Privacy Policy
Last updated: March 2026
1. Introduction
EzerHeal ("we", "our", "us") is operated by ESPR Creative Lab. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile applications and website (collectively, the "Platform").
We have designed this policy and our data practices around the requirements of the Digital Personal Data Protection Act, 2023 (DPDP Act) and applicable Indian regulations.
2. Information We Collect
Personal Information: Name, phone number, email address, date of birth, gender, profile photo, and preferred language.
Health Information: Medical history shared during consultations, chat messages exchanged with your doctor, prescriptions, lab reports, and any photos or documents you upload. Video and audio consultations are streamed in real time and are not recordedor stored by EzerHeal.
Payment Information: Transaction details processed through Razorpay. We do not store your card details or UPI PIN.
Device Information: Device type, operating system, app version, and crash logs for service improvement.
Doctor Verification: Medical council registration number, degree certificates, and government-issued ID for KYC verification.
3. How We Use Your Information
- To facilitate teleconsultations between patients and doctors
- To process payments and issue receipts
- To verify doctor credentials and maintain platform integrity
- To deliver medicines and lab test results
- To send appointment reminders and health notifications
- To improve our services and user experience
4. Data Storage and Security
Your data is stored on Supabase infrastructure in the Mumbai, India (ap-south-1) region. We use encryption in transit (TLS) and at rest. Aadhaar numbers, when collected for doctor verification, are converted to a keyed one-way hash (HMAC-SHA-256) before storage — the raw Aadhaar number is never written to our database.
Access to patient health records is restricted through Row Level Security policies. Doctors can only access records for patients with active appointments.
5. Third-Party Services
We use the following third-party services to operate the Platform:
- Supabase: Database hosting, authentication, and file storage (Mumbai, India region)
- Razorpay: Payment processing (UPI, cards, net banking, wallets)
- Agora: Video and audio call infrastructure for teleconsultations
- Firebase Cloud Messaging: Push notification delivery
- MSG91: SMS OTP delivery for phone verification
- PostHog: Product analytics and error reporting. In our apps, analytics are linked to an internal user ID and account role only. On the marketing website, PostHog stays off until you accept it in the consent banner. App-usage events may include non-identifying interaction data, and known sensitive fields (name, phone number, Aadhaar, payment identifiers) are stripped before an event is sent. No health record content is sent
- Resend: Transactional email delivery
Each third-party service processes only the minimum data necessary for its function. We do not sell your personal data to any third party.
Our primary data storage is in India (Supabase, Mumbai region). Some of the processors above operate infrastructure outside India — for example email delivery (Resend), push notifications (Firebase Cloud Messaging), video/audio call routing (Agora), and analytics (PostHog, hosted in the United States by default) — and may process limited data abroad in order to provide their service.
6. Data Sharing
We share data only with:
- Your assigned doctor during a consultation
- Payment processors (Razorpay) for transaction processing
- Pharmacy and lab partners for order fulfillment
- As required by Indian law or government authorities
7. Data Retention
We retain your data for the following periods:
- Account data: Retained while your account is active, deleted within 30 days of account deletion request
- Consultation records and prescriptions: 3 years (as required by Telemedicine Practice Guidelines 2020)
- Chat messages: 2 years from consultation date
- Files shared during a consultation (photos, documents, lab reports): 3 years, in line with the medical-record retention requirement
- Payment records: 7 years (as required by Indian tax regulations)
- Push notification logs: 6 months
- Audit logs: 3 years
- KYC documents (doctors): Duration of registration plus 1 year
After the retention period, data is permanently deleted or anonymised.
8. Your Rights
Under the DPDP Act 2023, you have the right to:
- Access your personal data held by us
- Request correction of inaccurate data
- Request deletion of your account and associated data
- Withdraw consent for data processing
- Nominate another person to exercise your rights
To exercise these rights, contact us at [email protected].
9. Account Deletion
You can request deletion of your account and all associated personal data at any time through the app (Settings > Account > Delete Account) or by emailing [email protected].
When you request deletion, your account is deactivated immediately and permanently erased after a 30-day grace period, during which you can cancel the request by signing back in. On permanent deletion, your profile, personal information, chat messages, profile photo, identity (KYC) documents, and sign-in credentials are removed. Consultation records, prescriptions, lab reports, and files shared during a consultation are retained for the medical-record retention period (3 years), and payment records and audit logs are retained as required by law (see Data Retention above). Your phone number is disassociated and can be used to create a new account.
10. Data Export (Portability)
Under the DPDP Act 2023, you have the right to receive a copy of your personal data in a structured, machine-readable format. You can request a data export through the app (Settings > Account > Export My Data) or by emailing us. Your export will include your profile information, consultation history, prescriptions, order history, wallet transactions, and consent records. File download links in an export are available for 24 hours.
11. Children's Privacy
EzerHeal accounts are held only by adults aged 18 and over, and the Platform enforces this at the account level. Minors may not create their own accounts. A parent or legal guardian may add a minor in their care as a dependent under the guardian's own account; in that case the guardian provides consent for, and manages, the minor's personal and health data on their behalf, consistent with the DPDP Act 2023. We do not use children's data for tracking, behavioural monitoring, or targeted advertising, and we never sell it. If you believe a minor has independently provided us with personal data outside a guardian-managed dependent profile, please contact us at [email protected] and we will address it.
12. Cookies and Tracking
Our mobile apps do not use cookies. On our website (ezerheal.com), analytics (PostHog) are off by default and load only after you accept them in the consent banner shown on your first visit. If you decline — or simply ignore the banner — no analytics code runs, no analytics cookies are set, and nothing is sent to PostHog. Your choice is remembered in your browser's local storage so we do not ask again; you can change it at any time using the button below. We do not use advertising trackers or sell data to advertisers.
13. Contact Us
For privacy-related inquiries:
ESPR Creative Lab
Aizawl, Mizoram 796001, India
Email: [email protected]
14. Grievance Officer
In accordance with the DPDP Act 2023, you may contact our Grievance Officer for any concerns regarding the processing of your personal data:
Email: [email protected]