Legal
Privacy Policy - India
Last updated: 26 July 2026 (v2.0)
Applies to: residents of India. Users in Singapore and other supported regions - see the version for your country.
Data Fiduciary: Maverigs.ai Pte Ltd, Singapore, which operates Fyxlife.
Data Protection Officer / Grievance Officer: Vibhor Saxena, Founding Member - privacy@fyxlife.com
Fyxlife ("Fyxlife", "we", "us", "our") is operated by Maverigs.ai Pte Ltd, a company incorporated in Singapore. This Privacy Policy explains how we collect, use, store, and protect your information when you use any of our products and services - including our websites, mobile apps, AI companion accessible through messaging and chat platforms, human-led consultations and onboarding sessions, connections to qualified professionals (such as doctors, nutritionists, fitness experts, and other wellness providers), and any other products or services we may offer from time to time (together, the "Services").
Fyxlife is operated from Singapore, but where you are a resident of India, our processing of your personal data is governed by India's Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 (together, "DPDP"). This Policy is written to meet those requirements. Nothing in this Policy, and no choice of law in our Terms of Service, limits the rights DPDP gives you.
We process your personal data on the basis of the consent you give us when you sign up, and which you can withdraw at any time (Section 6). Using the Services is not by itself treated as consent.
1. Who Fyxlife Is For
Fyxlife is for adults aged 21 and above. When you create your account we ask for your date of birth, and we do not create accounts for anyone under 21. If we later find that an account belongs to someone under 21, we close it and delete the data held under it.
Under India's DPDP Act, anyone under 18 is a child. Processing a child's personal data requires verifiable consent from a parent or lawful guardian. Fyxlife does not offer its Services to children, does not seek that consent, and does not track, behaviourally monitor, or direct advertising at children. If you believe a child's information has reached us, write to privacy@fyxlife.com and we will delete it.
The Services support proactive health and lifestyle improvement. They are not intended for individuals requiring continuous medical supervision or emergency care. We do not provide crisis or emergency services.
Fyxlife does not diagnose disease, prescribe medication, or replace medical care. For any medical decision, please consult a qualified doctor. If you are experiencing a medical emergency, contact emergency services immediately (112 for any emergency, or 108 for an ambulance in most states).
2. Information We Collect
Fyxlife collects the following categories of information when you use the Services:
2.1 Personal identification information
- Name
- Email address
- Mobile number used to reach you on chat platforms or in our apps
2.2 Health and related information
Provided directly by you through questionnaires or uploads, including:
- Biomarkers
- Medical reports you submit
- Lab values
- Medical history, conditions, medications
- Lifestyle patterns and personal goals
2.3 Wearable and device data
When you connect Apple Health or Google Fit:
- Sleep metrics
- Heart rate
- Activity levels
- Physiological indicators
Collected periodically and stored securely.
2.4 Conversation and session content
- Messages you exchange with us on messaging and chat platforms
- Messages sent within our apps or websites
- Notes or summaries from human-led consultations and onboarding sessions
- Photos, documents, or files you upload (for example, lab reports, menus, images)
Conversations and session content are stored and may be compressed or summarized to support ongoing personalized coaching.
2.5 Usage and technical information
- Basic device logs
- App interaction patterns
- System-generated event logs
3. How We Use Information - and What Each Use Gives You
We use each category of information for a specific purpose. We do not use your information for anything not listed here.
| What we use | Why | What it gives you |
|---|---|---|
| Name, email, mobile number (2.1) | To create and secure your account, and to reach you on the platform you use | Access to Fyxlife, and Fiya’s messages reaching you on WhatsApp or in the app |
| Health and related information (2.2) | To analyse your health picture and build your plan | Your whole-body analysis, your biological age and healthspan summaries, and Fiya’s day-to-day guidance on food, movement, sleep, tests and supplements |
| Wearable and device data (2.3) | To read your sleep, activity and heart-rate patterns alongside your lab results | Guidance that reflects how you actually slept, moved and recovered - not lab values alone |
| Conversation and session content (2.4) | To remember your history, your preferences and what you have already been told | Fiya answering without you repeating yourself, and following up on what you agreed to do |
| Health information and conversation content (2.2, 2.4) | Review by a licensed health or wellness professional | A qualified expert checking Fiya’s output for accuracy before you act on it |
| Health information (2.2), when you book a session | Delivering the consultation you asked for | The professional you booked seeing what they need in order to advise you |
| Usage and technical information (2.5) | To keep the Services running, detect faults, and investigate security incidents | An app that works, and a record we can use if something goes wrong |
Where a law requires us to retain or disclose information, we do so - see Sections 4.4 and 5.
We do not use your information for advertising. We do not sell or rent it. We do not use your conversations or health data to train AI models (Section 4.1).
4. How We Share Information
We share your information only in the situations below. In each case we remain responsible to you for how it is handled - under DPDP, engaging someone else to process your data does not transfer our obligations to them.
4.1 Service providers
- Cloud infrastructure and data storage - where your account and health data are held.
- Messaging and communication providers - which deliver Fiya’s messages on the platforms we support.
- AI language model providers - which generate Fiya’s responses. Before any content is sent, identifying details are tokenised so the provider does not receive your identity, although they do receive the content itself. Our business terms with these providers do not permit your content to be used to train their models.
- Form, analytics, payment and operational tooling - supporting onboarding, payments and day-to-day operation.
Every provider processes the data only to deliver the Services, and may not use it for any other purpose.
4.2 Health and wellness professionals
Two different things happen here, and we treat them differently.
Safety and accuracy review. Licensed professionals engaged by Fyxlife review your report so that what reaches you is accurate and safe. They work under contract with us and under their own professional confidentiality obligations, see only what the review requires, and their access is logged. This review does not create a doctor-patient relationship with you.
Consultations you book. When you book a session with a doctor, nutritionist or other professional, they see the information needed to advise you, and they carry their own professional responsibility for the advice they give.
Professionals who advise users in India are registered to practise in India.
You can ask us which providers and professionals have handled your data (Section 7).
4.3 Fyxlife personnel
All Fyxlife employees, contractors, and advisors are bound by written confidentiality obligations. Access to personal data is limited to those who need it to operate the Services, and is logged.
4.4 Legal requirements
We may disclose information where a law or a valid legal order requires it. Where we are permitted to tell you, we will.
4.5 We do not sell your data
We do not sell or rent your personal information to anyone, under any circumstances. We do not share it with advertisers or data brokers.
5. Where Your Data Is Stored, and How Long We Keep It
Where it is stored. Your personal data is stored on secure cloud infrastructure, primarily located in Singapore. Some of our service providers process data in other countries in order to deliver parts of the Services.
Transfers outside India. India's DPDP Act permits personal data to be transferred to any country the Central Government has not restricted by notification. We monitor those notifications, and if a country we rely on becomes restricted we will move the affected processing and tell you. Wherever your data is processed, our contracts require the protections described in this Policy, and our obligations to you under DPDP continue to apply regardless of where processing happens.
How long we keep it.
| What | How long |
|---|---|
| Account data - profile, conversations, health logs | While your account is active |
| Uploaded documents - lab reports, images | While your account is active, plus 12 months, so you can compare results over time |
| Administrative access logs | One year, so that we can investigate security incidents |
| Consent record - what you agreed to, when, and which version of this notice you saw | Three years, so we can demonstrate your consent if asked |
When we erase it. We erase your personal data once it is no longer needed for the purpose you gave it for. In practice:
- You withdraw consent - we and our service providers stop processing immediately, and erase within 30 days.
- You delete your account - we erase within 30 days.
- Your account goes inactive - if you have not used Fyxlife for 24 months, we erase your data.
In each case we keep only what the law requires - currently the security logs and the consent record above. We will tell you what was retained and why.
De-identified data. We may keep aggregate statistics that cannot be traced back to you or to any other individual - for example, how many reports we processed in a month. Identifiers are stripped irreversibly, so what remains is no longer your personal data and is not covered by the rights in Section 7.
6. Your Consent
How we ask for it. Before we collect anything, we show you this notice, setting out exactly what data we are asking for and what we will do with it (Sections 2 and 3). You give consent by an explicit action - reviewing the notice and tapping “I agree” when you create your account. We do not treat visiting our website, messaging Fiya, or continuing to use the Services as consent.
We ask separately for separate things. You can agree to some and decline others:
- Core Service - Fiya’s health guidance, built from the information you give us. This includes review of a sample of Fiya’s outputs by a licensed professional, which is how we check that what reaches you is accurate and safe. Required to use Fyxlife.
- Wearable and device data - connecting Apple Health or Google Fit. Optional.
- Consultations - sharing your information with a doctor, nutritionist, or other professional when you book a session. Optional, and asked at the time you book.
Declining an optional purpose does not affect the rest. We will never make consent to an optional purpose a condition of providing the core Service.
Language. This notice is available in English. You may ask us for it in any of the 22 languages listed in the Eighth Schedule to the Constitution of India, and we will provide it - write to privacy@fyxlife.com.
We keep a record. We record what you consented to, when, and which version of this notice you saw, so that we can show it if you or the Data Protection Board ask.
How to withdraw it - as easily as you gave it. Write to privacy@fyxlife.com and tell us you are withdrawing. No form, no reason required, and no retention call from us. Withdrawal takes effect immediately. We and our service providers then stop processing your data and erase it as described in Section 5, unless a law requires us to keep something.
What withdrawal means. Withdrawing consent for the core Service means we can no longer provide it - Fiya works by knowing your health picture, and without it there is nothing to manage. We will show you clearly what you are about to lose before you confirm. Withdrawing an optional consent simply switches that part off.
Consent Managers. From 13 November 2026, the DPDP framework will also allow you to give, manage, review, and withdraw consent through a Consent Manager registered with the Data Protection Board of India.
If you joined before this Policy took effect. We will send you this notice and ask you to confirm your consent under it. Until you do, we will continue to hold your data on the basis of the consent you originally gave, and will not use it for any purpose not covered by that original consent.
7. Your Choices and Rights
Under India's DPDP Act, 2023, you have the following rights. Exercising them is free, and you never have to give a reason.
- Know what we hold, and who has seen it. You can ask us for a summary of the personal data we hold about you and of how we are processing it. We will also tell you the identity of every service provider and every professional with whom your data has been shared, along with a description of what was shared with each of them.
- Correct, complete or update it. If anything we hold is wrong, incomplete or out of date, tell us and we will fix it.
- Erase it. You can ask us to delete your personal data - either specific information, without closing your account, or your account and everything under it. We will do so unless a law requires us to retain something, in which case we will tell you what we kept and why.
- Withdraw your consent. See Section 6.
- Raise a grievance. If you are unhappy with how we have handled your data or your request, Section 13 sets out how to raise it with us and what to do if our answer does not satisfy you.
- Nominate someone. You can nominate another person to exercise these rights on your behalf if you die or become unable to act for yourself. Send us their details and we will record them.
- And, though the law does not require it: portability. If you want your data in a machine-readable format - to take to another service, or to give to your own doctor - we will provide it as a JSON export.
How to exercise them. Write to privacy@fyxlife.com. We acknowledge within 7 business days and complete within 30 days. For your security, we may ask you to confirm the request from your registered email address or account before we act on it.
8. Security
We protect your information with the measures below, which are designed to meet the reasonable security safeguards required under the DPDP Rules, 2025:
- Encryption of your data in transit and at rest.
- Tokenisation of identifying details before any content is sent to AI language model providers (Section 4.1).
- Access control - access is limited to named individuals who need it to operate the Services, and is reviewed regularly.
- Access logging - administrative access to personal data is logged, and logs are kept for one year (Section 5).
- Backups - your data is backed up so that it can be restored if a system fails.
- Contractual data-handling obligations on every service provider that handles your data, and written confidentiality obligations on every Fyxlife employee, contractor and adviser.
No system can guarantee absolute security, but we work to reduce risk and to respond promptly when something needs attention.
9. If There Is a Data Breach
Protecting your health information is fundamental to how we build Fyxlife, not a compliance exercise bolted on afterwards. Your data is encrypted in transit and at rest, access is restricted to named people and logged, and we hold our service providers to the same standard (Section 8).
No system is immune, and we would rather tell you plainly what happens if one occurs than leave it unsaid.
If your personal data is affected by a security breach, we will tell you. We will not wait for you to ask, and we will not decide on your behalf that it was too minor to mention.
We will tell you without delay, by email and on the platform where you talk to Fiya. In plain language, we will describe:
- what happened, and how broadly
- which of your information was involved
- what could go wrong as a result
- what we have done and are doing about it
- what you can do to protect yourself
- who to contact for anything further
We will tell the Data Protection Board of India. We notify the Board as soon as we become aware of a breach, and provide a fuller report within 72 hours setting out the circumstances, the people affected, the likely impact, the steps we have taken to contain and remedy it, and a record of the notifications we sent to affected users.
We will also notify CERT-In where the incident falls within the categories covered by its directions, within the timelines those directions require.
What we will not do. We will not quietly close an incident without telling the people whose data was involved.
10. Health Data Safety
India's DPDP Act does not create a separate legal category for health information. We treat it with more care than the law requires anyway, because it is among the most personal information you will ever hand to anyone.
- We process your health information only for the purposes set out in Section 3.
- You decide what to share. Fiya will ask, but you can decline anything, and you can tell her what you would rather not discuss. She will respect that.
- Medical reports and wearable data are accessed only where one of those purposes requires it.
- Where a licensed professional sees your information, they see only what the task requires (Section 4.2).
- We do not perform clinical diagnosis, and we do not carry out emergency or continuous monitoring of your data. Fyxlife does not replace medical care (Section 1).
11. Changes to This Privacy Policy
We may update this Policy from time to time. The “Last updated” date at the top always reflects the current version.
Minor changes - clarifications, corrections, or reorganising information already covered - take effect when we post them.
Material changes - a new category of personal data, a new purpose, a new recipient, or anything that reduces your rights - require your consent. We will tell you in advance by email and in the app, explain what is changing and why, and ask you to agree. Until you do, we will not process your data for the new purpose. We do not treat continued use of the Services as agreement to a material change.
12. Where Fyxlife Is Offered
Fyxlife is currently offered to residents of India, Singapore, and select other Asia-Pacific countries. We do not knowingly accept users from the European Union, the United Kingdom, or the United States at this time. If you are resident in one of those regions, please do not use the Services until we formally expand there.
This version of our Privacy Policy applies to residents of India. Residents of other supported countries are covered by the version for their country, available here. Which version applies to you is determined by the country of residence you provide when you create your account, not by your location at any given moment. If you move permanently to another supported country, tell us at privacy@fyxlife.com and we will move you to the correct version.
13. Data Protection Officer / Grievance Officer
For any question, complaint, or request relating to your personal data - including exercising your rights under India's Digital Personal Data Protection Act, 2023 - contact:
Vibhor Saxena, Data Protection Officer / Grievance Officer - privacy@fyxlife.com
We acknowledge requests within 7 business days and complete them within 30 days.
If you are not satisfied with our response, or if we do not respond within that period, you may raise a complaint with the Data Protection Board of India. Please raise your concern with us first - the Act requires you to use our grievance mechanism before approaching the Board.
14. Contact
General support: help@fyxlife.com
Data requests and privacy questions: privacy@fyxlife.com