MedQlub is a clinical productivity tool for doctors. This policy explains
what data we collect, why we collect it, and the rights you have over it
under India's Digital Personal Data Protection Act, 2023 (DPDP)
and the Information Technology (Reasonable Security Practices and Procedures
and Sensitive Personal Data or Information) Rules, 2011 (SPDI Rules).
1. Who we are
MedQlub is operated by Karthik Appadurai (sole proprietor) based in India.
Contact: karthik.uic@gmail.com.
For DPDP purposes, we are the Data Fiduciary for your account
data and a Data Processor for clinical data you record about your
patients (you remain the Data Fiduciary for that).
2. What we collect
2.1 Account data (you, the doctor)
- Your name, email, profile photo (via Google Sign-In)
- Medical license ID, practice location, bio (optional, doctor-supplied)
- Plan, billing status, and usage counters (number of notes, ask queries, storage used)
- Device + browser metadata for security and analytics (IP address truncated, user agent)
2.2 Clinical data (your patients)
- Patient name, age, sex, phone (optional), diagnosis tags, allergies — only what you choose to record
- SOAP notes you dictate, type, or upload
- Voice dictations (audio files), photos, PDF / lab reports you attach
- AI-generated chart summaries and structured notes built from your inputs
- Ask Evidence questions you ask about a patient + the AI's cited answers
You decide what patient data enters MedQlub. We never
pull data from external EHRs or third-party services.
2.3 Analytics + diagnostics
- Anonymized event counts via Amplitude — what features are used, how often. Never patient names or chart content.
- Server logs (request timing, error traces). Retained 14 days.
3. How we use it
- To run the app: store your notes, transcribe your voice via Google's Gemini API, retrieve evidence from a PubMed-derived literature index (500K+ papers indexed in Milvus).
- To bill you: payment processing via Razorpay (we never see card numbers).
- To improve the product: anonymized analytics. We do not use clinical data to train models or share it with anyone for any commercial purpose.
- To meet our legal obligations: tax, audit, lawful government requests with valid process.
4. Where data lives
- Patient attachments (photos, audio, PDFs): AWS S3, Mumbai region (
ap-south-1), encrypted at rest with AES-256.
- Patient notes + your account: AWS DynamoDB, currently US East (Virginia), encrypted at rest. We plan to migrate to Mumbai region as we grow.
- Evidence index (500K+ papers): Zilliz Cloud — public medical literature only, no patient data.
- AI processing: Google Gemini API. Per Google's terms, prompts and outputs are not used to train models when accessed via the paid API tier.
All data in transit uses HTTPS (TLS 1.2+).
5. Who we share with
We do not sell, rent, or share clinical data with any third party for
marketing, advertising, or model training. Operational subprocessors:
- Amazon Web Services — hosting (Lambda, DynamoDB, S3, CloudFront)
- Google — Firebase Authentication (email + Google Sign-In), Gemini API for AI features
- Zilliz Cloud — Milvus vector database hosting the evidence index (no patient data)
- Razorpay — payment processing (no clinical data shared)
- Amplitude — anonymized product analytics
6. Your rights under DPDP
You have the right to:
- Access + export all your data. Use the Export my data button on your Account screen — you'll get a complete JSON dump.
- Correct inaccurate data. Edit directly in the app or email us.
- Delete your account and all associated data permanently. Use the Delete my account button on the Account screen, or email us. We process erasure within 30 days.
- Withdraw consent at any time by deleting your account.
- Lodge a grievance with us first (see §10) and escalate to the Data Protection Board of India if unresolved.
7. Data retention
- Account + clinical data: retained as long as your account is active.
- After account deletion: all data wiped within 30 days. Backups purged within 90 days.
- Voice dictations: persisted to S3 indefinitely while account is active (so you can replay), wiped on account deletion.
- Anonymized analytics: retained indefinitely (no personal identifiers remain).
8. Security
- All data encrypted in transit (HTTPS) and at rest (AES-256).
- Authentication via Firebase with secure session tokens.
- Backend access requires authenticated doctor role per request.
- Per-user rate limits on AI endpoints to prevent abuse.
- We will notify affected users and the Data Protection Board of India within 72 hours of becoming aware of a notifiable breach.
9. Children
MedQlub is a tool for medical professionals only. We do not knowingly
collect data from anyone under 18. Patient data recorded by doctors
may include minors — that data is governed by the treating doctor's
duty of care and applicable law.
10. Grievance officer
Karthik Appadurai · karthik.uic@gmail.com
We respond to all grievances within 7 days and resolve them within 30 days.
11. Changes
We'll notify you via the app and email at least 14 days before any
material change to this policy.
← Back to MedQlub