Privacy by design

Privacy Policy

MioSync is built on a simple promise: your wellbeing data belongs to you. This policy explains what we collect, how we protect it, and the choices you control.

Last updated: June 16, 2026

End-to-end encryption
Offline-first storage
No third-party trackers
Consent-based sharing

1. Information We Collect

We collect only what is necessary to provide the service. You are never required to share health data you are uncomfortable providing.

1.1 Account Information

  • Name and email address — used for account creation, authentication, and essential service communications.
  • Profile picture — optional; sourced from Google Sign-In if you choose to connect it.
  • Authentication identifiers — securely issued tokens that keep you signed in without storing passwords on our servers.

1.2 Wellness Data You Log

This is the core of MioSync and is stored with the highest protection:

  • Nutrition logs — meals, calorie estimates, and macro breakdowns.
  • Hydration logs — water intake amounts, timestamps, and trends.
  • Scan history — barcodes scanned and the resulting safety verdicts. Label photos are discarded immediately after transcription and are never stored.
  • Care logs — medications, supplements and routines, with taken/skipped status and adherence history.
  • Chat history with MioSync AI — your conversations with the AI buddy, stored so it can remember context and reference past discussions.

1.3 Optional Health Profile Data

You may choose to provide additional context to improve personalization:

  • Age, weight, height, and gender.
  • Dietary preferences, allergies, and conditions.
  • Wellness goals (e.g., daily water target, mindfulness minutes).

None of this is required. You can use MioSync fully without providing any of it.

1.4 Device & Technical Data

  • App version and OS version — for compatibility and bug fixes.
  • Crash logs and diagnostics — only when you opt in to share them.
  • Notification preferences — stored locally and synced with your account.
What we do NOT collect: We do not access your phone contacts, SMS messages, emails, browsing history, location (unless you explicitly enable location-tagged logs), or any data from other apps. We do not use cookies or tracking pixels for advertising.

2. How We Use Your Data

Every use of your data serves a specific, disclosed purpose. We do not use your wellness data for advertising or unrelated product development.

  • To provide the service — displaying your logs, calculating trends, generating insights, and powering MioSync AI's memory and context awareness.
  • To personalize AI interactions — MioSync AI uses your recent hydration, meals, care logs and chat history to offer relevant, empathetic responses. This processing happens securely; we do not train general AI models on your individual data.
  • To sync across devices — so your data is available when you sign in on a new phone or after reinstalling.
  • To send reminders — only the reminders you explicitly enable (e.g., hydration nudges, medication dose reminders).
  • To improve reliability — aggregated, anonymized metrics help us fix bugs and optimize performance. These metrics cannot identify you.

3. Offline-First Storage

MioSync is built with an offline-first architecture. This means your data lives on your device first, and syncs to the cloud when a connection is available.

3.1 Local Storage

All wellness data you log is stored locally on your Android device using encrypted local databases. You can view, edit, and analyze your data entirely without an internet connection. Your local data is protected by Android's app sandbox and, where supported, device-level encryption.

3.2 Cloud Sync

When you are online, your local data syncs to our secure cloud infrastructure. Sync is:

  • Encrypted in transit using TLS 1.3.
  • Encrypted at rest using AES-256.
  • Differential — only changes since the last sync are transmitted, minimizing data exposure.
  • Resilient — if a sync is interrupted, it resumes cleanly without data corruption.

3.3 What Syncs vs. What Stays Local

Synced to cloud
  • Nutrition, hydration and care logs
  • Chat history with MioSync AI
  • Profile, allergies & goals
  • Scan history and safety verdicts
Stays on device only
  • Notification timing preferences
  • UI theme & display settings
  • Cached AI responses (temporary)
  • Crash logs (until opted-in upload)

3.4 Network Independence

You are never locked out of your own data. Even if our servers become temporarily unavailable, you retain full read/write access to everything on your device. When connectivity returns, sync catches up automatically.

4. AI Processing & MioSync AI

MioSync AI processes your messages to generate empathetic, context-aware responses.

4.1 How MioSync AI Uses Your Data

  • Context window — recent chat history and wellness logs are included in the prompt so MioSync AI can reference your day and past conversations.
  • System prompt — includes today's hydration level, recent meals and care state to ground responses in your actual day.
  • Memory summaries — rolling summaries of conversations are stored so MioSync AI can recall topics from days or weeks ago.

4.2 AI Model Providers

MioSync AI's responses are generated using third-party AI services (e.g., Google AI). When you send a message:

  • Your message and the relevant context are transmitted securely to the AI provider.
  • Providers process the data only to generate a response and do not retain it for model training unless they have separate consent mechanisms, which we do not authorize on your behalf.
  • We select providers with strong data protection commitments and evaluate them regularly.

4.3 AI Is Not a Substitute for Professional Care

MioSync AI is a wellness companion, not a doctor, dietitian or pharmacist. It cannot diagnose conditions, prescribe treatment, or replace human professionals. AI nutrition figures are estimates, and AI never issues food-safety verdicts — those come from deterministic rules.

5. Data Sharing & Third Parties

We do not sell, rent, or trade your personal data. We share data only with the following categories of service providers, and only what is necessary for them to perform their function:

  • Cloud infrastructure (e.g., Supabase) — for encrypted database storage, authentication, and sync.
  • AI inference providers (e.g., Google AI) — for generating MioSync AI's responses. See Section 4.
  • Push notification services — to deliver reminders you opt into. They receive device tokens, not wellness content.
  • Analytics (optional) — if you opt in, anonymized usage metrics help us improve the app. These contain no wellness data.

All providers are contractually bound to use your data only for the purposes we specify and to maintain security standards comparable to our own.

6. Google Sign-In

You can sign in to MioSync using your Google account. When you do:

  • We request only your basic profile: name, email address, and profile picture.
  • We do not request access to Gmail, Google Drive, Google Calendar, Contacts, or any other Google service.
  • Your Google credentials are never stored on our servers. Authentication is handled via secure OAuth 2.0 tokens.
  • You can disconnect Google Sign-In at any time from Settings. Your account will remain accessible via email/password if you set one up.

7. Data Retention & Deletion

7.1 Retention

  • Active accounts: Your data is retained for as long as your account remains active, so you can build long-term nutrition and adherence insights.
  • Inactive accounts: After 24 months of inactivity, we may send you a notification offering data export or deletion. If you do not respond, we schedule automatic deletion after an additional 6 months.
  • Label photos: Discarded immediately after transcription; they are never written to storage.

7.2 Your Right to Deletion

You can delete your account and all associated data at any time:

  • Self-service deletion — available in Settings > Account > Delete Account. This is permanent and irreversible.
  • Email request — send a deletion request to support@miosync.live from your registered email. We process verified requests within 30 days.

Deletion removes your data from live systems and backups within 90 days. We may retain minimal transaction records if required by law (e.g., tax or fraud regulations), but these will not contain wellness content.

8. Security

We protect your data using a layered security model:

  • Encryption in transit: All data transmitted between the app and our servers uses TLS 1.3.
  • Encryption at rest: Cloud databases use AES-256 encryption. Local device storage uses Android's encrypted shared preferences and SQLCipher where available.
  • Row-level security (RLS): Database policies ensure you can only access your own data.
  • Authentication: OAuth 2.0 and JWT tokens with automatic expiry and refresh rotation.
  • Regular audits: We review access logs and infrastructure configurations for anomalies.

No system is perfectly secure, but we are committed to rapid response. If we become aware of a breach that affects your data, we will notify you within 72 hours and take immediate remedial action.

9. Children

MioSync is intended for adults aged 18 and over. In line with India's Digital Personal Data Protection Act, we do not knowingly collect personal data from anyone under 18. If you believe we have inadvertently collected data from a minor, please contact us immediately at support@miosync.live and we will delete the information promptly.

10. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

  • Access — request a copy of the data we hold about you.
  • Correction — update inaccurate or incomplete data.
  • Deletion — erase your data (see Section 7).
  • Portability — export your data in a machine-readable format from Settings.
  • Restriction — limit how we process your data in specific circumstances.
  • Objection — object to certain types of processing (e.g., optional analytics).
  • Withdrawal of consent — where processing is based on consent, you may withdraw it at any time.

To exercise any of these rights, email us at support@miosync.live. We will respond within 30 days and verify your identity before acting on the request.

11. International Data Transfers

Our infrastructure providers may process data in regions outside your country of residence. When this occurs, we rely on standard contractual clauses and adequacy decisions to ensure your data receives protection equivalent to that in your home jurisdiction.

12. Changes to This Policy

We may update this Privacy Policy as the app evolves. Material changes will be communicated via:

  • An in-app notification when you next open MioSync.
  • An email to your registered address if the change is substantial.

Continued use of the app after the effective date of an update constitutes acceptance of the revised policy. If you do not agree, you may delete your account.

13. Contact

If you have questions, concerns, or requests about this Privacy Policy or how we handle your data, please reach out:

MioSync Privacy Team
Response time: within 48 hours for urgent matters, 7 days for general inquiries.