Legal
Privacy Policy
Last Updated: 15/09/2026
Effective Date: 18 August 2025
Entity: Blood Warriors Foundation (“Blood Warriors,” “we,” “us,” “our”)
Scope: This Privacy Policy applies to our websites, mobile apps, WhatsApp/other chat interfaces, AI chatbot(s), communications, and any services or features we offer (collectively, the “Platform”).
We do not treat browsing alone as consent to this Privacy Policy. We ask you to accept our Terms and Privacy Policy before sign-in, registration, or other personal data collection.
1) Key Principles We Follow
- Transparency: We explain what we collect, why we collect it, how we use it, and your choices.
- Purpose Limitation: We only use data for clear, legitimate purposes described here.
- Data Minimization: We collect the minimum information needed to operate and improve the Platform.
- Security: We apply reasonable safeguards appropriate to the nature of data.
- User Control: We provide options to access, update, delete, and control certain uses (e.g., leaderboards).
2) What We Collect
We collect information in three main ways: (A) you provide it, (B) it’s generated through your use of the Platform, (C) it is submitted for public amplification (emergency requests).
A. Information You Provide
- Account & Profile Data: Name, mobile number, email, location, date of birth/age, and other contact details.
- Health & Donation/Transfusion Data (Sensitive): Blood group/type, donation history and eligibility intervals, transfusion schedules/history, test results (including HPLC), notes required to safely coordinate donations and transfusions.
- Minor Patients (via Guardian): If a patient is under 18, a parent/legal guardian provides their own contact details to operate the account on the minor’s behalf.
- Nonprofit toolkit inputs: If you use free nonprofit tools (for example the organizational capacity check-in), we store your responses, organisation details, generated reports, invite responses, and related metadata so you can save progress and access results over time.
- Consent & Preference Records: e.g., your consent for leaderboard visibility; communication preferences; any opt-outs.
- Emergency Request Submissions: Content, attachments, names, contact numbers, medical needs, location, and any other details you submit for public amplification.
B. Information Generated Through Use
- AI Chatbot Conversations: Content of your chats, intents, fallbacks, session metadata (timestamps, language, approximate geolocation if shared by you), and interaction outcomes (e.g., whether a suggestion was useful). We store and analyze these to diagnose misunderstandings, fix “fallback loops,” improve accuracy, and enhance user experience across the Platform.
- Device/Technical Data: IP address, device and browser type, OS version, app version, log files, diagnostic crash data, and cookie/SDK signals required for security, performance, and core functionality.
- Usage & Interaction Analytics (First-Party): Pages/screens viewed, clicks, features used, and time spent. We collect these only after you accept optional analytics cookies in the banner, or when you use features that record share funnel events with the same consent.
C. Public Amplification Inputs (Emergency Requests)
When you ask us to amplify an emergency blood request, you submit information that we store and then publish publicly (e.g., social media, our website, or community channels) purely to increase outreach and speed.
3) What We Do Not Collect or Use
- We do not record government ID numbers unless you voluntarily share them; if you do, we may redact or delete them.
- We do not enable third-party advertising cookies or sell, rent, or trade your personal information.
- We do not ingest third-party data broker lists.
4) How We Use Information
We use information strictly for:
- Core Operations: Matching donors and patients; planning/scheduling donations; coordinating with patients/guardians; sending confirmations, reminders, and updates.
- Safety & Eligibility Coordination: Managing donation intervals and suitability based on information you provide.
- AI Chatbot & Platform Improvement: Debugging and improving conversation flows, reducing fallback loops, and making the Platform more helpful.
- Communications: Service notices, operational alerts, and relevant updates (email/SMS/WhatsApp/in-app).
- Impact Measurement (Aggregated/De-identified): We may produce anonymous statistics (e.g., number of donors, number of bridges) without identifying individuals.
- Security & Abuse Prevention: Fraud prevention, rate limiting, and incident diagnostics.
- Compliance with Requests Properly Addressed to Us: Such as responding to valid safety or emergency disclosure requests per our internal process.
5) Our Sharing & Disclosure Position (Very Limited)
We do not share user personal data with anyone else for their own purposes. Specifically:
- No commercial sharing.
- No third-party advertising.
- No sale of data.
The only types of disclosure we make are:
- Emergency Public Amplification (You Ask Us To): We publish the emergency request content you submit (which may include personal information) to maximize outreach. Once public, others may further share it beyond our control; responsibility for content and permissions remains with the submitter.
- Leaderboards (Optional Name Display): We may display donor names only for recognition on leaderboards; you can opt out anytime on your profile.
- At Your Direction: If you explicitly ask us to share or forward information (e.g., connecting you to a specific donor/patient).
- To Protect Rights or Safety / Legitimate Requests: If we reasonably believe it’s necessary to prevent harm or respond to properly scoped, good-faith requests (e.g., substantiated safety emergencies), following our internal review process.
- Service Providers Acting for Us: The hosting, messaging, payment, email, analytics, and AI providers listed under “Service providers and processors” below. They process your data on our instructions to deliver the Platform — never for their own purposes.
Other than the above, we do not disclose personal data. We do not sell, rent, or trade it, and we do not share it with anyone for their own purposes.
6) Your Choices & Controls
- Profile & Account: View, correct, or delete profile information from your account settings or by contacting us.
- Leaderboard Opt-Out: Toggle off your name display on leaderboards at any time.
- Emergency Posts: You may request correction or takedown of emergency posts you submitted; we will action reasonable requests on a going-forward basis (note: we cannot control prior third-party reshares).
- Communications: Opt out of non-essential messages while continuing to receive essential service communications.
- Chat History & AI Improvement: You may request deletion of specific chat threads; you may also ask us to exclude your conversations from future model improvements where feasible (some usage may remain for safety or diagnostics).
7) Children & Minor Patients
- The Platform is intended for adults (18+) except where a parent or legal guardian uses it on behalf of a minor patient.
- We rely on your representation that you are (i) at least 18, or (ii) a parent/legal guardian acting for a minor patient. We do not independently verify ages or moderate this.
- If we learn that an account was created by a non-adult without a guardian, we may disable or restrict the account and request a guardian to manage it.
8) Cookies & Local Storage
We use first-party cookies/local storage and similar technologies for:
- Security and session continuity;
- Language/UX preferences;
- First-party analytics to improve functionality.
- We do not use third-party advertising cookies and we do not track you across other sites for advertising.
- If — and only if — you accept analytics cookies in our banner, we load Google Analytics, a third-party analytics service, which sets its own cookies. Decline, and it is never loaded. You can change your choice at any time; declining analytics does not limit any feature.
- You can also manage cookies via your browser or app settings; disabling essential cookies may limit sign-in and security functionality.
9) Data Retention
- Account & Core Records: Retained while your account is active; if you delete your account, we generally delete or de-identify within a reasonable period, subject to limited operational or safety needs (e.g., preventing duplicate abuse).
- AI Chatbot Logs: Retained for improvement and diagnostics; we target a practical retention window (e.g., up to 60 months) and may keep anonymized aggregates longer.
- Emergency Requests (Public): Kept as posted; upon your takedown request, we’ll remove/mark private on our channels going forward (cannot control external reshares).
- Backups/Archives: Time-limited, rolling backups for disaster recovery.
10) User-Generated Content & Public Areas
Content you post or submit for public sharing (e.g., emergency requests; leaderboard recognition) becomes visible to others and may be reshared or archived by third parties beyond our control. You are solely responsible for such content and for obtaining any permissions required to publish it.
11) International Access
Users may access the Platform from different places. Your information may be stored in infrastructure we manage for the Platform. By using the Platform, you consent to this storage and processing location arrangement.
12) Third-Party Links
Our channels may link to third-party sites or embeds. We are not responsible for their practices; please review their policies before engaging.
13) Contact Us
For privacy questions, access/deletion requests, or leaderboard/emergency takedowns, contact us via the Contact Us page on bloodwarriors.in
14) Changes to This Policy
We may update this Privacy Policy from time to time. If changes are material, we will provide a prominent notice on the Platform or by email before they take effect. Your continued use after the effective date constitutes acceptance.
Leaderboard and communication preferences
If you opt in to our public donor leaderboard, we display a masked version of your name, your donation count as recorded in our systems, and a broad location (for example area or state from your profile or pincode). We do not display your full name, phone number, or email on the leaderboard.
We store the fact that you agreed to leaderboard visibility, the time of consent, and the policy version that applied. You can withdraw consent when profile controls are available, or by contacting us.
Future profile tools will let you manage WhatsApp outreach, email, leaderboard inclusion, and related donation visibility separately. This policy will be updated when those features go live.
Data protection notice (India)
Effective addendum: June 2026
Blood Warriors Foundation acts as a data fiduciary for personal data collected through this portal. We process data for blood donation coordination, patient support, communications you opt into, and platform security.
Your rights
- Access and download your data from My profile when signed in
- Correct profile details in My profile
- Request erasure via My profile or by emailing our tech team
- Withdraw consent for optional uses such as public leaderboard display and program outreach messages
- Raise a privacy grievance with our Grievance Officer, Sandeep Kavety, by emailing tech@bloodwarriors.in
Consent
We ask for affirmative consent before sign-in and when policies change. Program outreach and public leaderboard name display require separate opt-in choices in your profile.
Processors and cross-border processing
We use service providers for hosting, messaging, payments, and AI-assisted features. Some processing may occur outside India under contractual safeguards. See product disclosures for chat and analytics choices.
Retention
Chat operational logs are retained for operations and support and are then deleted automatically — see the retention schedule below for each category. Financial receipt files follow a short retention window. Account deletion anonymizes your profile while retaining de-identified donation facts where required for safety.
Grievance Officer
Our Grievance Officer is Sandeep Kavety, Blood Warriors Foundation. For privacy requests or complaints, contact tech@bloodwarriors.in or visit /grievance.
Service providers and processors
We use trusted third parties to operate Blood Warriors programs. Most of them act only on our instructions, under contract, for the purposes described in this policy. Where a provider decides for itself how it uses the data, we say so in the list below. We do not sell personal data.
- Supabase: database, authentication, and file storage
- Amazon Web Services: application hosting, file storage, scheduled jobs, and hosting of the AI models described below (Amazon Bedrock)
- AI model providers: Anthropic (through Amazon Bedrock and directly), OpenAI, and Google. These receive your message content and the context needed to answer you. OpenAI also converts voice notes to text and text to speech when you send or request audio.
- Meta: WhatsApp Business Platform for programme messaging and the chatbot; Instagram where we publish emergency amplifications you have asked us to share
- SMS OTP providers (through Supabase Auth): mobile number verification
- Razorpay: donations and payment processing
- Resend: transactional email delivery
- Google Analytics (optional, only after you accept analytics cookies): website usage analytics
- Microsoft Clarity (optional, only after you accept analytics cookies): records how pages are used - clicks, scrolling and pointer movement - so we can find what is broken or confusing. The text and images on the page are hidden on your device before anything is sent, so what we receive shows the shape of the page and how it was used, not its contents. Anything you type is never sent. Microsoft keeps most recordings for 30 days, and keeps a randomly selected sample of recordings, and any recording we mark as a favourite, for up to 9 months. Summary statistics are kept for 9 months. Microsoft stores this in its Azure cloud and does not offer a choice of storage region for this service. Unlike our other providers, Microsoft decides for itself how it uses Clarity data, under its own terms rather than our instructions. Microsoft tells us it may use that data to improve its products and services, to create user profiles for purposes that include advertising, and — for data that does not identify a person — to train and evaluate machine learning models. Microsoft also collects or receives personal data from us to provide Microsoft Advertising. What Microsoft does with it is described in the Microsoft Privacy Statement: https://privacy.microsoft.com/en-us/privacystatement. If you would rather none of this happened, decline analytics cookies and Clarity is never loaded.
- Google Maps: map display and location lookup
- Upstash: rate limiting and abuse prevention
- Zoho People: staff attendance records only. It does not receive donor, patient, or volunteer data.
Where processing happens
Our primary database and application infrastructure are hosted in India. Some processing happens outside India: our AI model providers operate globally, and the model service we use routes a request to the region best able to serve it, so we cannot name a single fixed country for AI processing. Payment, messaging, email, and analytics providers may also process data outside India. Website session-replay data (Microsoft Clarity) is stored in Microsoft's Azure cloud; Microsoft does not offer a choice of storage region for this service and does not tell us which country it is held in. In every other case the provider acts under contract and only for the purposes above.
Data retention schedule
These windows are enforced by an automated daily job, not by hand. Where a window is configurable we state the value in force.
- Account profile: while your account is active; anonymized when you ask us to delete it
- Donation and bridge operational records: retained in de-identified form where needed for patient safety and audit
- WhatsApp and chatbot message content: 730 days
- Conversation insights (summaries drawn from your chats): 365 days
- Assistant memory about you: 540 days
- Your consolidated assistant profile: 730 days
- Raw inbound message queue: 14 days after the message is handled
- Message, email, and delivery logs (who we contacted and whether it arrived): 365 days
- AI usage records: we keep the size and cost of each request. We do not store the content of your prompts or the assistant’s replies in these records at all.
- Financial receipt PDFs: removed after about 15 days
- Auth verification audit events: up to 365 days for security investigations
- First-party share funnel analytics: up to 90 days, and only when you have granted analytics consent
- Consent and legal acceptance records: retained to demonstrate compliance, and not auto-deleted — they are the evidence of what you agreed to and when
Security measures
We protect personal data using HTTPS encryption in transit, role-based access controls, row-level security in our database, authenticated admin tools, hashed identifiers in security logs, and infrastructure encryption at rest provided by our cloud host. We do not use Aadhaar or PAN collection in public registration flows.
AI assistant (Veeru) and automated processing
Effective addendum: September 2026
What Veeru is
Veeru is an AI assistant that helps you on WhatsApp and in the portal with blood donation, Blood Bridge coordination, and Thalassemia care. Your conversation is handled by automated systems, not always by a person. You can ask for a human at any time, and we route you to one automatically for emergencies and anything we judge to be sensitive.
What we process
The messages you send us — including any photographs, images and PDF documents you attach; your name and mobile number; and, where it is relevant to helping you, your blood group, donation and transfusion history, Blood Bridge membership, eligibility, and the concerns you raise with us.
Where you send a photograph or a document, we also read what is in it. A picture of a lab report, a prescription, a hospital blood requisition or a donation record is converted to text so that Veeru can act on it — for example, to treat a photographed blood requirement as a request for blood, or to offer to record a haemoglobin or ferritin value. That extracted text is kept with your conversation. We ask the system not to copy identification numbers out of your documents (for example Aadhaar, PAN, insurance or hospital ID numbers), and to record the clinical details only.
The file itself is stored encrypted, so that a value recorded from a report can be checked against the report. It is never published, never given a public link, and is available only to the Blood Warriors team member helping you.
AI service providers
To understand your messages and generate replies we send your message content, and the context needed to help you, to the AI providers named under “Service providers and processors”. They process it to provide this service to us, under contract. We do not sell your data.
Photographs and documents you send are transmitted to those providers as well — as the image or the file itself, not only as words — so that their contents can be read.
Memory and profiling
So that you do not have to repeat yourself, Veeru keeps a short summary of what matters about you — for example your blood group, your bridge, and what you last asked about. This is a profile built by automated means. You can ask us what it holds (it is included in your data download), ask us to correct it, or ask us to delete it. If you opt out of AI profiling, we stop building it and delete what exists; Veeru still answers you, with less context.
Automated decisions
Veeru does not make final decisions about you on its own. It drafts and suggests; a person confirms anything consequential. Donor and bridge prioritisation is driven by operational need — transfusion timing, coverage risk, past reliability — and never by caste, religion, gender, or any other protected characteristic.
Photographs and documents
Reading a document automatically is not the same as a person checking it. Veeru can misread a handwritten or blurred report, and it does not interpret results clinically. Anything it reads back to you is there for you to confirm, and any value it offers to record is confirmed with you before it is saved. If a document matters medically, please also confirm it with your doctor, hospital or blood bank. You can ask us to delete a photograph or document you have sent, and what was read from it, using the contacts below.
We do not read every attachment automatically: where a very large number arrive from one number in a day, we save them and a person reviews them instead.
Accuracy
AI replies can be wrong or incomplete. Veeru does not give medical advice. Always confirm clinical questions with your doctor, hospital, or blood bank.
Your choices
- Reply STOP on WhatsApp to opt out of programme outreach and AI profiling
- Ask for a human at any point in a conversation
- Request, correct, or delete what Veeru holds about you through My profile or tech@bloodwarriors.in
Privacy grievance contact
For privacy requests — access, correction, erasure, withdrawing consent — or a complaint under applicable Indian data protection law, contact us at tech@bloodwarriors.in or visit /grievance.
How long we take
We acknowledge a request within 3 working days and complete it within 30 days of verifying your identity. If a request is complex and we need longer, we will tell you before the 30 days are up, and why.
We ask you to verify your identity before we act on a request about personal data — usually by confirming control of the mobile number on the account — so that nobody else can obtain, change, or delete your records.