Back to Home

Data Storage & Deletion Policy

Last Updated: April 1, 2026  ·  Effective: April 1, 2026

Data Controller

  • Company: Med97 Inc
  • Address: 8-43/5/12, Balaji Hills, Hyderabad – 500039, Telangana, India
  • Grievance Officer: Sathish
  • Phone: +91 7780771768
  • Email: hello@med97.com

1. Scope

This policy describes what data Med97 Inc collects through SocialMD.ai ("Platform"), where and how long it is stored, and how you can request its deletion. It supplements our Privacy Policy and complies with India's Digital Personal Data Protection (DPDP) Act 2023, GDPR, and applicable health-data regulations.

2. Categories of Data We Store

CategoryExamplesWhere Stored
Account & ProfileName, email, specialty, medical registration numberSupabase (encrypted at rest)
Clinical Case InputsDe-identified case descriptions, outcomes, key learningsSupabase (AES-256)
Generated ContentAI-generated social posts, calendars, thread outputsSupabase
Training FeedbackLiked posts saved for AI model improvement (anonymised)Supabase
Usage LogsAPI call timestamps, feature usage, error logsVercel / server logs
Payment RecordsInvoice amounts, subscription tier, dates (not card data)Razorpay + our records
OAuth TokensSocial media access tokens (encrypted)Supabase (encrypted)
Cookies / SessionsAuth session tokensBrowser + Supabase Auth

We never store: complete payment card numbers (handled exclusively by Razorpay PCI-DSS L1), patient names, or any re-identifiable Protected Health Information.

3. Retention Schedule

Data TypeRetention PeriodReason
Active account dataWhile account is activeService delivery
Account data after deletion request30 days (grace period)Accidental deletion recovery
Hard-deleted account dataPermanently removed after 30 daysYour right to erasure
Anonymised training dataIndefinitelyAI model improvement (no PII)
Payment & invoice records7 yearsIndian GST / tax law requirement
Server / access logs90 daysSecurity monitoring
Backup snapshots30 days rollingDisaster recovery
OAuth access tokensUntil revoked or account deletedPlatform integrations

4. Where Your Data Is Stored

  • Supabase (PostgreSQL): Primary database — hosted on AWS in the ap-south-1 (Mumbai) region. SOC 2 Type II certified infrastructure.
  • Vercel Edge Network: Application hosting and CDN — servers worldwide with encrypted connections.
  • Razorpay: Payment data exclusively — PCI-DSS Level 1 compliant, India-based.
  • AI Provider APIs: Case text sent to Groq, Mistral, or DeepSeek APIs for generation only. These providers do not retain your data per their terms of service.

Data transfers outside India (to Vercel/AI providers) are covered by Standard Contractual Clauses and are necessary for service delivery.

5. Your Deletion Rights

5.1 Deleting Specific Content

You may delete individual generated posts, case inputs, or connected social accounts at any time from your account dashboard. Deletion takes effect immediately in the interface; data is purged from our database within 24 hours.

5.2 Full Account Deletion

To permanently delete your account and all associated personal data:

Option A — Self-Service

  1. Log into your account
  2. Go to Settings → Account
  3. Click "Delete My Account"
  4. Confirm via email link

Option B — Email Request

  • Email: hello@med97.com
  • Subject: "DELETE MY ACCOUNT"
  • Include: Registered email address
  • Response: Within 72 hours

⚠️ What Cannot Be Deleted

  • Anonymised training data — no PII, cannot be linked back to you
  • Payment/invoice records — retained 7 years per Indian tax law
  • Aggregated analytics — no individual identifiers

6. Deletion Timeline

StepTimeframeWhat Happens
Request receivedImmediatelyAccount access suspended, confirmation email sent
Grace periodDays 1–30Data retained for accidental deletion recovery
Primary databaseDay 30All personal data hard-deleted from Supabase
BackupsDay 30–60Data purged from rolling backup snapshots
LogsDay 90Access logs purged after 90-day retention cycle
ConfirmationDay 30Deletion confirmation email sent to you

7. Data Portability

You may request a full export of your personal data before deletion. We will provide a machine-readable JSON export within 7 business days of your request. Email hello@med97.com with subject "DATA EXPORT REQUEST".

8. Grievance Redressal

If you have concerns about how your data is stored or have not received a deletion confirmation, contact our Grievance Officer:

  • Grievance Officer: Sathish
  • Phone: +91 7780771768
  • Email: hello@med97.com
  • Address: 8-43/5/12, Balaji Hills, Hyderabad – 500039
  • Response Time: Within 30 days (as required by DPDP Act 2023)

9. Changes to This Policy

We may update this policy. Material changes will be notified via email and a notice on the Platform at least 14 days in advance. Continued use after the effective date constitutes acceptance.

By using SocialMD.ai, you acknowledge that you have read and understood this Data Storage & Deletion Policy.