Privacy Policy
This Privacy Policy explains how MTD Technology Company Limited ("we," "us," or "Tarunow") collects, uses, and protects information when you use the Cardia: Blood Pressure & Sugar mobile application (the "App" or "Cardia").
We are based in Vietnam, but Cardia is offered globally and we take privacy seriously regardless of where you live. Please read this policy carefully. If you do not agree with it, please do not use Cardia.
1. Who we are
Company name: MTD Technology Company Limited (operating as Tarunow)
Registered address: L18-11-13, Floor 18, Vincom Center Dong Khoi Building, No. 72 Le Thanh Ton, Ho Chi Minh City, Vietnam
Contact for privacy inquiries: admin@tarunow.com
For the purposes of the EU General Data Protection Regulation (GDPR), we act as the data controller for the limited personal data we process. For the purposes of the California Consumer Privacy Act (CCPA), we act as the business that determines how data is handled.
2. A quick summary (for people in a hurry)
- Your health data stays on your device. Blood pressure, blood sugar, and heart rate readings you enter into Cardia are stored locally on your phone. We do not have a server that holds your health data.
- The camera is used only for measuring your heart rate when you choose to use that feature. Camera images are processed entirely on your device and are never stored, uploaded, or shared.
- We collect a small amount of technical and analytics data to keep the App working, fix crashes, and understand how it's used — through Google Firebase and Google Analytics.
- We show ads from Google AdMob. AdMob may use a mobile advertising identifier to show you relevant ads.
- We are based in Vietnam but follow GDPR (EU), CCPA (California), and DPDP Act (India) rules.
- You can ask us to delete any data we hold about you by emailing admin@tarunow.com.
The sections below explain everything in detail.
3. What data we collect
We collect the following categories of data. Each is described below.
3.1 Health data you enter into the App
When you record a reading in Cardia, the App stores:
- Blood pressure readings — systolic, diastolic, pulse rate, date/time, tags you select, optional notes
- Blood sugar readings — glucose value, unit (mg/dL or mmol/L), test type (FPG, OGTT, HbA1c), meal context, date/time, tags, optional notes
- Heart rate readings — pulse value (entered manually or measured via the camera-based feature in Section 3.2), date/time, tags, optional notes
- Settings — your preferred units, guideline preference (ACC/AHA 2017 or ESC/ESH 2018), optional display name, optional date of birth, optional sex
Where this data lives: This data is stored locally on your device in the App's private storage. We do not transmit this data to our servers. We do not have access to it. If you uninstall the App or clear its data, this information is permanently deleted from your device and cannot be recovered.
Future features: We may add optional cloud backup, sync across devices, and export-to-PDF features in the future. If we do, we will request your explicit consent before any health data leaves your device, and we will update this policy and notify you in the App.
3.2 Camera data (heart rate measurement)
Cardia offers an optional camera-based heart rate measurement feature that uses photoplethysmography (PPG) — a technique that detects small changes in light reflected from your fingertip when you cover the camera lens. The App analyzes these light changes in real time to estimate your pulse rate.
How camera data is handled:
- The camera is only activated when you tap the heart rate measurement button and place your finger on the lens. It is not used at any other time.
- All processing happens entirely on your device. Camera frames are analyzed in real time and immediately discarded.
- No images, video, or raw camera data are ever stored on your device or transmitted off your device. Nothing is saved to your photo gallery, sent to our servers, or shared with any third party.
- The only output that is saved is the final estimated pulse number (a single integer, e.g. "72 bpm"), which you can choose to log as a reading. This is treated the same as a manually entered heart rate reading under Section 3.1.
- You can deny or revoke the camera permission at any time in your Android system settings. If you do, the manual heart rate entry feature continues to work.
Important note about accuracy: Camera-based pulse measurement is an estimate for general wellness purposes only. It is not a medical-grade measurement and should not be used for diagnosing, treating, or managing any health condition. See Section 15.
3.3 Notification data
Cardia can send you reminders to log your readings (for example, "Time to log your morning blood pressure"). To do this, the App requests the POST_NOTIFICATIONS permission on Android 13 and above, along with SCHEDULE_EXACT_ALARM and USE_EXACT_ALARM to ensure your reminders fire at the precise time you choose (rather than being delayed by the system).
- Reminders are generated and scheduled entirely on your device. We do not have a server that sends push notifications.
- The exact-alarm permissions only allow Cardia to schedule a notification at a specific time on your device. They do not access, collect, or transmit any data about you.
- We do not collect or transmit any information about when notifications are shown, tapped, or dismissed.
- You can disable notifications at any time in Cardia's settings or in your Android system settings.
3.4 Technical and analytics data (Firebase + Google Analytics)
To keep the App stable and improve it, we use Google Firebase and Google Analytics for Firebase. These services automatically collect:
- Device information — device model, operating system version, screen size, language, country (inferred from IP address; we do not store the IP itself)
- App information — App version, install source, first-open and last-open timestamps
- Usage events — which screens you view, which features you use, which buttons you tap (e.g., "added blood pressure reading," "viewed dashboard"). These events record that an action happened, not the values you entered. We never send your actual blood pressure, blood sugar, or heart rate numbers to Firebase or Google Analytics.
- Crash reports (via Firebase Crashlytics) — when the App crashes, we receive a technical stack trace and device state at the moment of the crash. This helps us fix bugs. Crash reports may include a non-personally-identifiable installation ID.
- Pseudonymous identifiers — Firebase assigns a random installation ID to your App instance. This is not linked to your name, email, or phone number.
3.5 Advertising data (Google AdMob)
We use Google AdMob to display ads in the App. AdMob may collect:
- Your Advertising ID (Android AAID) — a resettable identifier provided by your device
- Approximate location derived from IP address (country/region level, not precise GPS)
- Ad interaction data — which ads you saw, which you tapped
- Device and app information as listed in section 3.4
AdMob uses this data to show you ads that may be relevant to you ("personalized advertising").
We do not collect or process precise GPS location, contacts, photos from your gallery, microphone, files, or SMS data. Cardia does not request these permissions.
4. Android permissions we request
| Permission | Why we need it | Privacy impact |
|---|---|---|
| CAMERA | To measure your heart rate using photoplethysmography (PPG) on your fingertip. Only activated when you tap the heart rate measurement button. | None — camera data is processed on-device only and never stored or transmitted. See Section 3.2. |
| POST_NOTIFICATIONS | To show you reminders to log your readings. | None — notifications are generated locally on your device. See Section 3.3. |
| SCHEDULE_EXACT_ALARM | To schedule reminder notifications to fire at the precise time you choose (e.g., exactly 8:00 AM). | None — does not access or collect any data. |
| USE_EXACT_ALARM | Same purpose as above; used on Android 13+ where this newer permission applies. | None — does not access or collect any data. |
| VIBRATE | To provide subtle haptic feedback during measurements and reminders. | None — does not access any data. |
We do not request location, contacts, microphone, storage, or any other sensitive permissions.
5. What we do NOT collect
To be clear about the limits:
- We do not collect your name, email address, phone number, or postal address — there is no account system in the App today.
- We do not collect your precise GPS location.
- We do not access your contacts, photo gallery, files, microphone, or SMS messages.
- We do not store or transmit camera images — the camera is used only for on-device PPG measurement as described in Section 3.2.
- We do not collect data from other health apps (Google Fit, Apple Health, Samsung Health, etc.) — Cardia does not integrate with these services.
- We do not collect data from Bluetooth devices — Cardia does not pair with blood pressure cuffs, glucose meters, or other connected devices.
- We do not sell your personal data to anyone, ever.
6. How we use the data
| Purpose | Data used | Legal basis (GDPR) |
|---|---|---|
| Operate the App and store your readings | Health data (on your device) | Performance of contract |
| Measure heart rate via camera | Camera frames (processed on-device, not stored) | Consent (Android permission) |
| Send reminders to log readings | Locally scheduled notifications | Consent (Android permission) |
| Fix crashes and bugs | Crash reports, device info | Legitimate interest |
| Understand how the App is used and improve features | Usage events, device info (Firebase Analytics) | Legitimate interest |
| Show ads to fund the free App | Advertising ID, device info, approximate location | Consent (EU/UK) / Legitimate interest (other regions) |
| Comply with legal obligations | All of the above as required | Legal obligation |
| Respond to your privacy requests | Information you provide in your request | Legal obligation |
We do not use your data for automated decision-making, profiling that produces legal effects, or any medical diagnosis.
7. Who we share data with
We share data only with the third-party service providers necessary to run the App:
| Provider | Purpose | What they receive | Their privacy policy |
|---|---|---|---|
| Google Firebase (Google LLC / Google Ireland) | Analytics, crash reporting | Usage events, crash logs, device info, installation ID | firebase.google.com/support/privacy |
| Google Analytics (Google LLC / Google Ireland) | App usage analytics | Same as Firebase Analytics | policies.google.com/privacy |
| Google AdMob (Google LLC / Google Ireland) | Display ads | Advertising ID, device info, approximate location, ad interaction data | policies.google.com/technologies/ads |
| AdMob advertising partners | Ad delivery and measurement | A subset of advertising data above | support.google.com/admob/answer/9012903 |
We never share your health readings (blood pressure, blood sugar, heart rate values) or camera data with any third party, because they never leave your device in the first place.
We may share data with law enforcement only if compelled by a valid legal request from a competent authority. Given that we hold almost no data about individual users, such disclosures are unlikely to be meaningful.
8. International data transfers
Our service providers (Google, Firebase, AdMob) operate globally and may process data in the United States, the European Union, India, Singapore, and other countries. Google uses Standard Contractual Clauses approved by the European Commission to legally transfer EU personal data outside the EU. By using Cardia, you understand that your technical and advertising data may be processed in countries other than your own.
9. How long we keep data
- Health data on your device — kept until you delete individual readings, clear the App's data, or uninstall the App. We have no role in retaining this data.
- Firebase Analytics events — retained for up to 14 months by default, then automatically deleted.
- Crashlytics crash reports — retained for up to 90 days.
- AdMob advertising data — retained according to Google's retention policies (see Google's privacy policy linked above).
10. How to delete or change your data
To request deletion of any data we hold about your installation — including analytics events, crash reports, and advertising data — or to make any other privacy request, simply email us:
Email: admin@tarunow.com
We will process your request within 30 days as required by applicable law.
For health data stored on your device, you can delete it yourself at any time by deleting individual readings inside Cardia, clearing the App's data from Android Settings → Apps → Cardia → Storage, or uninstalling the App.
11. Your rights under GDPR (EU, UK, EEA)
If you are in the European Union, the United Kingdom, or the European Economic Area, you have the following rights under GDPR:
- Right of access — request a copy of the personal data we hold about you
- Right to rectification — correct inaccurate data
- Right to erasure ("right to be forgotten") — request deletion of your data
- Right to restriction — limit how we process your data
- Right to data portability — receive your data in a portable format
- Right to object — object to processing based on legitimate interest
- Right to withdraw consent — where processing is based on consent, withdraw it at any time
- Right to lodge a complaint with your national data protection authority
To exercise any of these rights, email admin@tarunow.com. We will respond within 30 days. We may ask you to verify your identity for security reasons.
As a Vietnamese company without an EU establishment, we are not required under GDPR Article 27 to appoint an EU representative because we do not engage in large-scale processing of EU residents' data. If this changes, we will appoint a representative and update this policy.
12. Your rights under CCPA (California)
If you are a California resident, the California Consumer Privacy Act and California Privacy Rights Act give you the following rights:
- Right to know what personal information we collect, use, and share
- Right to delete personal information we have collected
- Right to correct inaccurate personal information
- Right to opt out of "sale" or "sharing" of personal information
We do not sell your personal information in the everyday meaning of the word. However, California law defines "share" broadly to include the use of advertising identifiers for cross-context behavioral advertising. Under that definition, our use of AdMob may qualify as "sharing." To opt out of such sharing, you can disable personalized ads in your Android system settings (Settings → Privacy → Ads → "Opt out of Ads Personalization") or email us at admin@tarunow.com.
We will not discriminate against you for exercising any CCPA right.
To exercise your rights, email admin@tarunow.com with the subject line "California privacy request."
13. Your rights under India's DPDP Act 2023
If you are in India, the Digital Personal Data Protection Act 2023 gives you rights similar to those above:
- Right to access information about your personal data
- Right to correction and erasure
- Right to grievance redressal
- Right to nominate another person to exercise your rights in the event of your death or incapacity
Grievance officer contact: admin@tarunow.com (subject line: "DPDP grievance"). We will acknowledge your grievance within 7 days and resolve it within 30 days.
14. Children's privacy
Cardia is intended for users 16 years of age and older. We do not knowingly collect personal data from anyone under 16. If you believe we have collected data from someone under 16, please email admin@tarunow.com and we will delete it.
Regional age requirements:
- European Union / UK: Our minimum age of 16 aligns with the highest digital age of consent set under GDPR across EU member states, so users in the EU and UK can use Cardia without additional parental consent requirements under GDPR.
- India: Under the DPDP Act 2023, users under 18 are considered children and require verifiable parental consent. We do not currently have parental consent infrastructure. If you are under 18 and in India, you should not use Cardia without a parent or guardian's involvement.
- United States: Our minimum age of 16 exceeds the threshold of the Children's Online Privacy Protection Act (COPPA), which protects children under 13. We do not knowingly collect personal data from anyone under 16, including children under 13.
For all users under 18 anywhere in the world: Cardia is a wellness logbook, not a medical service. Health-tracking apps are best used with the involvement of a parent, guardian, or healthcare professional.
15. Health information disclaimer
Cardia is a wellness and lifestyle logbook. It is not a medical device, does not provide medical advice, and is not intended to diagnose, treat, cure, or prevent any disease.
The zone classifications shown in the App (e.g., normal / elevated / high blood pressure; normal / prediabetes / diabetes ranges) are based on published medical guidelines for general informational purposes and should not be used as a substitute for advice from a qualified healthcare professional.
The camera-based heart rate (PPG) feature is an estimate for general wellness purposes only. It is not a medical-grade measurement, can be affected by lighting conditions, finger placement, movement, and skin tone, and should not be relied upon for the diagnosis or management of any cardiac or other health condition. If you have concerns about your heart rate, consult a qualified healthcare professional and use a properly calibrated medical device.
Always consult your doctor about your readings, especially if they are abnormal. In a medical emergency, call your local emergency number immediately.
This disclaimer is repeated in our Terms of Service.
16. Security
We protect your data through:
- On-device storage — your health data and camera data never leave your device, removing the largest category of risk
- Encrypted connections — all communication with Firebase, Google Analytics, and AdMob uses HTTPS/TLS
- Limited data collection — we collect only what's needed (data minimization principle)
- Vendor security — Google's services (Firebase, AdMob) are SOC 2, ISO 27001, and ISO 27018 certified
No system is perfectly secure. If we become aware of a security incident affecting your data, we will notify you and the relevant authorities within the timeframes required by applicable law (72 hours under GDPR).
17. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. When we do:
- Minor changes (clarifications, typos, updated contact info): we will update the "Last updated" date at the top of this page.
- Material changes (new data collection, new third parties, new uses of data): we will notify you in the App at least 30 days before the change takes effect, and where required, we will request your renewed consent.
Continued use of Cardia after a policy update means you accept the updated policy.
18. Contact
For any privacy question, request, or complaint:
Email: admin@tarunow.com
Postal mail: MTD Technology Company Limited, L18-11-13, Floor 18, Vincom Center Dong Khoi Building, No. 72 Le Thanh Ton, Ho Chi Minh City, Vietnam
We aim to respond to all inquiries within 7 business days, and to all formal data subject requests within 30 days as required by applicable law.