Legal

Privacy policy

Aarogyam exists to hold some of the most sensitive information a person has. This policy explains, in plain language, what we collect, why we collect it, and what we will and will not do with it.

1. What we collect

Account information

When you register we collect your name, email address, phone number and a password (stored only in hashed form). Patients additionally provide date of birth, gender, blood group, emergency contact and address. Doctors additionally provide their medical licence number, specialization, degree, practice details and verification documents.

Health records

The core of the platform: medical reports you or your doctors upload, diagnoses and prescriptions recorded during visits, and the timeline built from them. This data is created deliberately, by you or by a verified doctor treating you — we never source health data from anywhere else.

Technical data

Standard operational logs (login timestamps, request records) used for security and troubleshooting, and audit entries recording who accessed which record and when.

2. How we use it

  • To run the service — issuing your Aarogyam ID, generating your QR health card, rendering your timeline, producing prescription PDFs.
  • To verify identities — sending one-time passwords by email at registration, and reviewing doctor credentials before approval.
  • To notify you — service emails such as OTP codes, approval decisions and record activity. We do not send marketing email.
  • To keep the platform safe — detecting misuse through logs and audit trails.

3. Who can see your health record

Access is role-based and deliberately narrow:

  • You can see your complete record at all times.
  • Verified doctors can access your record in the context of your care — for example after scanning your QR card at a consultation.
  • Administrators manage accounts and approvals; their job is verification and oversight, not reading medical histories.

We do not sell data. We do not share health records with advertisers, insurers, employers or any third party for commercial purposes — full stop.

4. How it's protected

  • Passwords are hashed; they are never stored or transmitted in plain text.
  • Every API request is authenticated with signed JSON Web Tokens.
  • Role-based authorization is enforced on the server for every endpoint.
  • Doctor accounts are inactive until an administrator verifies licence and degree documents.

5. Your choices

  • Access & download — you can view and download your records and prescriptions from your dashboard at any time.
  • Correction — profile details can be edited from your account; factual errors in medical entries should be raised with the issuing doctor.
  • Deletion — you may request account deletion by contacting us. Some records may be retained where required for audit integrity, and we will tell you exactly what and why.

6. A note on scope

Aarogyam is an educational and research project. It follows the practices described here as a matter of design, but it is not a certified clinical system and should not be treated as one for regulated medical data.

7. Contact

Questions about this policy or your data: support@aarogyam.health, or use the contact page.