Legal · Privacy

Privacy Policy

Klynea ("we", "us") builds an AI-first healthcare platform for India. This policy explains what personal data we collect, why, how we protect it, and the rights you have under India's Digital Personal Data Protection Act, 2023 ("DPDP Act").

Last updated: 2 October 2026

Language help · भाषा सहायता · மொழி உதவி · ভাষা সহায়তা
  • This page is currently available in English. For help in your language, email privacy@klynea.in.
  • यह पृष्ठ अभी अंग्रेज़ी में उपलब्ध है। हिन्दी में सहायता के लिए privacy@klynea.in पर ईमेल करें।
  • এই পৃষ্ঠাটি বর্তমানে ইংরেজিতে উপলব্ধ। বাংলায় সাহায্যের জন্য privacy@klynea.in-এ ইমেল করুন।
  • இந்தப் பக்கம் தற்போது ஆங்கிலத்தில் உள்ளது. தமிழில் உதவிக்கு privacy@klynea.in-க்கு மின்னஞ்சல் அனுப்பவும்.
  • ఈ పేజీ ప్రస్తుతం ఇంగ్లీష్‌లో అందుబాటులో ఉంది. తెలుగులో సహాయం కోసం privacy@klynea.in కి ఇమెయిల్ చేయండి.
  • ಈ ಪುಟ ಸದ್ಯಕ್ಕೆ ಇಂಗ್ಲಿಷ್‌ನಲ್ಲಿ ಲಭ್ಯವಿದೆ. ಕನ್ನಡದಲ್ಲಿ ಸಹಾಯಕ್ಕಾಗಿ privacy@klynea.in ಗೆ ಇಮೇಲ್ ಮಾಡಿ.
  • ഈ പേജ് നിലവിൽ ഇംഗ്ലീഷിൽ ലഭ്യമാണ്. മലയാളത്തിൽ സഹായത്തിന് privacy@klynea.in-ലേക്ക് ഇമെയിൽ ചെയ്യുക.
  • हे पृष्ठ सध्या इंग्रजीत उपलब्ध आहे. मराठीत मदतीसाठी privacy@klynea.in वर ईमेल करा.
  • આ પૃષ્ઠ હાલમાં અંગ્રેજીમાં ઉપલબ્ધ છે. ગુજરાતીમાં મદદ માટે privacy@klynea.in પર ઇમેઇલ કરો.
  • ਇਹ ਪੰਨਾ ਇਸ ਵੇਲੇ ਅੰਗਰੇਜ਼ੀ ਵਿੱਚ ਉਪਲਬਧ ਹੈ। ਪੰਜਾਬੀ ਵਿੱਚ ਮਦਦ ਲਈ privacy@klynea.in 'ਤੇ ਈਮੇਲ ਕਰੋ।

1. Who we are

Klynea Private Limited is the data fiduciary responsible for the personal data processed through our patient app, clinician app, and websites. Klynea Private Limited is a company incorporated in India under the Companies Act, 2013 (CIN U62011UP2026PTC250071); our registered address is set out in the Grievance Officer section below (section 9).

2. Data we collect

We collect only what we need to provide care-related services:

  • Identity, profile & professional information — name, mobile number, email, date of birth, gender, profile photo and, where you choose to link it, your ABHA / Health ID. For clinicians this also includes professional credentials, registration and verification information, specialties, clinic details, practice address, availability, signatures and letterhead or other practice documents you upload.
  • Health records — symptoms, diagnoses, prescriptions, lab reports, vitals, allergies, medications, care notes, mood and wellness entries, device-health readings, family or dependant records, and other medical information you or your clinician add. Health data is treated as sensitive personal data.
  • Documents, photos, audio & video — clinical photos, prescription and report scans, vault documents, teleconsult audio/video and recordings where enabled with the required consent, voice notes, transcripts and scribe output.
  • Communications & safety actions — appointment and follow-up messages, AI conversations, support requests, feedback, and the reports or blocks you submit to keep patient-clinician communication safe.
  • Emergency (SOS) contacts — the name and phone number of each emergency contact you add in the app, and the SMS alert we send to those contacts when you trigger SOS. Please add only people who have agreed to be contacted; you can remove a contact at any time.
  • Payments & financial administration — order, transaction, refund, invoice and payment-status metadata. For clinicians who configure collections or payouts, this may also include beneficiary name, bank-account and IFSC details, UPI ID, PAN and payment-provider verification status. Full card or UPI credentials entered into a payment-provider checkout are handled by that provider, not stored by Klynea.
  • AI inputs & outputs — the prompt or records you choose to send to an AI-assisted feature, its generated output, citations, safety checks, and corrections or feedback you submit.
  • Account, device & usage data — internal user identifiers, login and security events, searches and feature interactions, registered device and push-notification identifiers, app and operating-system version, and privacy-filtered diagnostic, performance and crash logs used to keep the service secure and working.

2a. Health Connect (Android)

If you choose to connect Health Connect in the Klynea Android app, Klynea reads (never writes) only these data types: heart rate, respiratory rate, blood-oxygen saturation, weight, blood glucose, blood pressure, body temperature, steps and sleep. You pick which ones in Health Connect. Each sync is limited to readings from the preceding 30 days; Klynea does not request extended Health Connect history access.

  • Why: to show your vitals and trends in the app and, only when you choose to share them, with the doctors on your care team.
  • What we never do: use Health Connect data for advertising, sell or transfer it to data brokers, or use it for insurance, credit or employment decisions.
  • AI features: Health Connect readings are treated like the vitals you enter yourself — our AI features (for example, Aria's answers to you, and the visit briefing a doctor you share your records with sees) may process them to provide those features. AI providers process this data only on our instructions, under the sub-processor terms in section 5a.
  • Where it lives: with your other health records, in India (asia-south1, Mumbai), encrypted in transit and at rest.
  • Your control: revoke access at any time in Android Settings → Health Connect, and delete the data Klynea has already synced from the app (Health → Health Connect → “Disconnect & delete synced data”).

Klynea's use of information received from Health Connect adheres to the Health Connect Permissions policy, including the Limited Use requirements.

3. Why we use your data (purpose)

We process your data to: deliver and operate the care platform; maintain your health record and share it with the clinicians you authorise; provide AI-assisted features that support (never replace) a clinician's judgement; secure your account; meet legal and regulatory obligations; and improve the service. We do not sell your personal data, and we do not use your health data for advertising.

4. Consent & withdrawal

We process your personal data on the basis of your consent, which we ask for in clear language at the point of collection. You may withdraw consent at any time from within the app or by writing to our grievance officer (see section 9). Withdrawing consent will not affect the lawfulness of processing carried out before withdrawal, and may limit features that genuinely require that data.

5. Sharing your data

We share your data only with the clinicians and care teams you authorise, and with vetted processors (such as cloud hosting and messaging providers) who act on our instructions under contract. When you trigger SOS, we send an SMS alert to the emergency contacts you added. We may disclose data where required by law or a valid legal request. Any interoperability with India's Ayushman Bharat Digital Mission (ABDM) happens only with your explicit, per-request consent.

5a. Sub-processors & cross-border processing

To run the service we rely on a small set of vetted sub-processors, each engaged under contract and instructed to process data only for the purposes below. They fall into these categories:

  • AI / large-language-model providers — to power AI-assisted features that support (never replace) a clinician's judgement. This includes OpenAI, whose processing takes place outside India, and Google Cloud AI(Vertex AI, Document AI and Cloud Vision), which reads and structures the prescriptions, lab reports and other documents you upload in India (asia-south1, Mumbai).
  • Speech & translation — to transcribe, speak and translate for the AI scribe and the Aria voice assistant.
  • Payments — to process payments, refunds and clinician payouts securely.
  • Messaging & notifications — to send OTPs, transactional alerts, and service messages.
  • Cloud hosting & storage — to host the platform and store your records (primarily in India, asia-south1, Mumbai).

While your health records are stored in India, some processing occurs outside India — in particular, text sent to AI providers such as OpenAI, and certain payment processing. Where data is processed outside India, we rely on contractual safeguards (including data-processing agreements, purpose limitation, confidentiality, and security obligations on the processor) and we transfer data only to the extent permitted under the DPDP Act and applicable rules. We will keep this list current as our providers change.

Our current sub-processors: OpenAI (AI features such as the Aria assistant's replies, summaries and clinical-note drafts — processes consultation/record text outside India); Google Cloud AI (Vertex AI with Gemini 2.5 Flash, Document AI and Cloud Vision, in asia-south1, Mumbai, India — reads and structures the prescriptions, lab reports and other documents you upload); Sarvam AI (an India-based provider — speech recognition, speech synthesis and translation for the AI scribe and the Aria voice assistant, and translation of app text into your language — may be processed outside India); Google (Firebase Cloud Messaging for notifications, Firebase Crashlytics for app crash diagnostics — crash type, stack trace, device/app version and a Crashlytics installation identifier, no health data — and Google Cloud Storage in asia-south1/Mumbai for documents & recordings); Twilio SendGrid (transactional & OTP email — outside India); Sentry (error monitoring, no PHI — outside India); Razorpay (payments, refunds and clinician payouts — in India); and MSG91 (SMS/OTP and the SOS alerts you trigger — in India). Our teleconsult/recording media server (LiveKit) is self-hosted on our own India infrastructure. We update this list as our providers change.

6. Where your data lives & how it is protected

Your records are stored in India (asia-south1, Mumbai). Some specific processing — such as certain AI features and payments — may be carried out by vetted providers outside India; see section 5a on sub-processors and cross-border processing. Data is stored onencrypted infrastructure in India and protected in transit with TLS. Selected sensitive identifiers and clinical artifacts receive an additional application-level encryption layer. Access is role-based and security-relevant activity is logged. We retain data only as long as needed for the purposes above or as required by law, after which it is deleted, de-identified, or irreversibly anonymised as appropriate.

7. Your rights as a data principal

Under the DPDP Act you have the right to:

  • Access a summary of the personal data we hold about you.
  • Correct or complete data that is inaccurate or out of date.
  • Erase your data where it is no longer needed for the stated purpose.
  • Nominate another person to exercise your rights in case of death or incapacity.
  • Grievance redressal — raise a complaint and have it addressed (see section 9).

For full detail on how these rights are handled, see ourDPDP compliance notice.

8. Children's data

Klynea accounts are for adults aged 18 or older. Where a patient is a child or a person with a disability, they are added as a dependant or family profile managed by a verified parent or lawful guardian, whose consent we obtain before processing the child's data. We do not undertake tracking, behavioural monitoring, or targeted advertising directed at children.

9. Grievance officer

If you have any concern about how your data is handled, contact our Grievance Officer:

The Grievance Officer
Klynea Private Limited, a company incorporated in India under the Companies Act, 2013 (CIN U62011UP2026PTC250071)
474/9 Bari House, Kadam Rasool, Sitapur Road, Lucknow, Uttar Pradesh 226020, India
Email: grievance@klynea.in

We will acknowledge your grievance and respond within the timelines required under the DPDP Act and Rules. If unresolved, you may escalate to the Data Protection Board of India.

10. Cookies & similar technologies

Our marketing website uses only strictly necessary cookies and privacy-respecting, aggregated analytics needed to keep the site secure and understand high-level traffic. We do not use third-party advertising or cross-site tracking cookies. You can control cookies through your browser settings; blocking strictly necessary cookies may break parts of the site.

11. Changes to this policy

We may update this policy as the product and the law evolve. Material changes will be notified in the app or by email, and the "last updated" date above will change.

12. Contact

Questions about privacy? Write to us atprivacy@klynea.in.