Legal

Privacy Policy

Effective: 1 June 2026 · Last updated: 1 June 2026

1. Who we are

Anxya Health is a product operated by Anxya Tech Private Limited (CIN: U62099PN2024PTC230490) (“Anxya”, “we”, “us”), a company incorporated in India. This policy explains what personal data we collect, why, how long we keep it, and the rights you have. We are the data controller for personal data processed through the Service. For any privacy request, contact privacy@anxya.health.

2. The data we collect and why

We collect only what we need to run the Service. Categories:

CategoryWhat it includesWhy we use it
Account dataName, email, password hash, organization, role, verification status.Create and secure your account; authenticate you.
Uploaded documentsFiles you attach as reference (and the text/images extracted from them).Provide them to the AI to generate your requested output.
Health & product-safety inputsDigital Twin records, Ask Anxya / Product Safety / HealthWiki queries and results.Deliver the feature you asked for and your personal history.
Usage & device dataActions taken, pages viewed, credits used, IP address, browser/device, logs.Run, secure and improve the Service (first-party analytics).
Payment dataAmount, currency, order/transaction IDs. Card/UPI details go directly to our payment processors — we do not store them.Process purchases and keep tax/accounting records.
CommunicationsEmails you send us, support requests, newsletter/outreach preferences.Respond to you and send updates you opted into.

3. “Upload Documents for Reference” — how it works

When you attach a document to a build, assessment or query, we extract text (and, for images, the image itself) and send it to our AI sub-processors so the model can produce the output you asked for. Your uploads are stored in your account and are visible only to you (and members of a workspace you share with).

We do not automatically redact personal or sensitive information from your uploads. Please do not upload another person’s health records or other sensitive data unless you are authorised to do so. You can delete an upload at any time, which removes it from your account. We do not use your uploaded content or generated outputs to train our own models; AI providers process it under their terms solely to return your result.

4. Legal bases & your rights by region

Depending on where you live, you have the following rights. To exercise any of them, email privacy@anxya.health and we will respond within the timeframe required by your local law.

FrameworkYour rights & our basis
GDPR / UK GDPR (EEA & UK)Access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. Legal bases: consent, performance of a contract, our legitimate interests, and legal obligations (Art. 13/14).
India DPDP Act, 2023Access, correction, erasure, grievance redressal and nomination. We process on the basis of your consent or a legitimate use. Contact our Grievance Officer below.
California (CCPA/CPRA)Know, delete, correct and opt out. We do not “sell” or “share” your personal information for cross-context behavioural advertising.
HIPAA (US)For consumer use, Anxya Health is not your HIPAA covered entity. For enterprise customers processing PHI, a separate Business Associate Agreement (BAA) governs — contact us.

5. Sub-processors we share data with

We share the minimum necessary data with vetted service providers who process it on our behalf under contract. We do not sell your personal data.

Sub-processorServicePurpose
EmergentCloud hosting, object storage & AI model gatewayInfrastructure & routing of AI requests
OpenAIAI model provider (text, image, speech)Generate outputs from your prompts/reference material
Anthropic (Claude)AI model provider (text)Generate insights and analyses
Google (Gemini)AI model provider (image/text)Generate outputs where selected
ResendTransactional emailSend verification, notifications & digests
RazorpayPayment processor (India)Process credit purchases
StripePayment processorProcess credit purchases (being consolidated to Razorpay)
MongoDBManaged databaseStore your account and content

6. How long we keep it

We retain personal data only as long as needed for the purposes above or as required by law.

DataRetention
Account dataFor the life of your account, then deleted within ~90 days of account closure (residual backups purged on rotation).
Uploaded documents & generated outputsUntil you delete them or close your account.
Health & product-safety historyUntil you delete the entry or close your account.
Payment/transaction recordsAs required by applicable Indian law (financial records may be retained up to 8 years).
Server & security logsUp to 12 months.
Verification / password-reset tokensShort-lived (minutes to a few hours).
Marketing/outreach contactsUntil you unsubscribe or ask us to erase them.

7. International transfers

We are based in India and use sub-processors that may process data in the United States, the EU and other regions. Where data is transferred across borders, we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs), adequacy decisions, or your consent, as applicable.

8. Cookies & analytics

We use essential cookies for login, sessions and security, and preference storage for your theme and choices. We use first-party usage analytics to improve the product; any optional analytics cookies are set only if you choose “Accept all” in the cookie banner. We do not use third-party advertising or cross-site tracking. See our Cookie Policy.

9. Security

We protect your data with encryption in transit, hashed passwords, httpOnly session cookies, role-based access controls, de-identification for research cohorts, and access logging. No system is perfectly secure, but we work continuously to safeguard your information and will notify you and regulators of a breach where the law requires.

10. Children

Anxya Health is not directed to children. You must be at least 18 years old to create an account. We do not knowingly collect personal data from children; under the India DPDP Act, processing a minor’s data requires verifiable parental consent, which our consumer Service does not support. If you believe a child has provided us data, contact us and we will delete it.

11. Enterprise customers (DPA / BAA)

If you are a pharma, hospital, payer or provider customer processing personal or health data through Anxya on behalf of your organisation, a separate Data Processing Agreement (and, where PHI is involved, a Business Associate Agreement) applies — view & download the DPA/BAA. Request a countersigned copy at privacy@anxya.health.

12. Changes to this policy

We may update this policy from time to time. We will change the “Last updated” date only for substantive changes and, where required, notify you. Continued use after an update means you accept the revised policy.

13. Contact & Grievance Officer

Questions, requests or complaints? Our Data Protection Officer (GDPR) is Nagesh Jadhav — nag@anxya.health. For general privacy requests and our India DPDP Grievance Officer, contact privacy@anxya.health, Anxya Tech Private Limited (CIN: U62099PN2024PTC230490), Pune, Maharashtra, India. EEA/UK users may also lodge a complaint with their local supervisory authority.

We use cookies to run Anxya Health and improve your experience. Choose how we may use them. Read our Cookie Policy, Privacy Policy and Terms.