- Who is responsible for what
- What we hold
- How masking works
- What your practitioner sees
- The limits of anonymity
- Why this data is different
- Caresoft access
- Chat, calls and video
- Anonymous tools
- Store orders and delivery
- Payments
- Why we process it
- What we never do
- Sharing and sub-processors
- Where data is held
- How long we keep it
- Security
- If something goes wrong
- Your rights and controls
- Protecting yourself on your own device
- Cookies
- Contact and Grievance Officer
- Changes
Privacy Policy
Nirvaan exists because people cannot always talk to a doctor about sexual health without fear of being recognised. Privacy is not a policy we bolted on — it is the product. This page explains exactly how it works, and where it stops.
Nirvaan is operated by Caresoft Systems Private Limited ("Caresoft", "we"), Mumbai, India.
The five things that matter most:
1. Practitioners never see your real name or mobile number. Masking is enforced in the database, not by a screen setting.
2. Calls are bridged through a platform number — neither of you sees the other's number.
3. Every attempt to unmask a patient is logged and reviewed.
4. Your data is held in India, never sold, never shared between practitioners, never used to train AI models.
5. Nothing about your consultations is ever shared with an insurer, an employer, or anyone in your family.
1. Who is responsible for what
| Data | Responsible |
|---|---|
| Your account, wallet, consultations and platform records | Caresoft — Data Fiduciary |
| Clinical records the practitioner keeps under their own obligations | The practitioner — independent Data Fiduciary |
| Practitioner accounts, verification and payouts | Caresoft — Data Fiduciary |
| Website and content analytics | Caresoft — Data Fiduciary |
Practitioners have their own record-keeping obligations under the Telemedicine Practice Guidelines, 2020. They are bound by the Practitioner Terms and by professional confidentiality, and are prohibited from using your information for anything other than your care.
2. What we hold
2.1 Your account
Mobile number (verified by OTP), display name you choose, language preference, and any details you add. We do not require your real name, and you should not enter it unless you choose to.
2.2 Your consultations
Which practitioner, when, duration, mode (chat, voice or video), amount charged; the chat transcript (encrypted); advice notes the practitioner records; prescriptions issued; and your consent record.
2.3 Health information
Whatever you tell a practitioner during a consultation, whatever they record, and any assessment tool results you claim into your account.
2.4 Payments
Wallet recharges, consultation charges, refunds and tax invoices. Card details are held by our payment gateway, not by us — we receive a token, the last four digits and the network.
2.5 Technical
Device, browser, IP address, sign-in records, rate-limit records, and audit logs of access to your data.
3. How masking works
Masking is enforced at the data layer. The practitioner console does not query your real name or number and cannot display them — this is not a permission that could be misconfigured or a field that could be revealed by a UI bug.
Every attempt to access identity data is written to an audit log with an identity-access watch that we review.
- Voice and video calls are bridged through a platform number. The practitioner's phone shows our number, not yours. Yours shows our number, not theirs.
- Chat is encrypted at rest.
- Your display name is shown to the practitioner, so choose one that does not identify you.
- Images you upload are re-encoded and EXIF metadata is stripped — including any location data your camera recorded.
4. What your practitioner sees
| Sees | Does not see |
|---|---|
| Your display name | Your real name |
| Your age or age band, if you provide it | Your mobile number |
| What you tell them in the consultation | Your email address |
| Assessment results you choose to share | Your location or address |
| Your consultation history with them | Consultations with other practitioners |
| Their own advice notes | Your wallet balance or payment history |
| — | Your device, IP or any technical data |
Practitioners cannot see each other's consultations with you. If you consult two practitioners, neither knows about the other unless you tell them.
5. The limits of anonymity
Anonymity protects your privacy from practitioners, from other users, and from casual disclosure. It does not override the law.
We will disclose identity where:
- A legal obligation requires it — most importantly under the POCSO Act, 2012, where a disclosure indicates a child has been sexually harmed. This is a mandatory reporting obligation and we will comply with it.
- A court, tribunal or lawful authority compels it. We assess every request, disclose the minimum required, and notify you unless we are prohibited from doing so.
- It is necessary to prevent an imminent risk of serious harm to you or an identifiable other person.
- You choose to identify yourself — for example, by giving a delivery address for a store order.
You should also understand what anonymity cannot do: it cannot hide the fact that you used the Platform from someone with access to your phone, your messages or your payment statement. See §20.
6. Why this data is different
Health data is sensitive everywhere. Sexual health data in India carries a particular risk of stigma, family consequence and, for some people, real danger. We treat it accordingly:
- Notifications and messages we send are deliberately vague — they do not name a condition, a practitioner's speciality, or anything about the consultation.
- Our name on a payment statement is the company name, not a description of the service.
- We do not send marketing about sexual health topics.
- We do not retarget, profile or advertise to you anywhere.
- Support staff see the minimum necessary and never browse consultations.
7. Caresoft access
Caresoft personnel access consultation content only where:
- you have raised a support or refund request that requires it;
- a safety report or conduct complaint is being investigated;
- a security incident is being investigated; or
- we are compelled by valid legal process.
Every such access is individually authenticated, requires multi-factor authentication, and is logged with the person, time, records accessed and stated reason. The audit log includes an identity-access watch specifically for attempts to unmask patients, which is reviewed. Production data is never copied into development, test or demonstration environments.
8. Chat, calls and video
- Chat transcripts are encrypted at rest and retained so you have a record of advice given.
- Voice and video are not recorded by the Platform. Call metadata — that a call occurred, its duration — is retained for billing and dispute resolution.
- Recording by either party is prohibited (Terms §12). We cannot technically prevent someone recording their own screen, which is a limitation you should be aware of.
- Call bridging is performed by a telecom provider as our sub-processor. They handle the connection; they do not receive consultation content.
9. Anonymous tools
- Self-assessment tools can be used without an account. Results are held against a temporary identifier, not against you.
- You may choose to claim an anonymous result into an account at signup. If you do not, it expires and is deleted.
- Tool results are never shared with a practitioner unless you share them.
- We use aggregate, non-identifying tool statistics to improve the tools — never individual results.
10. Store orders and delivery
Ordering a product is a point at which you identify yourself. A delivery address and a name for the courier are unavoidable.
- Delivery details are used for that order and are shared only with the fulfilment partner and courier.
- Packaging is plain and does not indicate the contents, the platform or the category.
- The courier and fulfilment partner do not receive your consultation records, prescription content beyond what dispensing requires, or anything about your condition.
- Prescription products are gated on a valid prescription. Verifying it involves matching it to your account.
- You may use a different name and address for delivery, provided it is accurate enough for the courier to deliver.
11. Payments
- Payments are processed by our gateway. Card details never reach us.
- Your bank or card statement will show our company name. It will not describe the service.
- Tax invoices are issued as required by GST law and contain the details that law requires.
- Payment records are retained for the periods tax law requires, regardless of account closure.
12. Why we process it
- To operate your account and wallet, and to connect you to a practitioner.
- To run consultations, deliver chat and bridge calls.
- To meter and charge per minute, and to issue invoices.
- To retain consultation records and prescriptions as the Telemedicine Practice Guidelines require.
- To verify practitioners and manage payouts.
- To moderate content and reviews, and to investigate safety reports.
- To prevent fraud, abuse and misuse of free minutes.
- To meet legal obligations, including mandatory log retention and incident reporting.
Product improvement uses aggregate operational metrics only — never the content of consultations.
13. What we never do
We do not:
• sell, rent or trade your data — to anyone, at any price
• share consultation content between practitioners
• disclose anything to an insurer, employer, bank or lender
• disclose anything to your family, partner or anyone who asks
• use your data for research or publication
• use your data to train artificial intelligence models
• advertise to you, retarget you, or profile you
• send marketing that reveals what you consulted about
• allow any advertiser to target you based on anything you told a practitioner
Any change to this section will be notified prominently and in advance. These are the commitments that make the platform usable at all.
14. Sharing and sub-processors
| Who | Gets |
|---|---|
| Hosting provider (India) | Encrypted data at rest |
| SMS and messaging provider | Your mobile number and the message text (deliberately vague — §6) |
| Email provider | Your email, where you gave one, and the message text |
| Telecom call-bridging provider | Numbers to bridge and call duration. Not consultation content |
| Payment gateway | Payment details. Not consultation content |
| Fulfilment partner and courier | Delivery details for a store order only (§10) |
| Practitioner you consult | Only what §4 lists |
| Authorities | Only where compelled or legally required (§5) |
15. Where data is held
Your data, backups and disaster recovery copies are stored and processed within India. Caresoft support and engineering access is from India.
16. How long we keep it
Medical records carry statutory retention obligations. Closing your account does not delete records we are legally required to keep.
Under the Telemedicine Practice Guidelines and professional record-keeping regulation, consultation records and prescriptions must generally be retained for not less than three years.
| Data | Retention |
|---|---|
| Consultation records, advice notes, prescriptions | Minimum 3 years from the consultation, or longer where law or a proceeding requires |
| Chat transcripts | With the consultation record |
| Consent records | With the consultation record |
| Call metadata (duration, not content) | [24] months |
| Wallet, payment and invoice records | Up to 8 years as tax law requires |
| Assessment results claimed to an account | With the account; unclaimed results expire in [30] days |
| Account and profile | Until closure, then [30] days, subject to the above |
| Audit logs of data access | [24] months |
| Safety and conduct investigation records | [5] years, or longer where a proceeding is open |
| System logs required by law | Minimum 180 days, held in India |
| Backups | Rolling [35] days |
When you close your account, everything not subject to a retention obligation is deleted, and what remains is locked down — no longer visible in any console, accessible only for the legal purpose requiring it.
17. Security
Masking enforced at the data layer; encryption in transit and at rest, with consultation content encrypted using authenticated encryption; call bridging so numbers are never exchanged; EXIF stripping and re-encoding of uploads; OTP authentication with reuse prevention; per-actor and per-IP rate limiting on every action; brute-force lockout; authoritative server-side sessions so revocation actually works; content security policy and output escaping; role-based access with multi-factor authentication for administrative accounts; immutable audit logging with an identity-access watch; no production data in non-production environments; verified nightly backups; and a tested security suite covering cross-site scripting, injection, cross-site request forgery and header hardening.
18. If something goes wrong
- We notify affected users of a personal data breach without undue delay, and in any event within [6] hours of confirmation — this is health data and the window is the shortest we operate.
- Notification is deliberately worded so that it does not itself disclose what you consulted about.
- We are required to report specified cyber incidents to CERT-In within 6 hours, and to retain system logs for a minimum of 180 days within India.
- We report to the Data Protection Board of India as required.
- Evidence is preserved until the investigation closes, and we publish a root cause analysis with corrective actions within [10] working days.
19. Your rights and controls
19.1 In the app
- Change your display name at any time.
- See your full consultation history, advice notes and prescriptions.
- Export all your data.
- Log out everywhere — session revocation is real, not cosmetic.
- Close your account.
19.2 Legal rights
Under the Digital Personal Data Protection Act, 2023 you may request access, correction, erasure, and a summary of processing, may withdraw consent, and may nominate someone to exercise your rights. Write to [email protected]; we verify and respond within 30 days.
What erasure cannot do. We cannot delete consultation records within their statutory retention period, tax and invoice records, safety investigation records, or system logs required by law. We will tell you specifically what is retained and why. Everything else goes.
You may complain to the Data Protection Board of India if you are dissatisfied with our response.
20. Protecting yourself on your own device
We can protect your data on our systems. We cannot protect the phone in your hand, and for many of our users that is the real risk. A few things that genuinely help:
- Turn off notification previews on your lock screen for messaging apps and SMS.
- Use a device lock that others do not know.
- Be aware that a shared payment method may show a statement entry.
- Clear your browser history if you share a device, or use a private window.
- If you are in a situation where someone monitors your phone, consider whether using this platform is safe for you at all, and if not, seek help through a route you control.
21. Cookies
Strictly necessary cookies for sign-in, session and security; functional cookies for language preference; analytics only with consent. The signed-in application uses no advertising, tracking or retargeting cookies, and we do not place any third-party advertising pixel on consultation or condition pages. Full detail in our Cookie Policy.
22. Contact and Grievance Officer
Privacy: [email protected]
Grievance Officer (Information Technology Act, 2000; Digital Personal Data Protection Act, 2023)
Name: Rajeev Pillai
Email: [email protected]
Address: 311, Mahesh Industrial Estate , Silver Park, Mira Road East , Thane -401107
Acknowledgement within 24 hours; resolution within 15 days.
Caresoft Systems Private Limited, 311, Mahesh Industrial Estate , Silver Park, Mira Road East , Thane -401107, CIN [U72900MH2022PTC387875].
23. Changes
We may update this policy. The version date will change. Material changes are notified at least [30] days in advance. Any change to §3, §4, §5 or §13 will be notified prominently and in advance — those sections are the promise this platform is built on.