Privacy Policy
Last updated: 19 March 2026
1. Introduction
AI Bharata ("we", "us", "our") operates the MYAIRA platform, including MedixShare (scan sharing service) and MYAIRA AI (medical imaging analysis). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our services.
2. Information We Collect
2.1 Account Information
When you register, we collect your name, email address, phone number, organization details (for institutional accounts), and login credentials.
2.2 Medical Imaging Data
When you upload or share medical images through MedixShare, we process DICOM files and other medical imaging formats. This data may contain Protected Health Information (PHI) including patient names, study IDs, and imaging metadata.
2.3 Usage Data
We automatically collect device information, IP addresses, browser type, pages visited, and interaction data to improve our services.
3. How We Use Your Information
- To provide, operate, and maintain our services
- To process medical image sharing and AI analysis requests
- To manage your account and subscription
- To send transactional notifications (OTP codes, share links, analysis results)
- To improve our AI models (only with explicit opt-in consent)
- To comply with legal obligations and regulatory requirements
4. Data Storage and Security
Medical images are stored in encrypted cloud storage (Cloudflare R2) with AES-256 encryption at rest. All data in transit is protected by TLS 1.3. Access to medical data is strictly controlled through role-based access controls and audit logging.
Share links expire automatically based on the configured retention period. Expired data is permanently deleted within 30 days of expiration.
5. Data Sharing
We do not sell your personal or medical data. We share data only in these circumstances:
- With your consent: When you create a share link, the recipient can access the shared medical images.
- Service providers: We use Cloudflare (infrastructure), Neon (database), and Upstash (caching) to operate our platform. These providers are bound by data processing agreements.
- Legal requirements: We may disclose data when required by law, regulation, or legal process.
6. Your Rights
You have the right to:
- Access your personal data
- Request correction of inaccurate data
- Request deletion of your account and data
- Export your data in a portable format
- Withdraw consent for optional data processing
To exercise these rights, contact us at privacy@aibharata.com.
7. Data Retention
Account data is retained for the duration of your account plus 90 days after deletion. Medical images shared via MedixShare are retained according to the share expiration settings. AI analysis results are retained for 1 year unless you request earlier deletion.
8. Compliance
Our platform is designed to comply with applicable healthcare data regulations including India's Digital Personal Data Protection Act (DPDPA) 2023 and the Information Technology Act 2000. For institutional customers handling US patient data, we offer HIPAA Business Associate Agreements (BAA) on Professional and Enterprise plans.
9. Children's Privacy
Our services are not directed to individuals under 18. We do not knowingly collect personal data from minors.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify registered users of material changes via email. Continued use of our services after changes constitutes acceptance of the updated policy.
11. Contact Us
For privacy-related inquiries:
AI Bharata
Email: privacy@aibharata.com
Website: www.aibharata.com