AI Doctr
Privacy Policy
Last updated: 10 August 2026 · Version 1.0
Scope. This policy applies to AI Doctr — the web application and the iOS and Android apps — and to nothing else. It is a product policy, not a company-wide one. Other Arivaatral products publish their own policies at their own product pages, and those policies say different things because those products work differently.
The short version. AI Doctr is a service, not an offline app. It has accounts, and it stores health information on servers we operate — because a consultation has two people in it and both need to reach the same record. Your data is visible to you and to the clinicians you consult with, and to nobody else. We do not sell it, advertise against it, or ship analytics or advertising SDKs. Some of it is processed by named third parties, listed in section 7 — including consultation content sent to a large-language-model provider when a doctor requests a summary. Every one of those is set out below.
1. Who we are
AI Doctr is developed and operated by Arivaatral, an independent software studio based in Tamil Nadu, India. Arivaatral is the data controller for the account and service data described in this policy. You can reach us at althafrockss@gmail.com.
A note on roles that matters in a clinical product: the clinicians who use AI Doctr are independent practitioners, not our employees. When a doctor records a diagnosis, writes a prescription or keeps notes about you, they are doing so as your clinician and under their own professional and record-keeping obligations. We provide and operate the software they do it in.
2. What the service stores
Account
- Email address and a hashed password, or a phone number if you sign in with a one-time code
- Your role — patient, doctor or administrator — and the hospital or clinic you are attached to, if any
- Session tokens, so you stay signed in, and device tokens if you enable push notifications
If you are a patient
- Name, date of birth, gender, blood group, phone number, address and profile photo
- Allergies and free-text medical notes
- Emergency contact name and phone number
- Your consultations: chief complaint, symptoms, how long they have lasted, urgency, mode (online or in person), appointment time and location
- Every message in a consultation, including images, documents and voice recordings you send, and the text transcript of those recordings
- Documents you upload — reports, scans, results — with their type, category and review status. Some document types are flagged as sensitive inside the product and shown accordingly.
- Prescriptions issued to you: diagnosis, medicines, dosages, durations and instructions
- Test requests raised for you, their clinical indication, and any results and interpretation recorded against them
- Notes your doctor writes about the consultation, the reason it was closed, and any follow-up scheduled
- Any rating or feedback you leave about a consultation
If you are a doctor
- Name, specialisation, qualification, medical licence number, years of experience and profile photo
- Consultation fee, biography, languages, clinic name and clinic address
- Your availability, and everything you write inside consultations
3. Records created before you have an account
A doctor can register a patient in order to start a consultation before that person has signed up. That record may contain your name, date of birth, gender, phone number, address, blood group, allergies, medical notes and emergency contact — entered by your clinician, from your consultation with them.
When you later sign up with the same phone number, you claim that record and it becomes your account. We are stating this plainly because it means data about you can exist in AI Doctr before you have ever opened it. If you want to know whether a record about you exists, or want it removed, email us and we will deal with it — see section 10.
4. What we do not do
- We do not sell, rent or trade your data, and we never will.
- There is no advertising in the product, and no data is shared with advertisers or data brokers.
- We ship no third-party analytics SDK, advertising SDK, attribution SDK or social login in the apps.
- We do not use your consultation content to train AI models, and we send it only to providers whose API terms exclude using submitted content for training.
- We do not read your consultations. Staff access to production data is limited to what is necessary to operate the service or to investigate a fault you have reported.
5. Who can see what
Access is scoped by relationship, and enforced on the server rather than only in the interface:
- A patient sees their own profile, their own consultations, and the prescriptions, documents and test requests within them.
- A doctor sees the patients they are consulting with, and those patients' consultation history with them. A doctor cannot see another doctor's consultations.
- Uploaded documents are not served from public URLs. Access goes through short-lived signed links, generated per request and expiring within 24 hours.
One exception worth stating, because a consultation has to start somewhere. To begin a consultation with someone, a doctor can search the patient directory by name or phone number before any relationship exists. That search returns identifying details only — name, date of birth, gender, phone number, profile photo, and whether the person has any open consultations. It does not return your allergies, medical notes, messages, documents, prescriptions or test results. Those become visible to a doctor only through a consultation between you and them. Where a doctor belongs to a hospital or clinic, the directory they search is limited to that organisation's patients.
6. Artificial intelligence in the product
AI Doctr uses AI in two narrow places. Neither of them makes a clinical decision.
Consultation summaries
A doctor can ask for a written summary of a consultation. When they do, the consultation is assembled and sent to a large-language-model provider, which returns the summary. This happens on request only — no consultation is summarised automatically, and if no doctor requests a summary of your consultation, nothing about it is sent.
What is sent is not de-identified. The material sent includes the patient's name, age, gender and phone number, the chief complaint, symptoms and duration, messages in the consultation, prescribed medicines, test requests, and the doctor's notes. We would rather say this outright than describe it vaguely. The generated summary is stored against the consultation with the time it was produced, and is visible to the doctor.
Voice transcription
Voice messages and dictated notes are uploaded to a speech-to-text provider, which returns the text. The recording and the transcript are both stored with the consultation, as part of the record.
AI Doctr is not a medical device. The summary feature is a reading aid for a clinician over notes that clinician already has. It does not diagnose, does not prescribe, and does not give clinical advice to patients. Nothing generated by a model in AI Doctr should be relied on as a medical opinion. The product is also not an emergency service — in an emergency, contact your local emergency services.
7. Third parties that process your data
This is the complete list of services that receive data from AI Doctr, and what each one receives. If it changes, this page and this table change with it.
| Service | What is sent | When |
|---|---|---|
| Hosting and database provider | All service data, at rest and in transit | Continuously — this is where the application and its database run |
| Large-language-model provider an OpenAI-compatible API |
Consultation content including patient name, age, gender, phone, complaint, symptoms, messages, medicines, tests and doctor's notes | Only when a doctor requests a consultation summary |
| Speech-to-text provider Sarvam AI |
The audio recording you made, and nothing else | Only when a voice message or dictated note is recorded |
| SMS gateway an Indian DLT-registered sender |
Your phone number and the one-time code | Only when you sign in with a phone code |
| Apple Push Notification service | Device token and the notification text — typically who messaged you and the consultation it belongs to | Only if you enable notifications on an Apple device |
| Firebase Cloud Messaging |
Device token and the notification text | Only if you enable notifications on an Android device |
Each of these processes data on our instruction, for the purpose above and no other. We do not permit them to use your data for their own purposes, including model training. Depending on which provider is in use, processing may take place outside India.
Notification content is worth one extra sentence. Push notifications pass through Apple's or Google's infrastructure and can appear on your lock screen. If you would rather they did not reveal who is messaging you, turn off notification previews in your device settings, or turn notifications off in the app.
8. Data stored on your device
The mobile apps cache your consultations, messages and images on the device so the app opens instantly and reads offline, and queue messages you send while you have no signal. Your session token is held in the platform keychain or keystore, not in ordinary storage. All of it is removed when you sign out or delete the app.
9. Retention
- Consultation records — including messages, documents, prescriptions and test results — are retained as part of the clinical record for as long as your account exists, and are subject to the record-keeping obligations of the clinician who created them.
- Account and profile data is retained while your account exists.
- Sessions and refresh tokens expire on their own, and are removed when you sign out.
- Content sent to a processor is retained by that processor only for as long as their processing requires. We keep the result — the summary, the transcript — with the consultation.
10. Your rights
Email althafrockss@gmail.com and we will act on any of the following. We will ask you to verify that the account is yours before we do, because acting on an unverified request about a medical record is its own privacy failure.
- Access and export. A copy of everything the service holds about you.
- Correction. Most profile data you can correct yourself in the app. Clinical entries written by a doctor are corrected by that doctor, and we will pass on a request.
- Deletion. We will delete your account and the data associated with it.
- Withdrawal. You can stop using the service at any time, and turn off notifications, location-free features and voice input individually.
One honest limit on deletion. A consultation is a shared record between you and a clinician who has professional obligations to retain what they did and why. Where those obligations apply, we may retain the clinical record of a consultation after your account is deleted, disconnected from your account and used for nothing else. We will tell you specifically what was retained and why when we process your request, rather than leaving it as a clause on a page.
11. Security
Traffic between the apps and our servers is served over HTTPS. Passwords are stored hashed with bcrypt, never in plain text. Sessions use short-lived tokens with separate refresh tokens that can be revoked. Documents are stored outside the public web root and reachable only through signed links that expire. Access rules are enforced server-side on every request, not assumed from the interface.
No system is perfectly secure, and we are not going to claim otherwise. If a breach affects your data, we will tell you what happened, what was affected and what we did — directly, and without waiting to be asked.
12. Children
AI Doctr is intended for adults. A child's health information may appear in the service where a parent or guardian is managing their care with a clinician, in which case the adult is responsible for that record. We do not knowingly create accounts for children.
13. Changes to this policy
If this policy changes we will update the date at the top of this page. If a change is material — a new processor, a new category of data, a new use of AI — we will say so clearly in the app rather than quietly editing this page. This policy covers AI Doctr only and has no bearing on any other Arivaatral product.
14. Contact
Questions about this policy, about what the service holds, or about anything above go to althafrockss@gmail.com. We answer.