Privacy Policy

Last updated 6 August 2026 · CentraPrime Technologies Pvt. Ltd.

1. Introduction

CentraPrime Technologies ("we", "our", or "us") operates the Central mobile and web application (the "Service"). This Privacy Policy explains how we collect, use, store, and protect your personal health information when you use Central.

We take your health data seriously. All personal health information is stored securely, used only to provide you with personalised health insights, and is never sold to third parties.

2. Health Data We Collect

With your explicit consent, Central collects and processes the following categories of health data to provide personalised insights and recommendations:

DataPurpose
Workout logsExercise type, sets, reps, weight, duration, perceived effort
Nutrition logsMeals, calories, macronutrients (protein, carbs, fat), meal timing
Mood and psychologyEmotional state, stress level, energy level, motivation, triggers, notes
Body metricsBody weight, body fat percentage, circumference measurements
Sleep (self-reported)Bedtime, wake time, subjective sleep quality
HydrationDaily water intake
Step countDaily activity tracking and calorie estimation
Heart rateExercise intensity, resting heart rate, recovery analysis
Heart Rate Variability (HRV)Stress level analysis and recovery scoring
Sleep stagesDeep sleep, REM, light sleep durations for recovery insights
Sleep scoreOverall sleep quality metric from wearable device
Stress scoreComputed from HRV, used for burnout risk detection
Blood oxygen (SpO2)Health monitoring and altitude adaptation signals
Calories burnedActivity-based caloric expenditure for nutrition guidance
Exercise sessionsActivity type, duration, heart rate zones from wearable
VO2 Max estimateCardiovascular fitness tracking over time
Account informationName, email address, authentication credentials
Profile informationAge, height, weight, fitness goals, health targets
Device informationDevice type, OS version for app compatibility
Usage dataFeature usage patterns for app improvement (anonymised)

3. Wearables and Third-Party Integrations

Central offers optional integrations with wearable platforms so that data from your fitness tracker or smartwatch can be reflected in your insights. Every integration is opt-in. You can disconnect any integration at any time from the Wearables section of the app.

On Android devices, Central uses Google Health Connect to read aggregated activity, heart rate, sleep, and body composition data from compatible apps and devices (e.g., Samsung Galaxy Watch, Google Fit, Fitbit, Garmin). Health Connect is a system-level permission grant managed by Android — you control which data categories Central can read from your Health Connect settings.

We use Health Connect data solely to power your personal insights inside Central. We do not share Health Connect data with any third party, do not use it for advertising, and do not combine it with other users' data to build any kind of population profile.

Per Google's Health Connect data-use policy, we will not transfer Health Connect data to any third party except (a) as required by law and (b) with your explicit consent for a specific purpose you initiate (such as exporting your data to a healthcare provider).

If you choose to connect a Fitbit account, Central uses Fitbit's OAuth flow to request scoped access to activity, heart rate, sleep, and weight data. Tokens are stored encrypted at rest. You can revoke this access at any time from your Fitbit account at fitbit.com/settings/applications or by disconnecting Fitbit inside Central. Disconnecting stops new data syncs immediately. Data already synced is retained per Section 6 unless you delete your account.

Central does not currently offer an iOS native application. When iOS launches, HealthKit will be the wearable integration on iOS and will be governed by the same opt-in + disconnect-anytime rules described above. This Privacy Policy will be updated before iOS goes live.

4. Importing Your History from Another AI

You may already have told ChatGPT or a similar assistant a great deal about your body, your training, your injuries and your diet. Central can bring that across so you do not have to type it twice. This is entirely optional, it is never on unless you ask for it, and Central works fully without it.

The default path never shows us your conversations. We give you a short prompt to run inside your own AI. It writes a summary of what it knows about your health, you read that summary, and you paste it into Central. Your own AI does the filtering, under your control, and you see exactly what you are handing over before you hand it over.

The optional path is a full export, and it is tightly fenced. If you would rather bring everything, you can request a data export from the other service and upload the archive to Central. An export archive contains far more than we want, so we open the conversations file and nothing else — not the account file that holds your email and phone number at that service, not the feedback file, not shared conversations, not images. Inside the conversations file we read only the lines you wrote; what the AI said back is not a fact about you. Your lines are then filtered to the ones about health, fitness, food, sleep, body measurements or medication, and everything else is dropped and never sent to OpenAI.

Nothing is saved without your approval. We turn what is left into short statements — "trains four days a week", "does not eat eggs", "history of left-knee pain" — and show each one to you next to the exact line it came from. You accept or reject each one. We do not create workout logs, meals or weight entries from imported text, because logs are records of things we actually observed and inventing them would make your progress numbers fiction. We do not infer diagnoses. We do not keep facts about anyone but you.

We destroy the file you gave us. The archive is processed in memory where it fits; if it must touch disk it goes to a private bucket with a one-day lifecycle rule and our own encryption key. It is deleted as soon as extraction finishes — we aim for under ten minutes — and never later than 24 hours after upload, whether or not you have finished reviewing. We record when we deleted it so you can check.

You can undo the whole thing. Every imported fact is marked as imported, linked to the import it came from, and stored with its evidence line. At Profile → Settings → Privacy & Data you can read them all, delete one, or delete everything from an import in a single tap.

Central is not operated, endorsed or certified by OpenAI or by any other AI provider you may import from, and we claim no partnership with any of them. We name ChatGPT only so you know where to get your own data. What that service does with your data is governed by their privacy policy, not ours.

5. How We Use Your Data

We use your health data exclusively to provide the following services:

Personalised AI insights: Your data is processed by our AI engine (powered by OpenAI's GPT-4o-mini) to generate insights specific to your patterns. These insights are generated on-demand and are personal to you.

Health Memory: We maintain a structured history of your health events so you and your care providers (with your permission) can see your progress over time.

Pattern detection: Our synthesis engine analyses correlations between your sleep, mood, workout, and nutrition data to identify meaningful personal health patterns.

Progress tracking: Visualisations and reports of your health trends over time.

We do not use your health data for advertising, do not sell your data to third parties, and do not use it for any purpose other than providing you with the Central service.

Authorized Central operators (founders and designated team members) may access your data to provide support, improve the service, investigate safety concerns, and refine our health-coaching algorithms. Every operator access of your data is logged with a timestamp, the staff member's identity, and the surface they viewed. You may request a copy of this access log at any time.

6. Data Storage and Security

Your health data is stored on secured servers. All data is encrypted in transit (TLS 1.3) and at rest (AES-256). Access to your data is restricted to authenticated requests using your personal account credentials.

AI processing: when generating insights, anonymised health summaries are sent to OpenAI's API (subject to OpenAI's data processing agreement). Raw personal identifiers are never sent to third-party AI providers.

Data is retained for as long as your account is active. You can request deletion of specific entries or your entire account at any time.

7. Your Rights

Central is operated from India, and as a Data Fiduciary under the Digital Personal Data Protection Act, 2023 ("DPDP Act"), we honour every right the Act grants you as a Data Principal. The rights below are also available regardless of your location and are reflected in the in-app Privacy & Data screen (Profile → Settings → Privacy & Data).

Right to access: You can view all your stored data in the Health Memory section of the app at any time. You may also request a complete export (see below).

Right to correction and updating: You can edit or delete any manually logged entries from within the app. For corrections to account fields (name, date of birth, language) you can edit them in Profile → Edit Profile.

Right to erasure (deletion): You can delete your entire account and all associated personal data from Profile → Settings → Privacy & Data → Delete account. We use a thirty-day grace window: during this period your account is suspended and you can cancel deletion by emailing centraprimetechnologies@gmail.com. After thirty days, every table of personal data we hold about you is purged — logs, conversations, derived memory, uploads, wearable data, consent records and enquiries. Two things are deliberately kept: the deletion record itself and the audit trail of the deletion, because we have to be able to prove to you and to a regulator that the erasure happened and when. Those records name the account that was deleted and the actions taken on it, and nothing else about you. Aggregated, anonymised statistics that no longer identify you are also retained (per DPDP Section 17(1)(c)).

Right to data portability: You can export every record we hold about you, in machine-readable JSON format, from Profile → Settings → Privacy & Data → Export my data. The export is generated within seconds for typical accounts and made available as a download link, which expires after 24 hours for security.

Right to withdraw consent: You can toggle individual data streams off at any time in Profile → Settings → Privacy & Data → Consent. The optional categories covered are wearables sync, notifications, anonymous product analytics, marketing communications, and (when available) family sharing and provider sharing. Core categories required to operate your account at all — health records and AI coaching — are part of using Central; if you want those removed entirely, the right path is to delete your account (see right to erasure above), which purges everything within thirty days.

Right to grievance redressal: If you believe we have not met our obligations under the DPDP Act, you may contact our Grievance Officer, Syed Hasan Ahmed, at centraprimetechnologies@gmail.com. We respond to all DPDP-related queries within seven business days. If you remain dissatisfied, you may escalate to the Data Protection Board of India per the Act.

8. Third-Party Data Sharing

We do not sell, rent, or trade your personal health data with anyone for commercial or advertising purposes. The third parties below process specific, scoped data on our behalf — each is contractually bound to use that data only for the stated purpose:

OpenAI (AI processing): Your chat with Pearl, plus the structured context required to answer (recent workouts, meals, mood, vitals, current conditions), is sent to OpenAI's API for inference. OpenAI's enterprise data processing agreement prohibits training on customer data; we do not opt in to training. Identifiable personal account fields (email, exact name, phone) are stripped before any OpenAI call.

Google Cloud Platform (infrastructure): Central runs on Google Cloud Run (compute) and Google Cloud SQL (database), hosted in the asia-south1 region (Mumbai). Files (records, attachments) are stored in Google Cloud Storage in the same region. Data is not transferred outside India for routine operations.

OneSignal (push notifications): When you opt into push notifications, OneSignal handles delivery. OneSignal receives a device-level identifier plus the notification payload (no health data is included in notifications). You can revoke notification consent at any time.

Sentry (crash & error reporting): If the app crashes or hits a server error, an anonymised crash report including the device model, OS version, and stack trace is sent to Sentry. Personal health data is not included.

PostHog (product analytics): Aggregate product-usage events (which screens were opened, which features were tapped) are sent to PostHog. You can opt out from Profile → Settings → Privacy & Data → Analytics consent.

Razorpay (payments, when active): When you purchase a subscription, payment details are processed by Razorpay. We do not store card details. Razorpay is a SEBI-regulated and PCI-DSS-compliant payment processor.

If you explicitly choose to share specific records with a trainer, doctor, gym, or family member through the planned professional features, that sharing is opt-in, per-record where possible, consent-logged, and revocable at any time.

9. Children's Privacy

Central is not intended for users under the age of 18. We do not knowingly collect personal data from anyone under 18, in alignment with the DPDP Act's protections for minors. If you are a parent or guardian and believe your child has created an account, contact us at centraprimetechnologies@gmail.com and we will delete the account and all associated data within 72 hours of verification.

10. Contact Us & Grievance Officer

For any questions, concerns, or DPDP-related requests, contact our Data Protection & Grievance Officer:

CentraPrime Technologies

Grievance Officer: Syed Hasan Ahmed, Founder — centraprimetechnologies@gmail.com

General support: centraprimetechnologies@gmail.com

Registered office: Chennai, Tamil Nadu, India.

Response time: within seven business days for DPDP queries, within 72 hours for general support.