Skip to main content

Privacy · DPDP-aligned

TheraTreat Privacy Policy

How TheraTreat Health Private Limited ("TheraTreat", "we") collects, uses, shares and protects personal data — for patients and families, therapists, clinics and their staff, and everyone else who uses TheraTreat.

Last Updated: 2 October 2026Jurisdiction: IndiaDPDP Act 2023 aligned

1. Information We Collect

  • Your account: name, email, phone number, date of birth (to check age and guardian consent), and the details you add to your profile. If you sign in with Google, we receive your name and email from Google.
  • Your care: the therapists and clinics you book, session times and modes, the concerns you share, the notes your therapist writes, TheraSelf assessments and their results, and documents you upload. For home visits, your address.
  • AI conversations: what you write to Thera and to Tara, and the summary Thera keeps of earlier conversations so it can pick up where you left off (section 3).
  • Payments: amounts, payment and refund status, and references from our payment gateway. We never receive your full card number, CVV or UPI PIN.
  • Home care requests: the care needed, the age group and concerns of the person needing it, your locality and (if you share it) your location, your availability, and your contact details.
  • Therapists and clinics: identity and verification details (PAN, date of birth, licence or registration number and council, verification documents), bank account and UPI details for payouts, business details (legal name, GSTIN, authorised signatory, registered address), and everything published on your profile.
  • Consent records: what you agreed to and when, with the network address and browser it was given from.
  • Technical data: device and browser, network (IP) address, the country we infer from your connection, pages visited, and error reports.

We do not currently record or transcribe video or audio sessions. If we ever do, it will be only with the explicit consent of both you and your therapist, and we will update this policy first.

2. How We Use It

  • To run your account and bookings: search and matching, booking, payments and refunds, video sessions, reminders and receipts.
  • To deliver your care: giving your therapist or clinic what they need, and keeping session notes and assessment results.
  • To provide the AI features you choose to use (section 3).
  • To verify therapists and clinics, pay them their share of each booking, and bill them for their plans.
  • To keep TheraTreat safe: preventing fraud and abuse, limiting automated requests, and spotting messages that suggest someone may be in danger so we can show crisis helplines.
  • To meet legal duties, such as tax records and lawful requests from authorities.
  • To send marketing — only if you opt in, and you can opt out at any time.
  • To understand how TheraTreat is used, from analytics you allow and from counts that identify no one.

We process personal data on the basis of the consent you give (which you can withdraw), and for the legitimate uses the Digital Personal Data Protection Act, 2023 allows, such as complying with the law and responding to a medical emergency.

3. AI Features: Thera and Tara

TheraTreat has two AI assistants. They are separate, and they handle data differently.

  • Thera(Ask Thera and TheraSelf assessments) is powered by TheraAI. When you use Thera, your messages, your earlier Thera conversations and your assessment answers are processed by TheraAI to write replies, run assessments and summarise what you have shared. Your conversations are stored encrypted. Thera's replies are generated automatically: no clinician reviews them, and they are not a diagnosis or a treatment plan.
  • Tara, the assistant in the Help Center, answers questions about using TheraTreat. Your question and the last few messages of the conversation are sent to a cloud AI model provider to write the reply. Tara is not linked to your account: we keep a fingerprint of each question and the start of each reply to check quality and prevent abuse, and use your network address only to limit request rates. Please don't share health details, passwords or payment details with Tara.
  • Therapist matching sends the text of your search to TheraAI to suggest therapists.
  • For therapists and clinics: AI drafting sends the notes a therapist types to TheraAI. A draft becomes part of the record only when the therapist edits and signs it, and the therapist remains responsible for it.
  • If a message to Thera or Tara suggests someone may be in danger, we show crisis helplines and a link to urgent support. TheraTreat is not an emergency service.

Clinical AI processing depends on your consent. You can withdraw it by writing to dpo@theratreat.in. "Delete AI memory" in the Privacy tab deletes the memory summary stored by TheraTreat; when we carry out a request to delete your account, your conversations are erased too.

4. Who We Share It With

  • The therapist or clinic you book: your name, the booking, the concerns you share, and your address for a home visit.
  • Inside a clinic: the clinic's owner and front-desk staff see its bookings, including home-visit addresses; the treating therapist sees the patients they see, without contact details; a supervising therapist reads notes in full to co-sign them.
  • Clinics' own systems: a clinic with an Advanced seat, or on our legacy Enterprise plan, can connect its software to receive its bookings — patient name and ID, appointment and amount. Never your phone number, email, address or notes.
  • Home care requests: until you accept someone, therapists and clinics nearby see your request without your name, contact details or exact location. Your contact details go only to the therapist or clinic you accept.
  • A clinic's own patient list: a clinic may record its existing patients with us. We use those details only to match bookings to that clinic for billing between us and the clinic.
  • Service providers that run parts of TheraTreat (section 5).
  • Authorities: when the law requires it, or to protect someone's life in an emergency.

We never sell or rent personal data to advertisers or anyone else.

5. Service Providers

Each provider receives only what its job needs:

  • Payments and payouts: our payment gateway processes payments and refunds. For therapists and clinics, it also receives the identity, business, address and bank details needed to open their payout account and pay them.
  • Identity and bank verification: checks therapists' PAN and bank accounts, and GST registrations.
  • AI: TheraAI (Thera, matching and note drafting) and a cloud AI model provider (Tara).
  • Messages: email, SMS and WhatsApp providers, and the push services of your browser or phone.
  • Video sessions: our video provider carries the audio and video of online sessions.
  • Infrastructure: cloud hosting, database and file storage.
  • Analytics and error monitoring: analytics only with your consent; error monitoring to find and fix faults.

To ask which companies these are, write to dpo@theratreat.in.

6. Where Data Is Processed

TheraTreat is operated from India, but some of our providers store or process data in other countries. Uploaded files, including verification documents, are stored in the European Union. The Help Center's AI, analytics and error monitoring run on infrastructure in other countries, including the United States, and video sessions are routed through the nearest available region. We transfer data only to countries the law permits.

7. How We Protect It

  • Data travels encrypted (HTTPS).
  • The most sensitive fields are also encrypted one by one where they are stored — bank, UPI and PAN details, AI conversations, TheraSelf health answers, and clinical notes — with keys held in a managed key service.
  • Access follows roles: a therapist sees their own patients; clinic staff see what their role needs.
  • Administrator accounts use multi-factor authentication.

No system is perfectly secure. If a personal-data breach affects you, we will tell you and the Data Protection Board of India as the law requires.

8. Your Rights and Choices

From the Privacy tab of the patient dashboard you can:

  • Download a copy of your account data.
  • Delete the memory summary Thera keeps.
  • Choose whether to receive marketing by email and by SMS.
  • Request deletion of your account. We carry it out after a 30-day grace period, during which you can cancel it: your personal data is then erased or anonymised, except the records described below.
  • Raise a grievance, and manage guardian consent for a minor's account.

Anyone — including therapists, clinics and their staff — can ask to access, correct or delete their data, withdraw consent, or nominate someone to exercise these rights for them, by writing to dpo@theratreat.in. We will verify your identity first. Your profile details can be corrected from your dashboard at any time.

Deletion does not remove records we must keep by law: payment and invoice records, health records such as session notes and assessment results, and records needed for a dispute. We tell you what we keep and why.

9. Messages and Notifications

  • Booking messages — confirmations, reminders, changes, cancellations and refunds — go by email, SMS, WhatsApp and push notifications.
  • Therapists and clinics also receive billing messages about their plans and invoices.
  • You can switch any channel off in your notification settings. Some messages, such as security and legal notices, still reach you by email.
  • Marketing is off unless you opt in, and every marketing email has an unsubscribe link. You choose marketing by email, SMS and WhatsApp separately in the Privacy tab; marketing push notifications follow your email choice.

10. Cookies and Similar Technologies

  • Essential: keep you signed in, protect your account, and remember your cookie choice.
  • Analytics: set only after you accept them.
  • Page counts: we count visits to public pages on our own servers, without cookies, using an anonymous code that changes every day.
  • Anonymous chat: if you use Thera without signing in, a cookie counts your free messages for 30 days.
  • Error monitoring: may record a replay of some visits — a small share of all visits, and visits where something goes wrong — to diagnose faults, with text and media masked.

You can change your choice at any time in — the link is also at the foot of every page. Withdrawing analytics removes the analytics cookies from your browser.

11. How Long We Keep Data

  • Your account and AI conversations: while your account is open, and erased or anonymised when we carry out a request to delete it.
  • Payment and invoice records: as long as tax and accounting law requires.
  • Health records (session notes and assessment results): as long as the law requires for health records, which can be after your account is deleted.
  • Home care requests: expire after 14 days and are then kept as a record of the request.
  • Technical records and logs: for limited periods, generally up to eighteen months.

12. Children and Families

Accounts are for adults. People aged 13 to 17 can use TheraTreat with a parent's or guardian's consent, which must be confirmed before they book, use Thera or take an assessment; children under 13 cannot hold an account. Parents and guardians can book sessions for their children and complete screenings about them from their own account; we treat that information as health data in the parent's account. If you believe a child is using TheraTreat without consent, write to dpo@theratreat.in.

13. Visitors from the EEA and UK

TheraTreat is based in India and does not target people in the European Economic Area (EEA) or the United Kingdom. Where we process the personal data of people located there — for example, when someone outside India books a session after giving their consent — we apply the principles of the GDPR and the UK GDPR:

  • Lawful bases: consent (Art 6(1)(a)); performance of your booking (Art 6(1)(b)); legal obligations (Art 6(1)(c)); and, for health data, your explicit consent and the provision of health care (Art 9(2)(a) / (h)).
  • Your rights: access, rectification, erasure, restriction, portability, objection, and withdrawal of consent — through the Privacy tab or by writing to our DPO.
  • Transfers: data is processed in India and in the other countries described in section 6.
  • Complaints: you may complain to your local data-protection authority (in the UK, the Information Commissioner's Office).

14. Your Responsibilities

  • Keep your sign-in details to yourself.
  • Share someone else's information — a child's, a relative's, a patient's — only when you are entitled to.
  • Tell us straight away about any activity on your account you don't recognise.

15. Grievances and Contact

For any concern about your data, or to exercise a right, use the grievance form in the Privacy tab or write to us. We aim to acknowledge a grievance within 48 hours and to respond in substance within 15 working days.

Support and rights requests
📞 +91-8446602680 (Mon–Fri 9:30 AM – 6:30 PM IST)
Data protection and escalations
📧 Grievance Officer: grievance@theratreat.in

If you are not satisfied with our response, you may complain to the Data Protection Board of India under the Digital Personal Data Protection Act, 2023.

To report a security issue, include what happened, when, and anything that helps us find it.

16. Changes to This Policy

When this policy changes, the date at the top changes too. If a change materially affects how we use your data, we will tell you by email before it takes effect and ask for your consent again where the law requires it.
If translation differences occur, the English version prevails.