Skip to content
Metaboliq
Menu

Legal

Privacy

Version 1.1 · effective 18 August 2026. This is the current text. Earlier versions remain available on request, and we will tell you before these change.

What changed in this version

  • Version 1.1 corrects five statements in version 1.0 that were not true of this software. Nothing was removed to make a correction easier: every topic 1.0 covered is still covered, and where the product cannot do the thing 1.0 implied, this version says so and names the route that exists.
  • The assessment. 1.0 said there was no endpoint on our side that receives an assessment answer. There is, and there was when 1.0 was published: every answer is sent to us and stored. Clause 2 now describes what is stored, the split between the copy a clinician reads and the measurement record, and the database constraint that stops a measurement record holding an answer.
  • The recipients. 1.0 said four organisations receive anything at all. Two were missing: WTF Labs, a separate company whose WhatsApp service delivers the message confirming a call you booked, and Meta, which operates WhatsApp and therefore receives that message and your number on the way to you. Both are now named in clause 6 with what they get. The sentence about advertising tags has been rewritten so it cannot be read as a claim that Meta receives nothing, and the 2Factor entry no longer credits it with messages it does not carry.
  • Sending. 1.0 said a message re-checks your permissions at the moment of sending. The code that would do that exists and nothing in the live product calls it. Clause 5 now says where the check really happens — at the moment you give the permission, read back out of the ledger — and states plainly that there is no second read when a message leaves.
  • Age. 1.0 said age is checked before anything is charged. Nothing verifies anybody's age. Clause 12 now says that being 18 or over is a requirement we ask you to meet rather than one we check, describes the one place a stated age under 18 does stop onboarding, and says that the endpoint which charges you does not look at an age at all.
  • Forget this device. 1.0 said that control erases all of it. It clears what this site keeps on your device and never reaches us, so the stored assessment rows survive it. Clause 2 now says what it does and what to do about the rest.
  • Carried over from 1.0, unchanged: this document is written against the software rather than against a template. Where a right cannot yet be exercised in the product, it says so and names the route that does exist, instead of implying a button that is not there.

1Who this policy binds

1.1Metaboliq is a service of Witness the Fitness Private Limited. Where this policy says "we", it means that company. It is the company that takes your money, holds your data, and has to answer for both.

1.2India's Digital Personal Data Protection Act 2023 governs what we do with your personal data. Under that Act we are the data fiduciary and you are the data principal. This page is the notice that Act requires you to be given at or before the point we collect anything.

1.3It covers three separate systems: this public site, the member app at app.metaboliq.wtf, and the staff console our clinicians and operations team use. They are separate websites with separate sign-ins and separate sessions. A session on one is not a session on another, and that is what keeps a marketing page and a clinical record out of the same browser tab.

2What we collect, and when

2.1If you read this site and leave, nothing is written to your device. No identifier, no timestamp, no cookie. Storage starts only once you do something that needs remembering: choose a module, answer a question, leave your number, or ask to be remembered.

2.2If you take the assessment, each answer is written twice: into your own browser tab, and to us. It is sent to us as you give it and stored. What it is stored against is a reference we mint at random and a token your browser minted for itself — no mobile number, no email and no member reference, because an assessment is taken before any of those exist. The profile you are shown is still built on your device.

2.3Two kinds of row are written and they are not the same thing. One is the assessment itself — the question, the answer you chose, the unit for a measurement — and it is written for everybody who answers, whether or not you have agreed to be measured. It is written because it is the thing you asked us to do and because a clinician has to be able to read it, and refusing measurement is not a withdrawal of that request. The other is the measurement record — the database calls it a marketing row — and it is written only when you have given a current, explicit permission for it. It holds the question, which position in the list you picked, how many positions there were, and how long the question took.

2.4A marketing row cannot hold an answer. That is not a habit we keep, it is a condition on the table: the columns that carry an answer's value must be empty on a measurement row, and the database rejects the write if they are not. So the measurement record of your assessment holds a position in a list and never the words printed on the option you chose.

2.5There is a control on the plan page called Forget this device. It appears once you have built a stack and answered the measurement question, and it does what its name says and no more: it clears the profile and the measurement choice this site keeps on your device. It does not reach us. The rows described above are on our side and it does not touch them, and it does not clear the assessment answers your own browser is holding either. Those live in storage scoped to the tab you took the assessment in, which a browser is meant to clear when that tab closes — a phone that restores its tabs can hand them back, so we refuse an answer set that has gone stale when we read it rather than trusting the tab to have gone. We have not built a control that erases the rows on our side. If you want them gone, ask us to ring you back and say that is what the call is about; the erasure clause below sets out what happens then.

2.6If you ask us to call you, we store your mobile number, the day and time window you chose, and a booking reference to quote on the phone. We also store a fingerprint of the code we texted you and a fingerprint of the network address the request came from. The fingerprint of the address exists to stop somebody using the form to send thousands of texts; the address itself is never written down.

2.7If you become a member, we hold the mobile number you sign in with, what you enter during onboarding, the records your clinician writes, and your orders and payments. A clinician's note names the clinician, their medical registration number, and when they signed it.

2.8A document you upload is evidence, not a result. No value is read out of it into anything clinical automatically. It sits unreviewed until a clinician opens it and decides what, if anything, it establishes.

3What we do not collect

3.1There is no email address, no postal address and no date of birth in any of our databases. Not encrypted, not restricted — absent. If you have never been asked for one, that is why.

3.2We do not store your network address in a readable form anywhere. We do not store the sign-in code we send you; we store a fingerprint of it and compare fingerprints.

3.3We accept five documents to establish who you are: passport, driving licence, voter ID, PAN and Aadhaar. Not one of them is required, Aadhaar included, and we do not store the number from any of them. What we would keep is the fact that a check passed, not the document. Two things would be established and nothing else: that the person consulting is the person a prescription would be for, and that they are 18 or over. That check is not running yet — the clause on children says what happens today instead.

3.4No public form on this site has a free-text box for your symptoms. That is deliberate. A marketing page is the wrong place to type a health condition, and the way to stop it being typed is to remove the box rather than to promise to be careful with whatever lands in it.

4Why we use it, and the choices you are offered

4.1Purposes are a closed list of nine. A purpose that is not on that list cannot be recorded — the application refuses it and so does the database.

4.2Five of the nine are described to members and can therefore be chosen: clinical care, medicine delivery, service messages, product improvement, and marketing. Clinical care is the one that has to be on for us to treat you. The other four are genuinely optional, and switching one off does not switch off another.

4.3The remaining four are not offered to anyone. Behavioural advertising, research, diagnostics and billing have no notice describing them, and a permission we have not described to you cannot be recorded as given. If we ever want one of them you will be shown a notice first. That is not a courtesy; it is the only way the software will accept it.

4.4Each of the five tells you what it enables and what stops if you take it away. Withdrawing clinical care ends your care with us, and you are told that before you confirm rather than after.

6Who else sees your data

6.1Eight organisations receive anything at all. Each is named here with one job and with what they actually get. We do not sell personal data, and we do not share it for anybody else's marketing.

6.2One of the seven receives far more than the rest, and it is the laboratory. If a blood test is booked, Redcliffe Labs is told your name, your home address, your phone number and the panel to run, because a phlebotomist cannot come to an address nobody gave them. They are not told why the test was ordered. The full entry is below.

6.3Two of the seven are worth reading before the list. If you book a call we send you a WhatsApp confirming it, and a WhatsApp cannot be sent by us alone: your number and that message go to WTF Labs, which is a different company from ours, and on to Meta, which owns WhatsApp and carries it to your handset. So your mobile number reaches two companies that are not us, for one purpose, on one occasion. It is set out below rather than left to be inferred from the word WhatsApp.

Redcliffe Labs

They get your name, age, sex, email address, phone number, WhatsApp number, street address, landmark and the exact latitude and longitude of your door, together with the code for the panel being collected.

They send a phlebotomist to your home and run the blood tests. The coordinate is how the person finds you; the panel code tells the laboratory which tests to run, and it necessarily indicates what is being looked at. They are not sent a diagnosis, a clinician's note, a medicine, or anything from your intake beyond what is listed here. Your results come back to us and a doctor reads them; the laboratory does not interpret them for you.

Razorpay

They get the amount, the currency, our own order reference, and two catalogue codes for what you are buying.

They take the payment. They are never sent a condition, a test result, a medicine, or anything a clinician wrote.

2Factor

They get your mobile number and a pre-registered template carrying a six-digit code.

They deliver sign-in and call-booking codes by SMS, and that is the whole of it. A code is all that is in one: no name, no reason for the message, nothing about your health. They do not carry our other messages — those go over WhatsApp, which is the route described under WTF Labs and Meta below.

VideoSDK

They get a meeting identifier and an opaque participant identifier.

They carry the video consultation. No name, no condition and no programme is sent in any field, and recording is off unless it is turned on for a particular call.

A licensed pharmacy

They get the prescription a clinician wrote for you.

They dispense it. This happens only if you have given the medicine-delivery permission, and only for a pharmacy whose licence we can evidence.

WTF Labs

They get your mobile number, the name of a message template we have registered, and the two values that fill it in — when your call is, and your booking reference.

They run the WhatsApp service we send that message through, and they are a separate company from ours. It happens when you confirm a call you booked and at no other time. Nothing about your health is in one of these messages: a check refuses to build the request at all if a medicine, a condition or a test appears anywhere in it, so the failure lands in our logs rather than on your home screen.

Redcliffe Labs

They get your name, your home address and the landmark you gave with it, your phone and WhatsApp number, your email address, your age, your sex, and the code for the blood panel that has been ordered — and, on the way back, your results.

They are the laboratory. A phlebotomist of theirs comes to the address you gave, draws the sample, and their laboratory runs the panel and returns the values. This is the largest amount of information we hand to anybody, and it is the one recipient we cannot make smaller: nobody can collect blood from an address they have not been told, and no laboratory can run a test it has not been named. What they are NOT told is why. No condition, no medicine, no note a clinician wrote, and no reason for the test travels with the booking, and there is no free-text field anywhere in what we send that one could be written into. They will also email and message you directly about the appointment — that is their own message to you, sent off the contact details above, and we cannot switch it off.

Meta

They get the same mobile number and the same message, handed on by WTF Labs.

Meta owns WhatsApp and runs the wire that message travels on, so a WhatsApp from us reaches Meta on its way to you. They receive it as the messaging company, not as an advertiser: we run no Meta tag, we upload no audience, we send them no purchase or conversion, and we do not match your number against anybody's advertising profile. This is the only way anything about you reaches Meta, and it happens only if you asked us to call and then confirmed it.

7Who inside the company sees your clinical record

7.1Your clinical records are readable from the staff console and from your own account, and nowhere else. The staff console is a separate website with a separate sign-in, and no third-party code is permitted to run on it under any circumstances.

7.2Every query for a clinical record names your member reference in the database statement itself, rather than fetching a wider set and filtering afterwards. That is a small distinction with a large consequence: a future change cannot accidentally stop discarding somebody else's row, because somebody else's row is never fetched.

7.3If the permission record cannot be read, or cannot be verified, a clinical action is refused rather than allowed. We would rather stop than proceed on a permission we cannot evidence.

8Analytics and advertising

8.1No third-party analytics, advertising or session-replay code runs on this product today. No Google, Meta, LinkedIn or TikTok tag is loaded on any page, there is no heatmap tool, and nothing records your screen. That is a statement about the code that runs in your browser, and about nothing else.

8.2It is not a statement that those companies receive nothing. Version 1.0 of this notice made the tag point and stopped there, and an ordinary reader took it to mean Meta gets nothing from us. Meta does get something. If you book a call, the WhatsApp confirming it reaches you through Meta, and your mobile number goes with it — through WTF Labs first, as clause 6 sets out. That is the only thing any of those four companies receives from us, it happens only because you asked for a call, and it is a delivery rather than an advertising signal: no tag, no audience upload, no conversion, no matching of your number to a profile.

8.3Our own product measurement cannot carry a health fact, and not because we are careful with it. An event has no field capable of holding a sentence — the available shapes are numbers, durations, flags, identifiers and positions in a list. An answer to a question is recorded as which option you picked, never as the words on it. A second check rejects anything that looks like the name of a condition. Query strings are stripped off the page address before it is recorded, because a link carrying a condition in the URL is the exact disclosure this is built to prevent.

8.4Measurement is off unless you turn it on, permission is checked before anything else happens, and an event refused for want of permission is counted rather than held. A queue that empties the moment you say yes is consent deferred, not consent respected.

8.5For campaigns we keep six things from a URL and nothing else: the five standard utm values and our own variant tag. The list is closed, so a parameter somebody invents is dropped rather than stored. A value containing seven or more digits in a row is rejected by the database even under an allowed name, because that shape is how a phone number ends up in an analytics field.

9Your rights, and the route to each

9.1Six rights, and for each one the route you actually take today. Where we can do it in the product, the route is a control. Where we cannot, the route is asking us — and we say which is which rather than presenting all six in the same voice.

9.2Being honest about that difference matters more than looking capable. Four of these six need a person at our end, and implying otherwise would start a clock nobody is watching.

Withdraw a permission

You can do this yourself

You can take back any permission you gave, and it has to be as easy to take back as it was to give.

Sign in and open Your data. Each permission has its own Withdraw button, and withdrawing one does not touch the others. Nothing is emailed and nobody has to approve it.

Where: app.metaboliq.wtf, on the Your data screen

Get a copy of what we hold

You have to ask us

You can ask what personal data we are processing about you, and what we have done with it.

You have to ask us, because we have not built a screen that assembles it. Ask for a call back and say that is what the call is about.

Where: metaboliq.wtf/book-a-call · We answer within 30 days.

Correct something that is wrong

You have to ask us

You can have inaccurate or misleading personal data corrected, and incomplete data completed.

You have to ask us. There is no edit control for a clinical record, deliberately: a signed entry is corrected by a clinician adding an addendum, not by overwriting what was written.

Where: metaboliq.wtf/book-a-call · We answer within 30 days.

Have your data erased

You have to ask us

You can ask us to erase personal data we no longer need for the purpose you gave it for.

You have to ask us. Read the clause on erasure first, because two kinds of record in this system cannot be erased by anybody, including us, and we would rather you knew that before you asked than after.

Where: metaboliq.wtf/book-a-call · We answer within 30 days.

Nominate someone to act for you

You have to ask us

You can name a person to exercise these rights on your behalf if you die or become incapable of exercising them yourself.

You have to ask us. We hold no nomination today and no screen records one, so nothing is on file until you tell us and we write it down.

Where: metaboliq.wtf/book-a-call · We answer within 30 days.

Complain about how we handled your data

You have to ask us

You can complain to us first, and you can take it to the Data Protection Board of India if our answer does not satisfy you.

Ask for a call back and say the call is a complaint. We have not published a named officer or a mailbox, which is set out plainly in the complaints clause rather than left as an empty heading.

Where: metaboliq.wtf/book-a-call · We answer within 30 days.

10Erasure, and the two things that cannot be erased

10.1Two kinds of record in this system cannot be deleted by anybody, including us. The database refuses. It is a design decision, and the reason is worth reading before you ask.

10.2The first is the permission record. It is the evidence of what you agreed to and of the exact words you were shown when you agreed. Deleting it would delete your proof at least as much as ours, and a permission ledger that can be quietly edited is worth nothing to either of us.

10.3The second is your clinical record: a note a clinician signed, an addendum to one, a prescription, and the closure of a safety concern. A record that can be altered afterwards cannot be relied on by the next clinician who reads it, or by you.

10.4That constraint changes how we store things rather than serving as an excuse. When somebody who is not a member asks for a call, their number goes into the permission record as a fingerprint and never as a number — precisely because that record can never be deleted, and an undeletable mobile number would be an undeletable piece of personal data.

10.5So erasure here means this: we stop the processing, we erase what can be erased, and we tell you plainly what remains and why. What we will not do is accept an erasure request, delete nothing, and leave you believing otherwise.

11How long we keep things

11.1We are not going to print a retention schedule we do not run. No job in this system deletes anything on a timetable, and a policy claiming one would be a number with nothing behind it.

11.2Two periods are real, because code enforces them:

11.3Everything else is kept while it is needed for the purpose you gave it for, and erasure is the request route set out above rather than a clock.

  • What you type during onboarding is held in a signed cookie on your own device for two days, and it is refused rather than trimmed if it grows too large.
  • A sign-in code is usable for five minutes and for five attempts, and we store a fingerprint of it rather than the code.

12Children

12.1This service is for adults. Being 18 or over is a condition of using it and it is written into our terms. It is something we ask you to tell us truthfully, not something we establish: nothing in this product verifies your age against a document or against any other source, and there is no date of birth in any of our databases.

12.2There is one place a stated age under 18 stops you, and it is worth naming precisely. The safety questions during onboarding ask how old you are. An answer under 18 ends that questionnaire, is recorded as a halt, and closes every later step for as long as the halt stands — it is the third of the steps, it comes before an account exists and before anything is bought, and it is the reason nobody under 18 should be able to reach a purchase. It is still a number you typed and we took your word for.

12.3The endpoint that takes your money does not look at an age. It stands on the onboarding that sits in front of it rather than asking again, so we are not going to tell you age is checked at the moment you are charged, because it is not.

12.4A later onboarding screen asks your age again, beside a list of identity documents, and tells you on the spot what an under-18 answer would mean. That screen submits nothing and stores nothing. No identity provider exists behind it yet, and the screen says so on its own face rather than pretending. When one exists, this clause will say what it checks.

12.5There is no route into this programme with a parent's permission, deliberately. We have not built one, and we would rather say so than leave an under-18 reader to assume a pathway exists.

12.6The permission ledger will not record a permission for anyone marked as under 18 without a guardian, and it refuses marketing and behavioural advertising for a minor even when a guardian asks for it — a guardian cannot authorise either of those, so the software does not let one try. Read that as the floor if a check ever arrives rather than as a check running now: the rule fires on a person the system has marked as a minor, and nothing in the product marks one.

12.7If you are under 18, or you are a parent or guardian who believes a child has signed up, ask us to ring you back and say that is what the call is about. That reaches a person. It is the same route as every other request on this page, and it is what we actually have rather than a control we would like to describe.

13Paying is not treatment approval

13.1When you pay, the money is held rather than taken. A clinician then decides whether treatment is appropriate. Only after an approved clinical decision can the payment be captured, and the database will not accept a captured payment without one.

13.2That is the same undertaking as the first clause of our terms, enforced rather than promised. If the decision goes the other way, the hold is released.

13.3The payment record and the clinical decision are deliberately kept apart. What is stored beside a payment is that a decision was made, when, and by whom. It does not name a condition or a medicine.

14Medicines, and what a public page may say

14.1Medicines used in metabolic care in India are prescription-only under Schedule H of the Drugs and Cosmetics Rules. Advertising a prescription medicine to the public is not lawful here, whatever the wording.

14.2So no public page on this site names one, and that is enforced by the build rather than by a review: a page naming a molecule or a brand fails to compile. Conditions, symptoms and tests are lawful to name, and we do name those.

14.3There is a privacy consequence worth stating. Nothing we send you names a medicine either, for the same reason a notification never carries a result: the message is read by whoever is holding the phone.

15Complaints, and the gap we are not hiding

A complaint about how we have handled your data comes to us first. If our answer does not satisfy you, you can take it to the Data Protection Board of India.

We have not published a grievance officer’s name, a direct line, or an address to write to. There is no mailbox behind this page, and we are not going to print one that nobody is reading. This is a gap in what we have built rather than a position we hold, and it will be filled in here when it is filled in.

Until then the one route to a person is to ask us to ring you back, and to say on the form that the call is about your data. That reaches somebody. It is thinner than a named officer, and it is what we actually have.

Ask us to call you

16Changes to this policy

16.1This is version 1.1. When it changes we will publish a new version with a new date and say what moved, and earlier versions stay available on request.

16.2A change here does not retrospectively change what you agreed to. Every permission you gave is tied to a fingerprint of the exact words you were shown at the time, so an old permission stays provable against the old text instead of being quietly reinterpreted under the new one.

16.3This is a plain-language document written to be read. It is not a substitute for legal review, and the final governing text is subject to counsel.

Our terms cover what you are buying, refunds, and complaints about care. Read the terms.