01

What we collect

When you submit a case, we collect what you give us: your contact details, the medical reports and scans you upload, the symptoms and questions you describe, and any teleconsult recordings if you opt in. We also collect technical metadata — your IP address, browser, and the timestamp of each action — for security and audit purposes.

We do not collect: your insurance details, your treating doctor's contact information, anything from your phone's health app, or anything we don't explicitly ask for.

02

Who sees your file

Your file is visible only to:

  • The case manager who reads it first and routes it
  • The doctors on the panel you chose
  • Our two-person engineering team, only when investigating a specific technical issue and only with your written consent

That's it. Not our investors, not partner hospitals, not insurers, not advertisers, not LLM training pipelines.

03

How long we keep it

You decide. By default, we retain your file for 24 months so you can refer back to your opinions. You can request deletion at any time via support and we will purge within 30 days — backups included.

Audit logs (who-did-what-when, no medical content) are retained for 7 years to satisfy India IT Act and DPDP Act record-keeping requirements.

04

Where it lives

Database and file storage are hosted in ap-south-1 (Mumbai) by default. EU clients can request EU residency. Everything is encrypted at rest (AES-256) and in transit (TLS 1.3).

05

Your rights

Under India's DPDP Act, the EU GDPR, and equivalent laws, you have the right to: access your data, correct it, delete it, port it elsewhere, and object to processing.

To exercise any of these, write to privacy@docfriends.co. We respond within 30 days, usually within 3.

06

Contact

Our Data Protection Officer is reachable at privacy@docfriends.co. For other questions, see the contact page.