Home Privacy Policy

Privacy Policy

Effective Date: August 14, 2025
Last Updated: August 14, 2025
Governed by the DPDP Act, 2023

Your Privacy at a Glance

At Medisage, we protect your personal and health information under India's Digital Personal Data Protection Act, 2023, and build to international healthcare-privacy safeguards as a benchmark. This policy explains how we collect, use, and safeguard your data.

EMERGENCY NOTICE: For medical emergencies, call 112 (India's emergency number) immediately. Medisage provides educational insights only - not for diagnosis, treatment, or emergency situations.

Table of Contents ▼

1. Information We Collect 2. Purpose of Collection 3. Consent and Legal Basis 4. Sharing and Disclosure 5. Data Retention 6. Your Rights 7. Security Measures 8. Children's Privacy 9. International Data Transfers 10. Policy Changes 11. Contact Information

1. Information We Collect

Personal Information

  • Account Details: Name, email address, phone number
  • Profile Information: Age, gender, emergency contacts
  • Authentication Data: Encrypted passwords, login credentials

Health Information (PHI)

  • Medical Records: Uploaded documents, reports, prescriptions
  • Health Parameters: Blood pressure, glucose levels, weight, BMI
  • Blood Test Results: 22 analyzed parameters with educational trend data
  • Medication Data: Prescriptions, dosages, schedules, adherence
  • Family Health Data: Multi-profile health information for dependents

Technical Information

  • Device Data: Device ID, operating system, app version
  • Usage Analytics: Feature usage, session duration, interaction patterns
  • Performance Data: Crash logs, error reports, performance metrics
  • Location Data: Optional location services for emergency features

2. Purpose of Collection

Health Record Management

Store, organize, and provide secure access to your medical documents and health data for personal health management.

AI-Powered Educational Insights

Generate educational health summaries and reference information using advanced AI analysis for learning purposes only.

Medication Reminders

Provide timely medication reminders and track adherence to support your health management routine.

Family Collaboration

Enable secure sharing with family members and caregivers according to your permission settings.

Educational Health Analytics

Track health trends, generate educational reports, and provide data visualization for better health understanding and learning.

Service Improvement

Analyze usage patterns and feedback to enhance app functionality and user experience.

3. Consent and Legal Basis

Explicit Consent

By creating an account and using Medisage, you provide explicit consent for:

  • Collection and processing of your health data
  • AI analysis of uploaded medical documents
  • Generation of health insights and recommendations
  • Secure storage of personal and medical information

Withdrawal Rights

You may withdraw consent at any time by:

  • Accessing your account settings in the app
  • Contacting our support team at privacy@medisage.app
  • Requesting account deletion through the app
Note: Withdrawal of consent may limit or prevent access to certain app features.

4. Sharing and Disclosure

Google Play Data Safety Declaration

In compliance with Google Play's Data Safety requirements, we declare:

Data Sharing with Third Parties:
  • Analytics: We DO NOT share personal data with analytics providers
  • Advertising: We DO NOT share data for advertising purposes
  • Cloud Storage: Health data is encrypted and stored with certified cloud providers
  • AI Processing: Medical images and documents are processed by multiple third-party AI services to improve accuracy and insights. Current and future AI providers may include OpenAI (GPT), Google (Gemini), Anthropic (Claude), Microsoft Azure AI, AWS Bedrock, and other leading AI platforms. We continuously experiment with different AI algorithms to enhance service quality. Users explicitly consent to potential PHI exposure to these evolving AI services, understanding that complete anonymization may not be technically feasible across all AI processing methods.
Data Collection Purposes:
  • Health record management and storage
  • AI-powered health insights generation
  • App functionality and user experience
  • Security and fraud prevention

We Never Share For:

  • Marketing or advertising purposes
  • Sale to insurance companies or employers
  • Commercial data brokers or analytics companies
  • Social media platforms or consumer advertising
  • Purposes unrelated to your healthcare management
⚠️ Important: We DO Share Health Data for AI Processing

To generate educational insights, we process your documents with trusted third-party AI services under strict terms. This can include identifiable information in the files you upload. You can opt out in Settings → Privacy, but some features will be limited.

Limited Sharing:

Your data may be shared only in these specific circumstances:

AI Processing Services

IMPORTANT DISCLOSURE: When you enable AI features, we use third-party AI services to analyse the documents you submit:

AI Providers We Use
  • OpenAI: AI text extraction and summarisation of documents you submit after enabling AI
  • Google APIs: document, OCR and related services used by the app

If we add or change AI providers in future, we will update this notice; where the law requires, we will seek your consent before a new provider processes your data.

📋 Data Shared with AI Services
  • Medical Documents: Full images including visible PHI (names, dates, etc.)
  • Lab Results: Complete test results with patient identifiers
  • Prescription Images: Medication details with prescriber information
  • Health Records: Text and numerical health data for analysis
  • Context Information: Patient age, gender, medical history for accurate insights
🔒 Third-Party AI Service Policies

Your data is subject to the privacy policies of:

  • OpenAI: openai.com/privacy
  • Google: cloud.google.com/privacy
⚠️ AI Processing Consent & Risk Acceptance

AI analysis is optional and off by default. When you enable it, you consent to and accept the risk of:

  • Third-party exposure: The documents you submit being processed by our AI providers (OpenAI, Google)
  • Provider policies: AI providers handling and retaining data under their own policies, which are not healthcare-specific
  • Policy changes: AI providers updating their data-handling practices
  • Technical limitations: Understanding that perfect anonymisation is not always possible

User Acknowledgment:

"I understand that, when I enable AI, Medisage uses OpenAI and Google to analyse the medical documents I submit. I accept that my health information may be exposed to these third-party AI services to provide me with educational insights, and that those services operate under their own commercial terms and retention policies, not healthcare-specific agreements."

🚫 AI Processing Opt-Out

You can opt-out of AI processing, but this will:

  • Significantly limit app functionality
  • Prevent automated health insights generation
  • Require manual data entry for all health information
  • Disable blood test analysis and trending
  • Remove medication interaction checking

To opt-out: Contact privacy@medisage.app with subject "AI Opt-Out Request"

Service Providers

We work with trusted service providers under strict confidentiality agreements:

  • Cloud Storage: Encrypted storage with enterprise-grade security
  • Technical Support: Limited access for troubleshooting and maintenance
  • Security Monitoring: Infrastructure monitoring and threat detection
Family Members & Caregivers

With your explicit permission, we may share data with:

  • Family members you designate in the app
  • Caregivers with appropriate access levels
  • Emergency contacts during health crises
Legal Requirements

We may disclose information when required by:

  • Valid legal subpoenas or court orders
  • Law enforcement requests with proper authorization
  • Public health requirements during emergencies

5. Data Retention

Retention Periods

Medical Records
7 years after last access or as required by law
Personal Information
Active account duration + 1 year
Usage Analytics
2 years for service improvement
Security Logs
3 years for compliance and security

Data Deletion Process

You have the right to request deletion of your personal data at any time. Here's how:

📱 Through the App
  1. Go to Settings → Account → Delete Account
  2. Confirm your identity with password
  3. Review what will be deleted
  4. Submit deletion request
📧 By Email

Send a deletion request to: privacy@medisage.app

Include:

  • Your full name and email address
  • Subject line: "Data Deletion Request"
  • Verification of identity (account email)
⏱️ Deletion Timeline & Exceptions
Standard Deletion Process:
  • Immediate: Account access disabled
  • Within 30 days: Personal data permanently deleted from active systems
  • Confirmation: Email confirmation sent upon completion
What Remains After Deletion (And For How Long):
  • Legal Hold Data: Data subject to legal proceedings (until legal hold expires)
  • Encrypted Backups: Anonymized data in encrypted backups (up to 90 days for complete removal)
  • Security Audit Logs: Access logs without PHI (3 years for compliance)
  • Legal Compliance Records: Consent records and deletion requests (7 years as required by law)
  • Aggregated Analytics: Anonymized, non-identifiable usage statistics (indefinitely)
  • Third-Party AI Data: Data processed by AI providers subject to their retention policies
📋 Complete Retention Matrix:
Active PHI Account lifetime + 1 year Deleted within 30 days of request
Encrypted Backups 90 days rolling 90 days max after deletion request
Audit Logs 3 years Remains for compliance (no PHI)
Legal Records 7 years Required by law (consent, deletion proof)
AI Provider Data Varies by provider Subject to third-party policies
📞 Privacy Rights Contact

For all privacy-related requests and questions:

  • Email: privacy@medisage.app
  • Response time: Within 72 hours
  • Subject line format: "Privacy Request - [Your Request Type]"

6. Your Rights

Right to Access

Request a copy of all personal data we hold about you, including health records and usage information.

Right to Rectification

Correct any inaccurate or incomplete personal information in your account or health records.

Right to Erasure

Request deletion of your personal data when it's no longer necessary for the original purpose.

Right to Restrict

Limit how we process your data while maintaining your account and essential health services.

Right to Portability

Export your health data in a machine-readable format to transfer to another service provider.

Right to Object

Object to processing for direct marketing or legitimate interests while maintaining core health services.

How to Exercise Your Rights

To exercise any of these rights, contact us through:

Email: privacy@medisage.app
In-App: Account Settings → Privacy Rights
Response Time: Within 30 days

7. Security Measures

Data Encryption

  • In Transit: TLS 1.3 encryption for all data transmission
  • At Rest: AES-256 encryption for stored data
  • Databases: Encrypted at rest, with row-level access rules enforced by the database engine
  • Backups: Encrypted automated backups with secure key management

Access Control

  • Authentication: Signed-in session required for all actions (token-based)
  • Authorization: Role-based access control (RBAC)
  • Session Management: Secure JWT tokens with expiration
  • Monitoring: Continuous security monitoring and audit logs

Infrastructure Security

  • Cloud Provider: Managed cloud hosting with encryption at rest (Medisage itself holds no third-party certification)
  • Network Security: Firewalls, DDoS protection, and rate limiting at the platform level
  • API Security: Rate limiting, input validation, CORS protection
  • Compliance: Controls designed to India's DPDP Act, 2023; no third-party certification held

Data Protection

  • Isolation: User data isolation and cross-tenant security
  • Validation: Input sanitization and SQL injection prevention
  • Monitoring: Server-side request checks and audit logging
  • Incident Response: Breach-response and notification procedures being established for general availability

8. Children's Privacy

Age Requirements

Medisage requires users to be at least 18 years old or have verified parental consent. We take special care to protect children's privacy:

  • Under 13: Requires explicit parental consent and supervision
  • 13-17 years: Requires parental consent for account creation
  • 18+ years: Can create accounts independently

Parental Controls

For minors using Medisage:

  • Parents have full access to their child's health data
  • Enhanced privacy controls for sensitive health information
  • Limited data sharing capabilities
  • Additional security measures for account protection

9. International Data Transfers

Cross-Border Data Processing

Your data may be processed in countries other than your residence for:

  • Cloud storage and backup services
  • AI processing and analysis
  • Technical support and maintenance
  • Security monitoring and threat detection

Transfer Safeguards

We ensure adequate protection through:

  • Adequacy Decisions: Transfers to countries with adequate protection
  • Standard Contractual Clauses: EU-approved data transfer agreements
  • Binding Corporate Rules: Internal policies for international transfers
  • Encryption: All data encrypted during international transfers

10. Policy Changes

How We Notify You

We will notify you of significant privacy policy changes through:

  • In-App Notifications: Prominent notices in the mobile app
  • Email Alerts: Direct email to your registered address
  • Website Banner: Visible notice on our website
  • Push Notifications: Mobile push notifications for major changes

Implementation Timeline

  • Minor Changes: Effective immediately upon posting
  • Material Changes: 30-day notice period before implementation
  • Your Options: Review, accept, or discontinue service
  • Continued Use: Constitutes acceptance of updated policy

11. Contact Information

Data Protection Officer

For privacy-related inquiries and rights requests

privacy@medisage.app

Legal Department

For legal compliance and policy questions

legal@medisage.app

Support Team

For general questions and technical support

support@medisage.app

Security Issues

For reporting security vulnerabilities

security@medisage.app

Postal Address

Medisage — Privacy
Bengaluru, Karnataka, India

Our Response Commitment

  • Privacy Rights Requests: Response within 30 days
  • General Inquiries: Response within 5 business days
  • Security Issues: Acknowledgment within 24 hours
  • Data Breaches: Notification within 72 hours (if required)

Regulatory Framework

Medisage is an Indian service and our primary obligations are under Indian law. We have not completed any third-party security certification; the items below describe the standards we build to, not audits we have passed.

DPDP Act, 2023 (primary)
International healthcare-privacy standards
GDPR principles applied
ABDM / ABHA readiness planned