Privacy Policy
Last updated: March 2026
SimplisLabs Pvt Ltd. (“SimplisLabs”, “we”, “us”) operates the SimplisLabs platform. This Privacy Policy explains how we collect, use, store, and protect your data.
1. Information We Collect
Doctor Information: Name, email, phone number, medical registration number, state medical council, qualification, specialization, clinic details, and profile photo. Collected directly from the doctor during registration and profile setup within the app.
Patient Information (entered by doctors): Name, age, gender, phone number, medical history, clinical notes, prescriptions, and appointment details. Collected when doctors create patient records and conduct consultations within the app.
Usage Data: Device information, IP address, app usage patterns, and feature interaction metrics. Collected automatically during app usage.
Audio Recordings: Consultation recordings are captured via the device microphone during active consultations, processed for transcription, and immediately deleted after processing. Transcripts are stored as clinical notes.
2. How We Use Your Data
- Provide and improve the SimplisLabs platform
- Generate AI-powered clinical notes, prescriptions, and treatment plans (only with your explicit consent; de-identified clinical data such as age, gender, symptoms, and diagnosis is sent to third-party AI services — patient names and phone numbers are never shared)
- Transcribe consultation audio recordings into clinical notes (audio is sent to a transcription service and deleted immediately after processing)
- Verify doctor credentials with NMC and state councils
- Send appointment reminders, prescription documents, and treatment plans via WhatsApp and email at the doctor's request
- Process subscription payments
- Provide customer support
- Analyze usage patterns to improve our service (anonymized and aggregated only)
3. Data Storage & Security
- All data is stored on Google Cloud Platform servers located in Mumbai, India (asia-south1 region)
- AES-256 encryption for data at rest
- TLS 1.3 encryption for data in transit
- Google Cloud Key Management Service (KMS) for encryption keys
- Role-based access control for all internal systems
- Regular security audits and penetration testing
4. Data Sharing
We do not sell your data.
We obtain your explicit consent before sharing any data with third-party AI services. You can grant or revoke this consent at any time in the app's Settings. AI features are fully disabled until consent is granted.
We share data with the following service providers:
- Google Cloud Platform: Infrastructure hosting, data storage, and encryption key management. All data remains in India (asia-south1 region).
- OpenAI: AI-generated clinical notes, prescriptions, and treatment plans. Only de-identified clinical data (age, gender, symptoms, diagnosis) is shared — patient names and contact details are never sent.
- Sarvam AI: Speech-to-text transcription of consultation audio. Audio files are deleted immediately after transcription.
- MSG91: Delivery of OTP codes, appointment reminders, and prescription documents via WhatsApp and email.
All third-party service providers are bound by data processing agreements that require them to provide the same or equivalent level of data protection as described in this policy. They may only process data on our behalf and in accordance with our instructions.
We may also share data when required by Indian law or court order, or in anonymized, aggregated form for research and analytics.
Patient data entered by doctors is never shared with third parties except as required for core platform functionality (e.g., WhatsApp notifications sent at the doctor's request).
5. Data Retention
- Clinical records: Retained for a minimum of 3 years per ICMR guidelines, or longer as required by applicable medical record retention laws.
- Account data: Retained while your account is active and for 90 days after account deletion.
- Audio recordings: Deleted immediately after transcription processing (typically within minutes).
- Usage analytics: Retained in anonymized form indefinitely.
6. Purpose Limitation
Data collected for a specific purpose is only used for that purpose. We do not repurpose your data without obtaining your consent first. We do not use your data for advertising, marketing, or data mining. We do not build user profiles based on collected data, and we do not attempt to identify anonymous or de-identified users.
7. Your Rights
- Access your personal data
- Correct inaccurate data
- Request data export in a portable format
- Delete your account: You can delete your account directly within the app by navigating to Settings > Delete Account. All personal data will be permanently removed within 90 days, except clinical records retained as required by law.
- Revoke AI data consent: You can revoke consent for AI data processing at any time by navigating to Settings > AI Data Consent in the app and turning it off. AI features will be immediately disabled and no further data will be sent to third-party AI services.
- Withdraw consent for any other optional data processing
- Lodge a complaint with relevant data protection authorities
To exercise these rights, you may use the in-app settings or contact privacy@simplis.in.
8. Cookies, Tracking & Advertising
Our web application uses essential cookies for authentication and session management. We use anonymized analytics (no personal data) to understand usage patterns and improve the product. We do not use advertising trackers, advertising networks, or third-party SDKs for advertising purposes. We do not sell browsing data. We do not track user activity across other apps or websites. The app does not use the App Tracking Transparency framework because no cross-app tracking occurs.
9. Children's Privacy
The Service is intended for licensed medical practitioners (18+). We do not knowingly collect data from children under 18. Patient records for minors are entered and managed by their treating physician.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes via email or in-app notification. Continued use of the Service after changes constitutes acceptance of the updated policy.
11. Contact
Email: privacy@simplis.in
Data Protection Officer: dpo@simplis.in
SimplisLabs Pvt Ltd. Pune, Maharashtra, India