Effective Date: April 1, 2026 · Last Updated: April 17, 2026
Version 2.0
Med97 Inc. ("Company", "we", "us", "our") operates SocialMD.ai ("Platform", "Service"). We are deeply committed to protecting your privacy and being transparent about how we collect, use, share, and protect your personal information. This Privacy Policy explains our practices and your rights in accordance with applicable law, including India's Digital Personal Data Protection Act 2023 (DPDP Act), the Information Technology Act 2000, and where applicable, the EU General Data Protection Regulation (GDPR).
By creating an account or using the Service, you agree to this Privacy Policy. If you do not agree, please do not use the Service.
During Registration:
During Use:
Payment Information:
AI Training Data — Important Notice
Your anonymised Clinical Input and the AI-generated content produced from it may be used as training data to fine-tune and improve our AI models. "Liked" posts are treated as high-quality training signals. All data is stripped of personal identifiers before training. You cannot opt out of this use. If you do not consent, please discontinue use of the Service.
Under the DPDP Act 2023 and GDPR, we process your personal data on the following legal bases:
| Processing Purpose | Legal Basis |
|---|---|
| Account creation and service delivery | Contractual necessity |
| Payment processing | Contractual necessity |
| OTP verification and security | Legitimate interest / legal obligation |
| Service improvement and analytics | Legitimate interest |
| AI model training (anonymised) | Consent given at account creation |
| Marketing communications | Consent (opt-in) |
| Legal compliance | Legal obligation |
| Fraud prevention | Legitimate interest |
We do not sell your personal data. We share data only in the following circumstances:
We work with trusted third-party service providers who process data on our behalf under strict data processing agreements:
| Provider | Purpose | Data Shared |
|---|---|---|
| Supabase (USA) | Database and authentication | All user account data |
| Groq / Mistral / DeepSeek | AI content generation | Anonymised clinical input only |
| Razorpay (India) | Payment processing | Billing name, amount, email |
| Twilio (USA) | SMS OTP delivery | Mobile phone number only |
| Vercel (USA) | Web hosting and CDN | Application logs, IP address |
When you use direct publishing, we send your generated content to the connected social media platform's API on your behalf. We share only the content you instruct us to post — no other personal data.
We may disclose personal data if required by applicable law, court order, government authority, or to protect the rights, safety, or property of the Company or its users.
In the event of a merger, acquisition, or sale of assets, your personal data may be transferred as part of that transaction. We will notify you via email or in-app notice before your data is transferred and becomes subject to a different privacy policy.
Some of our service providers are located outside India. Your data may be transferred to and processed in the United States and other countries. Where required by law, we ensure appropriate safeguards are in place for such transfers, including standard contractual clauses and data processing agreements that provide equivalent protection to Indian and EU data protection laws.
We implement industry-standard technical and organisational measures to protect your personal data:
Despite these measures, no internet transmission is 100% secure. If you discover a security vulnerability, please responsibly disclose it to hello@med97.com.
| Data Type | Retention Period | Reason |
|---|---|---|
| Active account data | While account is active | Service delivery |
| Account data after deletion | 30 days (recoverable) | Accidental deletion protection |
| Account data after 30 days | Permanently deleted | User right to erasure |
| Payment records & invoices | 7 years | Tax and legal compliance (GST Act) |
| Security and access logs | 90 days | Security investigation |
| Anonymised AI training data | Indefinitely | AI model improvement |
| Phone verification records | 90 days | Fraud prevention |
We use the following types of cookies and similar technologies:
We do not use third-party advertising cookies. You can manage cookie preferences through your browser settings, though disabling strictly necessary cookies will impair the Service's functionality.
The Service is intended for licensed medical professionals who must be at least 18 years of age. We do not knowingly collect personal data from individuals under 18. If we become aware that a minor has provided personal data, we will delete it promptly. If you believe we have inadvertently collected data from a minor, contact us at hello@med97.com.
The right to erasure does not apply to: (a) anonymised Training Data incorporated into AI models (as re-identification is not possible); (b) payment records required for legal compliance; (c) data needed to resolve outstanding disputes or enforce agreements.
To exercise any of your rights, you may:
We will acknowledge your request within 24 hours and respond substantively within 30 days. We may request identity verification before actioning certain requests. We do not charge for requests unless they are manifestly unfounded or excessive.
We send product update and feature announcement emails only to users who have opted in. You may opt out of marketing communications at any time by:
Opting out of marketing does not affect transactional communications (invoices, security alerts, service updates) which are necessary for the provision of the Service.
We may update this Privacy Policy periodically. Material changes will be communicated via email to your registered address or an in-app notice at least 14 days before the changes take effect. We will also update the "Last Updated" date at the top of this page. Continued use of the Service after the effective date constitutes acceptance of the updated Policy.
If you have questions about this Privacy Policy, wish to exercise your rights, or wish to lodge a complaint, contact our Grievance Officer:
Grievance Officer: Sathish
Email: hello@med97.com
Phone: +91 7780771768
Response: Acknowledged within 24 hours, resolved within 30 days.
If you are dissatisfied with our response, you may file a complaint with the Data Protection Board of India (once operationalised under the DPDP Act 2023), or with your local data protection authority if you are an EU resident.
Legal Name: Med97 Inc.
Trade Name: SocialMD.ai
Registered Address: 8-43/5/12, Balaji Hills, Hyderabad, Telangana – 500089, India
Email: hello@med97.com
Phone: +91 7780771768
Data Fiduciary: Med97 Inc.
Grievance Officer: Sathish
By using SocialMD.ai, you acknowledge that you have read and understood this Privacy Policy and consent to the collection and use of your information as described herein.