What data do we collect?
ArogyaKosha collects only the minimum information required to operate the service:
- Your name, email address, and year of birth (for account creation)
- An optional phone number (for phone-based login)
- A profile picture, if you sign in with Google
- Your encrypted medical records — which we cannot read, as they are encrypted in your browser before being sent to us
- File attachments you choose to upload, stored as-is
We do not collect location data, device identifiers, behavioural analytics, advertising IDs, or any information beyond what you explicitly enter.
How do we protect your data?
Client-Side Encryption
All medical record fields are encrypted in your browser using AES-256-GCM before being transmitted to or stored on the server. The server stores and serves ciphertext only — it never has access to the plaintext content of your health records.
Vault PIN & Recovery Code
Your medical records are encrypted under a random data key that is itself wrapped by two independent keys: one derived from your 6-digit Vault PIN, and one derived from a 24-character Recovery Code shown to you once when you set up your vault. Both are derived via PBKDF2-SHA256 (600,000 iterations) with a per-user random salt, entirely on your device or in your browser — the server only ever stores the wrapped (encrypted) data key, never your PIN, your Recovery Code, or the encryption key itself in the clear. Either secret independently unlocks your vault, so losing one does not affect the other, and changing your PIN or regenerating your Recovery Code never re-encrypts your records. The derived key is held only in memory for your session and is never sent over the network.
Authentication Security
Passwords are hashed using bcrypt. Sessions are stored server-side, tied to HTTP-only, SameSite=Lax cookies. Google OAuth is an optional alternative login method.
Transport Security
All data travels over HTTPS with TLS. HTTP connections are automatically redirected to HTTPS.
Do we share your data with third parties?
No. We do not sell, rent, trade, or share your personal data or health records with any third party, ever.
- No analytics services (Google Analytics, Mixpanel, etc.)
- No advertising networks of any kind
- No data brokers or marketing platforms
- No cloud AI services that process your health records without your explicit action
Google Sign-In is an optional authentication method only. If you use it, Google authenticates your identity — your health records are never shared with Google. You may use email or phone login to avoid any Google interaction entirely. Subscription payments are processed by Razorpay (web) or Google Play Billing (Android in-app); we share only the minimum billing information required to complete a transaction, and neither Razorpay nor Google ever receives your medical records. If you use the optional AI document extraction feature (the "Scan" button) to auto-fill a record from a photo or PDF, that one file is sent to Google's Gemini API for text extraction at the moment you tap the button — it is processed to return the extracted fields to you and is not used to train any model or retained by Google beyond that call. Nothing is sent to Gemini unless you explicitly trigger this feature.
Data retention & deletion
Your data is retained for as long as your account is active. You have full control at all times:
- Vault Reset: Permanently and irreversibly deletes all your medical records and uploaded files. If you still have your Vault PIN or your Recovery Code, use "Forgot PIN" on the vault screen instead — it restores full access without losing any data. Reach for Vault Reset only if you have lost both.
- Account Deletion: Removes your account, all health records, vault keys, family memberships, and every uploaded file from the server — immediately and irreversibly. Delete it yourself any time from Profile → Delete Account in the app or on arogyakosha.in, or visit arogyakosha.in/delete-account, which also covers the case where you can't log in. No email or support ticket is required for self-service deletion.
Upon deletion, no backup copies are retained by us. Server-level backups maintained by our hosting infrastructure are outside this policy's scope and are purged on a routine rotation.
Cookies & session management
ArogyaKosha uses a single session cookie (ak_session) to maintain your login state. This cookie is:
- HTTP-only (not accessible to JavaScript — protection against XSS)
- SameSite=Lax (protection against CSRF attacks)
- Valid for 7 days from last activity
We use no tracking cookies, advertising cookies, or any third-party cookies of any kind.
Changes to this policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated effective date. Continued use of ArogyaKosha after changes constitutes acceptance of the updated policy. For significant changes, we will make reasonable efforts to notify registered users.
Contact
Questions about this policy? Email info@polytechnique.in or see our Contact Us page.
Last updated: August 2026 · Effective: August 2026