Arogya

Privacy Policy

Version 1.0  ·  Effective: 19 May 2026  ·  Governing law: India

Plain-language summary: Arogya stores your family's health documents and extracted health data to help you organise and review medical records. Your data lives in your own Google Drive (original files) and on our India-hosted servers (extracted values). We use Anthropic's AI to read documents. We never sell your data, never use it for advertising, and never share it with anyone outside the processors listed below. You can delete everything at any time.

1. Who We Are

Arogya is a personal personal health records management application available at ayur-arogya.com. It is operated by Kiran G R as a personal technology project. For all privacy matters, contact: support@ayur-arogya.com.

Under India's Digital Personal Data Protection Act 2023 (DPDP Act), Arogya is the Data Fiduciary — the party that decides what personal data is collected and why. You (the account holder) are the Data Principal.

2. What Data We Collect

2.1 Data you provide directly

2.2 Data extracted automatically

When you upload a health document, we send it to Anthropic's AI API for processing. The AI extracts:

This extracted data is stored on our servers and displayed on your health dashboard.

2.3 Technical data

3. Legal Basis for Processing

Under the DPDP Act 2023 and IT Act 2000 SPDI Rules 2011, we process your health data on the basis of your explicit consent given during onboarding. All health data is Sensitive Personal Data or Information (SPDI) under the SPDI Rules and receives the highest protection available under Indian law.

By creating a workspace and ticking the consent box, you confirm you have the authority to upload health records for yourself and the family members you add, and that you consent to Arogya processing this data for the purposes described in this policy.

4. How We Use Your Data

PurposeData used
Display your health records on the dashboardExtracted metrics, findings, profiles
Answer health questions via Ask Arogya chatExtracted metrics and findings for the queried member
Generate vaccination schedules and health alertsDate of birth, vaccination history, flagged metrics
Send Telegram remindersReminder text, Telegram chat ID
Attribute uploaded documents to the right family memberPatient name on document, age, sex, family member profiles
Maintain your session and keep you logged inGoogle account email, session token
Detect and fix processing errorsServer logs (no health values)

We do not use your health data for advertising, profiling for commercial purposes, research, or any purpose not listed above.

5. Who We Share Your Data With

We share data only with the following processors, solely to provide the service:

ProcessorRoleWhat they receiveTheir privacy terms
Anthropic, PBC AI document extraction The document you upload (image or PDF bytes) is sent to Anthropic's API for text and data extraction. No extracted data is sent back to Anthropic beyond the API response. anthropic.com/privacy
Google LLC Authentication (OAuth) and file storage (Drive) Your Google identity is used to sign in. Uploaded documents are stored in a dedicated "Arogya Health" folder in your own Google Drive — Arogya can only access files it created (drive.file scope). policies.google.com/privacy
Fly.io, Inc. Server hosting Our application server and database run on Fly.io infrastructure in the Mumbai (bom) region. Fly.io does not access your health data. fly.io/legal/privacy-policy

We do not sell, rent, or disclose your data to any other third party. We do not use data brokers or advertising networks.

6. Data Storage and Security

Note on backup: Automated database backups are not yet in place (we are working on this). Your original documents are safe in Google Drive. Extracted data may be lost in a server hardware failure. We will update this notice when automated backup is implemented.

7. Data Retention

Data typeRetention period
Health records and extracted data for an active memberRetained while your account is active
Data for a deleted family memberDeleted within 30 days of member deletion
All data on account closureDeleted within 30 days of account closure request
Server access logs30 days, then automatically purged
Audit events (no health data)12 months

8. Children's Data

Arogya allows you to add family members who are under 18 years of age (minors). When you add a minor, you are required to confirm that you are their parent or lawful guardian and that you consent to Arogya processing their health records on their behalf.

We do not knowingly allow minors to create their own Arogya accounts. We do not track minors' behaviour, serve them advertising, or use their data for any purpose beyond organising their health records. When a minor in the system turns 18, we will prompt the account admin to invite them to manage their own records.

This is consistent with the DPDP Act 2023 Section 9, which requires verifiable parental consent for the processing of personal data of children and prohibits behavioural monitoring of minors.

9. Your Rights

Under the DPDP Act 2023 and SPDI Rules 2011, you have the following rights:

RightHow to exercise it
Access — view the data we hold about youYour dashboard shows all extracted health data. Email support@ for a full data export.
Correction — fix inaccurate dataEdit member profiles via the web dashboard. For extracted metric corrections, contact support@.
Erasure — delete your dataDelete individual members from the dashboard (data erased within 30 days). To close your account and delete all data, email support@.
Withdrawal of consent — stop processingEmail support@. We will close your account and delete all data within 30 days.
Grievance — complain about how we handle your dataContact our Grievance Officer (details below). We will respond within 30 days.

10. Grievance Redressal

As required under the IT Act 2000 SPDI Rules 2011 (Rule 5(9)) and the DPDP Act 2023 (Section 13), we have designated a Grievance Officer to receive and resolve complaints about our data practices.

Grievance Officer
Kiran G R
Arogya / ayur-arogya.com
Email: support@ayur-arogya.com
Response time: Within 30 days of receipt

If you are not satisfied with our response, you may file a complaint with the Data Protection Board of India (once its portal is operational under the DPDP Act 2023).

11. Anthropic and AI Processing

Arogya uses Anthropic's Claude AI to extract structured data from uploaded health documents. This means the content of your uploaded document is sent to Anthropic's servers for processing.

Anthropic's API Terms of Service state that data submitted via the API is not used to train their models by default. We have reviewed Anthropic's data processing terms and rely on them as our Data Processor. You can review Anthropic's privacy policy at anthropic.com/privacy.

Note: Document processing by Anthropic occurs on servers outside India. We have assessed this as consistent with the DPDP Act's cross-border transfer provisions for processor relationships. We will update our practices if the Government of India issues specific localisation requirements for health data under the DPDP Rules.

12. Cookies and Tracking

Arogya uses a single authentication cookie (arogya_web) to keep you signed in. This cookie is HttpOnly, Secure, and expires after 30 days. We do not use advertising cookies, analytics tracking, or third-party tracking scripts of any kind.

13. Changes to This Policy

We will update this policy when our data practices change in a material way. We will notify you of significant changes by showing a notice in the app and, where possible, via email. The version number and effective date at the top of this page will be updated with each change. Continued use of Arogya after a policy update constitutes acceptance of the updated terms.

14. Contact

Arogya Privacy Contact
Email: support@ayur-arogya.com
Website: ayur-arogya.com
Governing jurisdiction: India

This policy is governed by the laws of India, including the Information Technology Act 2000, the IT (Reasonable Security Practices and Procedures and SPDI) Rules 2011, and the Digital Personal Data Protection Act 2023.