Privacy Notice — Asha Health

Version: 2026-08-10 Last updated: 2026-08-10 Brand: Asha Health Related: Terms of Service · Grievance Officer page · In-product consent copy


1. Who we are

Public brand: Asha Health

Data Fiduciary (interim): Nishkaam Mehta / the Asha Health team (pending designation of a formed legal entity).

Contact for privacy matters

Services covered

  • Marketing site: https://ashahealth.co
  • Application: https://app.ashahealth.co
  • Related Asha Health apps and APIs we operate
  • Legacy surfaces at withasha.com / api.withasha.com until retired

2. What this Notice covers

This Notice describes how we collect, use, store, share, and protect personal data when you use Asha Health.

It is written primarily against:

  • India’s Digital Personal Data Protection Act, 2023 (DPDPA)
  • India’s Information Technology Act, 2000 and SPDI Rules, 2011 (where still relevant)

If we process personal data of people in the US, EEA/UK, or other regions as residents (not only diaspora coordinators helping family in India), we will add region-specific sections where required.

This Notice is not a HIPAA Notice of Privacy Practices. Asha is not positioned as a covered health-care provider. Separate internal HIPAA posture docs (if any) do not expand user-facing certifications we do not hold.

3. Product framing that affects privacy

Asha provides AI decision support on an existing physician recommendation. It does not diagnose, prescribe, or replace the treating physician. You and your clinicians remain responsible for care decisions.

Because cases involve health-context data, we treat that information as sensitive and apply stricter handling than ordinary marketing data.

4. Categories of data we collect

Category Examples Source
Identity & account Name, email, password or auth tokens, age attestation (18+) You provide at signup / login
Contact & support Messages you send to support or grievance channels You provide
Health-context Treating physician recommendation, history, symptoms, meds, labs/imaging descriptions, uploaded records, panel inputs/outputs You provide during use
Family / third-party context Names, relationships, ages, health details of people you consult about You provide (you must have authority)
Voice (if enabled) Audio while speaking to an AI persona during a session Captured in-session; not intended to be stored as a permanent Asha recording
Device & usage Device/browser type, approximate logs, app version, performance events Automatically
Payment (when enabled) Limited billing metadata from payment processors (we aim not to store full card numbers) You / payment processor
Marketing site Pages visited, referrer, basic analytics/cookies if enabled Automatically / cookies

We aim to collect only what is needed for the stated purposes below.

5. Purposes of processing

  • Operate the Service — intake with Alex, multi-agent panel review, Chair verdict, doctor-ready questions
  • Authenticate and secure accounts
  • Customer support and grievance handling
  • Service improvement — debugging, quality review, prompt/product improvement using de-identified or aggregated data where feasible
  • Payments and fraud prevention (when paid features are live)
  • Legal compliance, security investigations, and enforcement of Terms
  • Service communications — transactional email (receipts, security, case status). Marketing email only with appropriate consent where required

We do not sell your personal data.

6. Lawful basis (DPDPA-oriented)

For India-oriented processing, we primarily rely on your consent for collection and processing of personal data needed to run Asha, including health-context data you submit for a case.

We may also process data where necessary to:

  • provide a service you request
  • meet legal obligations
  • address security incidents

You may withdraw consent as described in Section 11. Withdrawal does not affect processing already completed lawfully. If you withdraw consent needed to run a case, we may be unable to provide the Service.

7. How AI processing works

  1. You provide case information to Asha (typed and/or voice, depending on client).
  2. Technical safeguards may redact or minimize identifiers before some model calls (implementation varies by client; web and mobile stacks are converging).
  3. AI model providers generate intermediate specialty views and a Chair synthesis.
  4. Results are returned to your account/session.

Important limitations we disclose

  • AI outputs can be inaccurate or incomplete.
  • Providers process data to generate outputs under contractual restrictions; zero-data-retention or similar settings are operational goals where available and must be verified per vendor before launch claims.
  • Do not submit more personal detail than needed for a useful review.

8. Data sharing (processors / recipients)

We share personal data only as needed with processors who help us run Asha, for example:

Role Typical function Notes (current / legacy posture)
AI inference provider Generate panel/Chair reasoning Identifiers minimized/redacted where implemented
Cloud database & auth Accounts, case storage Legacy product used managed DB in Singapore (ap-southeast-1); Cofounder-managed stack may differ — confirm before publish
Application hosting API / web hosting Legacy API hosted with India region components; confirm current regions
Voice / avatar provider (if enabled) Real-time voice loop Session processing; not intended as long-term Asha audio archive
Email provider Transactional mail Account and support messages
Error monitoring Crash/error reports Configured with scrubbing; health free-text should not be sent
Payment processor (when enabled) Charges, invoices Card data handled by processor
Professional advisors / authorities Legal, accounting, lawful requests Only as needed

We may share data if required by law, to protect rights and safety, or in a merger/entity formation/assignment (with continuity protections).

Specific vendor legal names may be withheld from public pages for security posture and disclosed to regulators, the Data Protection Board, or your counsel on legitimate request to the Grievance Officer.

Open item: publish a current subprocessor list (or confidential schedule) that matches the live stack (legacy Fly/Supabase vs Cofounder Vercel/Supabase), not a mix of both.

9. Cross-border transfers

Some processors operate outside India (for example Singapore and the United States).

Under DPDPA s.16, cross-border transfers are subject to India’s government framework for permitted jurisdictions. We will revise this Notice if destinations become restricted.

If you are a diaspora user outside India coordinating care for someone in India, your data may still be processed in the regions above.

10. Retention

Data type Working retention target
Account data While account is active
Case / health-context records While account is active, or until you delete the case/account
After account deletion request Primary deletion target within 30 days; backups age out within about 90 days
Grievance records As needed to resolve and meet legal retention duties
Security / audit logs Statutory or security minimums
De-identified analytics May be kept longer if they cannot reasonably identify you

Exact category-by-category schedules should be finalized before broad public launch.

11. Your rights (Data Principal rights)

Subject to law, you may request:

  • Access to personal data we hold about you
  • Correction of inaccurate or incomplete data
  • Erasure (subject to legal retention needs)
  • Withdrawal of consent
  • Nomination of another individual in case of death or incapacity (DPDPA)
  • Grievance redressal through our Grievance Officer

How to exercise: email privacy@ashahealth.co or grievance@ashahealth.co from your account email, or use in-product account settings when available.

We will acknowledge and respond within timelines required by applicable rules. We may need to verify your identity.

12. Children

Asha is not designed for users under 18. Signup should confirm you are 18+.

Pediatric *subject-matter* cases must be run by a parent or legal guardian. We do not knowingly collect personal data directly from children under 18. If you believe we have, contact us for deletion.

13. Security

We implement reasonable security practices appropriate to health-context data, which may include:

  • encryption in transit (HTTPS)
  • encryption at rest where platform-supported
  • access controls and least-privilege admin access
  • redaction/minimization before some external model calls
  • error monitoring with scrubbing
  • breach-response procedures

No method of transmission or storage is 100% secure.

Do not claim ISO 27001, HIPAA certification, SOC 2, or similar unless a current certificate exists. Legacy materials mentioned ISO-aligned controls as aspirational; that is not a certification claim.

14. Cookies and similar technologies

The marketing site and app may use essential cookies or local storage for login, security, and preferences.

If we use non-essential analytics or advertising cookies, we will disclose them and obtain consent where required. Prefer privacy-preserving, minimal analytics for India-first launch.

15. Account and data deletion

You may request deletion:

We aim to confirm receipt within 24 hours and complete primary deletion within 30 days. Deletion is generally irreversible. Aggregate analytics and legally required logs may remain.

16. Grievance Officer

See the public Grievance Officer page for the designated individual, contact email, and process under DPDPA / SPDI Rule 5(9) posture.

Working designation: Nishkaam Mehta, email grievance@ashahealth.co.

17. Changes to this Notice

We may update this Notice. Material changes will be communicated by email or in-product notice where reasonable. The “Last updated” date will change.

18. Contact

— End of Notice —

Asha Health provides decision support only and does not diagnose, prescribe, or replace your treating physician.