Arogya

Privacy Policy

Version 1.3  ·  Effective: 16 August 2026  ·  Governing law: India

Plain-language summary: Arogya stores your family's health documents and extracted health data to help you organise and review medical records. Your data lives in your own Google Drive (original files) and on our India-hosted servers (extracted values). We use AI models from providers such as Anthropic, Google, and OpenAI to read documents (see Section 5 for the current list and what each receives). We do not sell or rent your identifiable data to third parties. We may use your extracted health data to recommend relevant products and services to you, and we may use anonymised aggregate data for research and commercial purposes (see Section 4). You can delete everything at any time.

1. Who We Are

Arogya is a personal health records management application available at ayur-arogya.com. For all privacy matters, contact: support@ayur-arogya.com.

Under India's Digital Personal Data Protection Act 2023 (DPDP Act), Arogya is the Data Fiduciary — the party that decides what personal data is collected and why. You (the account holder) are the Data Principal.

2. What Data We Collect

2.1 Data you provide directly

2.2 Data extracted automatically

When you upload a health document, we send it to an AI system (currently Anthropic, Google, or OpenAI depending on document type — see Section 5) for processing. The AI extracts:

This extracted data is stored on our servers and displayed on your health dashboard.

2.3 Technical data

3. Legal Basis for Processing

Under the DPDP Act 2023 and IT Act 2000 SPDI Rules 2011, we process your health data on the basis of your explicit consent given during onboarding. All health data is Sensitive Personal Data or Information (SPDI) under the SPDI Rules and receives the highest protection available under Indian law.

By creating a workspace and ticking the consent box, you confirm you have the authority to upload health records for yourself and the family members you add, and that you consent to Arogya processing this data for the purposes described in this policy.

4. How We Use Your Data

PurposeData used
Display your health records on the dashboardExtracted metrics, findings, profiles
Answer health questions via the AI chatExtracted metrics and findings for the queried member
Generate vaccination schedules and health alertsDate of birth, vaccination history, flagged metrics
Send Telegram remindersReminder text, Telegram chat ID
Attribute uploaded documents to the right family memberPatient name on document, age, sex, family member profiles
Maintain your session and keep you logged inGoogle account email, session token
Recommend relevant products and services to youExtracted health data (used only within Arogya to select which recommendations to show; not shared with third-party ad networks)
Research and commercial analysisAnonymised aggregate data (individual users cannot be re-identified from this dataset)
Detect and fix processing errorsServer logs (no health values)

5. Who We Share Your Data With

We share data only with the following processors, solely to provide the service:

ProcessorRoleWhat they receiveTheir privacy terms
Anthropic, PBC AI document extraction (PDFs) The document you upload (image or PDF bytes) is sent to Anthropic's Claude API for text and data extraction. No extracted data is sent back to Anthropic beyond the API response. Called under Anthropic's standard commercial API terms (no training use of your data). anthropic.com/privacy
Google LLC (Drive + Sign-In) Authentication (OAuth) and file storage (Drive) Your Google identity is used to sign in. Uploaded documents are stored in a dedicated "Ayur_Arogya_AI" folder in your own Google Drive — Arogya can only access files it created (drive.file scope). policies.google.com/privacy
Google LLC (Gemini API) AI document extraction (images) + chat Images of health documents (photographed reports, scans) and the health-record context for AI chat answers are sent to Google's Gemini API. Called on a paid Google Cloud billing account under Gemini's paid-tier terms (Google does not use paid-tier prompts or responses to improve their products). ai.google.dev/gemini-api/terms
OpenAI, Inc. AI extraction for specific clinical document types Images of a small set of document types — ECGs, echocardiograms, stress tests, and consultation / OPD notes — are sent to OpenAI's API because it currently produces better results for those specific document classes. Called under OpenAI's standard API terms (no training use of API data by default). openai.com/policies/privacy-policy
Fly.io, Inc. Server hosting Our application server and database run on Fly.io infrastructure in the Mumbai, India region. Fly.io does not access your health data. fly.io/legal/privacy-policy
Tigris Data, Inc. Encrypted database backups (S3-compatible object storage) Our live database is continuously replicated to Tigris using Litestream, so that a server-hardware loss doesn't destroy your data. The backups are private (server-side encrypted) and retained for 7 days on a rolling window. tigrisdata.com/privacy
Functional Software, Inc. (Sentry) Error monitoring When the application crashes or logs an error, Sentry receives the error type, stack trace, and a build identifier so we can debug. We configure Sentry with send_default_pii=False and include_local_variables=False so that request bodies, user identities, and stack-frame values are not attached to events. A small number of internal error messages may still include short LLM output snippets used for debugging — we are working on removing these. sentry.io/privacy
Google LLC (Analytics) Product usage analytics Anonymised usage events — pages visited (with all personal identifiers removed from the address), approximate location from an anonymised IP, device type, and referring site. No health data, names, or document contents are sent, and Google's advertising / cross-device features are disabled. You can opt out in Settings → Privacy. policies.google.com/privacy

We do not sell or rent your identifiable data to third parties, and we do not use external advertising networks. If we introduce partner offers or share data with additional processors (for example, to deliver product recommendations described in Section 4), we will update this list before doing so.

5.1 Google user data — Limited Use

Arogya's access to your Google account is limited to signing you in and to the drive.file scope. drive.file lets the app create files in a dedicated "Ayur_Arogya_AI" folder in your own Google Drive and read back only the files it created there. Arogya cannot see, open, or access any other file in your Google Drive.

Arogya's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. The data we obtain through Google APIs is used only to provide and improve the user-facing features described in this policy; it is never sold, never used for advertising, and never transferred to others except as necessary to provide the service, to comply with applicable law, or in connection with a merger or acquisition. No human reads this data except with your explicit consent, for security purposes, or to comply with applicable law.

6. Data Storage and Security

Note on backup: The live database is continuously replicated to Tigris (S3-compatible object storage) using Litestream. Backups are private, server-side encrypted, and retained on a rolling 7-day window — data you delete disappears from backups within that window. Your original uploaded documents also remain in your personal Google Drive.

7. Data Retention

Data typeRetention period
Health records and extracted data for an active memberRetained while your account is active
Data for a deleted family memberDeleted within 30 days of member deletion
All data on account closureDeleted within 30 days of account closure request
Server access logs30 days, then automatically purged
Audit events (no health data)12 months

8. Children's Data

Arogya allows you to add family members who are under 18 years of age (minors). When you add a minor, you are required to confirm that you are their parent or lawful guardian and that you consent to Arogya processing their health records on their behalf.

We do not knowingly allow minors to create their own Arogya accounts. We do not track minors' behaviour, serve them advertising, or use their data for any purpose beyond organising their health records — the product-recommendation use described in Section 4 does not apply to minors' data. When a minor in the system turns 18, we will prompt the account admin to invite them to manage their own records.

This is consistent with the DPDP Act 2023 Section 9, which requires verifiable parental consent for the processing of personal data of children and prohibits behavioural monitoring of minors.

9. Your Rights

Under the DPDP Act 2023 and SPDI Rules 2011, you have the following rights:

RightHow to exercise it
Access — view the data we hold about youYour dashboard shows all extracted health data. Email support@ayur-arogya.com for a full data export.
Correction — fix inaccurate dataEdit member profiles via the web dashboard. For extracted metric corrections, contact support@ayur-arogya.com.
Erasure — delete your dataDelete individual members from the dashboard (data erased within 30 days). To close your account and delete all data, email support@ayur-arogya.com.
Withdrawal of consent — stop processingEmail support@ayur-arogya.com. We will close your account and delete all data within 30 days.
Grievance — complain about how we handle your dataContact our Grievance Officer (details below). We will respond within 30 days.

10. Grievance Redressal

As required under the IT Act 2000 SPDI Rules 2011 (Rule 5(9)) and the DPDP Act 2023 (Section 13), we have designated a Grievance Officer to receive and resolve complaints about our data practices.

Grievance Officer
Email: support@ayur-arogya.com
Response time: Within 30 days of receipt

If you are not satisfied with our response, you may file a complaint with the Data Protection Board of India (once its portal is operational under the DPDP Act 2023).

11. AI Processing

Arogya uses AI to extract structured data from uploaded health documents. This means the content of your uploaded document is sent to external servers for processing. The specific providers we use today are listed in Section 5; we may add or change providers over time as models evolve.

The AI providers we currently use (such as Anthropic and Google) publish Terms of Service stating that data submitted via their APIs is not used to train their models by default. We have reviewed their data processing terms and rely on them as our Data Processors. When we change providers we will update this policy to reflect the new list.

Note: Document processing by these AI providers occurs on servers outside India. We have assessed this as consistent with the DPDP Act's cross-border transfer provisions for processor relationships. We will update our practices if the Government of India issues specific localisation requirements for health data under the DPDP Rules.

12. Cookies and Analytics

Arogya uses a single authentication cookie (arogya_web) to keep you signed in. This cookie is HttpOnly, Secure, and expires after 30 days. We do not use advertising cookies.

We use Google Analytics to understand how the app is used — which pages are visited, for how long, and where visitors arrive from — so we can improve it. It is configured to protect your privacy: your IP address is anonymised, page addresses are stripped of every personal identifier (member, document and record IDs are replaced with placeholders) before being sent, page titles are never sent, and Google's advertising and cross-device features are switched off. No health data — no names, conditions, medications, documents or metric values — is ever sent to Google Analytics. You can turn analytics off at any time from Settings → Privacy → Usage analytics; the app works exactly the same either way.

13. Changes to This Policy

We will update this policy when our data practices change in a material way. We will notify you of significant changes by showing a notice in the app and, where possible, via email. The version number and effective date at the top of this page will be updated with each change. Continued use of Arogya after a policy update constitutes acceptance of the updated terms.

14. Contact

Arogya Privacy Contact
Email: support@ayur-arogya.com
Website: ayur-arogya.com
Governing jurisdiction: India

This policy is governed by the laws of India, including the Information Technology Act 2000, the IT (Reasonable Security Practices and Procedures and SPDI) Rules 2011, and the Digital Personal Data Protection Act 2023.