BloodRadar ("we", "our", or "the platform") is a non-commercial, voluntary emergency blood and platelet donor communication network operating in India. We are dedicated to maintaining the highest standards of user privacy, medical confidentiality, and data protection.
This Privacy Policy explains how information is collected, used, processed, and safeguarded when you use the BloodRadar mobile application and website, specifically addressing our integration with the official Truecaller SDK, location services, and address book hashing.
1. Information We Collect
To facilitate rapid, life-saving emergency matching while adhering to the principle of data minimization, we collect only strictly necessary data:
- Account Profile Data: Full Name, Blood Group (ABO and Rh type, including rare phenotypes like Bombay hh or Rh-null), Gender, and City/State.
- Verified Phone Number: Collected via Truecaller 1-Tap OAuth verification or SMS authentication. Used strictly for emergency donor contact and account identity.
- On-Demand Location (Hospital Emergency Geofence): GPS coordinates of the destination hospital when an emergency blood or platelet request is broadcast, and coarse city coordinates of donors to calculate the 10km proximity radius. BloodRadar does NOT track background location when the app is closed.
- Cryptographic Contact Hashes (Stage 1 Address Book Broadcast): When you initiate an emergency request, phone numbers in your address book are hashed locally (SHA-256) on your device to match against registered compatible donors in your contact list. Raw address books are never uploaded or stored in plain text.
- Donation History & Cooldown Timers: Date of last verified whole blood or platelet (SDP) donation to enforce mandatory recovery intervals (90 days for whole blood, 48 hours to 14 days for platelets) under National AIDS Control Organisation (NACO) and DGHS guidelines.
Official Truecaller SDK Phone Verification & Data Safety Declaration
BloodRadar integrates the official Truecaller SDK to allow users to verify their mobile number with zero-OTP friction. This ensures instant account creation during time-critical medical emergencies without waiting for SMS delivery.
2. Truecaller SDK Data Handling Compliance
In strict compliance with Truecaller Developer Policies, Google Play Developer Requirements, and the Indian Digital Personal Data Protection (DPDP) Act 2023:
- Zero Commercial Data Selling: We NEVER sell, lease, rent, trade, or monetize your Truecaller profile data, phone number, or name to third-party advertisers, data brokers, or marketing networks.
- Explicit User Consent: Truecaller authentication is triggered strictly upon your deliberate tap on the "Verify with Truecaller" button. No background profile extraction occurs.
- Encrypted Storage: Phone numbers obtained via Truecaller are stored in an encrypted database using AES-256 encryption at rest.
- Phone Number Masking & Privacy: Your phone number is NEVER publicly displayed in search directories. It is only revealed to a verified requester after you explicitly accept an emergency blood broadcast.
3. How We Use Your Information
All data processed by BloodRadar is used exclusively for life-saving emergency blood connectivity:
- To compute compatibility matching algorithms between patient requirements and donor blood groups.
- To deliver high-priority push notifications (FCM) when an emergency occurs within a 10km radius of your city.
- To enforce the 90-day NACO medical donation cooldown period to prevent premature blood donation.
- To display anonymized real-time radar nodes on the active radar screen.
4. Non-Commercial & Zero Ads Policy
BloodRadar is 100% voluntary, unpaid, and non-commercial. Under the Drugs and Cosmetics Act and NACO guidelines, commercial trading or paid donation of human blood is illegal in India. BloodRadar contains zero third-party advertising SDKs, commercial trackers, or behavioral profiling mechanisms.
5. Data Security Standards
We implement enterprise-grade security controls to protect your health profile and identity:
- Encryption in Transit: All communications between the mobile application, website, and servers are encrypted using TLS 1.3.
- Encryption at Rest: Database records and phone hashes are encrypted with AES-256.
- Role-Based Access: Production database access is strictly isolated and restricted under zero-trust access architecture.
6. Account Deletion & Data Retention (DPDP Act 2023)
Under the Indian Digital Personal Data Protection Act 2023 and global privacy standards, you maintain absolute control over your personal data:
- Instant In-App Deletion: You can permanently delete your BloodRadar account at any time directly from App Settings > Account > Delete My Account.
- Permanent Purge: When you delete your account, your profile data, phone number, contact hashes, and donation logs are permanently wiped from active databases within 24 hours.
- No Residual Shadow Profiles: We do not retain ghost or shadow profiles following user deletion requests.
7. Grievance Officer & Contact Information
If you have any questions, feedback, or grievance requests regarding this Privacy Policy, Truecaller verification, or data rights, please contact our designated Data Protection & Grievance Officer:
BloodRadar Data Protection Office
Email: privacy@bloodradar.org
Support Desk: support@bloodradar.org
BloodRadar Emergency Network — Hyderabad, Telangana, India.