Skip to content

Legal

Privacy Policy

Apta holds some of the most sensitive information a family owns. This page explains what we collect, where it lives, who can see it, and the choices you have.

Last updated 12 September 2026

Who we are

Apta is a family health-record tracker that helps people organize a parent’s medical history so nothing gets missed by their doctors. We are an information organizer — not a clinical monitoring, diagnostic, or emergency service. Apta is operated by Sketchli Pty Ltd (ABN 77 676 744 620), Melbourne, Victoria, Australia (“we”, “our”, or “us”).

What we collect

  • Account information — your name, email address, and/or phone number, taken from how you sign in (phone OTP or Google). We never store a password.
  • Care profile information you add about the people you look after — name, relationship, age, blood group, allergies, conditions, care team, emergency contacts, and a non-sensitive insurance snapshot.
  • Health records — lab reports, prescriptions, and notes you or your family upload or forward, and the values we extract from them (markers, results, medications, appointment details, home BP and blood-sugar readings).
  • Activity logs — a record of who viewed or changed health data, and when.
  • Operational telemetry — de-identified usage metrics that contain no personal or health information.

We collect only what is needed to run the service and delete what is no longer needed.

How we use it

  • To build the longitudinal health timeline, trends, medication list, and appointment tools.
  • To let you share a read-only doctor’s view and invite family members you choose.
  • To send reminders you have set up (for example, home vitals).
  • To keep the service secure, debug problems, and meet legal obligations.

We do not sell your data, use it for advertising, or use it to make clinical judgements about your family.

Where it is stored

Health data of Indian residents is stored and processed in India, in line with the Digital Personal Data Protection Act, 2023 (“DPDP Act”): a managed Postgres database and a private file bucket, both in Google Cloud’s Mumbai (asia-south1) region. Everything is encrypted at rest and in transit (TLS 1.2+). Source documents are never public — the bucket is reachable only through Apta’s own API, which runs an access check, a malware scan, and content sanitisation on every request. Encrypted database backups with point-in-time recovery are kept on a rolling 7-day window.

International data transfers

Sketchli Pty Ltd is incorporated in Australia, but Apta is built and operated as an India-resident service: your health data stays in India as described above. The DPDP Act applies to our processing of your personal data regardless of where we are incorporated, because the service is offered to you in India — nothing about our Australian incorporation reduces the rights this policy and the Act give you.

The one exception to India-only processing is AI document reading, described below: the file is sent across a border for transient processing and is not stored by the provider. Where any of our infrastructure or sub-processors handle data outside India, we choose providers under contractual data-protection commitments and, where required, take the steps the DPDP Act requires for such transfers.

Uploads

Every file is checked by type and size, scanned for malware (a failed scan is rejected and never stored), stripped of image location and camera metadata, and — for PDFs — rebuilt to remove embedded scripts and actions before anything is read. Password-protected lab PDFs are common in India: if we can’t open one automatically we ask you for the password once and use it in memory only to decrypt the file. The password is never stored, logged, or written to the activity trail.

Who can see it

  • You, and the family members you explicitly invite — as a viewer (read-only), an editor (can add records), or a subject (a parent’s own limited view). Invitation links are single-use and expire after 7 days; you can revoke a person’s access at any time.
  • Anyone you give a doctor share link to. These links are read-only, need no login, expire after 30 days, and can be revoked at any time. We record only when a link was last opened and how many times.
  • Apta support, limited to a small number of people, and only when needed to help you or fix a problem — never for any other purpose.

We’re building toward full, time-boxed audit logging for every internal access to health data as the team and product grow.

AI features

Apta uses AI in two places, both through OpenRouter, which routes each call to an underlying model provider (currently Anthropic and Google). We use no-training, no-retention routes, and we choose providers on that basis specifically because of the sensitivity of health data.

  • Reading your uploads. The document itself is sent for extraction — it may contain the patient name and other details printed on it — but nothing from your profile is added. The provider returns structured values (markers, results, medications, dates), which we validate. Every extracted value is marked “AI-read — verify against original”; the app is never a silent source of truth. We log the model, version, and a reference to the input for each call.
  • The care assistant. This read-only explainer is given only de-identified structured data — internal marker names, values and dates — never a name, date of birth, or contact detail. Your messages are screened for misuse before an answer is generated. The conversation is not stored on our servers.

Other processors

We rely on a small number of sub-processors, each chosen under contractual data-protection commitments:

  • Google Cloud — the Mumbai-region database and document storage.
  • Firebase Authentication (Google) — verifies your phone number or Google sign-in. It holds identity data only, never health data.
  • OpenRouter, and through it the model providers it routes to (currently Anthropic and Google) — the AI features above.
  • The provider that receives lab reports you forward by email or WhatsApp, when that channel is enabled for your account.
  • Stripe, once paid plans launch — card details will be handled entirely by Stripe and will never touch Apta’s servers.

We do not add sub-processors for advertising, and none of them receive your data to use for their own purposes.

How long we keep it

We keep your data for as long as your account is active. When you close your account we purge your account and the records you own, except where the law requires us to retain something. Encrypted database backups roll off a 7-day window; deleted files are removed from storage on a short soft-delete delay.

Data breach notification

If a breach of your personal data is likely to affect you, we will act in accordance with our obligations under the DPDP Act — including notifying affected individuals and, where the law requires it, the Data Protection Board of India. We will take immediate steps to contain any breach, assess the risk, and notify affected users as soon as practicable.

Your rights

You can ask us to access, export, correct, or delete your data, or to withdraw consent, and we will action it within the timeframe the DPDP Act sets. You can edit or delete a care profile and its records yourself from the app; for a full export or account closure, use the request buttons on your account page or email help@apta.care.

For any grievance about how we handle your personal data, contact our Grievance Officer at help@apta.care. We will acknowledge your complaint promptly and aim to resolve it within the timeframe the DPDP Act sets. If you are not satisfied with our response, you may escalate your complaint to the Data Protection Board of India.

Children

Apta is for adults organizing care for other adults. It is not intended for people under 18 to create their own accounts.

Changes

We will update this page as Apta evolves and will tell you before any material change takes effect.

Contact

Questions, concerns, or a data request: help@apta.care.

Sketchli Pty Ltd
ABN: 77 676 744 620
Melbourne, Victoria, Australia