Legal

Privacy Policy

Version 2026-06-01

Back to home

Who we are

Folio Health provides a patient-owned encrypted health record vault. We operate primarily for users in India, with optional support for users in the United States and European Union subject to the controls described below.

What we collect

Account identifiers (email, phone), profile and family health metadata, encrypted medical files stored in your linked cloud drive, appointment and sharing metadata, audit logs, and consent records. Medical file contents are encrypted on your device before upload; we do not hold your decryption keys.

How we use data

To provide the service, secure your account, enable consent-based sharing with clinicians you approve, and meet legal obligations. Server-side OCR/LLM processing runs only when you explicitly opt in.

India (DPDP Act)

We process personal data based on your consent and legitimate service delivery. You may access, export, correct, and request deletion of your account data. Contact our grievance officer for complaints.

United States (HIPAA-ready posture)

We apply encryption, access controls, and audit logging. Server-side PHI processing in US deployments requires Business Associate Agreements with subprocessors and may be restricted by region policy until BAAs are in place.

European Union (GDPR)

EU users have rights to access, portability, rectification, erasure, and restriction. Cross-border transfers use appropriate safeguards. Contact our Data Protection Officer for EU inquiries.

Retention

Account data is retained while your account is active. Deletion requests enter a 30-day grace period before metadata purge. Immutable audit logs may be retained in anonymized form where legally required.

Subprocessors

Google Firebase, Google Drive/Cloud, and optional OCR/LLM providers when you opt in. A current subprocessor list is available on request.

Google Limited Use

Folio Health use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Drive stores encrypted vault containers; Calendar/Meet create consult events and join links only - not used for ads.

Grievance officer (India) / DPO (EU): privacy@zendoc.in, dpo@zendoc.in