Khur Lite

Privacy Policy

Last Updated: June 17, 2026

Privacy Policy

Last Updated: 2026-06-17


1. Introduction

This Privacy Policy explains how LVIM Ltd, a company registered in England and Wales (Companies House no. 16842316, "we", "us", "our"), collects, uses, and protects information when you use the Khur Lite mobile application ("Application").

Data Controller: LVIM Ltd, London, United Kingdom — team@lvim.io

Regulatory Scope

This policy is designed to comply with:

  • UK GDPR and Data Protection Act 2018 (primary — operator jurisdiction)
  • EU General Data Protection Regulation (GDPR)
  • Turkish Personal Data Protection Law (KVKK, Law No. 6698)
  • California Consumer Privacy Act / CPRA (CCPA)
  • Brazil LGPD
  • Canada PIPEDA
  • Australia Privacy Act 1988

2. Our Core Privacy Architecture

Khur Lite is built on a privacy-by-design, hybrid data architecture. While we store as much sensitive data as possible exclusively on your device, some technical and medical data must leave your device to provide core features like push notifications and trial searching.

Because the data processed relates to your health and genetics, it is treated as special category data under GDPR (Art. 9) and KVKK (özel nitelikli kişisel veri).


3. Data We Collect and How It Is Processed

3.1 Data Stored Only on Your Device (Stays on Device)

The detailed health profile you create is stored locally on your device using iOS Keychain / Android Secure Storage (hardware-backed encrypted storage). This detailed profile is never transmitted to our servers. Note: when you choose to contact a researcher, some of these details (for example your name, diagnosis, and medications) are included in the outreach email that you send yourself from your own device — see §3.2.C.

  • Full name
  • Age and gender
  • Current medications
  • ECOG activity level and care setting
  • Biomarker details (other than the core genetic subtype used for matching)
  • Treating physician/clinic name
  • Search history
  • List of clinical trials you have contacted

3.2 Data That Leaves Your Device

To make the Application work, the following data is transmitted from your device:

A. Diagnosis and Genetic Subtype

  • To our backend (MongoDB/Railway, US): Your diagnosis (MeSH code) and core genetic subtype are sent to our backend to route trial alerts. This data is stored pseudonymously, keyed only to a random device identifier (installationId). It is not linked to your name, email, or account on our servers.
  • To Google Firebase Cloud Messaging: Your diagnosis/subtype is hashed (e.g., using SHA-256) and sent to Firebase as a push-topic to deliver relevant trial notifications to your device.
  • To ClinicalTrials.gov (US Government): Your diagnosis/subtype is sent as search terms (along with your device IP address) directly to the ClinicalTrials.gov API when you perform a search.

B. Account Data

  • Your email address, account ID (Firebase UID), user role, subscription plan, and records of the policy versions you have accepted are stored on our backend servers in the US.

C. Outreach Emails

  • When you choose to contact a clinical trial researcher, the Application builds an email draft on your device using the details you entered (name, diagnosis, medications, etc.). The Application then opens your native mail app to send the email directly to the researcher. We never receive, view, or store these outreach emails.

D. Location / City Search

  • When you search for trials by city or location, the city/location term you enter is sent to our backend to return matching results. We do not continuously track your device location.

3.3 Third-Party Processors

We use the following third-party services, all of which involve cross-border data transfer to the United States:

Service Data Processed Purpose
Google Firebase Firebase UID, email (Auth), Hashed topic, Device push token (FCM) Authentication and push notifications
Railway / MongoDB Atlas Server-side data listed in §3.2 (Pseudonymous diagnosis, Account data) Backend hosting and database
ClinicalTrials.gov (NIH) Search query parameters, Device IP address Fetching trial listings (read-only)
Resend Your email address Sending transactional emails (e.g., login links)
RevenueCat Your account ID and purchase transaction data Subscription management
Apple / Google Payment information In-app purchase billing

Sign in with Apple — relay email: If you use "Hide My Email," we only receive the private relay address.

We do not sell, rent, or share your data with any third party for advertising or marketing purposes.


4. Consent and Withdrawal

By accepting this Privacy Policy and the Terms of Service when you first use the Application — and again when we notify you of material changes — you consent to the processing described in §3, including the processing of your special category health data (diagnosis and genetic subtype) to deliver clinical trial alerts and search. You may withdraw consent at any time by unsubscribing from alerts or removing your condition in the Application's settings; this stops further processing and removes the pseudonymous diagnosis record from our backend servers. You may also delete your account, which removes all associated data from our systems except records we must retain for legal compliance (see §7).


5. Push Notifications

If you grant notification permission, your device's push token is registered with Google Firebase Cloud Messaging (FCM) so we can send you alerts about new or updated clinical trials matching your hashed diagnosis topics.

  • You can withdraw notification permission at any time via your device Settings.
  • Your push token is stored by Firebase, not by us directly. See Firebase Privacy Policy.

6. Guest (Unregistered) Users

You may use the Application without creating an account. In this case:

  • A unique device identifier (installationId) and Firebase UID are assigned to your device session.
  • Your pseudonymous diagnosis (MeSH code) is linked to this installationId on our backend to deliver push notifications.
  • No personally identifiable information (like email) is linked to this identifier.

7. Data Retention

Data Retention Period
Account data (UID, email, plan) Until you delete your account
Pseudonymous diagnosis data Until you delete your account or unsubscribe; inactive device records are subject to periodic automatic cleanup.
Policy consent records Retained to evidence consent for legal compliance.
Push token / Hashed topics Until you revoke notification permission or delete your account
On-device detailed profile Until you delete the Application from your device

When you delete your account, associated data is removed from our servers promptly; any residual records are then removed by automatic cleanup, except consent records retained for legal compliance.


8. International Data Transfers

Our backend infrastructure and third-party processors are hosted in the United States. By using the Application, your data (as described in §3) is transferred from the UK/EU/Turkey to the United States. Our third-party processors publish their own data-transfer safeguards under their respective terms.


9. Third-Party Services — Privacy Policies


10. Your Rights

UK and EU Users (UK GDPR / EU GDPR)

You have the right to:

  • Access — request a copy of the data we hold about you
  • Rectification — ask us to correct inaccurate data
  • Erasure — ask us to delete your data ("right to be forgotten")
  • Restriction — ask us to pause processing in certain circumstances
  • Portability — receive your data in a structured, machine-readable format
  • Object — object to processing based on legitimate interests
  • Withdraw consent — where processing is based on consent, withdraw it at any time

To exercise these rights, contact team@lvim.io. We will respond within 30 days.

You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk, or the relevant EU supervisory authority in your country.

Turkish Users (KVKK Article 11)

If you are resident in Turkey, you have the right to:

  • Learn whether your personal data is being processed
  • Request information about the purpose and use of processing
  • Know whether your data is transferred to third parties domestically or abroad
  • Request correction if your data is incomplete or inaccurate
  • Request deletion or destruction of your data
  • Object to outcomes arising from automated processing that affect you
  • Claim compensation for damage suffered due to unlawful processing

To exercise KVKK rights, contact team@lvim.io. You may also apply to the KVKK Board (Kişisel Verileri Koruma Kurumu) at kvkk.gov.tr.

California Users (CCPA / CPRA)

If you are a California resident, you have the right to:

  • Know what personal information we collect and how it is used
  • Request deletion of your personal information
  • Opt out of the sale or sharing of personal information — we do not sell or share your personal information
  • Non-discrimination for exercising your privacy rights

To submit a CCPA request, contact team@lvim.io.

Brazilian Users (LGPD)

You have the right to confirmation of processing, access, correction, anonymisation or deletion, portability, and information about third-party sharing. Contact team@lvim.io.

Canadian Users (PIPEDA)

You have the right to access your personal information and challenge its accuracy. Contact team@lvim.io.

Australian Users (Privacy Act 1988)

You have the right to access and correct personal information we hold about you. Contact team@lvim.io.


11. Children's Privacy

The Application is not intended for children under 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal data, contact team@lvim.io and we will delete it promptly.

Users aged 13–17 may use the Application only under parental or guardian supervision.


12. Security

We implement industry-standard security measures to protect data stored on our servers, including:

  • TLS encryption for all data in transit
  • Encryption at rest for database records
  • Access controls limiting who can access production data
  • Firebase security rules restricting data access to authenticated users

For health data stored on your device, security is provided by iOS Keychain / Android Secure Storage — the encrypted, hardware-backed credential storage on your device. Your detailed health profile is stored using this mechanism and is not accessible to other apps or to us. We recommend using a device passcode or biometric lock to further protect this access.


13. Changes to This Policy

When we update this Privacy Policy, we will update the "Last Updated" date at the top of this document. For material changes, we will notify you via an in-app prompt on your next launch, and you will be asked to review and acknowledge the new version before continuing to use the Application.


14. Contact and Complaints

LVIM Ltd London, United Kingdom Email: team@lvim.io

For UK users, you may also contact the ICO: ico.org.uk/make-a-complaint For Turkish users, you may contact the KVKK Board: kvkk.gov.tr For EU users, contact the supervisory authority in your country of residence.