Zelvia Privacy Policy
Version 2026-09-23 · c0a0f3b16ee6
Version: 2026-09-23
Status: Product-ready draft; final publication requires approval by qualified counsel in each launch jurisdiction.
1. Scope and roles
This policy applies to the Zelvia patient application, provider marketplace, seller portal and Zelvia CRM. Depending on the feature, Zelvia may act as an independent controller, joint controller or processor for a clinic. The clinic agreement and Data Processing Addendum define those roles for CRM and provider workflows.
2. Data we collect
We may collect account and contact data; verified telephone number; device and security telemetry; selected skin condition; journal, symptom, trigger, nutrition, medication and skincare records; uploaded photographs and documents; appointment, consultation and support messages; location when permission is granted; health data imported through platform APIs; provider, clinic and seller verification data; transaction, fiscal, refund and payout records.
Zelvia does not sell personal health data. Advertising use of health data is prohibited.
3. Purposes
Data is used to authenticate accounts, secure the service, personalize condition tracking, generate user-requested AI assistance, enable consultations and bookings, process marketplace orders and payments, provide support, meet legal and fiscal duties, detect abuse, and improve reliability using minimized or aggregated telemetry.
4. Health and AI notice
Health data is sensitive data. AI features provide informational support and drafts; they do not replace diagnosis, emergency services or professional medical judgment. Users control whether optional photos, health integrations and location are supplied.
Before personalized external AI processing starts, Zelvia presents the current purpose and consent version. The current question and selected skin condition are necessary for the requested answer; the user can separately allow or disable journal and symptom tracking, weather and location context, nutrition and digestive records, photo tracking, skincare, medications, procedures, health-platform data, supplementary conditions, a patient-reviewed support summary and prior conversation history. Support conversations require a separate opt-in and patient review before a health summary can enter AI context.
The user may change these choices or withdraw consent in Settings. Withdrawal stops future external AI processing under that consent but does not erase the consent audit event or processing that was already lawful. For each external AI response, Zelvia records a minimized source manifest and hash, purpose, consent version and status, and the provider retention mode. Zelvia does not store a duplicate copy of the assembled raw health-context prompt by default. The user’s own chat message and the underlying records remain subject to their documented product retention rules. Raw AI debug snapshots are disabled by default; they may not be enabled without an approved encrypted, access-restricted and automatic-deletion control.
5. Legal basis and consent
The applicable basis depends on country and feature and may include contract performance, explicit consent for sensitive health data, compliance with legal obligations, protection of vital interests, and legitimate interests for proportionate security. Consent may be withdrawn, but withdrawal does not invalidate earlier lawful processing or records that must be retained by law.
6. Sharing and processors
Data is shared only as required with the clinic or doctor chosen by the user, sellers and delivery parties needed to fulfill an order, payment and fiscal providers, communications providers, hosting and security providers, and authorities when legally required. Processors receive documented instructions, confidentiality and security obligations. A current subprocessor register must be maintained before launch.
7. International transfers
Zelvia is designed for multiple countries. Before transferring personal data internationally, Zelvia and participating clinics must document the lawful transfer mechanism, localization requirements and contractual safeguards applicable to the user and clinic.
8. Retention
Tracking and optional content are retained only for the documented product purpose or until deletion is requested. Security logs, consent evidence, clinical records, fiscal records, payment, refund and marketplace accounting records may be retained for mandatory periods. When records must be retained, direct identifiers are minimized or pseudonymized where legally permitted.
9. User rights
Users can export tracking data, correct profile data, withdraw optional permissions, request access, restriction or deletion, and initiate account deletion in the app. Requests are recorded with a reference and due date. Deletion may require identity verification and may be delayed for open orders, provider ownership or records subject to legal retention; the user must be told the reason and expected timeline.
10. Account deletion
Account deletion is available in Settings. After confirmation, active sessions are revoked. When no legal hold applies, the account is scheduled for deletion and health tracking data is erased; the remaining account shell is anonymized for referential integrity. Legally required financial, fiscal, consent, fraud-prevention and clinical records are retained only for the required period and are not used for unrelated purposes.
11. Security
Zelvia uses least-privilege access, tenant isolation, encrypted transport, private signed media access, rate limits, audit records, secret management, backups, monitoring and incident response. No statement in this policy represents certification under a specific law or standard.
12. Children and emergencies
The service is not intended for children unless a country-specific guardian flow and legal approval are enabled. Zelvia is not an emergency service. Users with severe or rapidly worsening symptoms should contact local emergency or medical services.
13. Contact
Privacy and data-rights requests: [email protected]
Support: [email protected]
Material policy changes create a new version and require renewed acceptance when legally necessary.
14. Named AI processors and explicit permission
Zelvia receives AI data directly from information the user types, selects, uploads or separately authorizes in the app. For a requested AI response, this may include the current question and only the health or care source groups the user enables. A selected image is included only for a user-initiated vision request. Zelvia does not send disabled source groups.
The in-app notice names the processors in the current production routing policy before consent: OpenAI API is the primary text and vision processor, and Zelvia private Qwen infrastructure is the Zelvia-controlled fallback. The data is used only to generate the response requested by the user, provide continuity from selected recent context and operate safety controls. It is not sold or used for advertising. Under the configured OpenAI API terms, submitted API data is not used to train provider models; the private Qwen route does not create third-party retention.
Before any external AI processing, the user must actively confirm the named processors, purpose and selected data categories. Zelvia stores the accepted disclosure version, processor list and cryptographic hash with the consent audit. Users can change source choices or withdraw consent in Settings; a changed disclosure requires new consent. Data is minimized, encrypted in transit, access-controlled and accompanied by a source manifest. Zelvia does not retain a duplicate assembled raw health prompt by default.