1. Scope
This policy covers the Swastho website and web application. It applies to all three kinds of account — patient, doctor and clinic — and takes effect from 24 September 2026.
Swastho is a scheduling and record-keeping platform. It is not a medical provider, pharmacy, diagnostic laboratory or insurer. For what that means clinically, see the medical & AI disclaimer.
In the language of the Digital Personal Data Protection Act 2023 (“DPDP Act”), we are the Data Fiduciary for the data described below and you are the Data Principal.
2. What we collect
Everyone, at sign-up
- Your name, phone number and email address.
- Your date of birth and, optionally, your gender.
- Your full postal address — address lines, landmark, city, state, country and 6-digit PIN code.
- Your password, stored only as a salted hash. We never see or store the password itself.
- A profile photo or clinic logo, if you upload one.
- A unique QR token for your profile, which is what a clinic scans to identify you. It is created once, with your account, and does not change.
Patients
- Weight, height and blood group.
- Allergies and chronic conditions, as free text you write yourself.
- An emergency contact name and phone number.
- A log of weight and height readings over time, which a clinic may also record during a visit.
Doctors
- The year you began practising, your consultation fee and an optional bio.
- Your specializations, and the clinics you are associated with.
- Your weekly schedule per clinic, and your holidays — including any reason you write on one.
Clinics
- GST number and registration number.
- An optional bio, your specializations, operating hours and holidays.
Clinical and financial records
- Appointments — the slot, the doctor, the clinic, your queue position, the status, whether it was a walk-in, who booked it, and the reason for visit you write in your own words.
- Prescriptions and their items — medicine or test name, quantity, dosage, timing and whether to take it before or after food — plus any notes the doctor adds.
- Follow-up instructions, including a due date where the doctor sets one.
- Bills and their line items — fees, discounts, amounts due, amounts paid and who raised the bill.
- Medical reports uploaded as PDFs, by you or by a clinic, with a title, category, report date, file name and size, and any notes attached.
AI drafting inputs
Where a doctor uses AI to draft a prescription, we store what they typed, or — if they dictated it — the text transcript of what they said, together with the structured draft the model produced and whether it succeeded. The audio recording itself is never stored. See how AI drafting works.
Operational records
- A log of doctor–clinic association requests and responses: who acted, what changed, and whether it succeeded or was refused. This exists so a disputed association can be reconstructed.
- Standard server and platform logs kept by our hosting provider, which include IP addresses and browser user-agent strings.
3. Where it comes from
Three sources, and the second one surprises people.
- From you, when you sign up, complete your profile, book an appointment or upload a report.
- From a clinic or doctor, about you. Clinic staff can book a walk-in in your name, upload a report to your record, and record your weight and height during a visit. We store who did each of these, and when.
- From Google, if you choose to sign in with Google — your email address, name and profile picture, and nothing else.
Someone else's data
Your emergency contact is another living person. Please add someone who knows you have given us their name and number, and remove them if that changes.
4. Why we collect it
We process your personal data on the basis of the consent you give when you create an account and accept this policy, and for the following purposes only:
- To create and operate your account, and to verify it is yours.
- To let you find a clinic and doctor, book an appointment and see your live position in the queue.
- To hold your prescriptions, bills and reports in one place, and to show them to you and to the clinician treating you.
- To let a clinic raise and settle the bill for your consultation.
- To let a doctor draft a prescription faster, where they choose to use that feature.
- To send the transactional email the account needs — confirming your address and resetting your password. We do not send marketing email.
- To keep the platform secure, investigate misuse, and meet a legal or regulatory obligation where one applies.
We do not sell your personal data, we do not share it for advertising, and we do not profile you.
5. Who can see it
Access is enforced in the database itself, on every single query, rather than by the app asking nicely. In practice that means:
Who
Can see
You
Your own profile, appointments, prescriptions, bills and reports. Nothing belonging to anyone else.
A doctor
The record of a patient who has an appointment with them at a clinic they are associated with — including reports uploaded by that clinic. Not the wider patient list of the clinic, and not a patient they have no appointment with.
A clinic
Appointments at that clinic, the bills it raises, the reports it uploads, and the associated doctors. Not a patient record from another clinic.
Swastho staff
A small number of people can reach the database to operate and support the platform. We look at a record only when we need to in order to fix something or answer a request from you.
When you show your QR code
Scanning your QR is how you hand your record to a clinic, and it discloses more than a name. When a clinic or doctor scans it, they see your name, photo, age, date of birth, gender, phone number, email address, city, state and country, together with your blood group, weight, height, allergies, chronic conditions and emergency contact details.
Only a clinic or doctor account can read a patient’s QR. If anyone else scans it — including another patient on Swastho — the platform refuses and shows them nothing, and an ordinary QR reader sees only a random code that means nothing outside Swastho. The code cannot currently be changed, so show it only to a clinic or doctor you are consulting.
6. Third parties
These are the only parties your data reaches, and exactly what each one gets.
Recipient
What it receives
Supabase
Our database, authentication, file storage and realtime provider — everything described in section 2. Hosted in India — Supabase, ap-south-1 (Mumbai).
Google Gemini (gemini-2.5-flash)
Only what a doctor types or dictates when asking for a prescription draft, sent from our server. In dictation mode this includes the audio recording. We attach no patient identifiers, and we do not redact any the doctor chooses to speak.
Google Sign-In
Only if you use it: a standard OAuth exchange returning your email address, name and profile picture. We request no additional scopes.
India Post PIN lookup
Your 6-digit PIN code alone, to fill in city and state for you. This call is made by your browser, so your IP address is visible to that service. No name, phone number or account reference is sent, and if the lookup fails you simply type the fields yourself.
Resend
Sends our account emails — sign-up confirmation, password reset and the password-changed notice. It receives your email address and the message itself, which carries a one-time link and no health data.
Vercel
Hosts the website and web app. It receives every page request — including your IP address and browser user-agent — and keeps them in short-lived logs. Your records do not pass through it: the app in your browser talks to Supabase directly.
Cloudflare
Runs the domain name system for our domain, and forwards email you send to our support, privacy and grievance addresses on to our mailbox, which is hosted on Google Gmail — so the contents of an email you send us pass through both. Website traffic is not routed through Cloudflare.
Your account and health records are stored only in India (section 7). Vercel, Cloudflare, Resend and Google run global networks, so the limited data listed above for them — request logs, email addresses and the contents of emails — may be processed outside India.
Swastho contains no analytics, advertising or tracking software of any kind. There is no third-party script on the page measuring what you do.
7. Storage and security
Your data is stored in India — Supabase, ap-south-1 (Mumbai). Access rules live in the database and are applied to every read and write, so a mistake in the app cannot hand one user another user’s record. Data is encrypted in transit and at rest.
Medical report PDFs are held in private storage. We store only the internal file key, never a shareable link, and each time you open a report we mint a signed link that expires after five minutes. There is no permanent URL to a report that could be forwarded or leaked.
Profile photos are public
Profile photos and clinic logos are the one exception: they are served from public storage, so anyone who has the image URL can open it without signing in. Avatars are not clinical documents, and treating them the same way as reports would mean signing every image on every screen — so this is a deliberate trade-off rather than an oversight, and we intend to close it. Please do not upload anything to your profile photo that you would not be comfortable being public.
8. How long we keep it
- Account and profile data: for as long as your account is open.
- Appointments, prescriptions and bills: retained as medical and financial records even after the appointment is over, because a health record loses its value if it can be partly erased.
- Medical reports: retained while your account is open. Deleting a report removes it from your record and immediately stops it being openable by anyone, including the clinic that uploaded it — but the underlying file is retained in our storage rather than destroyed.
- AI drafting inputs: retained against the appointment so a prescription can be audited later. Dictation audio is never stored at all.
- Server and platform logs: kept for a short period by our hosting provider for security and troubleshooting.
Where we are required to keep something longer to comply with a legal obligation, we keep it for that period and no longer.
9. Your rights
Under the DPDP Act you may ask us to confirm what we hold about you and who we have shared it with, correct or complete anything inaccurate, erase data we no longer need, nominate someone to exercise these rights if you die or become incapacitated, withdraw your consent, and raise a grievance.
Some of this you can do yourself today: you can edit your address and your health details from your profile, manage your specializations and schedule, and delete a medical report.
Three things you cannot yet do in the app
Your name, phone number, email address, date of birth and gender are not editable from your profile, and there is no button to delete your account, and your QR code cannot be changed. We would rather say that plainly than describe a control that does not exist.
The first two are handled manually for now. Write to privacy@swastho.in from the address on your account, and we will action it and reply within 30 days. On erasure we will tell you what we have to retain as a medical or financial record and why, before we act. If you think your QR code has been captured by someone you did not intend, tell us at the same address.
Withdrawing consent means we can no longer operate your account, so treat it as a request to close it. We may ask you to verify your identity before acting on a request, and we may decline one that is repetitive or that would disclose another person’s data.
10. Children's data
An account must be held by someone aged 18or over. A parent or legal guardian may hold an account and book appointments, upload reports and hold records on behalf of a child in their care — the account remains the adult’s, and so does responsibility for it.
We do not knowingly let a child create an account in their own name, we do not profile children, and we do not advertise to them. If you believe a child has created an account, write to privacy@swastho.in and we will remove it.
12. Changes to this policy
If we change how we handle your data we will update this page and move the “last updated” date at the top. Where a change materially affects you, we will tell you by email or in the app before it takes effect. Continuing to use Swastho after that point means you accept the updated policy.
13. Grievance officers
If you are unhappy with how we have handled your data or a request about it, contact our Grievance Officers directly. We will acknowledge you and respond within 30 days.
If we do not resolve it to your satisfaction, you may escalate to the Data Protection Board of India. For anything else, our contact page lists every address we answer.