Effective: September 2026 · Governed by India's Digital Personal Data Protection Act, 2023
Quick summary
BloodKonnect India (bloodkonnect.in) is a free blood donor matching platform operated by Amritesh Shrivastava. We plan to register as a Trust or NGO. We are based in India and serve Indian users only.
We are not a blood bank, hospital, or medical service. We connect people. That is all.
Phone number
Your account identifier and the number people call you on to coordinate a donation. You sign in with a password or your Google account; we only send a one-time code by SMS if you use the optional code-based sign-in. Required.
Google account (if you use “Continue with Google”)
When you sign in with Google, we receive your name, email address, and Google account ID to create and secure your account. This is governed by Google's own privacy policy.
Name
Shown to requestors when you accept their request, so they know who to expect. Required.
Blood group
The core matching signal. We only notify you about requests compatible with your blood group. Required for donors.
City + Pincode
We match donors to requests in the same geographic zone. Required for donors.
Date of birth
Collected from May 2026 onwards to verify you are 18 or older, as required by Indian law for blood donors. Not collected from requestors. Not editable after registration.
Email address
Optional. You can add one, or it comes from your Google account if you sign in with Google. It is the fallback channel when a push notification cannot be delivered, so it carries blood request alerts and updates about a request you accepted, including the hospital name and city. We never verify the address you type, so please check it. We do not send marketing email.
Push notification token
Stored only if you allow push notifications in your browser or device. Used to send real-time blood request alerts. You can revoke this any time from your browser or device settings.
Donation history
We track which requests you were notified about, which you accepted, when you last donated, and when you are next eligible. This stops the platform from alerting you during your post-donation rest period (90 days for whole blood).
Login timestamps and failed attempts
Stored for account security. Consecutive failed password attempts are counted and the account is locked for a period once there are too many.
What you enter when you raise a request
The patient's blood group, the hospital name, its address and pincode, the city, how many units are needed, how urgent it is, and when it is needed by. Your first name is attached to the request so a donor knows who they are helping. A request has a link you can share, and anyone holding that link sees the hospital, city, group and urgency. No phone number appears on it.
Consent and install records
The date and time you accepted the Privacy Policy and Terms, and the first time you opened BloodKonnect as an installed app. Kept so we can show what you agreed to and when.
A city or pincode mismatch flag
If the pincode you enter resolves to a different city from the one you selected, we record that mismatch for a human to look at. It never disables your account automatically, and it exists because a wrong pincode sends blood requests to the wrong place.
City waitlist entries
If we cannot serve your city yet and you ask to be told when we can, we store which city you asked about.
Reports about a donor
The requestor whose request you accepted can report you, for example for a wrong blood group or a no-show. A report records who reported whom, against which request, and any note they wrote. We read it. Fabricating a report is itself a breach of the Terms.
Referral link and signup device info
Every account gets a personal invite link. If you sign up through someone's link, we record who invited you so we can recognise the people who bring the most donors. To protect this invite programme from fake signups, we also record the IP address and browser type seen when you register. This anti-fraud information is used only for that review and is automatically deleted 90 days after you sign up (and immediately if you delete your account).
Read this before you accept a request. When you accept a blood request, your name and phone number are shown to the requestor as a "Call donor" button. This is how blood donations are coordinated. You are shown a consent screen before you accept.
Requestors cannot see your phone number before you accept. Once you accept, the requestor can call you directly. If you withdraw your acceptance, your contact details are no longer visible to the requestor.
Your phone number is never shown publicly on any donor listing or the "Find Donor" page. That page shows how many available donors a city holds for each blood group, and nothing about any individual: no name, no number, no pincode, and no way to contact anyone from it.
One page is deliberately public: a blood request's own page, so the link can be forwarded to a WhatsApp group by the person who raised it. It shows the hospital, its address, the city, the blood group and the urgency. It does not show a donor's name, a donor's number, or the requestor's number.
We use the following services to run BloodKonnect. Each receives only the minimum data needed for its job.
Supabase (Supabase Inc., USA — servers in Mumbai, India)
Our database. Stores all account data, donation records, and request history. Data is hosted in the ap-south-1 (Mumbai) region.
Vercel (Vercel Inc., USA)
Hosts the web application. Vercel keeps standard access logs (IP address, browser type, page visited) per their own privacy policy.
Google (Google LLC, USA)
Authenticates you when you choose “Continue with Google”. Google receives the sign-in request and returns your basic profile (name, email, Google account ID). Governed by Google's privacy policy.
2Factor.in, Fast2SMS and MSG91 (all India)
One of these delivers a one-time sign-in code by SMS when you use the code-based login fallback, whichever is configured at the time. They receive your mobile number and the code, nothing else. MSG91 is also the intended route for blood request alert SMS, which is not active: that needs DLT registration, and we will update this page if it goes live.
Resend (USA)
Delivers all of our email. That is the contact form, and also the alerts and updates we send you when a push notification cannot be delivered. Resend therefore receives your email address, your first name, and the blood group, hospital name and city of the request the email is about.
Sentry (Functional Software Inc., USA)
Receives crash reports when the app hits an error: the error and its stack trace, the browser and operating system, the address of the page you were on, and a trail of recent actions such as which buttons were tapped. We do not record your screen, and we do not send your blood group, phone number or health information. A page address can contain the identifier of a blood request.
Some of these services are based in the United States. Under India's DPDP Act 2023, the rules for cross-border data transfers have not yet been fully notified by the Central Government. We will update this once that happens.
We keep your data for as long as your account exists. We do not automatically delete inactive accounts.
What deleting your account does. Everything that identifies you is erased: your name, your phone number, your email address, your password, and the IP address and browser recorded at signup. Your push subscriptions and any sign-in codes are deleted outright, and any blood request you had open is withdrawn so no donor is sent to a hospital for a request nobody is waiting on. This cannot be undone and you cannot sign in afterwards.
What is kept is a record with nothing identifying left on it: the blood group, city and pincode, the date of birth, and the donation history attached to it. We keep that so a donation that was made is not erased from the platform's record of what it has done. If you want that record removed as well, write to the Grievance Officer below and we will remove it by hand.
The IP address and browser type recorded at signup, used only to prevent fake referral signups, are deleted 90 days after you register, or immediately when you delete your account.
A record that you were merely alerted about a request is deleted 30 days after that request closes, whether it was fulfilled, withdrawn or expired. Records where you accepted, donated, or were the subject of a report are kept, because those are the donation history. A request itself expires 72 hours after it is raised.
All communication between your browser and BloodKonnect is encrypted using HTTPS/TLS. Your data is stored on Supabase's infrastructure, which uses AES-256 encryption at rest.
One-time sign-in codes are valid for 10 minutes, single-use, and locked after 5 failed attempts. Passwords are hashed with bcrypt and never stored in plaintext.
As an Indian resident, you have these rights over your personal data:
To use any of these rights, use the in-app options or contact our Grievance Officer directly.
We use a single session cookie to keep you logged in. We do not use advertising cookies, tracking pixels, or analytics cookies. We do not use Google Analytics or any similar service.
The app also remembers a few things in your browser's own storage, which never leave your device and are not sent to us: whether you dismissed the install or notification prompt, so it does not ask again immediately, and whether you have seen certain one-time notices. Clearing your browser data clears all of it.
Under the DPDP Act 2023, you can raise a grievance with us. We will acknowledge your complaint within 48 hours and resolve it within 30 days.
If we make significant changes to this policy, like collecting new types of data or adding new third-party services, we will show an in-app notice before the change takes effect. Using the platform after that date means you accept the updated policy.
What changed in September 2026. Nothing new is being collected. This revision describes things that were already true and were described too narrowly before: