Privacy Policy
This describes what we actually do today. Whenever what we collect or how we use it changes, this page is updated first.
The short version
We operate under India's Digital Personal Data Protection Act (DPDPA) 2023. We collect only what we need, we never sell anything, we log every access, you can always see what we hold on you, and you can delete it whenever you like.
1. What we collect
- Staff account: name, email, role, optional languages spoken, optional home city and coordinates (used for staff routing only).
- Elder profile (captured by the family, or by our staff during intake): name, preferred language, age, address (city / locality / PIN / latitude / longitude), mobility class, household composition, RPwD disability category and severity, and — if you choose to add it — a WhatsApp number and ABHA health ID.
- Medical records you upload: prescriptions, lab reports, discharge summaries and imaging you add to the vault. Text is extracted on your own device — the file is not sent to any third-party OCR service.
- Vitals and medication tracking: readings you log, medication schedules, and whether a dose was marked taken or skipped.
- Medical context: conditions, medications, hospitalisation / surgery history, scores from validated assessment instruments (Lawton IADL, FRAIL, GDS-5, De Jong Loneliness Scale).
- Care interactions: staff-typed free-text notes and intake transcripts, responses to trigger reminders, acute signal events (falls, hospital visits, bereavement).
- Family contacts (when captured): relationship, role, distance to elder, contact channels.
Family members sign in to the app to manage their elder's care (an adult may also add themselves as the person receiving care). Elders themselves interact over WhatsApp: they opt in by messaging us from their own number, and we send only care messages — appointment reminders and medication check-ins.
2. What we do NOT collect
- No card or bank details. Subscription payments are handled by Razorpay, our payment gateway — your card / UPI details go to Razorpay directly and are never stored by SaralCare. We keep only the payment reference, amount and status needed to issue your receipt and keep the subscription active.
- No location tracking. We never track your device's location. We do convert the address you type into map coordinates using OpenStreetMap's Nominatim service, so the elder's locality can be shown on a map — only that address text is sent, and only when you save it.
- No non-SaralCare communications. We do not read or store anything outside the channels you use to talk to us.
- No third-party advertising or behavioural-tracking analytics.
3. What we use it for
Exactly three things:
- delivering the care service you (or your family member) subscribed to;
- improving the service in aggregate — we do not use individual data to train AI models, and we do not sell any insight derived from your data;
- meeting legal and regulatory obligations.
That is the whole list.
4. What we never do with it
We never sell personal data. Not to advertisers, not to pharmaceutical companies, not to insurance companies, not anonymised-but-identifiable. Never. We never use your or your parent's health data for advertising or marketing. We never share data with any third party that is not essential for delivering the service, and every such vendor signs a data-processing agreement before any data reaches them.
5. Where it lives
- Database: Supabase Postgres, Mumbai region (ap-south-1). Data stays in India.
- Application: Cloudflare Pages, served from the India edge.
- Encryption: encrypted at rest by Supabase (AES-256, provider-managed) and TLS 1.2+ in transit.
- Authentication: Supabase Auth manages passwords with industry-standard hashing.
- Intake processing: the matcher and semantic embeddings run inside the staff member's browser during a call. No intake text or transcript is sent to a third-party processor during the call itself.
The processors we use. Your care record itself lives in India. Some services we depend on to deliver it operate outside India, and only ever receive the narrow slice named here:
- Supabase (Mumbai, India) — the database and sign-in.
- Cloudflare — serves the app.
- Razorpay (India) — subscription payments. Card / UPI details go to them directly and never reach us.
- Meta (WhatsApp Business Cloud API) — delivers reminders and check-ins. Meta receives the phone number and the message text; message content is processed on Meta's global infrastructure, outside India.
- Resend — sends our emails (invitations, receipts, reminders). Receives the recipient address and the email body. Operates outside India.
- OpenStreetMap (Nominatim) — turns a typed address into map coordinates. Receives that address text only.
Every one of these is bound by a data-processing agreement, receives only what that specific job needs, and is never given your data for its own purposes.
6. Who can see it
- You (the data principal), always, in full.
- SaralCare ops and care staff who deliver care to you or your parent. Every access is logged in our audit trail.
- A doctor you explicitly ask us to consult on a specific question, for that question only.
- Anyone you send a share link to from the records vault — view-only, expires within 24 hours, and you can revoke it at any time.
- Family members you invite, at the access level you choose (owner, editor or viewer). You can change or revoke that access whenever you like.
- No one else.
We don't yet expose the access log in-app. To request a copy of who accessed your record, email contact@saralcare.com and we'll send it within seven days.
7. Your rights under DPDPA
You have the right to:
- Access everything we hold on you — email contact@saralcare.com, we respond within seven days.
- Correction — anything wrong, we fix it. Email the same address with what needs to change.
- Erasure — one request, processed within seven days. The audit log retains the deletion record itself for compliance, but no further use of your data is made.
- Withdraw consent for any non-essential scope (e.g. family notifications, future LLM-based review). Email us; we acknowledge within 48 hours.
- Nominate a digital nominee — for elders, a family member can be designated.
- Grievance redressal — contact our Grievance Officer (below).
We can't make any of these rights harder than they need to be, and we won't try. In-app self-service for access and consent is on the roadmap; until it ships, the email path is the one we honour.
8. Children
SaralCare is not for people under 18. If you believe we are inadvertently holding data on a minor, email us immediately and we will delete it within 24 hours.
9. Cookies & tracking
We use authentication session cookies (httpOnly, same-site) so you stay signed in. The map view caches state in your browser's local storage so the page survives a refresh.
We currently run no analytics. No PostHog, no Google Analytics, no behavioural tracking of any kind. If we ever add product analytics, this policy will name the tool and the data category before it goes live.
10. Data breaches
If there is a data breach, we will notify affected users within 72 hours of detection (the DPDPA standard). Material incidents are published in an annual transparency report.
11. Grievance officer
Ashwin Kulkarni (founder, acting DPO)
contact@saralcare.com
+91 98450 65330
15-day response SLA under DPDPA §13. We acknowledge receipt within 48 hours.
12. Changes
Material changes are posted here. The "last updated" date below moves on every change. Where the change affects what we collect or how we use it, we email logged-in users at least 30 days before it takes effect.