MediCab Privacy Policy
Last updated: 18 July 2026
1. Introduction — who we are and what this policy covers
MediCab is operated by AAYUU SOFTWARE (OPC) PRIVATE LIMITED (CIN: U62099KA2026OPC223028), a company incorporated in India with its registered office at Sabari Complex, National Plaza, 24, Field Marshal Cariappa Rd, Shanthala Nagar, Ashok Nagar, Bengaluru, Karnataka 560025 ("MediCab", "we", "us", "our").
For the purposes of the Digital Personal Data Protection Act, 2023 ("DPDP Act"), AAYUU SOFTWARE (OPC) PRIVATE LIMITED is the Data Fiduciary — the entity that determines the purpose and means of processing your personal data — for the MediCab mobile applications (iOS and Android), the MediCab caregiver web dashboard, and the medicab.co.in website (together, the "Service").
This policy explains what personal data we collect, why we collect it, who we share it with, how we protect it, how long we keep it, and the rights you have over it. It applies to everyone who uses the Service: household admins, members (patients), caregivers, and visitors to our website.
MediCab handles information about your family's health. We have written this policy to be readable by anyone in your household — not only by lawyers. Where the law uses a specific term, we explain it in plain words.
What we will never do: we do not sell your personal data, we do not use your health data for advertising, and we do not show advertising of any kind in the Service.
2. What data we collect
We collect only what the Service needs to work. Grouped by category:
2.1 Account data
- Name, email address, and phone number
- Language preference
- Your role in a household (admin, member, or caregiver)
2.2 Health data — sensitive personal data
This is the most important category. Under Indian law (including the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 — the "SPDI Rules"), health information is sensitive personal data, and we treat it with the highest level of protection described in Section 5 and Section 6 of this policy.
- Medicines in your household's shared cabinet (names, strengths, quantities, expiry dates)
- Treatment details: which medicine, for whom, on what schedule, and for how long
- Dose logs: whether each dose was taken, missed, skipped, or taken late, and when
- Adherence records derived from dose logs
- Prescription images you choose to upload
- Drug-interaction flags generated by the Service's safety checks
- Your Cabinet Query questions and the medicine lists checked by our interaction checker, kept as a record of your use of the AI safety features (see Section 4.3 and Section 7)
2.3 Household and relationship data
- Which household you belong to and who its other members are
- Admin, member, and caregiver relationships within the household
- Caregiver access grants: which caregiver may view which member's dose status
2.4 Refill and fulfilment data
- Delivery address for a refill order
- Order details (medicine, quantity, price, order status)
- The prescription image shared with the partner pharmacy you choose for that order
2.5 Payment data
- Payments are processed by Razorpay, our payment processor. We do not store your card, UPI, or bank details.
- We record only: the order amount, the payment status, and the platform fee charged on the order.
2.6 Website data
- If you join our waitlist on medicab.co.in: your email address, your city or area, and (optionally) your pincode.
- The website uses the same structural, health-content-free analytics described in Section 2.7 to understand visits and drop-offs. We do not use advertising cookies, ad trackers, or any third-party advertising technology on the website or in the app.
2.7 Technical and product-analytics data
- Device information (device model, operating system, app version)
- Structural product-analytics events — for example, that a feature was opened or a step in a flow was completed
- Error and crash reports
Important limit: our analytics and error-monitoring tools are configured to record structural events only. They are explicitly configured not to receive health content — no medicine names, no dose statuses, no prescription content, no treatment details.
3. How and why we use your data
Under the DPDP Act, our lawful basis for processing your personal data is your consent, given when you create an account (or, for the waitlist, when you submit the form). We process each category of data only for the specific purposes below, and for nothing else ("purpose limitation"). We collect only what those purposes require ("data minimisation"), and we collect sensitive personal data (health data) only where it is strictly necessary to provide the Service.
| Data category | Purpose |
|---|---|
| Account data | Creating and securing your account; signing you in; contacting you about the Service; showing the app in your preferred language |
| Health data | Running the core Service: tracking the household cabinet, scheduling treatments, sending dose reminders, recording dose confirmations, showing the caregiver dashboard, and running drug-interaction safety flags |
| Relationship data | Enforcing who in your household may see and do what — so a caregiver sees only what they have been granted, and a member's data is visible only to the household members entitled to it |
| Refill and fulfilment data | Coordinating a refill order with the partner pharmacy you choose, and letting you and your pharmacy track that order |
| Payment data | Charging and recording the platform fee on refill orders; handling refunds and disputes |
| Website data | Telling you when MediCab is available in your area |
| Technical data | Keeping the Service reliable and secure; diagnosing crashes and errors; understanding which features are used so we can improve the product |
We do not use your data for advertising, profiling for marketing, or automated decisions that have legal effects on you. We do not sell or rent personal data to anyone.
If we ever want to use your data for a new purpose not listed here, we will ask for your consent first.
4. Who we share your data with
We share personal data only with the parties below, only to run the Service, and only to the minimum extent needed. Except for partner pharmacies (explained below), each of these parties is a Data Processor acting on our instructions — they may not use your data for their own purposes.
4.1 Infrastructure and service providers (processors)
- Google Firebase (Firestore database, Authentication, Cloud Functions, Cloud Storage, Cloud Messaging, Hosting) — our primary infrastructure. Your data is stored in the asia-south1 (Mumbai, India) region. Your health data resides in India.
- Google Gemini (AI) — powers the "Cabinet Query" feature (Section 4.3).
- Razorpay — processes payments for refill order fees. Razorpay handles your payment instrument under its own security certifications; we never see or store card details.
- WhatsApp, via 360dialog (a WhatsApp Business Solution Provider) — delivers dose reminders and order-status notifications to patients and caregivers who use WhatsApp notifications. The message content is limited to what the notification requires.
- PostHog (product analytics) and Sentry (error monitoring) — receive structural and operational events only, configured to exclude health content (see Section 2.7).
4.2 Partner pharmacies (independent businesses)
When you request a refill, we share the relevant prescription image and delivery address with the local partner pharmacy you choose, so that it can decide whether to dispense and then deliver the order.
Partner pharmacies are independent licensed businesses, not part of MediCab. For the act of dispensing, the pharmacy is the legal gatekeeper: it independently decides whether your prescription is valid and whether a medicine (including Schedule H prescription drugs) may lawfully be dispensed. For the data it receives to perform dispensing and delivery, the pharmacy acts as an independent data fiduciary in its own right, subject to its own legal obligations.
4.3 The AI "Cabinet Query" feature
When you ask a Cabinet Query question (for example, "which of my medicines are for fever?"), your question and your household's cabinet medicine list are processed by Google Gemini entirely server-side, through our own proxy — never directly from your device to the AI provider. The AI is intended and configured to answer questions about medicines logged in your household's cabinet. It never diagnoses, never recommends what medicine to take for a symptom, and if a query looks like a medical emergency it does not answer — it tells you to call your local emergency number or get medical help right away. Your question and the AI's response are recorded in your private AI query log, described in Sections 2.2 and 7.
4.4 Legal disclosures
We may disclose personal data if required by Indian law — for example, in response to a lawful order of a court, the Data Protection Board of India, or another authority empowered to require it. We will disclose only what the order requires.
We do not sell personal data. We do not share personal data with advertisers, data brokers, or insurers.
5. Prescription and health data — special handling
Because prescription images are among the most sensitive things you entrust to us, they receive additional, specific protections:
- Metadata stripping. When you upload a prescription image, embedded EXIF metadata — including GPS location — is stripped before storage.
- Content hashing. Each image is content-hashed (SHA-256) on upload, so we can detect duplicates and verify integrity.
- India-resident storage. Images are stored in Google Cloud Storage in the asia-south1 (Mumbai) region.
- No public URLs. Prescription images are never exposed through public or guessable links.
- Short-lived access links. Whenever a prescription image is shown — to you in the app, or shared with your chosen pharmacy for a refill — it is served only through a time-limited signed link that expires automatically: always within 72 hours, and usually within minutes. Once a link expires it stops working and a fresh one must be issued; we do not keep a standing link open.
- Access logging. Every access to a prescription image is recorded in an access log: who accessed it and when. These logs are append-only and cannot be edited.
A note on reminder messages. A dose reminder necessarily names the medicine — that is what makes it useful. Reminders sent as push notifications may be visible on a locked screen depending on the member's device settings, and reminders sent over WhatsApp appear in that chat. We keep reminder content to the minimum needed (medicine and time), and household admins can choose which channels each member uses.
6. Data storage, security, and location
- Location. All personal data is stored in India, in the Google Cloud asia-south1 (Mumbai) region. We consider India-resident storage of Indian families' health data a core design commitment, not an accident of configuration.
- Encryption. Data is encrypted in transit (TLS) and at rest.
- Access controls. Access within the app is governed by household roles — an admin, a member, and a caregiver each see only what their role permits. Server-side, access to production data is restricted to the minimum personnel and systems needed to operate the Service.
- Application integrity. Our backend accepts requests only from attested, genuine instances of the MediCab app (application attestation is enforced on all backend functions).
- Audit logging. Reads of one user's health data by another user (for example, a caregiver viewing a member's dose status) and accesses to prescription images are recorded in append-only audit logs.
- Reasonable security practices. We maintain reasonable security practices and procedures consistent with the SPDI Rules and the DPDP Act, and we review them as the Service evolves.
- Breach notification. If a personal data breach occurs, we will inform affected users and the Data Protection Board of India without delay, and provide the Board detailed information about the breach within 72 hours of becoming aware of it, as required by the DPDP Act and its Rules.
No system is perfectly secure. If you believe your account has been compromised, contact support@medicab.co.in immediately.
7. Data retention
- While your account is active: we retain your data for as long as your account (and your household) is active, because the Service — dose history, adherence records, inventory — depends on it.
- When you delete your account or household: deletion enters a 30-day reversible grace period. During those 30 days you can change your mind and restore the account. After 30 days, your data is permanently purged. Household deletion cascades: it removes the household's cabinets, treatments, dose logs, prescriptions, and related records. One exception protects other members: if you are the sole admin of a household that still has other members, your deletion request stands and your grace period runs as normal, but the final purge of the shared household is completed only once the household has another admin or the remaining members have been removed — so that other members' health data is neither destroyed without their consent nor orphaned in an unmanageable household. (See Terms of Service Section 11.)
- Backups. After a purge, residual copies of purged data may persist for a short additional period in our encrypted system backups, which rotate automatically. All residual backup copies are deleted within 35 days of the purge. Backups are never used to restore data that a user has deleted.
- Prescription images: currently retained until you delete them or until the account/household is deleted (subject to the 30-day grace period).
- AI query history: your Cabinet Query questions and interaction-check history are kept while your account is active, and are permanently deleted when your account is deleted (after the 30-day grace period).
- Payment and order records: retained as required by Indian tax and accounting law, even after account deletion, in a form limited to what those laws require.
- Waitlist data: retained until we launch in your area and you decide whether to sign up, or until you ask us to delete it.
- Compliance records kept after deletion: when an account or household is purged, we keep a minimal audit record — for example, that a deletion took place and when, and the associated consent record — so we can demonstrate that we acted on your request. We keep this to the minimum needed and it contains no health data.
Where the DPDP Rules prescribe a maximum retention period for a category of data, we will comply with the shorter of that period and the periods above.
8. Your rights under the DPDP Act
As a Data Principal under the DPDP Act, you have the following rights. To exercise any of them, email grievances@medicab.co.in from your registered email address (or contact us by the other means in Section 14 if you no longer have access to it).
- Right to access. You may ask for a summary of the personal data we hold about you, the processing activities we perform on it, and the identities of the parties with whom it has been shared.
- Right to correction, completion, and updating. You may ask us to correct inaccurate data, complete incomplete data, and update outdated data. Most account and health data can also be edited directly in the app.
- Right to erasure. You may ask us to erase your personal data. Erasure is carried out through the account-deletion process in Section 7 (including the 30-day grace period), except where Indian law requires us to retain specific records.
- Right of grievance redressal. You may raise a grievance about how we handle your data (Section 12).
- Right to nominate. You may nominate another individual who can exercise your rights on your behalf if you die or become incapacitated. To register a nominee, contact grievances@medicab.co.in.
- Right to withdraw consent. See Section 9.
- Data export. You may request an export of your data in a structured, machine-readable format by writing to grievances@medicab.co.in.
We will respond to rights requests within the timeframe prescribed under the DPDP Act and its Rules, and in any event within 30 days, unless a shorter period is legally required.
A note on households. Some data is shared by design within your household — for example, the shared cabinet belongs to the household, and a member's dose status is visible to the household's admin and to caregivers the member's data has been shared with. Exercising your rights over your own data does not give you rights over other members' data.
9. Consent and withdrawal
- How consent is obtained. When you create an account, we present a consent notice describing the personal data to be processed and the purposes, and we ask for your clear affirmative agreement before processing begins. The current consent notice is published as the MediCab Consent Notice, version-stamped and presented at signup and at account claim.
-
Consent is specific and layered. Your consent covers only the purposes in Section 3, and not everything is bundled together:
- Essential processing — account data, the household cabinet, treatments, dose tracking, dose reminders via push notification, and household roles. This is the Service itself; it cannot run without this processing.
- Per-action processing — some processing happens only when you take a specific action, and never otherwise. Your prescription and delivery address are shared with a pharmacy only when you place a refill order with that pharmacy. Your question and cabinet medicine list are processed by the AI only when you ask a Cabinet Query. If you never use these features, this processing never occurs.
- Optional processing — features you can switch on or off without losing the core Service: WhatsApp notifications (an alternative reminder and order-update channel, involving Meta/WhatsApp via 360dialog — used only if enabled for a member), and product analytics used to improve the Service. You may opt out of either without losing any core functionality.
- Withdrawing consent. You may withdraw your consent at any time, as easily as you gave it — through the app's settings or by emailing grievances@medicab.co.in. Withdrawal does not affect the lawfulness of processing already carried out. Withdrawing consent for optional or per-action processing (for example, opting out of analytics, or simply not using refills or Cabinet Query) does not affect your use of the core Service.
- Withdrawing consent for essential processing. Because the core Service cannot run without the essential processing above, withdrawing that consent means we can no longer provide the Service to you. It is treated as a request to delete your account and follows the deletion process in Section 7 (including the 30-day grace period, during which you may reverse the withdrawal).
- Managing another person's medication. If you are a household admin managing a member's medication (for example, an adult child managing a parent), you are responsible for having that member's knowledge and consent before entering their health information. Every adult member has their own account, their own consent, and their own rights under this policy. Caregiver access to a member's data is a permission granted in the app, and it can be revoked.
10. Children's data
The Service is intended for adults (18 years and older). Household admins, members, and caregivers must all be adults. The patients whose medication the Service manages are adults.
We do not knowingly collect personal data from anyone under 18. Under the DPDP Act, processing a child's personal data requires verifiable parental consent and is subject to additional restrictions; the Service is not designed or offered for that use. If we learn that an account belongs to a person under 18, we will delete it. If you believe a minor is using the Service, contact grievances@medicab.co.in.
11. Cross-border access (NRI caregivers)
Many MediCab caregivers live outside India while the patient lives in India. Here is how that works with your data:
- Your data stays stored in India (asia-south1, Mumbai), regardless of where household members log in from.
- A caregiver or admin outside India accesses that India-resident data remotely over an encrypted connection, with the same role-based permissions as any other user. Displaying data to an authorised user abroad is itself a cross-border processing event: by granting household or caregiver access to a person located outside India, the member concerned consents to their data being remotely viewed and processed from that location. This consent is part of the access grant and ends when the grant is revoked.
- We do not transfer or replicate the household's health data to servers outside India for storage.
12. Grievance redressal
If you have any concern about how your personal data is handled — or want to exercise any right in Section 8 — contact our Grievance Officer:
- Grievance Officer: Avijeet Kartikay, AAYUU SOFTWARE (OPC) PRIVATE LIMITED
- Email: grievances@medicab.co.in
- Postal address: Sabari Complex, National Plaza, 24, Field Marshal Cariappa Rd, Shanthala Nagar, Ashok Nagar, Bengaluru, Karnataka 560025
We will acknowledge your grievance promptly and respond within 30 days, or any shorter period mandated by applicable law (including the timelines under the DPDP Rules and the SPDI Rules).
If you are not satisfied with our response, you have the right to approach the Data Protection Board of India under the DPDP Act.
13. Changes to this policy
We may update this policy as the Service or the law changes. When we make a material change, we will notify you in the app and/or by email before the change takes effect, and — where the change involves processing that requires it — ask for your consent again. The "Last updated" date at the top always reflects the current version. Earlier versions are retained for audit.
14. Contact us
AAYUU SOFTWARE (OPC) PRIVATE LIMITED (CIN: U62099KA2026OPC223028)Sabari Complex, National Plaza, 24, Field Marshal Cariappa Rd, Shanthala Nagar, Ashok Nagar, Bengaluru, Karnataka 560025
- General enquiries: info@medicab.co.in
- Customer and refill support: support@medicab.co.in
- Privacy, data rights, and grievances: grievances@medicab.co.in
End of document.