← Back to mypai.in

Privacy Policy

Draft — last edited July 2026, not yet published

⚠ This is a working draft, not a final legal document. It has not been reviewed by a lawyer, and the formal legal consult for how India's Digital Personal Data Protection (DPDP) Act applies to this product is still pending. Sections marked (AI-drafted) below are boilerplate generated to speed up review, not legal advice — do not treat this page as binding or publish it as final until it has been reviewed by qualified counsel.

What this covers

This policy describes how pAI ("we", "the assistant") handles information when a doctor uses the pAI widget embedded in a clinic's existing patient management system.

What we don't do

pAI does not hold a standing copy of a clinic's patient records. It does not store diagnoses, prescriptions, or clinical notes — it has no fields for them. Every patient lookup is a live, one-time request to the clinic's own system, not a mirrored database.

What passes through pAI

What reaches the outside AI providers (Google Gemini / OpenAI)

Most requests are resolved by pattern-matching and never reach an AI model at all. For the ones that do, the patient's name and phone number are automatically replaced with a generic reference before the request leaves our infrastructure — the AI providers never see real patient identity.

OpenAI is explicitly instructed not to retain or train on this data (store: false on every request). We do not yet have a signed Data Processing Agreement in place with either provider — this is a known gap, tracked internally, and worth confirming is resolved before relying on this policy for anything beyond a small pilot.

How long things are kept

Where this is hosted

The pAI service runs on cloud infrastructure operated by us. The clinic's own patient and appointment system is a separate system the clinic already runs and controls — pAI only ever calls it over the network, it never takes it over.

Your rights

If you're a clinic, doctor, or patient with a question about data handled through pAI, contact us at pankajagarwal8890@gmail.com.

(AI-drafted) Under India's Digital Personal Data Protection (DPDP) Act, 2023, where it applies to information handled through pAI, you may have the right to:

(AI-drafted) Grievance Officer: [Name and designated contact details to be published here, as required under the DPDP Act, once appointed.] Until then, direct any grievance to pankajagarwal8890@gmail.com, and we will respond within a reasonable time.

[This section is placeholder boilerplate reflecting the DPDP Act's general framework — it must be reviewed against the final Rules and completed by counsel before publication, including confirming which rights apply given pAI processes data as a processor on behalf of clinics rather than as the primary data fiduciary.]

Changes to this policy

This is an early draft and will change, likely substantially, once formally reviewed. Once published as final, updates will be dated on this page.

Contact

pankajagarwal8890@gmail.com