Privacy

What we do with your family’s health records.

Last updated 29 August 2026

The short version, and the rest of this page only elaborates on it:

· Your records are yours. We do not sell them and we do not show them to advertisers.

· They are stored in India, on our own servers.

· Nobody outside your family sees them unless you share them, and you can withdraw that the same second.

· The public marketing pages load Google Analytics and the Meta pixel; the app itself, where your records live, loads neither. In the EEA, the UK and Switzerland we ask before either loads.

· We count records into published population statistics — never your name, never your file, never a figure covering fewer than ten families — and one switch in Settings leaves you out.

· You can export everything as ordinary files, or delete everything, at any time, without asking us.

1 · What we hold

Only what you or someone in your family puts in, plus the minimum needed to run an account. In the language of the Digital Personal Data Protection Act, 2023, almost all of it is personal data about health, which is treated as sensitive throughout.

CategoryExamples
AccountMobile number or email address, your name, preferred language, and — if you sign in with Google — the name, email address and profile picture Google returns.
FamilyThe people you add: name, date of birth, relationship, blood group, and whether they have their own login.
RecordsPhotographs and files of prescriptions, lab reports, discharge summaries and scans; the text read out of them; medicines and schedules; vitals and lab values; visits, admissions and vaccinations.
RecordingsAudio of consultations you choose to record, the transcript, and the notes extracted from it.
InsurancePolicy documents, sums insured, renewal dates, and the claim files assembled from your records.
PaymentsWhat you bought, when, and the payment reference. We never see or store your card, UPI ID or bank details — those go directly to the payment gateway.
TechnicalSign-in times and IP address for security, device type, error logs, and — if you allow notifications — an anonymous push token from your browser or phone.

2 · Why we hold it

To provide the service you asked for: to keep a record you can find again, remind you about doses and due dates, read your reports, chart the same test over years, check what your policy covers, and tell you what a medicine should cost. We also keep enough to bill you correctly, to keep the account secure, and to meet legal obligations.

One further purpose, added in August 2026 and set out in full in section 8: we count records into population statistics that we publish. Counts across everybody, with every figure covering fewer than ten families withheld — and a switch in Settings that leaves your family out of them entirely.

We do not sell your records, show them to advertisers or data brokers, or use your health records to train anybody’s AI models. We do not build a profile of you for anyone else’s purposes. Publishing a statistic about ten thousand people is a different act from either of those, and it is the only one of the three we do.

Two honest qualifications on that. Our public marketing pages — the front page, blog posts, feature pages — load Google Analytics and the Meta pixel to see which of them people find useful; those pages have no health data on them, and every page inside the app, where your records live, loads neither. Section 4 sets that out in full. And separately, the AI providers in section 6 receive the text and images described in section 7 — they are processors we pay to do a job on our behalf, contractually barred from selling or advertising against what they see, but they are outside India and worth naming plainly.

3 · Where it is stored

On servers in India — specifically Mumbai. The database and the files you upload — every photograph, report and recording — stay there.

Two things leave: the text and images sent to the AI providers described in section 6, and payment details, which never reach us at all because they go straight to the gateway. Both are set out below rather than buried, because “stored in India” would otherwise be a half-truth.

If you are in the EEA, the UK or Switzerland this is a restricted transfer under the GDPR: India has not been found by the European Commission to provide a level of data protection equivalent to yours, and we do not have standard contractual clauses in place with ourselves (there is no separate corporate entity to sign them with). We rely on your explicit consent given at signup — the basis GDPR Article 49(1)(a) provides — and section 12 sets out what that means, including that Indian authorities may access data under Indian law and that the remedies open to you there may be weaker than the ones your own courts and regulator provide.

4 · The public site, and its trackers

Two things load on the public marketing pages — the front page, blog posts and the feature pages — and nowhere else:

  • Google Analytics tells us which of these pages people find useful. It stores an identifier on your device and sends it, with the URL and an IP address, to Google.
  • The Meta pixel lets us see whether an ad on Facebook or Instagram brought somebody here. It stores an identifier on your device and sends the same shape of information to Meta.

Neither runs inside the app. The check happens before the script is fetched, not inside it, so on any page that holds a name, a medicine or a report there is no request to Google or Meta at all — not blocked, never made. That includes the members area, the documents vault, the assistant, the scribe, the settings page and the console.

In the EEA, the UK and Switzerland we ask before either loads. The banner offers Accept and Reject as one click each — same button, same width — with refusal listed first. Nothing is fetched from Google or Meta while a visitor has not answered, so a first paint in Berlin sees the banner and no third-party requests. A stored refusal keeps them off on every later visit until it is changed. Outside those countries the trackers load by default on the public pages, which is the behaviour this app has always had. Anywhere in the world, the Cookie settings link in the footer opens the same choice — a refusal stored from there stops the trackers everywhere, and a consent granted from there allows them everywhere. An explicit answer always wins over the regional default.

5 · Who can see it

  • You and your family. A family shares one file. An adult member with their own login sees the family’s records; a member can also choose to keep their own records private from the rest.
  • A doctor you grant access to. Only after you grant it, only what you selected, and only until you revoke it — which takes effect immediately, not at the end of a session.
  • Anyone holding a share link you created. These expire on a date you set, and can be revoked earlier.
  • Us. Our staff do not browse records. A small number of administrators can reach account-level information to provide support, investigate abuse or fix a fault, and every such access is written to an audit log that records who looked, at what, and when.

The database enforces this in the database itself, not only in the application: rows are isolated per family, so a bug in one screen cannot show one family another family’s records.

6 · Who else touches it

We use a small number of processors. Each does one job, receives only what that job needs, and is bound to use it for nothing else.

ProcessorWhat it doesWhat it receives
Sarvam AI (India)Transcribes consultation recordings in Indian languagesThe audio you recorded
Deepgram (USA)Transcription fallbackThe audio you recorded
DeepSeek (China)Extracts medicines and results from text, answers assistant questions, drafts summariesText from your documents and the health context described in section 7
Google Gemini and OpenAI (USA)Read photographs of prescriptions, lab reports and policy schedules. Either may serve a given request — if one is unavailable, the other is tried.The image you uploaded
Cashfree Payments (India)Takes paymentYour name, contact and the amount. Card and UPI details go to them, never to us.
GoogleOptional sign-inOnly what you approve when you connect it

Please read this one carefully. The AI providers above — DeepSeek in China, Gemini and OpenAI in the United States — process data outside India. Everything else, including every file you upload and the database itself, stays here.

If you would rather no part of your records be processed abroad, do not use the assistant, the automatic reading of reports and prescriptions, or the scribe. The record-keeping, reminders, sharing, insurance wallet, vaccination tracking and medicine pricing all work without them.

7 · What the AI sees

When you ask the assistant a question, we send it a summary of the selected person’s record — current medicines, allergies, conditions and recent results — because an answer without that context is worth very little. When you upload a report, we send the text of that report. When you record a visit, we send the transcript.

We do not send your name, phone number, email address or your account identifier with these requests.

AI output can be wrong. Every summary, extracted medicine and answer is shown to you for review before it is treated as part of your record, and none of it is medical advice. Check anything that would change a dose with the doctor who prescribed it.

8 · Research and statistics

We look at the records in this app as a population, and we publish what we find. Questions like: how often is a medicine actually taken rather than just prescribed; how many families use Ayurveda alongside allopathic medicine; what reasons people give for stopping a drug; whether a marker like HbA1c moves after a medicine is started. These are questions India’s health data cannot currently answer, and answering them is part of why this app exists.

This is counting, not reading. What we work with are totals across everybody:

  • No individual records. Nobody browses your file for research. The figures are produced by counting, and a count is all that comes out.
  • Nothing identifiable. No name, no phone number, no email address, no account identifier, and no date of birth appears in any of it. Where location matters we use the first three digits of a pincode — the postal district, which is public geography — and never the full pincode.
  • Never a small number. Any figure covering fewer than ten families is withheld rather than published. This is the rule that matters: a rare medicine in a small town could otherwise point at one household, and one household is a person.
  • No dataset leaves. There is no export button on these figures and no file to hand anybody. What can be shared is a published number or chart, not rows.
  • Not for advertising, not for insurers. We do not sell these figures to advertisers or data brokers, and we do not give an insurer anything that could affect your premium or your claim.

Section 17(2)(b) of the Digital Personal Data Protection Act, 2023 provides for processing for research and statistical purposes, and an aggregate spanning ten or more families is not information about an identifiable person at all. So we could do this without asking. We would rather you were able to say no.

Settings → Research has one switch. Turn it off and your family is left out of every figure described above, from the next time they are calculated. Nothing else about the app changes, no feature is withdrawn, and it costs you nothing.

There is nothing to delete afterwards: these figures are calculated fresh each time they are looked at and no extract is kept, so being left out of the next calculation is the whole of being left out.

To be clear about what this section is not: it does not mean your records are used to train AI models. They are not, and section 2 says so without qualification. Nor does it mean researchers outside medicalfile.in get access to your file — the figures above are the only thing that exists to share.

9 · Recordings and consent

Recording a consultation is never automatic. Before the first recording you are shown what is being recorded and asked to confirm that everyone present has been told, and that confirmation — its wording, its version and the language you read it in — is stored with the recording.

Recording other people has legal consequences that vary. Tell the doctor and anyone else in the room before you start. If you are asked to stop, stop.

You can delete a recording, its transcript, or both, at any time.

10 · How long we keep it

Nothing you upload expires because it got old. What starts a clock is the account going unused, and we do not delete anything quietly:

  • While you use the app, your records are kept. A report from five years ago is treated exactly like one from this morning.
  • If the account goes unused for a year, we freeze it. Nothing is deleted at that point: we build you a download of everything, and we email you when it freezes, again after two days, and again after five. Records are deleted eight days after the freeze. Signing in at any time before that stops the whole process.
  • If a paid plan lapses, the allowance stops — fewer AI questions, less storage — but nothing is deleted. Your records stay for as long as you keep using the app.
  • If someone in the family has died, that account is never wound down by the timer. A record does not stop mattering because nobody opened it.
  • Audit logs and payment records are kept longer, because security and tax obligations require it.

11 · Your rights

In India these are the rights the Digital Personal Data Protection Act, 2023 gives you; in the EEA, the UK and Switzerland they overlap with the rights the GDPR gives you, and section 12 covers the parts specific to that. Everywhere, you can:

  • Know what we hold about you and who we have shared it with — this page, and the export below.
  • Correct or complete anything wrong — every record in the app is editable by you.
  • Erase what we hold, when it is no longer needed for the purpose you gave it for.
  • Withdraw a consent you gave at signup — Settings → What you agreed to. The optional marketing consent can be withdrawn on its own; the consents that let us keep your records at all — to process health data, to store it in India — cannot be honoured while the account still holds records, so withdrawing them means closing the account, and the screen says so instead of flipping a flag that would do nothing. Withdrawal never affects what was lawful before it.
  • Nominate someone to exercise these rights if you die or become incapable of doing so — email us and we will record it.
  • Complain to us, and then to the Data Protection Board of India if we do not resolve it.
  • Refuse the research use in section 8 — Settings → Research, one switch, no reason needed.

You do not need to ask us to exercise most of these. They are buttons in the app.

One honest limit on erasure. Deleting your account removes your records, so from then on nothing of yours is counted. A statistic already published — a number in a report, a chart in an article — cannot be recalled, in the same way a printed page cannot. That is only ever a total across ten or more families with nothing identifying anybody in it, which is precisely why it can be published at all.

12 · If you are in the EEA, the UK or Switzerland

Everything above applies. This section adds what is specific to the GDPR (and its UK and Swiss equivalents), which is:

Who we are. medicalfile.in is operated as a sole proprietorship based in India. There is no separate EEA or UK entity and no representative appointed under GDPR Article 27 — we serve people in the EEA and the UK, so if you need to raise a data-protection matter with us, write to contact@medicalfile.in and a person reads it.

Legal bases.

  • For your health records — everything you upload, the readings we extract, the transcript from a scribe recording — we rely on your explicit consent under Article 9(2)(a), given at signup and recorded per purpose.
  • For the account itself — creating and running it, sending you the transactional emails you need to receive to use it — the necessary basis is Article 6(1)(b), performance of the contract you asked us to provide.
  • For product email about new features, we rely on the separate, optional consent ticked at signup under Article 6(1)(a); you may withdraw it at any time from Settings.
  • For Google Analytics and the Meta pixel on the public site, we rely on the consent the banner asks for — see section 4.
  • For the aggregate research described in section 8, we rely on the safeguards in Article 89(1): statistics never fall below ten families, no direct identifiers ever enter the calculation, no dataset is produced or shared, and the Settings switch removes you from the next calculation.

International transfer. Storing your records in India, described in section 3, is a transfer to a country the European Commission has not recognised as providing an equivalent level of protection, and for which we do not have standard contractual clauses in place. The Article 49(1)(a) derogation — your explicit consent, given after being told the risk — is the basis, and the risk you consented to is that Indian authorities may lawfully access data held in India, and that the rights and remedies open to you there differ from those in the EEA. If you would rather not consent to this transfer, do not create an account: we cannot host your records anywhere else.

Additional GDPR rights. On top of the rights listed in section 11, you have:

  • Data portability under Article 20. The Export button in Settings produces a machine-readable copy of everything you have added — section 13.
  • Restriction of processing under Article 18, and to object under Article 21. In practice, withdrawing the relevant consent achieves both: turning off research statistics stops the aggregation, and closing the account stops everything.
  • Complaint to a supervisory authority under Article 77. Your home country’s data-protection authority is the right first stop; the Data Protection Board of India is the corresponding body here. We would rather hear from you first, but there is no requirement to.
  • No solely automated decisions. We do not make decisions with legal or similarly significant effects about you using automated processing.

13 · Exporting and deleting

Export. Settings → Export gives you every report, note, scan and recording as ordinary files, plus your records as data you can read elsewhere. There is no fee and no waiting period.

Delete. Settings → Delete my account removes your family’s records, the files behind them, and the account. Deletion is permanent and we cannot undo it, so export first if you want a copy. Backups are overwritten on their own cycle within 30 days; audit and payment records are retained as described above.

If you cannot reach the app, email contact@medicalfile.in from your registered address and we will do it for you.

14 · Children

The account holder is an adult who is responsible for the family file, including records they add for their children — which is the ordinary case here, since vaccination tracking is one of the reasons people use this.

We do not knowingly allow anyone under 18 to create their own account, and we do not use children’s data for tracking, profiling or advertising of any kind.

15 · Security

  • Traffic is encrypted in transit, and files are stored on servers we control.
  • Sign-in is by one-time code or Google — there is no password for anyone to steal or reuse.
  • Family isolation is enforced by the database, not only by the application.
  • Administrative access to accounts is recorded in an audit log.

No system is perfectly secure. If a breach affects your data we will tell you and the Data Protection Board, as the Act requires. If you find a vulnerability, please write to contact@medicalfile.in — we will not pursue anyone who reports one in good faith.

16 · Changes, and how to reach us

If we change this policy in a way that materially affects you, we will tell you in the app or by email before it takes effect, rather than quietly changing the date at the top.

Questions, requests or complaints: contact@medicalfile.in. A person reads them. We reply within one working day, and to a formal DPDP request within the period the Act allows.

Read the terms →