Privacy Policy
Swasthy Health Technologies Private Limited
Version 1.4 · Effective 30 September 2026
This Privacy Policy explains how we handle your personal data when you use the Swasthy patient app, the Swasthy doctor app, or any related service (together, the Platform).
Health information is among the most sensitive data a person has. We have written this policy to be read, not skimmed past. If anything here is unclear, write to us at the address in Section 15 and we will explain it.
1. Who we are
Swasthy Health Technologies Private Limited ("Swasthy", "we", "us") is a company incorporated in India under the Companies Act, 2013.
Our registered office, Corporate Identity Number and every contact detail are published in one place: Contact & Company Information. For data-protection matters, write to privacy@swasthy.ai.
Swasthy Health Technologies Private Limited is the Data Fiduciary for all personal data processed through the Platform in India, within the meaning of the Digital Personal Data Protection Act, 2023 ("DPDP Act"). This means we decide why and how your data is processed, and we are accountable to you and to the Data Protection Board of India for that processing.
Swasthy AI, Inc., a company incorporated in the United States, is our parent company. It provides engineering, infrastructure and artificial-intelligence services to Swasthy Health Technologies Private Limited. When Swasthy AI, Inc. handles your data, it does so only on our written instructions as a Data Processor, under a contract that imposes the same security and confidentiality obligations described in this policy. Swasthy AI, Inc. does not use your health data for its own purposes and does not sell it.
Your contract for the health service is with Swasthy Health Technologies Private Limited. Your grievances are addressed by us in India, under Indian law.
2. The laws this policy is built on
We process personal data in accordance with:
- the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025;
- the Information Technology Act, 2000, in particular Section 43A, and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules"), under which health and medical records are Sensitive Personal Data or Information;
- the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021;
- the Telemedicine Practice Guidelines, 2020 issued by the Ministry of Health and Family Welfare and the Board of Governors in supersession of the Medical Council of India, read with the National Medical Commission (Registered Medical Practitioner Professional Conduct) Regulations, 2023;
- the Health Data Management Policy of the Ayushman Bharat Digital Mission, and the Electronic Health Record Standards for India, 2016, as applied to our records architecture;
- the Consumer Protection Act, 2019 and the Consumer Protection (E-Commerce) Rules, 2020.
We also align our administrative, physical and technical safeguards with the US Health Insurance Portability and Accountability Act (HIPAA) Security Rule. See our Data Security Policy for how, and for the important limits on what that alignment means.
3. What we collect
We collect only what the service actually needs. Data is grouped below by why we hold it.
3.1 Data you give us when you create an account
- Mobile number (used as your login identity and verified by one-time password)
- Full name, age or date of birth, and gender
- City, state and PIN code
- Preferred language for consultations
3.2 Health data you give us during a consultation or in your health profile
- Symptoms you select or describe, and their duration and severity
- A voice recording, if you use voice intake, and the text transcript produced from it
- Height, weight and blood group, if you give them
- Past medical history, chronic conditions, hospital admissions and surgeries
- Current medications and known allergies
- Photographs and documents you attach, such as images of a rash, lab reports or an earlier prescription, and medical documents you save to your health profile
- Lab reports you upload for tests your doctor ordered
- Your answers to the reviewing doctor's questions, typed or spoken (for spoken answers we keep the text, not the audio)
- Your rating, your written feedback, and the reasons you give for a low rating
3.3 Data generated by the service
- The AI-generated draft assessment, differential diagnoses and draft prescription
- The reviewing doctor's diagnosis, clinical notes, modifications to the draft, and the final signed prescription
- Consultation timestamps, status, assigned doctor, specialty routing and escalation records
- The prescription PDF issued to you
- Records of any follow-up consultation and how it was linked to the earlier one
- Records of which versions of our terms and policies you accepted and when, the history of your choices about the use described in Section 6.1, and the consent we record with a consultation
3.4 Payment data
- Amount, date, status, payment method, and the payment reference and UPI transaction reference returned by our payment gateway
- Refund records and their reasons
- UPI IDs you choose to save in your profile, with the label you give each one
- Which UPI app you paid with, worked out from the UPI ID used for the payment. We do not store that UPI ID.
We do not collect or store your full card number, CVV, UPI PIN, or net-banking credentials. You enter card and UPI payment details directly into the checkout of our payment gateway, Razorpay Software Private Limited, which is authorised by the Reserve Bank of India as a payment aggregator and maintains PCI-DSS certification. We keep only the payment details listed above.
3.5 Data collected from doctors on the Platform
- Name, date of birth, phone number, email address, profile photograph and a short professional bio
- Qualifications, specialty, years of experience and languages spoken
- National Medical Commission or State Medical Council registration number, and your Healthcare Professionals Registry ID if you give it
- A photo ID (Aadhaar or PAN), your registration and degree certificates and a passport photograph, uploaded for verification. We keep these for as long as you practise on Swasthy and for 3 years after the last prescription you sign (Section 9), as evidence that every prescriber was verified. They are never used for the purposes in Section 6.1 and never sold
- Your city, state and PIN code, your clinic's name, address and contact details, your availability, and when you last had the app open
- Bank account number, IFSC, UPI ID and PAN, to pay you and deduct tax at source
- Your earnings, payouts, patient ratings and any issues you report to us
3.6 Technical data
- Device model, operating system version and app version, sent with crash and error reports
- Push notification token
- Crash reports and error diagnostics
- When you last had the app open, updated every few minutes while it is open
- A random identifier for this installation of the app, and your phone's platform
- An audit log of security-relevant actions, such as opening a health record or file, making a payment, signing a prescription, changing bank details or asking to delete your account. It records the account or consultation involved and the time, and for many actions the IP address and the app or browser used
- Request logs kept by our infrastructure provider, which include the IP address and time of each request
We do not track your location in the background, we do not read your contacts, calendar, SMS or call logs, and we do not use advertising identifiers or third-party advertising trackers.
3.7 Data collected on our website
If you join a waitlist on swasthy.ai, we collect your name, email, optional phone number and whether you are a patient or doctor (for doctors, also your state, degree and specialty), plus your IP address and basic device details to stop spam. We use this only to contact you about Swasthy, never for Section 6.1, and delete it within 12 months or sooner if you ask.
4. Why we process each category
Under the DPDP Act we must tell you the specific purpose for each item of data. We do not process your data for any purpose you have not been told about.
- Mobile number
- To authenticate you by one-time password and to contact you about your consultation
- Name, age, gender, city
- To identify you to the reviewing doctor and to print a valid prescription
- Language preference
- To route you to a doctor who speaks your language and to translate where needed
- Symptoms, history, medications, allergies, height, weight and blood group
- To generate the AI draft assessment and to give the reviewing doctor the clinical picture required to prescribe safely
- Voice recording
- To turn what you said into text, and so the reviewing doctor can listen to it while reviewing your case
- Photographs and documents
- So the doctor can see what you are describing
- Lab reports you upload
- So a doctor, usually the one who ordered the tests, can review the results
- Answers to the doctor's questions
- So the doctor has what they asked for before completing your consultation
- Rating and feedback
- To check and improve the quality of consultations
- AI draft and doctor's final record
- To produce your prescription, to maintain the medical record the law requires us to keep, and to audit the quality and safety of AI-assisted care
- Records of what you accepted, your Section 6.1 choices and the consent recorded with a consultation
- To show what you agreed to and when, and to respect your choice about Section 6.1
- Payment records
- To collect the consultation fee, issue receipts, process refunds, meet tax and accounting obligations
- Saved UPI IDs
- To keep the list of UPI IDs you saved in your profile, which you can remove at any time
- UPI app used
- To show your usual UPI app first when you pay
- Doctor registration and identity documents
- To verify that every prescribing doctor is a Registered Medical Practitioner, as the Telemedicine Practice Guidelines, 2020 require
- Doctor bank details and PAN
- To pay doctors and to deduct and deposit tax at source
- Doctor name, photograph and qualifications
- To show patients who is treating them, and to print the doctor's details on each prescription
- Doctor specialty, languages, years of experience and bio
- To offer cases to doctors with the right specialty and language, and to keep each doctor's professional profile
- Doctor date of birth, email address, city, and clinic name, address and contact details
- To verify the doctor and to contact them
- Doctor availability and when a doctor last had the app open
- To offer cases to doctors who are available, and to see which doctors are online
- Doctor earnings, payouts, patient ratings and issues reported
- To pay doctors, to monitor the quality of care and to resolve problems doctors raise
- Device and crash data
- To keep the app working and to fix faults
- Push token
- To tell you about your consultation, such as when a doctor accepts your case and when your prescription is ready, and to tell doctors about new cases
- When you last had the app open
- To see whether you can be reached during a consultation
- Installation identifier and platform
- To keep you signed in on one device at a time
- Security audit log and request logs
- To investigate misuse and faults, and to show who accessed a health record
- Website waitlist details
- To contact you about Swasthy, as Section 3.7 describes
5. The legal basis on which we process
We process your personal data on the basis of your consent, given freely, specifically and with knowledge of this policy, and withdrawable at any time.
Consent is collected as follows:
- When you create a patient account, you must affirmatively agree to this Privacy Policy, the Terms of Service and the Medical Disclaimer by ticking a box that is not pre-ticked. When a doctor creates an account, they agree to the Practitioner Terms and this Privacy Policy in the same way, and accept the Clinical Responsibility Agreement. If you already had an account, we ask you once in the app to accept the updated terms. That agreement covers the use of de-identified information from your consultations to improve Swasthy's own AI, described in Section 6.1, which you can switch off at any time. If you had already switched it off, or said no when we asked during doctor onboarding, it stays off.
- When you start a consultation, including a review of lab reports, you consent to receiving care remotely, as the Telemedicine Practice Guidelines, 2020 allow. When you start one by describing your symptoms, we record that consent with the version of our Telemedicine Consent published at the time. You can read it at any time in the patient app under Profile, All Legal Documents, and we recommend reading it before your first consultation.
- Voice recording, camera access and photo-library access are each requested at the moment they are needed, and each may be refused. Refusing them limits the corresponding feature only; you may still complete a consultation by typing.
- You may withdraw your agreement to Section 6.1 at any time, in the patient app under Profile, Privacy & Data (doctors: Settings). Withdrawing it does not affect your consultations, what you pay or how quickly a doctor sees you.
A small amount of processing rests on certain legitimate uses permitted by Section 7 of the DPDP Act rather than on consent, namely: responding to a medical emergency involving a threat to your life or immediate health; complying with a legal obligation, court order or lawful direction of a government authority; and enforcing legal rights or claims.
Where we retain records after you withdraw consent, we do so only because a law requires it. This is explained in Section 9.
6. Artificial intelligence, and what it does not decide
Swasthy uses artificial intelligence to speed up the parts of a consultation that do not require clinical judgement. You should understand exactly where the line is.
What AI does
- Converts your spoken description into text
- Translates your description of your symptoms into English, when the reviewing doctor asks for a translation
- Extracts structured symptoms from what you wrote or said
- Suggests which specialty should review your case, and looks for signs that you may need emergency care so the app can warn you
- Produces a draft assessment, a list of differential diagnoses, and a draft prescription for the doctor to consider
- Suggests lab tests, if the doctor asks for suggestions
What AI does not do
- It does not diagnose you.
- It does not issue a prescription.
- It does not decide whether you receive care or what you pay. The specialty it suggests helps decide which doctors we notify about your case, and you can change that specialty before you pay. A doctor makes every clinical decision.
Every prescription is reviewed, amended where the doctor considers it necessary, and signed by a Registered Medical Practitioner who takes full clinical responsibility for it. The doctor may accept the draft, change it, replace it entirely, ask you further questions, escalate your case, or advise an in-person examination.
You will not be subject to a decision that produces a legal or similarly significant effect on you based solely on automated processing.
We retain the AI prompt and response for each consultation as part of the audit trail, so that the AI's part in any prescription can later be reviewed. Access to that audit trail is restricted to authorised clinical-quality and compliance staff. If a patient's account is erased, the text of those prompts and responses is removed, and the AI draft itself stays with the consultation record.
Our AI vendors are contractually barred from training their models on anything we send them. That bar is absolute. It is not something you can switch on or off.
Checking that the AI is safe is part of the service. Because AI helps prepare every consultation, we continuously check how well it is doing: we compare the AI's drafts with what doctors actually decided, look for cases where it missed something urgent or suggested something a doctor had to correct, and fix the instructions, rules and reference information it works from. This safety and quality checking is part of providing the consultation, so it is not optional. It is done inside Swasthy, by authorised clinical-quality staff, using de-identified information wherever the check does not need to know who you are, and it is never used to make a decision about you. Training AI models on your consultations is different, and is covered by Section 6.1.
6.1 Helping us improve Swasthy's own AI
Beyond the safety checking in Section 6, we run a programme that trains and improves Swasthy's own AI, so that its suggestions are more accurate, misdiagnosis is less likely, triage is safer and speech recognition works better in Indian languages. It learns from real consultations, because nothing else teaches a model what Indian primary care actually looks like.
You agree to this when you create your account, or when you accept our updated terms in the app, and you can switch it off at any time. If you had already switched it off, or said no when we asked during doctor onboarding, accepting the updated terms does not switch it back on. Switching it off changes nothing about the care you receive, what you pay, or how quickly a doctor sees you. It applies only to consultations signed on or after 19 October 2026.
A consultation is used only if both the patient and the reviewing doctor had agreed to this, and neither had switched it off, when the doctor signed it. If you are a doctor, what we use from your clinical decisions is covered by the Practitioner Terms, Section 11.
We de-identify before we use anything. Your name, phone number, email address, postal address, photographs, uploaded documents, voice recordings, payment details and account identifiers are all removed. For anything you said, we use only the text, never the audio. We also remove or blur details that could single you out: exact dates become a month and year, your city, state and PIN code are removed, rare combinations of details are grouped or removed, and we check the risk of anyone being re-identified before anything is used. No consultation is used until that process is in place. What we use is:
- which symptoms you selected, how long they lasted and how severe they were, an age band rather than your age, and your sex;
- the conditions, allergies and medicines on your record;
- what you described in your own words, typed or spoken, as text, and the doctor's notes, after names, phone numbers, addresses, identity numbers and other identifying details have been automatically removed;
- the specialty your case was triaged to, and what the doctor diagnosed, prescribed and changed.
It is held separately from your account, with no key that links it back to you. Automated removal of identifying details from free text is careful but not perfect, so access to this information is restricted, it is reviewed, and we never attempt to work out who anyone is.
What we use it for, and nothing else:
- improving the accuracy of the draft assessments and draft prescriptions that doctors review;
- improving triage, including how reliably we recognise a case that needs urgent or in-person care;
- improving speech recognition and translation for Indian languages;
- measuring how often doctors change our drafts, which is how we know whether any of this is working.
What we will not do with it. We will not sell it, licence it, or make it available to another company to train their models. We will not use it for advertising, insurance pricing, credit scoring, employment screening, or any decision about you as an individual. Nothing this programme produces is ever used to make a clinical decision about you: a Registered Medical Practitioner reviews and signs every prescription, exactly as the rest of this section describes.
You can change your mind at any time: in the patient app under Profile, Privacy & Data, or in the Swasthy Doctor app under Settings. Switching it off is as easy as switching it back on. From that moment your later consultations are not used for it. Consultations signed while it was switched on may still be used. One limit we should be straight with you about: information that has already been de-identified is kept with no key that links it back to you, which also means we cannot pick it out to remove it from work already completed.
For the same reason, de-identified records already in this set are not removed if your account is deleted. When your account is erased at the end of the 60 days described in Section 9, your choice is erased with it, and nothing more from your consultations is used after that. To stop this use sooner, switch it off before you ask us to delete your account.
7. Who we share your data with
We do not sell your personal data. We do not share it for anyone else's marketing. The full list of who receives it is below.
7.1 Doctors on the Platform
Before a doctor accepts your case, approved doctors on Swasthy can see a summary of it so they can decide whether to take it. The summary shows your name, age, sex, language, height, weight and blood group, and the symptoms and health details you entered. It also shows the conditions, allergies, medicines and hospital stays saved on your profile, the AI's suggested specialty and its draft for your case, including the suggested diagnoses and prescription, and whether you attached files or a voice recording. For a follow-up, it shows the earlier diagnosis and its date. These doctors cannot open your photos, documents or voice recording.
The doctor who accepts your case sees your full consultation, including your attachments, your voice recording and the AI draft. They also see your saved health profile (conditions, allergies, medicines, hospital stays and uploaded medical documents), your phone number and date of birth, and earlier consultations you had with that same doctor. That doctor keeps access to the consultations they handled and to your profile.
Doctors are bound by the confidentiality obligations of the National Medical Commission regulations and by contract with us.
7.2 Service providers
Except where a row below says otherwise, each of these acts on our instructions under its data processing terms with us, which require confidentiality, security and use of the data only for the service it provides to us.
- Supabase
- Database, authentication, file storage, server functions — India (primary region) — All application data
- Anthropic
- AI triage, draft assessment and prescription, symptom extraction, and lab test suggestions — United States — Clinical details of your consultation, including anything you typed or said; not your name, phone number or payment data
- Sarvam AI
- Speech-to-text and translation (our default for both); also an alternative AI drafting provider, used only if we switch to it — India — Voice recording, transcript and text to be translated; the same clinical details as Anthropic if used for drafting
- ElevenLabs, OpenAI
- Alternative speech-to-text providers, used only if we switch to them — United States — Voice recording
- OpenAI, Google, Meta
- Alternative providers for AI drafting (OpenAI and Meta also for translation), used only if we switch to them — United States — The same clinical details as Anthropic, or text to be translated
- Razorpay Software Private Limited
- Payment collection and doctor payouts — India — Patients: the payment details you enter at checkout, the amount and your phone number. Doctors: name, email, phone number and bank or UPI details for payouts
- VideoSDK
- Video and audio consultation calls — India — Real-time media stream; calls are not recorded by us
- Twilio
- One-time password delivery by SMS — India / United States — Mobile number
- Expo, Apple and Google
- Push notification delivery — United States — Device push token and notification text; notifications say what happened, such as a prescription being ready, and do not include your symptoms, diagnosis or medicines
- Sentry
- Crash and error reporting — European Union (Germany) — Technical diagnostics (device model, app version, the screen in use and recent app activity) and an internal account identifier; an error report can sometimes include other details shown in the app at the time
- PIN code lookup service (api.postalpincode.in)
- Filling in your city and state from your PIN code. It is a free public service that we use without a contract, so it does not act on our instructions — Not published by the service; may be outside India — The PIN code you enter and your phone's IP address, sent directly from your phone
- Website hosting provider
- Website hosting and waitlist storage — United States — Waitlist details and basic device information
- Google (reCAPTCHA)
- Spam protection on website forms, under Google's own terms — United States — IP address and basic device information
- Swasthy AI, Inc.
- Engineering, infrastructure and AI services; also our parent company — United States — Application and consultation data, as needed to build and operate the Platform
Swasthy AI, Inc. appears in this table because it processes your data on our written instructions, exactly like any other processor, notwithstanding that it also owns us. Being our parent gives it no additional right to your data. Section 1 explains the relationship and Section 8 the cross-border safeguards.
We update this table when our providers change. Continuing to use the Platform after an update constitutes acceptance of the updated list; if you object to a new provider, you may withdraw consent and close your account.
7.3 Where the law requires it
We disclose data when compelled by a court, by a competent authority acting under law, or where disclosure is necessary to prevent an imminent threat to life. We record every such disclosure and, unless legally prohibited from doing so, we tell you about it.
7.4 On a change of control
If Swasthy is acquired, merged or reorganised, your data may transfer to the successor entity. That entity will remain bound by this policy or by a policy no less protective, and you will be notified before any transfer takes effect.
7.5 Ayushman Bharat Digital Mission: planned, and entirely optional
Swasthy is not yet connected to the Ayushman Bharat Digital Mission. We describe here what will happen when it is, so the change is disclosed to you now rather than sprung on you later.
Every part of this is opt-in. You can use Swasthy fully and indefinitely without an ABHA number, and none of what follows happens unless you switch it on. Where it applies, the ABDM Health Data Management Policy governs it, and you approve each request through an ABDM consent manager of your choosing, for a stated purpose and a stated period.
- Creating or linking an ABHA number. If you choose to create or link an Ayushman Bharat Health Account from inside the app, the identity details needed to do that, such as your name, date of birth, gender and mobile number, are sent to the National Health Authority, which operates the ABDM. The National Health Authority is not one of our service providers and does not act on our instructions; it operates under its own policy, which governs what it does with those details.
- Making your Swasthy records reachable elsewhere. Once you have linked an ABHA number, we may publish a care context for a consultation: a pointer recording that a record exists, alongside a structured copy of your consultation and prescription. Publishing a pointer does not disclose the record. Another provider can obtain the record itself only where you have approved that specific request through your consent manager.
- Bringing records from elsewhere into your consultation. You may choose to share records held by other providers with the doctor reviewing your case. Where you approve that, those records are fetched, shown to that doctor, and kept as part of your Swasthy consultation record under Section 9.
You can withdraw an ABDM consent at any time through your consent manager. Withdrawal stops further sharing. It cannot recall a copy another provider already obtained lawfully, which that provider then holds under its own obligations. Unlinking your ABHA number does not delete your Swasthy records. Section 9 and the account-deletion process govern those.
8. Storage location and cross-border transfer
Your application data, meaning your profile, consultations, prescriptions and attachments, is stored primarily in India, in our provider's Mumbai region.
Some processing takes place outside India, as set out in the table in Section 7.2. Today the countries involved are the United States (AI processing, push notifications, one-time password delivery, engineering support by our parent company Swasthy AI, Inc., website hosting and spam protection on our website) and Germany (crash reports). The PIN code lookup service does not publish where it processes data, so we treat it as possibly outside India. We make these transfers because they are needed to provide the Platform and the consultations you ask for.
Section 16 of the DPDP Act permits transfer of personal data outside India except to countries that the Central Government restricts by notification. We transfer only to countries not so restricted, and we monitor those notifications. Except where the table in Section 7.2 says otherwise, each recipient outside India handles your data on our instructions under its data processing terms with us, which require confidentiality and security.
If the Government restricts transfers to a country we rely on, or designates us a Significant Data Fiduciary with localisation obligations, we will move the affected processing into India and update this policy.
9. How long we keep your data
- Prescriptions and the clinical record of a consultation
- At least 3 years from the date of the consultation, then deleted once no law requires us to keep them — Required of every Registered Medical Practitioner by the Telemedicine Practice Guidelines, 2020 and the National Medical Commission regulations
- Payment, invoice and tax records
- At least 8 years from the end of the relevant financial year, then deleted once no law requires us to keep them — Companies Act, 2013 and the Income-tax Act
- Account profile
- For as long as your account is open — To provide the service
- Voice recordings
- Up to 36 months from the consultation, kept with the clinical record; deleted within 90 days of a request to delete your account, or earlier where Indian health-record or IT rules require. The transcript is retained with the clinical record, and a de-identified copy of the transcript may be used under Section 6.1 — The reviewing doctor may listen to the recording; the transcript is the clinical record
- Doctor verification documents (photo ID, certificates, photograph)
- For as long as the doctor is on the Platform, and 3 years after the last prescription they signed — Evidence that every prescriber was verified, for complaints and claims about the prescriptions they signed
- AI prompt and response audit trail
- At least 3 years, alongside the clinical record. If a patient's account is erased, the text of the prompts and responses is removed and the AI draft itself is kept — Clinical safety auditing
- Security audit log
- At least 3 years from the event — Investigating misuse and showing who accessed a health record; the IT Rules, 2021 and CERT-In directions require at least 180 days
- Request logs kept by our infrastructure provider
- Up to 30 days — Diagnosing faults and investigating misuse
- Crash and error diagnostics
- Up to 90 days — Fault diagnosis
- Encrypted database backups
- Data you delete, or that we erase, can remain in backups for up to 30 days — Recovering the Platform after a failure
- De-identified records in the AI improvement set (Section 6.1)
- For as long as they are needed for the purposes in Section 6.1, reviewed every 3 years — They are kept with no key that links them to you, so they cannot be picked out and removed when you switch this off or delete your account
- Website waitlist details (Section 3.7)
- Deleted within 12 months, or sooner if you ask — To contact you about Swasthy
When you ask us to delete your account, we sign you out on every device straight away, and a doctor stops receiving new cases. Your account is then erased 60 days after your request. We use this window because payment disputes, refunds and doctor payouts can take up to 60 days to settle, and we must be able to resolve them; it also protects you against an accidental tap. During those 60 days you may sign back in at any time and choose to keep your account, with nothing lost. If your phone can still receive Swasthy notifications, we will remind you about seven days before the erasure date. After erasure, signing in again with the same phone number creates a new, empty account, and your old records cannot be recovered.
When a patient account is erased, we delete your photographs, documents, voice recordings, prescription PDFs, saved medical documents and saved UPI IDs. We delete the text you typed or said to describe your symptoms or answer the doctor, except the one copy described below, and the text of the requests we sent to AI providers about your consultations and of their replies. We remove your name, phone number, date of birth, gender, city, state, PIN code, height, weight, blood group, and the conditions, allergies and medicines saved on your profile.
We keep, without your name or contact details, the record of each consultation (including the health details that were part of it, your age and sex at the time, the diagnosis and the prescription) and your payment and refund records, for the periods in the table above. Some details you gave stay with the consultation records, such as the hospital stays, medical history, medicines and allergies you reported. These records stay in our main database, where only the doctor who treated you and authorised Swasthy staff can see them.
Our deletion process does not yet remove some details: the summary of your details we asked you to confirm when a doctor took your case, which includes how you described your symptoms; your ratings and the comments you gave with them; the list of past hospital stays on your profile; and when you last opened the app. Email privacy@swasthy.ai and we will remove them.
When a doctor account is erased, we remove the doctor's name, phone number, email address, photograph, bio, practice details and availability from their profile. Their verification documents (photo ID, certificates and photograph) are kept for 3 years after the last prescription they signed, then deleted. We keep the doctor's registration number and qualifications, so the prescriptions they signed stay attributable to a registered practitioner. We also keep their verification record, which includes their name, and their payout and tax records, including bank account, IFSC, UPI ID and PAN. Our deletion process does not yet remove the email address and phone number in the doctor's verification record, or the doctor's date of birth, city, years of experience, languages, specialties, Healthcare Professionals Registry ID or when they last opened the app. Email privacy@swasthy.ai and we will remove them.
For every erased account, we delete the history of choices made about Section 6.1 and the list of terms and policy versions accepted. The account record, with no name or contact details, still shows which version of the Terms was accepted at sign-up and when, and each consultation record keeps the consent recorded with it. We also keep our security audit log, which records account identifiers, IP addresses and the time of actions. Some entries include a person's name or phone number, or a note written by our staff.
Where the DPDP Rules require it, we will give you at least 48 hours' notice before erasing data on grounds of inactivity, so that you can log in and retain your records.
10. Your rights
Under Chapter III of the DPDP Act you have the following rights. To exercise any of them, write to privacy@swasthy.ai. In the patient app, under Profile, Privacy & Data, you can also delete your account and switch off the use described in Section 6.1 (doctors: Settings in the Swasthy Doctor app). A self-service download of your data is not available yet: write to us and we will send you your records within 30 days. Patients can also save each prescription as a PDF from Past Visits.
Right to access. To obtain a summary of the personal data we hold about you, the processing we have carried out, and the identities of the Data Fiduciaries and Processors with whom it has been shared.
Right to correction and completion. To have inaccurate or misleading data corrected, and incomplete data completed. Note that a signed prescription is a clinical record and cannot be altered after signature. If you believe it contains an error, raise it with us and we will ask the doctor who issued it to review it and tell you the outcome. The signed original is kept.
Right to erasure. To have your personal data erased, except where retention is required by law. See Section 9.
Right to withdraw consent. To withdraw consent as easily as you gave it. Withdrawal stops future processing; it does not make past processing unlawful, and it does not oblige us to delete records the law requires us to keep. Withdrawing consent for core processing means we can no longer provide consultations to you. Switching off the use described in Section 6.1 has no effect on your consultations at all.
Right to nominate. To nominate another person to exercise these rights on your behalf if you die or become incapable of exercising them yourself.
Right of grievance redressal. To complain to us first, through the mechanism in our Grievance Redressal Policy. We acknowledge within 24 hours and resolve within 15 days. If you are not satisfied, you may complain to the Data Protection Board of India.
We respond to rights requests within 30 days.
We may ask you to verify your identity before acting on a request. We do this to stop someone else obtaining your health records, not to obstruct you. We do not charge for exercising these rights.
11. Children and persons with disabilities
Swasthy is currently for adults aged 18 and over, consulting for themselves. Please do not use your account for a child or another adult: prescriptions are issued in the name, age and sex on your account. A child needs to see a doctor in person.
The app refuses a sign-up with a date of birth under 18, and we do not knowingly collect personal data from a person under 18. If you believe a child has created an account, write to privacy@swasthy.ai and we will verify and delete it.
A lawful guardian cannot yet consult on behalf of a child, or of an adult who cannot give consent independently, because the consultation and the prescription would carry the guardian's own details. We will update this policy, and ask for the consent the law requires, before consultations for a dependant become available.
12. How we protect your data
Full detail is in our Data Security Policy. In summary:
- All data is encrypted in transit using TLS 1.2 or higher, and encrypted at rest.
- Access to patient records is enforced at the database level by row-level security. A patient can read only their own records. A doctor can open a patient's full record and files only for cases assigned to them; doctors who can take a waiting case see its summary, as Section 7.1 describes.
- Prescriptions are immutable once signed.
- Our admin console requires a second sign-in factor, and access to production systems is limited to named staff on a least-privilege basis.
- When a doctor opens a case to review it, or a staff member opens a case or patient record in the admin console, this is logged in an audit trail. Each time a doctor or staff member opens an uploaded photo, document or voice recording, that is logged too.
- Except where Section 7.2 says otherwise, each service provider handles data on our instructions under its data processing terms with us.
No system is perfectly secure. If a personal data breach occurs, we will inform the Data Protection Board of India without delay and send it a full report within 72 hours of becoming aware of the breach, as Rule 7 of the DPDP Rules, 2025 will require once it takes effect. We will notify you without undue delay, describing the nature of the breach, the data affected, the steps you can take, and what we are doing about it.
13. Cookies and tracking
The Swasthy mobile apps do not use cookies or third-party advertising trackers.
Our websites use only strictly necessary cookies required for session management and security. We do not run advertising or cross-site tracking cookies. If we introduce analytics cookies in future, we will ask for your consent first.
14. Changes to this policy
We may update this policy. When we do, we will change the version number and effective date at the top and publish the revised version in the app and on our website. Until a revised version takes effect, the previous version continues to apply, and we will send you a copy of it if you ask.
If a change materially affects how we use your data, such as a new purpose, a new category of data or a new class of recipient, we will notify you in the app and by push notification or SMS at least 14 days before it takes effect, and where the law requires it we will ask for fresh consent.
15. Contact us
General privacy queries: privacy@swasthy.ai
Data Protection Officer: dpo@swasthy.ai
Grievance Officer: grievance@swasthy.ai, appointed under the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 and Section 13 of the DPDP Act. We acknowledge within 24 hours and resolve within 15 days.
The name of each officer, our postal address and our phone number are published in Contact & Company Information.
Escalation. If we do not resolve your complaint to your satisfaction, you may complain to the Data Protection Board of India established under the DPDP Act, 2023, or approach a consumer forum under the Consumer Protection Act, 2019.
16. Governing law
This policy is governed by the laws of India. The seat of jurisdiction is stated in Contact & Company Information.
Questions about this document? Email privacy@swasthy.ai, or raise a grievance at grievance@swasthy.ai.