๐Ÿ”’ Privacy Policy

We take your health data seriously.

Effective: 1 January 2025 Last updated: March 2025 Governing law: India (DPDP Act 2023)
Table of Contents
  1. Who We Are
  2. What Data We Collect
  3. How We Use Your Data
  4. How We Store and Protect It
  5. Who We Share It With
  6. Your Rights (DPDP Act 2023)
  7. AI Processing & Claude
  8. Cookies
  9. Children
  10. Changes to This Policy
  11. Contact & Grievance Officer
Plain English Summary: MyMediLedger stores your personal health information to generate clinician-ready reports. We do not sell your data, we do not show ads, and we do not share your health information with third parties without your consent. You can delete your data at any time.

1. Who We Are

MyMediLedger ("we", "us", "our") is a personal health record platform operated by [Your Company Name], [City], India. We provide longitudinal health record management, risk calculation tools, and clinician-sharable PDF report generation.

For the purposes of the Digital Personal Data Protection Act, 2023 (DPDP Act), MyMediLedger is the Data Fiduciary.

Contact: privacy@mymediledger.com ยท Grievance Officer contact below.

2. What Data We Collect

2.1 Data You Provide Directly

CategoryExamplesPurpose
IdentityName, date of birth, sex, ABHA IDPatient record creation
ContactMobile number, email, addressAccount management, emergency contact
Health dataDiagnoses, medications, allergies, vitals, lab results, vaccinationsCore health record functionality
Risk dataASCVD inputs, FINDRISC questionnaire answersRisk score calculation
Uploaded filesLab report images/PDFs for OCR extractionAuto-populate lab results

2.2 Data Collected Automatically

2.3 Data We Do NOT Collect

3. How We Use Your Data

We process your data only for the following purposes, each with a lawful basis under the DPDP Act 2023:

PurposeLawful Basis
Creating and maintaining your health recordConsent (you register voluntarily)
Generating clinician PDF reportsConsent (you initiate report generation)
Calculating ASCVD, FINDRISC and other risk scoresConsent (you complete the questionnaires)
AI-powered lab report OCR extractionConsent (you upload the document)
Authentication and securityLegitimate interest (securing your account)
Service improvement and bug fixingLegitimate interest (anonymised/aggregated only)
We do not use your health data for advertising, profiling, or selling to third parties under any circumstances.

4. How We Store and Protect Your Data

Infrastructure

Security Measures

Retention

Your data is retained for as long as your account is active. You may delete your account and all associated data at any time (see Section 6). Deleted data is permanently removed within 30 days.

5. Who We Share Your Data With

We share your data only in these limited circumstances:

RecipientWhatWhy
Google Cloud PlatformEncrypted database recordsInfrastructure hosting (data processor)
Anthropic (Claude AI)Lab report images you upload for OCRAI extraction โ€” see Section 7
Your chosen clinicianPDF report you generate and shareYour explicit action (you share the PDF)
Law enforcementMinimum required by lawLegal obligation under Indian law

We never sell, rent, or share your personal health data with insurance companies, pharmaceutical companies, employers, or advertisers.

6. Your Rights under the DPDP Act 2023

Under the Digital Personal Data Protection Act, 2023 (India), you have the following rights:

To exercise any right: email privacy@mymediledger.com with subject "Data Rights Request โ€” [your name]". We will respond within 72 hours and fulfil requests within 30 days.

Account Deletion

To permanently delete your account: Settings โ†’ Account โ†’ Delete Account, or email privacy@mymediledger.com. All health records, reports, and personal data will be permanently erased within 30 days.

7. AI Processing & Claude (Anthropic)

MyMediLedger uses Claude AI by Anthropic for the lab report OCR (image/PDF extraction) feature. When you upload a lab report image or PDF:

Anthropic's privacy policy applies to data processed through their API: anthropic.com/privacy

If you do not wish to use the AI OCR feature, you can manually enter all lab values without uploading any document.

8. Cookies and Session Storage

MyMediLedger uses sessionStorage (not cookies) to store authentication tokens during your active session. These are:

We do not use third-party advertising cookies, tracking pixels, or analytics SDKs that collect personal data.

9. Children and Minors

MyMediLedger is designed for adults aged 18 and above. We do not knowingly collect personal data from individuals under 18. If you believe a minor has created an account, please contact us at privacy@mymediledger.com and we will delete the account immediately.

10. Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices or applicable law. When we make significant changes, we will:

Continued use of MyMediLedger after the effective date of changes constitutes acceptance of the updated policy.

11. Contact & Grievance Officer

For any privacy concerns, data requests, or grievances, contact:

Grievance Officer โ€” MyMediLedger

Name[Grievance Officer Name]
Address[Your Registered Address], India
ResponseWithin 72 hours of receipt

If your grievance is not resolved within 30 days, you may approach the Data Protection Board of India once established under the DPDP Act 2023.