Clarifying the hacker’s claim that the app had fetched user locations on a few occasions, the government stated that it fetches the user location and stores them on the server in a “secure, encrypted, anonymised manner".
“The app stores an encrypted signature when you come in proximity with other registered devices. This interaction information is not pushed to the server unless you turn COVID-19 positive. While all unique interaction stored is only for 30 days while the data on the server is deleted in 45 days for non-risk users and 60 days from the data of cure for COVID-19 positive patients,” it stated.
The government has also stated that user data location is used, in case a person has tested positive, only to map places they visited in the last 14 days for sanitisation and the testing of people to prevent the further spread of the disease.
“We have been continuously testing and upgrading our system and team Aarogya Setu assures that no data or security breach has been identified,” the statement read.