Last updated: 22 July 2026
This Privacy Policy explains how Mobile Health Vault (“the Platform”, “we”, “us”, “our”, operated by Vitaar Technologies Private Limited, a company incorporated in India) collects, uses, stores, and protects personal and health data across all account types the Platform supports: patient, doctor, reception/nurse, hospital, diagnostics, and medical shop. We act as a Data Fiduciary under the Digital Personal Data Protection Act, 2023 (“DPDP Act”) for the personal data described below.
Account details (name, phone number, date of birth, role); health records you or a linked doctor/hospital/diagnostics centre add (prescriptions, lab results, vitals, allergies, conditions, immunizations, appointments, diary entries, imaging studies); documents you upload or receive; voice recordings you submit for dictation (doctor accounts, deleted from our servers immediately after transcription); diagnosis and vitals text submitted for AI medicine suggestions; professional credentials for doctor/hospital/diagnostics/medical-shop accounts (medical council registration number, GST number, drug licence number); and basic usage data (device/browser, IP address, timestamps) to keep the Platform secure and working.
To store and organise health records and present them as a timeline, reports and reminders; to enable communication between patients and their doctors, hospitals, diagnostics centres and medical shops; to generate AI-assisted medicine suggestions and voice-dictation transcripts at a doctor’s request; to verify professional credentials before activating doctor, hospital, diagnostics or medical-shop accounts; to process appointments, video consultations, and pharmacy orders; to process subscription payments; to send OTPs and account/security notifications; and to respond to support requests.
We process your personal data on the basis of your consent, collected through the itemised Privacy & Consent controls in Settings and at signup — some purposes (such as accepting these Terms and processing health data needed to operate your account) are required to use the Platform; others (such as marketing communications and analytics) are optional and can be withdrawn at any time without affecting your account. Where a family member’s profile is created by a guardian, or a minor’s profile requires guardian consent, that consent is recorded against the guardian’s account.
Health records and documents are stored in encrypted object storage and transmitted over HTTPS. Passwords are hashed with PBKDF2-HMAC-SHA512 at a high iteration count — we never store your password in plain text or in any recoverable form. Secure Vault documents use end-to-end encryption: the encryption key is derived from your own PIN and is never sent to or stored on our servers, so we cannot decrypt Vault contents ourselves. Aadhaar numbers, where provided, are encrypted separately from the rest of your account.
We do not sell your health data. Records are shared with a third party (an insurer, another provider, or a linked account) only when you or your treating doctor/hospital explicitly initiate that share from within the Platform. We use the following categories of third-party service providers to operate the Platform, each processing only the data needed for their function: cloud storage and email delivery (AWS); payment processing (Razorpay); SMS/WhatsApp/OTP and voice-call delivery (Exotel, Twilio); AI-generated summaries and medicine suggestions (Anthropic’s Claude API, given only the diagnosis/vitals or record content you or your doctor choose to include); voice-dictation transcription (OpenAI’s Whisper API, given only the audio clip submitted, and the clip itself is deleted from our servers immediately after transcription); and nearby-lab search (Google Places API, given only the coordinates you provide for that search).
When a doctor uses AI medicine suggestions or a user looks up medicine information or “Compare alternatives”, we process only the diagnosis, vitals, or medicine name/composition submitted, in order to return suggested medicines or matching brands with general safety information from our own catalog and, for suggestions, a third-party AI model. We do not collect, scrape, or store pharmacy or provider pricing, stock, or any provider’s customer data through this feature — see the corresponding section of the Terms of Service.
Where hospitals or diagnostics centres transmit medical imaging (DICOM studies) through the Platform, that imaging and its metadata are stored encrypted and are only accessible to the patient it belongs to and, for sharing features, providers the patient has explicitly granted access to.
Linking Aadhaar or an Ayushman Bharat Health Account (ABHA) is optional. If provided, this data is encrypted separately from the rest of your account and used only for identity verification and Ayushman Bharat Digital Mission (ABDM) record-interoperability features you choose to use. ABDM-linked record sharing occurs only through specific, informed, time-bound consent you grant for each transaction via the consent-manager flow.
Medical council registration numbers, GST numbers, and drug licence numbers submitted by professional accounts are used solely to verify eligibility to operate on the Platform, including automated verification against available government registries where technically possible, and are retained for as long as the account remains active plus any period required by applicable law.
We retain your personal and health data for as long as your account is active. If you delete your account, we delete your personal data and records within a reasonable period, except where retention is required by law (for example, billing records, or professional-verification records for regulated account types).
Under the DPDP Act and as reflected in Settings → Privacy & Consent, you may access, correct, export (as a JSON download), or request erasure of your personal data at any time, and withdraw any optional consent without affecting your account. Guardians may exercise these rights on behalf of a minor’s profile they manage. Grievances that cannot be resolved through in-app tools can be raised with our Support team — see section 15.
Family-member profiles for children are managed by the parent or legal guardian account holder, who provides guardian consent at the time the profile is created and remains responsible for the accuracy and appropriate use of that data.
Some third-party service providers we use (see section 6) may process data outside India in the course of providing their service to us (for example, AI model inference). Where this occurs, we require those providers to maintain security and confidentiality obligations consistent with this Policy and applicable law.
In accordance with the Digital Personal Data Protection Act, 2023, grievances relating to this policy can be raised with our Support team at support@mobilehealthvault.com. We acknowledge complaints within 24 hours and aim to resolve data-related grievances within 90 days. If a personal data breach occurs that is likely to affect you, we will notify you and, where required, the Data Protection Board of India, describing the nature of the breach and steps you can take to protect yourself.
We may update this Privacy Policy from time to time. Material changes will be announced on the Platform. Continued use of the Platform after an update means you accept the revised Policy.
Questions about this Privacy Policy, or requests relating to your data rights, can be sent to support@mobilehealthvault.com.