✨ Your health data, only yours

Your Personal
Health Vault

Store medications, prescriptions, diagnostic reports, hospital records, and family health data — all protected with client‑side AES‑256‑GCM encryption. Your records never leave your control.

AES-256 Encrypted 100% Private Up to 6 Members
Features

Everything your family needs

A complete health record system — private by design, encrypted by default, always with you.

🔒

Vault PIN Encryption

All records are encrypted client-side using AES-256-GCM before reaching the server. Only you hold the key — we literally cannot read your data.

💊

Medications & Prescriptions

Track ongoing medications with schedules and dosage, and manage prescriptions with doctor details, expiry, and status.

🧪

Diagnostic Reports

Store lab results, scan findings, and diagnostic reports. Attach the original PDF or image directly to each entry.

🏥

Hospital Admissions

Maintain a complete history of hospitalizations, surgeries, and procedures — with dates, hospitals, and clinical details.

👪

Family Accounts

One vault, the whole family. Manage records for up to 6 members and add dependents who don’t have their own login.

📌

File Attachments

Attach PDFs, JPGs, and scanned documents to any record. Scan on the spot using your phone camera — no separate app needed.

100%
Client-side
encrypted
0
Data shared with
third parties
6+
Family members
per vault
Records stored
per member
About Us

Vision & Mission

We believe health data is deeply personal — it should be private, secure, and fully in your hands.

🌟 Our Vision

A world where every family owns and controls their health story.

We envision a future where personal health records are not locked inside hospital systems or distant cloud servers beyond your reach — but stored securely in a vault that belongs entirely to you. ArogyaKosha is built to give every family that power, regardless of where they live or who treats them.

🎯 Our Mission

To make secure personal health record‑keeping simple for every family.

Our mission is to provide a simple, encrypted health vault that puts patients — not hospitals, not insurers, not tech companies — in control of their own medical data. We build for privacy first, with zero tracking, zero ads, and zero compromise on your family’s health information.

Legal

Privacy Policy

Your privacy is the foundation of ArogyaKosha. Here is exactly how we handle your data.

What data do we collect?
+

ArogyaKosha collects only the minimum information required to operate the service:

  • Your name, email address, and date of birth (for account creation)
  • An optional phone number (for phone-based login)
  • A profile picture, if you sign in with Google
  • Your encrypted medical records — which we cannot read, as they are encrypted in your browser before being sent to us
  • File attachments you choose to upload, stored as-is

We do not collect location data, device identifiers, behavioural analytics, advertising IDs, or any information beyond what you explicitly enter.

How do we protect your data?
+

Client-Side Encryption

All medical record fields are encrypted in your browser using AES-256-GCM before being transmitted to or stored on the server. The server stores and serves ciphertext only — it never has access to the plaintext content of your health records.

Vault PIN Key Derivation

Your Vault PIN derives an encryption key via PBKDF2-SHA256 (600,000 iterations) with a per-user random salt. This key is held only in your browser's sessionStorage and is never sent over the network.

Authentication Security

Passwords are hashed using bcrypt. Sessions are stored server-side, tied to HTTP-only, SameSite=Lax cookies. Google OAuth is an optional alternative login method.

Transport Security

All data travels over HTTPS with TLS. HTTP connections are automatically redirected to HTTPS.

Do we share your data with third parties?
+

No. We do not sell, rent, trade, or share your personal data or health records with any third party, ever.

  • No analytics services (Google Analytics, Mixpanel, etc.)
  • No advertising networks of any kind
  • No data brokers or marketing platforms
  • No cloud AI services that process your health records

Google Sign-In is an optional authentication method only. If you use it, Google authenticates your identity — your health records are never shared with Google. You may use email or phone login to avoid any Google interaction entirely.

Data retention & deletion
+

Your data is retained for as long as your account is active. You have full control at all times:

  • Vault Reset: Permanently and irreversibly deletes all your medical records and uploaded files. There is no recovery without your Vault PIN.
  • Account Deletion: Removes your account, all health records, vault keys, family memberships, and every uploaded file from the server.

Upon deletion, no backup copies are retained by us. Server-level backups maintained by a self-hosting operator are outside our direct control.

Cookies & session management
+

ArogyaKosha uses a single session cookie (ak_session) to maintain your login state. This cookie is:

  • HTTP-only (not accessible to JavaScript — protection against XSS)
  • SameSite=Lax (protection against CSRF attacks)
  • Valid for 7 days from last activity

We use no tracking cookies, advertising cookies, or any third-party cookies of any kind.

Changes to this policy
+

We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated effective date. Continued use of ArogyaKosha after changes constitutes acceptance of the updated policy. For significant changes, we will make reasonable efforts to notify registered users.

Last updated: May 2026  ·  Effective: May 2026

Disclaimer

Disclaimer

Please read this carefully before using ArogyaKosha.

Not a medical device or service
+

ArogyaKosha is a personal record-keeping application. It is not a medical device, clinical decision support system, diagnostic tool, or healthcare service. It is not regulated or approved by any medical regulatory authority (such as CDSCO, FDA, CE, or equivalent bodies).

The application is designed solely to help individuals store and organise their own personal health information in a secure and accessible manner.

No medical advice
+

Nothing within ArogyaKosha — including any feature, template, suggestion, or displayed content — constitutes medical advice, diagnosis, treatment recommendation, or a substitute for the advice of a qualified healthcare professional.

  • Always consult a licensed physician or specialist for medical decisions
  • Do not use this application to self-diagnose or self-treat any condition
  • In a medical emergency, contact emergency services immediately
Accuracy of information
+

ArogyaKosha stores information exactly as entered by the user. We do not verify, validate, or cross-check any medical data entered into the system. The accuracy, completeness, and currency of all health records stored is entirely the responsibility of the user.

Records stored in ArogyaKosha should not be used as the sole authoritative source of medical truth in any clinical setting without independent verification by a qualified professional.

Limitation of liability
+

To the fullest extent permitted by applicable law, Polytechnique System Services LLP and the ArogyaKosha team shall not be liable for any direct, indirect, incidental, special, consequential, or punitive damages arising from:

  • The use or inability to use the application
  • Any medical decision made based on information stored in the app
  • Loss of data due to a forgotten Vault PIN (recovery is impossible by design)
  • Unauthorised access resulting from user negligence (e.g., sharing credentials or PINs)
  • Server downtime, data corruption, or technical failures beyond our control

Use of ArogyaKosha is entirely at your own risk.

Vault PIN & data recovery
+

The Vault PIN is the sole key to your encrypted health records. If you forget your Vault PIN, your records cannot be recovered by anyone — including us. This is by design: true privacy means no backdoor, not even for the service provider.

  • Store your Vault PIN securely (e.g., in a trusted password manager)
  • A Vault Reset permanently and irreversibly deletes all your records — this cannot be undone
  • We strongly recommend keeping a separate encrypted backup of any critical records