Legal

Consumer Health Data Notice

Mental health information deserves its own notice rather than a paragraph buried inside a longer policy. This page sets out, in plain terms, what health data Mindcarter holds about you, who can see it, what we will never do with it, and how to have it erased.

Last updated — 27 September 2026

01

Why this notice exists

Indian law treats information about your physical or mental health condition and your medical records as sensitive personal data or information under the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and the Mental Healthcare Act, 2017 gives every person a specific right to confidentiality in respect of their mental health care and treatment. The Digital Personal Data Protection Act, 2023 adds a further layer of obligations on us as a Data Fiduciary.

This notice supplements our Privacy Policy. Where the two documents cover the same ground, they are meant to say the same thing — this one is simply more specific about health data.

Mindcarter

Module No. A, Tejaswini, Technopark, Thiruvananthapuram, Kerala, India

Email: info@mindcarter.com
Phone: +91 75940 71071

02

What counts as health data

In this notice, "health data" means any information that relates to your mental or physical health status, the care you receive, or that could reasonably be used to infer either. For a practice like ours that includes the obvious things — what you tell a clinician — and also less obvious ones, such as the fact that you booked a therapy session at all.

03

Health data we hold

WhatWhere it comes fromSensitivity
Your stated primary concern and the clinical tags on your recordYou, during intake and profile setup; your clinician thereafterClinical
Wellness journal entries — free text, mood ratings from 1 to 5, your own tags, and the date of each entryWritten by you in the client portalClinical
Clinician notes on your journal entriesWritten by your clinician when reviewing an entryClinical
Session notes — your clinician's record of each sessionWritten by your clinician after a sessionClinical, most restricted
Assessment information, where you take a psychometric assessmentRecorded by the practitioner who administers itClinical
Your care team — which clinicians you are assigned to, and which is primarySet when you are matched with a clinicianClinical
Booking records — dates, times, session type, mode, status and notesGenerated when you book or attendHealth-adjacent: the existence of care, not its content
Emergency contact name, number and relationship to youYou, in your profileSensitive personal data
Date of birth, preferred languageYou, in your profilePersonal data

We do not collect biometric data, genetic data, precise location data, or data from wearables or fitness trackers, and we do not buy health data about you from anyone.

04

How we use it

  • To let your clinician prepare for, conduct and document your sessions, and to maintain continuity of care if you see more than one clinician in your care team.
  • To let you keep and review your own wellness journal, and to let your clinician respond to entries you submit for review.
  • To schedule and run your sessions, including reminders and rescheduling.
  • To respond to a medical emergency involving a threat to your life or immediate health — a use the DPDP Act permits without separate consent.
  • To meet professional record-keeping and legal obligations.

We do not use your health data to make automated decisions about you, and we do not profile you.

05

Who can see it

RoleAccess to clinical content
YouYour own profile, bookings, journal entries and mood history, at any time in the portal.
Your clinicianYour profile, bookings, journal entries submitted for review, and the session notes they wrote for you.
Other cliniciansOnly if they are part of your care team. A clinician who is not on your care team cannot open your record.
Your employer, if your access is sponsoredNothing clinical. Roster membership and session counts only.
Our service providersOnly infrastructure-level access (hosting, database, email delivery) under contract, to operate the service.

Session notes are the most restricted record we keep

Notes your clinician writes about a session are visible to that clinician alone. They are not surfaced in your portal, are not shown to anyone else, and are written once — the system has no edit or delete path for them, so the clinical record cannot be quietly rewritten later.

06

What we never do

  • We never sell your health data. Not to anyone, for any price.
  • We never share it with advertisers, data brokers or analytics networks, and we run no advertising or behavioural tracking technology on this site.
  • We never share it with your employer, including the fact of what you discussed, your mood ratings, your journal, or which psychologist you see.
  • We never share it with insurers, prospective employers or background-check services.
  • We never use your journal entries or session notes to train machine-learning models.
  • We never publish testimonials, case studies or marketing content that identifies you, unless you give separate written consent for that specific use.

The only disclosures we make outside the circle above are the ones the law compels or permits: a serious and imminent risk to your life or safety or to someone else's, a risk of harm to a child or vulnerable person, a medical emergency, or a lawful order from a court or competent authority. If we ever have to make such a disclosure we will tell you, unless the law forbids us from doing so.

08

How it is protected

  • Access to clinical records is enforced on the server according to your role and care-team membership — not merely hidden in the interface.
  • Passwords are stored only as bcrypt hashes; verification codes and reset tokens are stored as hashes and expire quickly.
  • Session tokens are signed, expiring and revocable, so access can be cut off immediately.
  • Third-party calendar credentials are encrypted at rest using AES-256-GCM.
  • All traffic is encrypted in transit over HTTPS.

These measures are intended to satisfy the reasonable security practices standard under Section 43A of the Information Technology Act, 2000 and our security obligations under the DPDP Act.

09

Retention and deletion

Clinical records are kept for as long as professional and legal record-keeping obligations require, because an incomplete clinical history can itself be a risk to your care. Journal entries, profile information and bookings are kept while your account is active.

When you ask us to erase your data, we erase everything we are not legally required to retain, and we tell you specifically what has been kept and why rather than giving you a vague answer.

10

Your rights

  • Know what we hold. Ask for a summary of the health data we process about you and who it has been shared with.
  • Access your records. The Mental Healthcare Act, 2017 gives you a right to access your own mental health records, subject to the narrow exceptions in that Act — for instance where access would present a serious risk of harm.
  • Correct what is wrong. Have inaccurate or incomplete information corrected or completed.
  • Have data erased, where no law requires us to keep it.
  • Withdraw consent at any time, as easily as you gave it.
  • Nominate someone to exercise these rights for you if you die or become incapacitated.
  • Complain — to our Grievance Officer, and then to the Data Protection Board of India if you are not satisfied.

11

Visitors outside India

Mindcarter operates from India and our services are intended for people in India. If you access this website from a jurisdiction with its own consumer health data legislation — such as the State of Washington's My Health My Data Act or Nevada's SB 370 in the United States — we apply the commitments in this notice to you as well: we do not sell your consumer health data, we do not collect or share it beyond what is described here, and you may ask us to confirm what we hold and to delete it by writing to the address below.

This notice does not make Mindcarter a "covered entity" under the United States Health Insurance Portability and Accountability Act (HIPAA), and we are not regulated under it.

12

How to reach us

For any question about your health data, or to exercise any right above, contact our Grievance Officer. Please write from the email address registered on your account so we can verify who you are.

Grievance Officer

Mindcarter
Module No. A, Tejaswini, Technopark, Thiruvananthapuram, Kerala, India
Email: info@mindcarter.com
Phone: +91 75940 71071

If you are in crisis, please do not wait for a reply to an email. Call 112, or Tele-MANAS on 14416.