Privacy Policy
Last updated: 29 September 2026
This policy explains what personal and health information Jalmed collects, why we collect it, how we protect it, and the choices you have. It applies to the Jalmed website and mobile app. By using Jalmed you agree to this policy.
1. Who we are
Jalmed is an AI-assisted telemedicine platform that connects patients with doctors, rural health practitioners, laboratories and pharmacies. We act as the data controller for the information described below.
2. Information we collect
- Account and identity: name, email address, mobile number, age, gender, address, blood group, and the role you register under (patient, doctor, lab, pharmacy or rural health practitioner).
- Health information: symptoms you describe, AI triage reports, medical history, current medications and allergies, prescriptions, laboratory reports and results, appointment details, and vitals you record.
- Connected device data: if you connect a wearable or phone health source, we read the health data types you approve — heart rate, steps, calories burned, distance, sleep, blood oxygen (SpO₂) and body temperature. Blood pressure and blood sugar are only stored when you enter them yourself.
- Payments: the reference and screenshot of a UPI transfer you upload so our team can verify it. We do not store card numbers, UPI PINs or bank credentials.
- Technical data: basic device and usage logs needed to keep the service secure and working.
3. How we use your information
- To provide triage, consultations, prescriptions, lab coordination and pharmacy fulfilment.
- To share relevant clinical information with the doctor, lab or pharmacy you are being treated by.
- To generate AI-assisted summaries and drafts that a clinician reviews and approves.
- To detect dangerous vital readings and alert you and, where appropriate, your care team.
- To verify payments, prevent misuse, and meet our legal and record-keeping obligations.
We do not sell your personal or health information, and we do not use it for advertising.
4. Google Health Connect and Apple Health
- Jalmed reads health data from Google Health Connect (Android) and Apple Health (iOS) only after you explicitly grant permission, and only the data types you select.
- Access is read-only. We do not write data back into Health Connect or Apple Health.
- Data obtained through Health Connect is used solely to display your vitals and trends and to alert you or your care team about readings outside safe ranges. It is never used for advertising, marketing, or to assess credit or insurance eligibility, and it is never sold.
- You can revoke access at any time in your device's Health Connect settings (Android) or Health settings (iOS). Jalmed will then stop reading new data.
- Deleting your Jalmed account removes the data we hold, but does not delete the original records stored in Health Connect or Apple Health.
5. Who we share it with
- Clinicians and facilities involved in your care: the doctor treating you, the laboratory running your tests, the pharmacy dispensing your medicines, and the rural health practitioner who registered you where applicable.
- Our operations team, strictly to verify payments, review registrations, and respond to privacy requests.
- Authorities, where disclosure is required by law or necessary to prevent serious harm.
6. AI-assisted features
Symptom triage, report summaries and clinical notes may be drafted with the help of AI. These outputs are decision support only — they are not a diagnosis, and a qualified clinician reviews and approves any treatment or prescription before it is issued to you.
7. How we protect your data
Clinical documents and reports are held in private storage and are not publicly accessible. Access requires an authenticated session and is limited by role, and file links are issued as short-lived signed URLs. Sensitive operations are checked on the server, and access to records is logged for audit.
8. How long we keep it
- Clinical records are retained for 3 years as required by Indian medical record-keeping rules.
- When you delete your account, your personal identifiers (name, phone, email) are anonymized; the clinical record itself is retained for the period above.
- Verification codes and one-time challenges expire shortly after they are issued.
9. Your rights
- Access and portability: download a copy of your health data from Privacy & Data Rights inside the app.
- Correction: ask us to correct inaccurate details.
- Erasure: delete your account and personal identifiers from Privacy & Data Rights.
- Withdraw consent: revoke device health access at any time in your device settings.
- Grievance: raise a privacy complaint from Privacy & Data Rights. We respond to every complaint within 7 days.
10. Children
Where a patient is a minor, we require verified consent from a parent or legal guardian before their account is activated, and the guardian's address is bound to the account.
11. Changes to this policy
We may update this policy as the service develops. The date at the top of this page always shows the current version, and material changes will be communicated in the app.
12. Contact and grievance officer
Privacy questions, data requests and complaints can be raised through the Privacy & Data Rights page inside the app, where they are logged and tracked. Our Grievance Officer reviews every submission and replies within 7 days.