Privacy Policy

Privacy Policy

Effective: August 2026 Version: 1.0.0 (DPDP-Ready Standard V1)

PediaRoots is responsible for the personal data processed through PediaRoots.

This Privacy Policy is designed with reference to the Digital Personal Data Protection Act, 2023 (DPDP Act), the Digital Personal Data Protection Rules, 2025, and other applicable Indian law.

PediaRoots voluntarily adopts the applicable DPDP-ready controls from launch, including appropriate safeguards for children’s personal data.

We aim to collect only information reasonably necessary for these purposes.

3. Analytics We measure parent interaction with PediaRoots, including registration, onboarding completion, feature use and return visits. Analytics are configured to avoid collection of children’s names, health measurements, or symptom descriptions.

4. AI Processing Dr. Roots uses Google Gemini API. Information necessary to generate an AI response (anonymized prompt context) is transmitted to the provider. Prompts are sanitized server-side to exclude personal child names.

6. Security PediaRoots implements technical and organisational safeguards including encrypted transport (HTTPS/TLS), user-scoped access rules in Firestore and Storage, server-side secret management, and access control.

7. Retention & Rights Parents may request access to, correction of, deletion of, or consent withdrawal concerning personal data. Contact: legal@pediaroots.com

Back to PediaRoots Home