Privacy Policy

Pre-release draft · Last updated: July 30, 2026

This pre-release notice explains the intended handling of personal and health information. It must be completed with deployment-specific processors, regions, retention periods, and operator details before commercial launch.

1. Information We Collect

We collect information you provide directly to us, such as: • **Account Information**: Email address, adult-use attestation, and account-security fields when you create an account • **Medical Documents**: Prescriptions, lab reports, and other medical documents you upload for analysis • **Usage Data**: Service events needed for security, reliability, and product operation • **Device Information**: Browser and device information included in standard service logs Uploaded records and the information extracted from them may form part of your health timeline. The production data inventory, optional fields, and retention periods must be published before commercial launch.

2. How We Use Your Information

Your information is used solely to: • Organize medical documents and create a private machine draft • Route clinical interpretations for verified-doctor review before patient release • Support the source-record timeline, patient-authored metadata, visit brief, and doctor-gated review workflow • Communicate service and support information through an approved channel • Comply with legal obligations We never use your data for: • Selling to third parties • Targeted advertising • Profiling for non-health purposes

3. Data Security

The application includes authentication, role checks, row-level database policies, upload validation, rate-limit support, and audit-oriented workflow fields. Production security depends on the deployed infrastructure and providers. Before commercial launch we will publish the in-scope encryption, access-control, logging, retention, independent-assessment, and incident-response evidence. We do not claim end-to-end encryption, India-only hosting, certification, or a completed independent audit from application code alone.

4. Data Sharing

We share your information only in these limited circumstances: • **Assigned Doctor**: When the governed review workflow authorizes an eligible doctor to access the applicable source record • **Service Providers**: Contracted hosting, database, storage, model, observability, or support providers needed for features enabled in the selected deployment • **Legal Requirements**: When required by law or to protect rights and safety We do not sell personal data. A deployment-specific subprocessor list, processing purpose, and region register must be available before real health data is accepted.

5. Your Rights

Subject to applicable law and verified identity, a deployed operator may need to support: • **Access**: Operator-verified access to personal data held by the selected deployment • **Correction**: Correction of inaccurate personal data • **Erasure**: Identity, scope, retention, and downstream-system review before any erasure outcome • **Grievance**: A published contact and response process for concerns • **Withdraw Consent**: Change optional consent preferences, subject to the purpose and consequences shown in the product This pre-commercial repository does not accept new access, correction, erasure, grievance, or nominee submissions. It preserves patient-scoped read-only history for previously recorded requests and sharing events. No direct data-export or automatic-erasure executor is shipped. Reintroduction requires a verified operator contact, published response period, identity and authority checks, notice, revocation where applicable, tested fulfilment, lawful-retention review, downstream-processor procedures, and deployment evidence.

6. Legal and standards posture

MedicalRecords.in is being designed with India’s applicable data-protection, cybersecurity, telemedicine, health-data, and medical-device obligations in view, including the phased commencement of the DPDP Act and Rules. The interoperability target is the published ABDM FHIR Implementation Guide. This notice does not claim certification, regulator approval, a medical-device class, or complete compliance. Those conclusions require a defined deployment, operating procedures, contracts, and qualified external review.

7. Children's Privacy

The pre-commercial service is intended for adults. No family, child, or guardian account flow is offered. We do not knowingly accept a child’s personal data without a separately approved, verifiable parent or guardian workflow. No operational privacy-reporting channel is published in this build; a deployed operator must provide one before accepting real patient data.

8. Changes to This Policy

We may update this Privacy Policy periodically. The operator must define the applicable notice channel, effective date, and consent consequences before commercial launch. Where required, we will request fresh notice or consent instead of treating silence or continued use as consent.

9. Contact Us

No operational privacy or grievance contact is published in this pre-commercial draft. The legal entity name, postal address, applicable privacy contact, grievance contact, escalation route, and response period must be inserted, verified, staffed, tested, and counsel-approved before commercial launch. Do not post personal data, health information, or a privacy request in the public GitHub issue tracker.