.
Storage and protection
Your device holds the working records database in Android app-private storage. The database is not separately encrypted by the app. Imported medical-document file contents use AES-256-GCM application-layer encryption.
Portable backups are encrypted using a passphrase you choose. Sync encrypts record and document content before sending it to Google Drive. Device PIN and optional biometric app access are separate from backup protection. The app uses the device’s biometric authentication mechanism; it does not receive your fingerprint or face template.
Protect your device and backup passphrases. Encryption does not protect information that you deliberately export in a readable report or disclose to another person.
Optional Google Drive services
When you choose Drive backup or sync, Google processes account authentication and stores app files in your selected account. The app requests the drive.file permission to work with files it creates or that you explicitly grant it access to, rather than unrestricted access to your entire Drive.
Backups are stored in the “Dialysis Saathi Backups” folder; sync files are stored in “Dialysis Saathi Sync”. Encrypted content is accompanied by file and service metadata needed to operate these features. Encryption does not hide all account, file-size, timing or network metadata from Google.
Current sync is manual and intended for your own devices using the same Google account. Separate family-member Google accounts are not supported by the current release. Signing out or leaving a sync vault does not delete files already stored in Drive.
Google’s services operate under Google’s Privacy Policy. You can review or revoke the app’s connection in your Google Account connections. Revoking access does not itself delete uploaded files.
Keeping and deleting information
Local records remain on your device until you delete them through available app controls or clear the app’s storage. Clearing storage removes local records and local encryption keys. Save any information you need before doing so.
Local removal does not erase exported reports, portable backups, copies on other devices or files already in Google Drive. To remove all copies, stop sync on connected devices and separately remove the relevant backups and sync files in your Drive account, including trash where applicable. Other recipients control copies you have shared with them. Deleting a record does not rewrite older backups.
The developer cannot remotely erase your phone or personal Google Drive. Contact support for help identifying which copies to remove. For emails you sent to support, you can request deletion by contacting the same address.
We retain support emails while your issue is open and for 12 months after resolution. We then delete them unless continued retention is necessary for an ongoing dispute or to meet a legal obligation. This period applies to support correspondence, not records on your device or in your Google Drive.
Pending before public release: website hosting and access-log retention details must still be confirmed.
Device permissions and reminders
The app uses internet access for optional Drive services, system file selection for documents, and device authentication for optional biometric access. Notifications and alarm scheduling support reminders; boot handling allows reminders to be rescheduled after a restart.
Reminder delivery depends on device permissions, notification settings, battery restrictions and device availability. Review permissions in Android Settings. Disabling a permission may prevent the associated feature from working.
This website
This site provides app information, support links and policy drafts. It has no medical-record upload form, newsletter registration, advertising tags or developer-added analytics scripts. Email links open your own email application.
Questions and future changes
For privacy, access, correction or deletion questions about information you have sent to the developer, email dialysissaathi.support@gmail.com. For records kept only on your own device or Drive, use those storage locations and the app’s controls; the developer does not hold a central copy.
This draft will be updated when the public publisher, operational retention rules or data-handling behaviour changes. The final policy will show its effective date and the publisher’s verified details.
Hosting and Infrastructure Services
Our website is hosted using Cloudflare Pages, a service provided by Cloudflare, Inc. ("Cloudflare"). Cloudflare may collect and process limited technical telemetry data, including IP addresses, browser configurations, and access timestamps, solely to optimize delivery speed, ensure platform security, and mitigate malicious traffic or distributed denial-of-service (DDoS) attacks in accordance with their privacy standards.