← Back to home

Privacy Policy

Amara Health Canada (Public Beta) Privacy Policy | v1.2 Amara Health by MetaNova AI · amara@metanovaai.com Amara Health Canada (Public Beta) Privacy Policy Public Beta | Free Service | Last Updated: July 10, 2026 | Version: Beta v1.2 www.amarahealth.tech Data Fiduciary / Operator: MetaNova AI Pvt. Ltd. Registered office: Hno.423, Navodaya Colony, Sagar Society, Banjara Hills, Road No. 2, Hyderabad, Telangana, India - 500034 Contact: MetaNova AI Inc., Toronto, Ontario | support@metanovaai.com | +1 647 530 0595 Plain English summary Amara Health helps users upload, organize, extract, summarize, explain, and track health reports and related health documents during public beta. We use your data only to provide, secure, support, maintain, debug, and legally operate Amara. We do not sell your personal information or health information. We do not use your identifiable health data for advertising, resale, external research, or public/general AI model training unless you give separate explicit written opt-in consent and the use is legally permitted. Amara does not provide medical advice, diagnosis, treatment, prescriptions, emergency support, or clinical decision making. Always verify outputs with original reports and qualified healthcare professionals. 1. Scope and beta notice This Privacy Policy explains how Amara Health collects, uses, stores, protects, shares, transfers, and deletes personal information and health-related information when you use our website, public beta product, applications, dashboards, AI tools, upload tools, family profile features, sharing features, support channels, and related services. We call these the Service in this Policy. Amara Health is operated by MetaNova AI Pvt. Ltd. and its applicable affiliates, representatives, contractors, and service providers. In this Policy, Amara Health, Amara, we, us, and our refer to MetaNova AI Pvt. Ltd. where applicable. The Service is currently a public beta. Beta software may have bugs, interruptions, incomplete features, changing functionality, inaccurate AI outputs, and operational limitations. We are thankful that you are trying Amara during beta. Please send feedback, privacy questions, deletion requests, and safety concerns to amara@metanovaai.com. If Amara enters into a separate business associate agreement, PHIPA service agreement, data processing agreement, hospital pilot agreement, clinic agreement, enterprise agreement, or other written contract, that contract may add or override privacy, security, retention, and processing obligations for that relationship only. 2. Important medical and AI notice Amara Health is not a doctor, clinic, hospital, diagnostic provider, emergency service, pharmacy, insurer, or medical device unless expressly stated in writing after required regulatory clearance or approval. Amara does not diagnose, treat, cure, prevent, or manage any disease or medical condition. Amara does not provide medical advice, clinical advice, treatment recommendations, prescriptions, medication instructions, emergency advice, or decisions that replace a licensed healthcare professional. AI outputs, OCR, extraction, translations, summaries, trends, flags, charts, medicine explanations, and plain-language explanations may be inaccurate, incomplete, outdated, mistranslated, misread, misclassified, or misleading. Lab reference ranges vary by lab, country, age, sex, pregnancy status, clinical condition, and medical context. You must verify all outputs against the original source document and consult a qualified doctor, pharmacist, lab, hospital, clinic, or other licensed healthcare professional before making any medical, medication, treatment, lifestyle, insurance, employment, or health-related decision. Do not use Amara in an emergency. In an emergency, call 911 in the United States or Canada, 112 or 108 in India where available, or your local emergency number immediately. 3. Regional compliance position We are designing and operating Amara with privacy and health-data sensitivity in mind, including Canadian privacy obligations and provider-specific health privacy frameworks where applicable. This does not mean Amara operates under every law, and we do not make unsupported privacy claims. 3.1 India For Canadian users, MetaNova AI Inc. is responsible for the personal data it determines how and why to process under applicable Canadian privacy law. Health data is treated by us as highly sensitive in practice, even where a specific law does not use the term sensitive personal data in the same way as older privacy frameworks. We process personal data for the purposes listed in this Policy, including creating accounts, storing uploaded reports, extracting and organizing data, generating summaries and trends, providing user-selected sharing, securing the Service, supporting users, fixing bugs, improving stability and extraction reliability during beta, and complying with law. 3.2 Canada For Canada, Amara is intended to align with principles under PIPEDA and applicable substantially similar provincial privacy laws where relevant, including consent, limited collection, limited use, safeguards, openness, access, correction, breach handling, and accountability. For Ontario, PHIPA may apply depending on the role Amara plays. In direct-to-consumer use, Amara may not be a health information custodian. If Amara provides services to an Ontario health information custodian, clinic, hospital, physician, or other regulated organization, Amara may act as an agent, electronic service provider, or service provider depending on the final facts and written agreement. In that case, a separate PHIPA-aligned agreement must be signed before production use. Amara is designed against PHIPA safeguards and contracting practices where applicable. The final role and obligations depend on the use case and written agreement. For Quebec residents, we apply the Act respecting the protection of personal information in the private sector as amended by Law 25, including transparency about processing of personal information outside Quebec. Our designated Privacy Officer (responsable de la protection des renseignements personnels) is Sharath Bhavaraju, reachable at amara@metanovaai.com. 3.3 Other jurisdictions This Canadian build is intended for Canadian users and does not make claims about regulatory frameworks outside Canada. For direct-to-consumer health apps in the United States, the FTC Health Breach Notification Rule, consumer protection laws, state privacy laws (such as the California Consumer Privacy Act as amended), and state consumer health data laws (such as the Washington My Health My Data Act, Nevada SB 370, and Connecticut's consumer health data provisions) may apply depending on user location, data flows, business model, size thresholds, and integrations. Amara will assess and comply with applicable notice, consent, and breach notification obligations. Where state consumer health data laws apply: we collect and share consumer health data only with consent or as necessary to provide the Service you request; we do not sell consumer health data and will not do so without the valid written authorization those laws require; and this Policy serves as our Consumer Health Data Privacy Notice. Washington residents may appeal a refusal of a rights request by replying to our decision email, and if the appeal is denied, may contact the Washington Attorney General. Where the California Consumer Privacy Act applies, you have rights to know, access, correct, delete, and opt out of sale or sharing; we do not sell or share personal information for cross-context behavioral advertising, and we honor legally recognized opt-out preference signals where required. We will not discriminate against you for exercising any privacy right. 4. Personal data we collect We collect only the personal data reasonably needed to provide, secure, support, maintain, improve reliability of, and legally operate the Service. Depending on how you use Amara, we may collect the following categories: • Account data: name, phone number, email address, login method, OTP events, authentication metadata, country or region, language preference, account settings, communication preferences, and consent records. • Uploaded health documents: medical reports, lab reports, diagnostic reports, prescriptions, discharge summaries, medication information, images, PDFs, screenshots, camera photos, and related health documents that you choose to upload. • Extracted health information: test names, values, units, reference ranges, report dates, abnormal markers, medicine names, dosage text from uploaded documents, trend data, and structured information derived from your documents. • AI-generated information: summaries, explanations, translations, charts, flags, user questions, AI responses, report comparisons, trend descriptions, and other outputs generated from your data or prompts. • Family and caregiver profile data: information you enter or upload for a child, parent, spouse, dependent, family member, caregiver, or other person whose profile you manage. • Sharing data: share links, invited recipients, access settings, expiry settings, revocation records, access logs, and information about doctors, caregivers, family members, or organizations you choose to share with. • Usage, device, and technical data: IP address, approximate location from IP, device identifiers, browser type, device type, operating system, app events, timestamps, session logs, crash logs, diagnostic logs, performance logs, security logs, and fraud-prevention logs. • Support data: emails, messages, attachments, screenshots, call notes, feedback, bug reports, and other information you send to support or beta feedback channels. • Payment data: if paid features are introduced later, payment status, plan, invoice details, billing contact information, and limited payment identifiers from payment processors. We do not intentionally store full credit card numbers on Amara servers. • Cookies and similar technologies: essential cookies, session storage, authentication tokens, security tools, and limited analytics needed to operate, secure, debug, and improve reliability of the Service. We do not require Aadhaar, PAN, Social Insurance Number, Social Security Number, or other government identity numbers for ordinary public beta use. Do not upload these unless specifically required by a future feature and clearly requested by Amara. 5. Where data comes from • You, when you create an account, upload reports, ask questions, create profiles, configure settings, contact support, or use sharing features. • People you authorize, such as a caregiver, parent, spouse, family member, or invited recipient who interacts with your profile or shared record. • Healthcare providers, clinics, hospitals, or organizations only where you authorize the connection or where a separate written agreement and lawful basis apply. • Service providers, systems, devices, logs, and security tools that help us operate, authenticate, secure, debug, and support the Service. 6. Why we use data We use personal data and health data only for limited and disclosed purposes, including: • Provide the Service: create and maintain accounts, upload and store reports, extract data from documents, organize health records, show summaries, generate trend charts, enable search, enable family profiles, and enable user-controlled sharing. • Generate user-requested AI outputs: answer questions about uploaded reports, explain health parameters in plain language, compare current and prior reports, translate information, and summarize information for user review. • Support users and beta testers: respond to support requests, deletion requests, privacy requests, feedback, bug reports, and safety concerns. • Maintain safety and security: authenticate users, detect unauthorized access, prevent fraud and abuse, protect accounts, investigate suspicious activity, and maintain audit logs. • Improve reliability during beta: fix bugs, troubleshoot crashes, improve uptime, test stability, measure system errors, improve extraction reliability, and improve product quality without using identifiable health data for advertising or resale. • Comply with law and enforce rights: respond to lawful requests, comply with applicable legal obligations, enforce Terms, investigate violations, defend claims, and protect users, Amara, and the public. 7. Consent, authority, and lawful basis By creating an account, clicking consent checkboxes, uploading a report, creating a family profile, or using a feature that requests health information, you provide clear affirmative consent for Amara to process the personal data and health data needed for the purposes described in this Policy. If you upload health documents, you confirm that you have the legal right, consent, guardianship, power of attorney, caregiving authority, or other lawful authority to upload and process that information through Amara. You may withdraw consent by deleting the relevant report, turning off a feature where available, revoking a share link, deleting your account, or emailing amara@metanovaai.com. Withdrawal does not affect processing already completed before withdrawal. Some features may stop working if consent is withdrawn. Where applicable law permits processing without consent for limited purposes, such as security, fraud prevention, legal compliance, dispute handling, or protecting rights and safety, we may rely on those legal grounds only to the extent permitted by law. 8. Family profiles, caregivers, and minors Amara may allow family or caregiver profiles. If you upload data for another person, you are responsible for having valid authority and for using that person's information lawfully and respectfully. Children and minors may not create or use Amara directly unless permitted by applicable law and with verified parent or legal guardian consent. If you create a child profile, you confirm that you are the parent or legal guardian and that you will complete reasonable verification steps, such as OTP verification and a guardian declaration. We may suspend or delete child profiles if authority cannot be reasonably established. We do not knowingly use children's health data for targeted advertising, behavioral advertising, profiling for advertising, or sale. We do not knowingly process children's information in a way that is detrimental to their well-being. 9. What we do not do with your data • We do not sell, rent, broker, or trade your personal information, uploaded health documents, extracted health data, AI questions, AI answers, or family profile health information. • We do not use identifiable health data for advertising, targeted advertising, marketing profiling, resale, or data-broker activity. • We do not use your health information to market third-party products or services to you. • We do not provide your identifiable health data to employers, insurers, pharmaceutical companies, advertisers, data brokers, or external researchers unless you specifically direct us to do so or applicable law requires it. • We do not use identifiable uploaded reports, extracted health data, medicine data, symptoms, AI questions, AI answers, or family profile information to train public or general AI models unless you give separate explicit written opt-in consent and the use is legally permitted. • We do not place third-party advertising pixels or behavioral marketing trackers inside authenticated health-report pages unless a future version obtains any legally required consent and updates this Policy first. 10. AI processing and product improvement Amara may use AI, OCR, language models, extraction tools, translation tools, and related software to process documents and generate outputs requested by users. These tools may be operated by Amara or by trusted service providers acting under contractual restrictions. No identifiable training by default: We do not use identifiable personal data, identifiable health reports, extracted identifiable lab values, medicine information, family profile information, or identifiable AI chats to train public or general AI models unless you provide explicit, separate, optional opt-in consent in the app or in writing and the processing is legally permitted. Anonymized and aggregated improvement: We may use irreversibly anonymized data, aggregated data, error metrics, crash patterns, extraction-quality metrics, and operational analytics that cannot reasonably identify you to improve extraction accuracy, product reliability, safety, and user experience. We will not attempt to re-identify anonymized data. Service providers that process AI requests for Amara must process the data only as necessary to provide services to Amara, unless we disclose otherwise and obtain any required consent. We will work to configure AI vendors so that user health data is not used by the vendor to train public models where such controls are available and contractually supported. 11. Sharing and disclosures We share personal data only in limited circumstances: • With service providers and processors: trusted cloud hosting, storage, authentication, OTP or email delivery, security, monitoring, crash reporting, support tooling, AI infrastructure, analytics for reliability, and payment processing providers, only as needed to operate the Service and under confidentiality and security obligations. • With recipients you choose: doctors, caregivers, family members, clinics, hospitals, or other people or organizations you choose to share with through the Service. You are responsible for selecting recipients and revoking access where appropriate. • With healthcare organizations under separate agreement: if you use Amara through a clinic, hospital, doctor, employer-sponsored benefit, insurer, research program, or other organization, additional terms and privacy notices may apply. We will not use this route for production healthcare workflows without appropriate agreements. • For legal and safety reasons: when required by law, court order, valid government direction, regulator request, legal process, security investigation, fraud prevention, or to protect rights, safety, users, Amara, or the public. • During business changes: in connection with a merger, acquisition, financing, restructuring, transfer of assets, or similar transaction, subject to confidentiality, applicable law, and protection of user data. • With your direction or consent: for any other purpose you specifically request or consent to. We do not treat user feedback as permission to disclose personal health information. If we use beta feedback to improve the product, we will avoid exposing personal health information in public materials or unrelated internal channels. 12. Sharing links and user-directed sharing If you generate or send a share link, invite a recipient, export a summary, download a file, or otherwise share information from Amara, you control that action. Recipients may copy, download, forward, screenshot, or further disclose information after they receive it. Amara cannot fully control what recipients do outside the Service. Use sharing features carefully. Check recipient identity, expiry settings, access settings, and revocation options before sending health information. 13. Cross-border transfers Amara may process and store personal data in India, Canada, the United States, and other countries where we or our service providers operate. Privacy laws in those locations may differ from the laws in your country or province/state. For India users, we will process or transfer personal data outside India only as permitted by applicable Indian law. If the Government of India notifies restrictions on transfers to specific countries or territories, we will comply and adjust transfers where required. For Canada users, personal information may be transferred or accessed outside Canada, including in India or the United States, for processing and support. We use reasonable contractual, technical, and organizational safeguards for cross-border processing. Your information may be subject to lawful access requests in those jurisdictions. For United States users, personal information may be processed in India, Canada, the United States, and other jurisdictions as needed to provide and secure the Service. 14. Security We use reasonable administrative, technical, and organizational safeguards appropriate for a beta health-data product. These may include encryption in transit, encryption at rest where supported, authentication controls, restricted internal access, role-based access, secure cloud infrastructure, monitoring, logging, vendor controls, incident response practices, and security reviews. Only authorized personnel and service providers should access personal data when needed for service operations, support, security, legal compliance, incident response, or debugging. We work to limit internal access to health data. No system is perfectly secure. Beta systems may carry higher operational risk than mature products. We cannot guarantee that unauthorized access, data loss, bugs, outages, or security incidents will never occur. You should keep your own copies of medical records outside Amara. 15. Data retention and deletion You can delete reports and/or your account in-app where the feature is available, or by emailing amara@metanovaai.com. For account safety, we may verify your identity before processing deletion requests. • Deleted reports and account data are targeted for removal from active systems within 30 days after a verified request or in-app deletion. • Backups are targeted for purge or overwrite within 90 days, unless retention is legally required or reasonably necessary for security, fraud prevention, incident investigation, dispute resolution, tax/accounting, compliance, or enforcement of Terms. • Support communications, consent logs, security logs, deletion request records, and legal records may be retained longer where needed for lawful purposes. • Anonymized or aggregated data that cannot reasonably identify you may be retained longer because it is not treated as personal data under many privacy laws. • If you received Amara through a doctor, clinic, hospital, or organization, deletion may also be subject to that organization's legal retention duties and written agreement with Amara. Deletion may make reports, trends, summaries, AI outputs, family profiles, share links, and account history unavailable permanently. Keep copies of important medical records outside Amara. 16. Your rights and requests Depending on where you live and how you use the Service, you may have rights to access, correct, update, delete, export, withdraw consent, restrict certain processing, request information about processing, nominate a person to exercise rights after death or incapacity where applicable, and complain to a privacy authority or data protection board. To exercise rights, email amara@metanovaai.com. Include the email or phone number linked to your account and the request type. We may ask for verification before fulfilling a request. We aim to process verified requests within 30 days unless a different timeline is required or permitted by law. We may decline or limit a request where permitted by law, including where we cannot verify identity, the request is fraudulent or excessive, the data belongs to another person, disclosure would reveal another person's information, retention is legally required, or retention is necessary for security, fraud prevention, dispute resolution, or legal compliance. 17. Canada rights and breach notices For Canada users, we aim to provide meaningful notice and consent for collection, use, and disclosure of personal information. Health information is sensitive, so express consent should generally be obtained for health-data processing unless another legal basis applies. If a breach of security safeguards involving personal information under Amara's control creates a real risk of significant harm, we will take steps required by applicable Canadian law, which may include notifying affected individuals, notifying the Office of the Privacy Commissioner of Canada or applicable provincial regulator, keeping breach records, and notifying organizations or government institutions that may reduce risk. 18. United States rights and breach notices For United States users, state privacy laws, state consumer health data laws, unfair or deceptive practices laws, and the FTC Health Breach Notification Rule may apply depending on the user location, data involved, product design, integrations, and business thresholds. We will assess and comply with applicable obligations. We will notify affected users and applicable Canadian privacy regulators of breaches as required by applicable Canadian law. 19. India rights, grievance, and incident handling For India users, you may request access to information about your personal data, correction, completion, updating, deletion, withdrawal of consent, grievance redressal, and nomination where applicable. You may also complain to the Data Protection Board of India in the manner prescribed by law. If we detect a personal data breach, we will take reasonable steps to contain, assess, and remediate it and follow applicable Canadian breach-notification requirements. Canadian privacy contact: support@metanovaai.com. We aim to acknowledge privacy requests within 72 hours and resolve them within 30 days, subject to verification and applicable law. 20. Cookies, analytics, and tracking We may use essential cookies and similar technologies for login, authentication, security, session management, preferences, fraud prevention, diagnostics, and Service reliability. We may use limited analytics to understand errors, crashes, usage patterns, and performance during beta. We do not use health data for advertising or targeted advertising. We should not place third-party advertising pixels, retargeting tags, or behavioral marketing trackers on authenticated health-report pages unless this Policy is updated and legally required consents are obtained first. 21. Communications We may contact you by email, SMS, phone, in-app notification, or other contact details you provide for account verification, OTP, security alerts, legal notices, support responses, deletion confirmation, product changes, beta feedback, and service-related communications. We do not use health data for marketing. If future marketing communications are introduced, you may opt out as required by law. Service, security, legal, and transactional messages may still be sent. 22. Doctor, clinic, hospital, and provider usage Amara may offer features for doctors, clinics, hospitals, care teams, and enterprise healthcare organizations. Production provider workflows should be governed by separate written agreements that define roles, permitted uses, security obligations, retention, audit rights, incident handling, and applicable Canadian privacy obligations. No provider should use Amara as the sole clinical record, sole diagnostic tool, sole medication decision tool, or sole basis for patient care unless a separate written agreement, regulatory assessment, clinical validation, and legal review expressly authorize that use. 23. Changes to this Policy We may update this Policy as the Service, business model, laws, or beta program changes. Material changes will be communicated through the website, app, email, SMS, or in-product notice where appropriate. We may request renewed acceptance or consent where legally required. The Last updated date at the top shows when this Policy was last changed. Continued use after a change means you accept the updated Policy where permitted by law. 24. Contact us General privacy and support contact: support@metanovaai.com Canada phone: +1 647 530 0595 Office: Toronto, Ontario 25. Developer implementation notes These notes are for website and product implementation. They may be removed from the public-facing page after the legal page and product UI are configured. 25.1 Website placement • Create route: /privacy-policy • Add footer link label: Privacy Policy • Show Last updated and Version at the top of the page. • Do not hide this Policy behind login. It must be publicly accessible. • Include India and North America phone numbers exactly as listed in this document. 25.2 Signup consent checkbox Required unchecked checkbox text: I agree to the Amara Health Terms of Use and Privacy Policy, and I consent to Amara processing my uploaded health documents and related health information to provide the Service. Store: user ID, policy version, terms version, timestamp, country/region if available, IP address if legally permitted, device/browser metadata, and consent source screen. 25.3 Upload-screen consent and warning Suggested upload-screen text: By uploading this document, I confirm that I have the legal right to upload it and I consent to Amara using AI/OCR to extract, organize, summarize, and explain the information for my personal review. Amara is not a doctor and does not provide medical advice. I will verify all outputs with the original report and a qualified healthcare professional. 25.4 AI-output disclaimer Suggested persistent AI-output text: AI output may be wrong, incomplete, outdated, mistranslated, or misread. Verify against the original report. Do not use this for emergencies, diagnosis, treatment, medication changes, or medical decisions. Consult a qualified healthcare professional. 25.5 Delete-account page wording Suggested delete page text: You may request deletion of your account and reports at any time. Deleted data is targeted for removal from active systems within 30 days. Backups may persist for up to 90 days. Some records may be retained where legally required or necessary for security, fraud prevention, dispute resolution, or compliance. To request deletion, use the in-app delete option or email amara@metanovaai.com. 25.6 Legal counsel review before publishing • Confirm correct contracting entity, registered office, legal name, and phone numbers. • Confirm whether Amara is direct-to-consumer only, doctor-facing, clinic-facing, hospital-facing, or all of the above. • Complete PHIPA role analysis before any Ontario provider pilot and sign provider/agent/electronic service provider agreements where applicable. • Review FTC Health Breach Notification Rule and state consumer health data law exposure for US direct-to-consumer users. • Confirm cloud regions, subprocessors, AI vendors, data retention, deletion workflow, backup purge timing, and vendor training controls. • Confirm medical device positioning with legal and regulatory counsel before adding diagnosis, treatment, triage, dosing, risk scoring, or clinical decision-support functionality. • Confirm enforceability of limitation of liability, arbitration, governing law, and consumer terms in Canada, the United States, and India. • Review App Store, Google Play, Google Fit/Health Connect, Apple Health, payment processor, and platform-specific privacy requirements before integrations.