How Hello Homeo collects, uses, stores and protects information across the platform.
1. Who We Are & Scope of This Policy
Hello Homeo is a Software-as-a-Service (SaaS) clinic management platform that provides technology tools to homeopathic clinics and healthcare practices across India. This Privacy Policy explains how we collect and handle personal data from two groups:
• Clinic Subscribers & Clinic Users: practices and staff who register to use Hello Homeo to manage their operations.
• Patients: individuals who book appointments and receive services through clinics powered by Hello Homeo.
Data Roles: Hello Homeo acts as a data controller for Subscriber and Clinic User account data. For patient data, Hello Homeo acts as a data processor on behalf of the clinic (the data controller). Clinics are responsible for lawfully collecting and processing their patients' personal and medical data.
2. Information We Collect
From Clinic Subscribers & Clinic Users:
• Business details (clinic name, address, GSTIN, contact information)
• Account credentials (name, email, role)
• Subscription and payment information (processed via Razorpay)
From Patients (processed on behalf of the clinic):
• Personal details (name, date of birth, contact information including WhatsApp-registered mobile number)
• Medical history, consultation records, prescriptions, and lab reports
• Appointment and billing information
• WhatsApp conversation data (messages, timestamps, delivery status, opt-in/opt-out status) where the clinic has enabled WhatsApp notifications
3. How We Use Information
For Subscribers & Clinic Users:
• Providing, operating, and maintaining the Hello Homeo platform
• Processing subscription payments and managing billing
• Sending platform-related communications (updates, payment receipts, usage alerts)
• Customer support and troubleshooting
For Patients (under instruction from the clinic):
• Enabling appointment booking, consultation records, prescriptions, and billing within the clinic's portal
• Sending WhatsApp notifications (appointment reminders, prescription alerts, follow-ups) where the patient has opted in through the clinic
• Legal and regulatory compliance
4. Third-Party Sub-Processors
Hello Homeo uses the following trusted third-party service providers to operate the platform. Data is shared with them only to the extent necessary to provide the service:
• Supabase (supabase.com): cloud database and storage (servers in the EU/US)
• Meta Platforms, Inc.: WhatsApp Business Cloud API for patient notifications
• Twilio Inc.: SMS OTP verification and WhatsApp message delivery
• Stream (getstream.io): video and audio infrastructure for teleconsultation
• Google (Gemini API): the Vita AI assistant, consultation summaries, and transcription of Scribe recordings (AI features only)
• Razorpay: payment gateway for subscription and bundle purchases
• Vercel Inc.: cloud hosting and deployment infrastructure
• Functional Software, Inc. (Sentry): application error and crash diagnostics
Hello Homeo does not sell personal data to any third party.
5. Data Security
• All data is encrypted in transit (HTTPS/TLS) and at rest where supported by our infrastructure providers.
• Each clinic's data is strictly isolated: no data is shared across tenants.
• Access to patient data is role-restricted: only authorised Clinic Users can access their clinic's data.
• Session tokens are stored server-side with httpOnly cookies. No sensitive data is stored in client-side localStorage.
• Despite these measures, no digital system is completely risk-free. Hello Homeo cannot guarantee absolute security.
6. Data Retention
• Subscriber and Clinic User account data is retained for the duration of the active subscription.
• Upon account termination or non-renewal, clinic data (including patient records) is retained for 30 days to allow export, then permanently deleted.
• WhatsApp message logs are retained for up to 12 months for audit and compliance purposes, after which they are deleted.
• Subscribers may request an export of their data at any time by contacting contact@hellohomeo.in.
7. Your Rights
Clinic Subscribers & Clinic Users may:
• Request access to their account and billing data
• Correct inaccurate account information
• Request deletion of their account (subject to legal retention requirements)
Patients should direct data access, correction, or deletion requests to the clinic they registered with. Clinics are the data controllers for patient data and are responsible for responding to such requests. Hello Homeo will assist clinics in fulfilling verified requests.
8. WhatsApp & Meta Data Processing
Clinics using Hello Homeo may enable the Meta WhatsApp Business Cloud API to send appointment reminders, prescription notifications, and other healthcare communications to their patients.
Data shared with Meta/WhatsApp:
• Patient's WhatsApp-registered phone number
• Message content (appointment details, prescription status, reminders)
• Message metadata (timestamps, delivery and read receipts)
Meta Platforms, Inc. processes this data as a sub-processor in accordance with their own Privacy Policy at: https://www.facebook.com/privacy/policy/. Hello Homeo does not control Meta's data processing practices.
Opt-In: Patients consent to WhatsApp messages by providing their mobile number when booking an appointment with a clinic.
Opt-Out: Patients may withdraw consent at any time by sending STOP to the clinic's WhatsApp business number, or by contacting the clinic directly. Opting out does not affect access to medical services.
Hello Homeo does not use WhatsApp data for advertising or sell it to any third party.
9. Mobile Applications
Hello Homeo publishes native mobile applications. The HelloHomeo Doctor app is used by clinicians whose accounts are issued by their clinic; there is no public sign-up. This section describes what those apps do on the device, in addition to everything stated above.
Device permissions the app requests, and why:
• Camera — video teleconsultations, and photographing a report a patient brings in so it can be attached to their case sheet.
• Microphone — teleconsultation audio, and Scribe, which records a consultation so it can be transcribed into a draft case sheet.
• Photo library — attaching an existing photo of a report or scan to a case sheet.
• Notifications — telling a clinician about a new or changed appointment, or a completed lab result.
• Face ID / biometrics — optionally locking the app so patient records are not left open on an unattended device.
Each permission is requested only when the feature that needs it is used, and the app works without the optional ones. The apps do not request location, and do not access contacts, calendar, or files beyond what the clinician explicitly attaches.
What the app stores on the device:
• Sign-in tokens, held in the platform keychain or keystore.
• The signed-in clinician's name, email and clinic, to show who is signed in.
• The clinician's acknowledgement of the in-app data disclosure, and their app-lock preference.
Patient records are read from the clinic's server each time they are viewed and are not cached to the device's disk. Personal health information is not written to iCloud or any consumer backup service.
Artificial intelligence in the app: the Vita AI assistant and the Scribe feature send the case text a clinician asks about, and the audio Scribe records, to Google's Gemini models for processing, so that notes can be drafted and remedies ranked. The app discloses this and asks the clinician to acknowledge it before they can use the app. Vita assists with drafting and lookup only — it does not diagnose, prescribe, or replace clinical judgement, and the clinician remains responsible for every entry in a patient's record.
Session security: a clinician's session can be locked behind the device's own authentication, and is signed out automatically after a prolonged period of inactivity.
Account deletion: a clinician can delete their account from within the app (Settings → Delete my account) or online at /data-deletion. Deletion immediately revokes every session and deactivates the account. Clinical records the clinician authored remain part of their patients' medical records and are retained by the clinic for as long as medical-records law requires; they are the clinic's records, not the clinician's, and are not deleted by this request.
Crash reporting: technical diagnostics are reported through Sentry (Functional Software, Inc.) to identify faults. Patient content is not deliberately included in a diagnostic report.
The apps contain no advertising, no advertising identifiers, and no third-party analytics or tracking SDKs. No data collected through the apps is used for advertising, marketing, or sold to any third party.
10. External Links
The Hello Homeo website and clinic portals may contain links to external websites or platforms. Hello Homeo is not responsible for the privacy practices of those external services.
11. Cookies & Analytics
Hello Homeo uses minimal, session-based cookies for authentication and platform operation. We use limited analytics to monitor platform performance and improve the user experience. No personally identifiable information is tracked across websites or shared with advertising platforms.
12. Policy Updates
This Privacy Policy may be updated periodically to reflect changes in our platform or applicable law. Material changes will be communicated to active Subscribers. Continued use of the platform after an update constitutes acceptance of the revised policy.
Last updated: April 2026 · Questions about this policy? Email contact@hellohomeo.in