Privacy Policy
Bidwarriors Online Smart Solutions Pvt. Ltd. · Operates DoctorLib · Last updated: 20 Jun 2026
1. Who we are
DoctorLib is operated by Bidwarriors Online Smart Solutions Pvt. Ltd. (GSTIN: 37AAHCB3630K1ZM) (“we”, “us”). We provide an online platform to search doctors, book appointments, make payments, and manage health-related records. Our registered office is at 11/286-1-18, Brahmapuram,
Revenue Ward No. 18, Pedana,
Krishna District, Andhra Pradesh – 521366,
India.
DoctorLib does not use patient medical information for advertising, behavioral profiling, or sale to third parties.
2. Data categories
DoctorLib processes the following categories of data:
1. Personal data
- Name
- Mobile number
- Email address
- Address
2. Health data
- Medical history (allergies, chronic conditions, medications, surgeries, family history)
- Prescriptions (RX ID, medicines, fulfillment status, per-pharmacy dispensing records)
- Doctor-ordered diagnostic tests and diagnostic reports
- Patient-uploaded medical files (PDF/images)
- Appointment notes and visit history
- Self-reported vitals and health metrics (blood pressure, heart rate, SpO₂, sleep, weight, and similar entries from manual input or device import)
- Health timeline events derived from doctor visits, prescriptions, lab reports, vitals, health alerts, and payments
- Automated health alerts (threshold warnings from logged vitals; optional email notification)
- AI-generated wellness summaries from food, water, and coffee photo scans (estimated calories / hydration — educational only)
- Daily wellness tracking logs (food calories, water intake, coffee cups from Care AI scanners)
- Digital health card summaries (DoctorLib Wellness Score, health age estimates — wellness indicators only, not disease risk scores)
- Family member profiles linked under a primary patient account (name, relation, date of birth where provided)
- Emergency contact details and health-card helpline preferences
- Health card / insurance search queries (selected card type and city — not your full medical record)
- Lab report AI summaries (automated, educational text — not a clinical diagnosis)
3. Provider data
- Doctor, hospital, diagnostic, and pharmacy registration details
- KYC and license documents
- Public listing information (name, address, phone, license numbers)
4. Partner catalog & search data
- Medicine names, quantities, expiry dates, and selling prices entered by verified pharmacies in their inventory (only in-stock, non-expired items may appear in public medicine search)
- Whether a pharmacy chooses to display medicine prices publicly or show “contact pharmacy” instead
- Diagnostic test names, descriptions, durations, slot capacity, and prices in a diagnostic’s public test catalog
- Whether a diagnostic chooses to display test prices publicly or per-test overrides
- Diagnostic test booking references (date, time slot, test name, diagnostic name, booking status, optional notes) when a patient books through the platform
5. Transaction & workflow data
- PA ID, RX ID, diagnostic test IDs, pharmacy sale references, and pharmacy dispensing timestamps
- Partner pharmacy sales and diagnostic billing records linked to PA ID where recorded on the platform
- SMS OTP logs for password reset (mobile number and delivery status — not the OTP itself after use)
- Email verification OTP events (for notification consent only)
6. Financial data
- Transaction references
- Payment status
7. Mobile app & authentication data
- Mobile API access and refresh tokens (DoctorLib Family app — patient accounts only)
- Registered device identifiers and last health-sync timestamps (for device import)
- Google account identifier (
sub) when you choose Continue with Google — patients only; we receive name and email from Google, not your Google password
8. Security data
- IP addresses
- Login history
- Consent records
- Audit logs
Passwords are stored only as secure hashes. We do not store full card or UPI credentials.
3. Who can access your data
- Patient — full access to own profile, appointments, prescriptions (including pharmacy-by-medicine history), diagnostic tests, diagnostic reports, uploaded files, health tracker, health timeline, digital health card, family members, emergency contacts and Medical ID card, partner directories, medicine availability search, diagnostic test search, health card / insurance finder, diagnostic test bookings, health alerts, and the same data via the DoctorLib Family mobile app when logged in.
- Doctor — clinical history for patients they have treated (non-cancelled appointments): profile, medical history, appointments, prescriptions, diagnostic tests, diagnostic reports, and patient uploads. Cannot browse unrelated patients. May use partner medicine and diagnostic test search directories for referral information (no patient PHI required for search).
- Hospital admin, receptionist & hospital clinical staff — role-based access per hospital policies: operational appointments, minimum-necessary patient demographics for reception, time-limited clinical access windows for hospital doctors, staff vitals entry, and internal hospital messaging where enabled. See hospital terms at registration.
- Diagnostic — patient lookup by PA ID only; tests assigned to or accepted by their lab; upload reports to the patient account; manage their public test catalog and see diagnostic test bookings for their diagnostic. No full medical record browsing.
- Pharmacy — patient lookup by PA ID only; remaining prescription medicines; record dispensing and sales per item; manage inventory shown in public medicine search (if in stock and not expired). No unrelated record access.
- DoctorLib administrators — limited access for operations, security, compliance, and support (audit-logged; compliance role separated where configured).
We do not sell your personal data to advertisers or data brokers.
4. How we use your data
- To create and manage your account.
- To book and manage appointments between patients and doctors.
- To share relevant health information with doctors you book with and verified partner diagnostics/pharmacies for fulfillment you initiate.
- To record which pharmacy dispensed which medicine for patient safety and traceability.
- To let patients, doctors, and hospital admins search verified partner pharmacys for in-stock medicines and verified diagnostics for offered diagnostic tests, including optional price display controlled by each partner.
- To let patients book diagnostic test time slots offered by verified partner diagnostics and record booking confirmations.
- To display health tracker readings, timeline, digital health card, and refill reminders in your patient dashboard.
- To manage family member profiles you add under your account (Health Hub on web and DoctorLib Family app — shared login; vitals and alerts may be recorded per family member where supported).
- To show informational health education and automated insights derived from your profile and vitals (not medical advice).
- To let you search which hospitals, doctors, labs, or pharmacies accept selected health cards or insurance schemes in a chosen city.
- To find nearby care using city search or device location (with your permission) via geocoding services.
- To send SMS OTP for password reset and transactional notifications to your registered mobile.
- To send email OTP, appointment confirmations, health-alert notices, and other notifications when you verify your email address.
- To send optional WhatsApp health assistant messages (medication reminders, appointment reminders, family alerts, wellness summaries) when you opt in inside the app and your registered mobile matches the WhatsApp account — see WhatsApp Health Assistant.
- To deliver in-app notifications on your phone at the priority level you receive (informational, reminder, or critical) — see In-app notification levels.
- To authenticate the DoctorLib Family mobile app and sync vitals you choose to import from your device (including Android Health Connect where you grant permission on your phone).
- To generate automated health alerts when logged vitals cross configured wellness thresholds (informational — not a diagnosis).
- To process payments and provide receipts.
- To verify doctor credentials before listing them.
- To comply with law and prevent fraud.
5. Sharing of data
We do not sell your personal data. We share data only:
- With doctors you choose to book — they see your clinical history for continuity of care.
- With partner diagnostics and pharmacies — only the minimum data needed to fulfill a prescription, diagnostic order, sale, or diagnostic test booking you initiate (including PA ID where required).
- Public partner catalog information (shop/diagnostic name, address, phone, medicine or test names, stock/slot availability, and prices only when the partner enables public display) — visible to logged-in patients, doctors, and hospital admins using search and directory features. This does not expose your personal health records.
- With hospital admins for doctors linked to their hospital.
- With payment partners (e.g. Razorpay) to process transactions.
- With optional third-party services that support platform features when enabled: geocoding / map display (e.g. OpenStreetMap / Nominatim), weather and air-quality APIs for nearby-care context, AI language-model providers for support chat or educational summaries, Meta WhatsApp Cloud API for optional WhatsApp health reminders you opt into (registered mobile and message type only — not your full medical record), and Google when you use Continue with Google (OAuth — name, email, and account ID for patient login only). We do not send full medical records to these providers; only the minimum text or coordinates needed for the feature.
- When required by law or court order.
6. Data export
Data exports may be provided in machine-readable electronic formats. DoctorLib reserves the right to verify identity before processing export requests. Patients may download their data from My Account → My Data.
7. Storage & retention
Data is stored on secure servers in India. We retain data while your account is active and as required for legal, tax, and healthcare record purposes. You may request deletion (see Your Rights).
8. Security
- HTTPS encryption for all traffic; Cloudflare web application firewall where configured.
- Password hashing (bcrypt). Password reset requires SMS OTP to the registered mobile — not email.
- Role-based access — patients see only their data; doctors see only patients they have treated; labs and pharmacies see only lookup results for PA ID presented at counter.
- Prescriptions, diagnostic reports, and medical files are not publicly accessible; downloads require authenticated access.
- Sensitive profile and note fields are encrypted at rest (AES-256-GCM; encryption keys managed via AWS KMS where configured).
- Multi-factor authentication (TOTP) available for doctor, hospital, diagnostic, pharmacy, and admin accounts.
9. Health data protection
DoctorLib recognizes that medical records, prescriptions, diagnostic reports, allergies, appointment notes, and healthcare-related information are sensitive personal data.
We apply additional safeguards to health data, including:
- Role-based access controls limiting access to authorized healthcare providers and operational personnel.
- Encryption of sensitive information during transmission and storage where technically applicable.
- Audit logging of significant access and administrative actions involving patient records.
- Restricted access to uploaded prescriptions, reports, and medical documents.
- Verification requirements for doctors, hospitals, laboratories, and pharmacies before access to healthcare workflows is granted.
DoctorLib does not sell, rent, profile, advertise against, or otherwise commercially exploit patient medical records.
See also our Medical Records & Data Usage Policy for detailed access rules.
10. Ownership of medical information
Patients remain the owners of the personal and health information they provide to DoctorLib.
DoctorLib acts as a technology platform and custodian of such information for the purposes of healthcare coordination, appointment management, record access, compliance, security, and related services.
DoctorLib does not claim ownership of patient medical records.
11. Audit and compliance logging
DoctorLib maintains security and compliance logs including login activity, consent events, document access, account changes, and administrative actions. These logs support fraud prevention, regulatory accountability, and incident investigation. Consent records are retained permanently and are not deleted.
12. Business continuity
DoctorLib maintains backup and recovery procedures designed to support platform continuity and data restoration in the event of system failures. Database backups are performed on a scheduled basis with integrity verification.
13. Data breach response
DoctorLib maintains an incident response process for unauthorized access, disclosure, or loss of personal data. Incidents are investigated, contained, documented, and addressed according to applicable legal requirements. Affected users and authorities will be notified where required by law. Report security concerns to info@doctorlib.in or our Grievance Officer.
14. Telemedicine & online video consultations
Doctors may optionally enable online video consultations on their profile. When enabled, the doctor provides a third-party meeting link (e.g. Google Meet, Zoom, Microsoft Teams). DoctorLib facilitates booking and shares the link with the patient for confirmed online appointments; we do not host, record, or store video sessions unless separately disclosed.
Teleconsultations are subject to applicable Indian telemedicine guidelines. Doctors remain solely responsible for medical advice during online visits. Patients should use a private connection and understand that online care has limitations compared to in-person examination.
15. AI features (help chat, Healthcare Copilot & health insights)
DoctorLib may offer several automated, informational AI-powered features. None of these replace a registered medical practitioner.
Footer help assistant — general platform support (bookings, labs, prescriptions, account questions).
Healthcare Copilot (patient portal) — natural-language navigation to book doctors, find care, or view your appointments and medicines. Responses are automated and may use FAQ logic and, when configured, a third-party language model.
Care AI assistant (patient portal & mobile app) — explains reports, prescriptions, reminders, and wellness insights. Upload summaries and photo scanners (food, water, coffee) provide estimated calories, estimated hydration, and educational nutrition guidance only.
Health insights & digital health card — rule-based DoctorLib Wellness Score (0–98), health-age estimates, timeline summaries, and education suggestions derived from data you enter. These are wellness engagement indicators only — not medical health ratings, disease risk scores, diagnoses, or treatment advice.
Lab report summaries — optional automated bullet summaries of reports already in your account. Always review the original report and consult your doctor.
All AI features:
- Do not provide medical advice, diagnosis, treatment, or emergency care.
- May process the text or structured data you submit to generate a reply. Do not enter passwords, OTPs, or unrelated third-party health data.
- Are not intended for long-term clinical storage unless separately disclosed.
- When a third-party AI provider is used, we limit shared content to what is necessary for the request and avoid sending identifiable medical records where possible.
For emergencies, call 108 or use the in-app Emergency page for contacts and helplines — not AI chat. This information is educational only and is not a diagnosis or prescription. Please consult a qualified healthcare professional before making medical decisions. For human support: info@doctorlib.in.
16. Location data (Nearby Care)
If you use Nearby Care or similar features, you may enter a city or allow browser location access. Location coordinates are used to find nearby partner doctors, hospitals, diagnostics, or pharmacies and may be sent to geocoding services. We do not continuously track your location in the background. You can deny location permission and search by city instead.
17. Family accounts & Health Hub
You may add family members under your patient login on the website (My Health → Family) or in the DoctorLib Family app (name, relation, optional date of birth, optional emergency contact). You confirm you have authority to provide their information. Vitals and health alerts may be logged per family member where the feature is enabled. Vaccination reminders shown on the platform are informational schedules only — confirm with your paediatrician or immunization provider.
18. Health card & insurance finder
The health card and insurance finder shows which listed providers may accept selected schemes in a city, based on data entered by partners and administrators. Results are informational; always confirm cashless eligibility, network status, and coverage with the hospital, insurer, or TPA before treatment. DoctorLib is not an insurer or third-party administrator.
19. Your rights (India DPDP Act, 2023)
- Access and download your data from My Account → My Data.
- Correct inaccurate information in your profile.
- Withdraw consent and request account deletion.
- Contact us with privacy concerns at privacy@doctorlib.in or info@doctorlib.in.
- Report security incidents at security@doctorlib.in.
- Raise a formal grievance with our Grievance Officer at grievance@doctorlib.in.
- Consent records (timestamp, IP, policy version) are stored permanently for compliance.
20. DoctorLib Family mobile app & device sync
The DoctorLib Family Android app (and matching web Health Hub) lets patient accounts view vitals, family profiles, health alerts, timeline previews, and emergency information. The app authenticates with secure tokens issued by our API — not your password stored on the device.
If you enable device sync (e.g. Android Health Connect, compatible wearables via Health Sync), vitals you authorize on your phone are sent to your DoctorLib account. Sync runs only when you grant permission in the app; we do not access other apps’ data without your action. Imported readings are stored like manually entered vitals and may trigger informational health alerts.
Web and app sessions may be linked through a one-time sign-in bridge so you are not asked to log in twice. You can revoke app access by logging out of the app or changing your password (which invalidates active tokens).
21. Google Sign-In (patients only)
Patients may optionally register or log in with Continue with Google. Google shares your verified email, display name, and a unique account ID with us. We do not receive your Google password. Google Sign-In is not available for doctors, hospitals, labs, pharmacies, or admin accounts — those roles must use mobile + password login with MFA where required. New Google sign-ups still require your Indian mobile number and acceptance of our Terms, Privacy Policy, and health-data consent.
22. WhatsApp Health Assistant
Inside the DoctorLib Family app you may opt in to receive transactional WhatsApp messages on the mobile number registered on your profile. Message types include medication reminders, appointment reminders, family health alerts, morning/evening wellness summaries, and weekly health summaries. Each category can be toggled separately after opt-in.
- Consent — WhatsApp messages are sent only after you turn on WhatsApp opt-in in Account → WhatsApp Assistant. Turning opt-in off stops new WhatsApp sends; we store your preference and consent timestamp.
- Provider — Messages are delivered through Meta WhatsApp Cloud API (WhatsApp Business Platform). Meta processes your mobile number and message content as a processor for delivery only.
- Templates — Health alerts use approved utility message templates (e.g.
doctorlib_notification). Test messages may use Meta’s pre-approvedhello_worldtemplate. - No marketing spam — We do not use WhatsApp for promotional offers unrelated to your health account. You can opt out anytime in the app.
- Not for emergencies — WhatsApp reminders are not monitored continuously and do not replace 108 or in-person care.
23. In-app notification levels (DoctorLib Family app)
The mobile app classifies alerts into three levels so you can distinguish routine updates from urgent health notices:
- Green (informational) — Daily wellness briefings, missions, and general updates. Standard notification; minimal interruption.
- Yellow (important) — Medication and appointment reminders. Audible alert and lock-screen visibility where your device settings allow.
- Red (critical) — Urgent health and safety alerts (e.g. high blood pressure or low SpO₂ thresholds). Highest priority on your device; may show an in-app banner. Not an emergency dispatch service — call 108 for emergencies.
You can review notification history in the app. Device sound, vibration, and lock-screen behaviour also depend on your phone’s system notification settings.
24. Health alerts
When you log vitals (manually or via device sync), the platform may create automated health alerts if readings cross configured wellness thresholds. Alerts appear in your dashboard and timeline; critical alerts may trigger email if your email is verified. Alerts are informational reminders only — not a diagnosis or emergency dispatch. Always consult a registered doctor for clinical decisions; call 108 for emergencies.
25. Emergency mode & Medical ID card
The Emergency page and Medical ID card display allergies, blood group, medications, PA ID, emergency contacts, nearby hospitals/pharmacies, and a shareable text summary from data you entered. You choose when to copy or share this information (e.g. via your phone’s SMS or messaging apps — we open your device’s compose screen; we do not send SMS on your behalf without your action). Emergency mode does not dispatch ambulances, monitor you continuously, or replace 108 or hospital emergency departments.
26. Children
Our services are not directed at children under 18 without parental or guardian consent. A parent or guardian may add a child as a family member under their account and is responsible for the accuracy of that information.
27. Changes
We may update this policy. Continued use after changes constitutes acceptance.
Company information
- Company
- Bidwarriors Online Smart Solutions Pvt. Ltd.
- Platform
- DoctorLib (doctorlib.in)
- CIN
- U74999AP2017PTC106342
- GSTIN
- 37AAHCB3630K1ZM
- Registered address
- 11/286-1-18, Brahmapuram,
Revenue Ward No. 18, Pedana,
Krishna District, Andhra Pradesh – 521366,
India - Support email
- info@doctorlib.in
- Phone
- +91-99590-87171
Questions? Contact us · Privacy Policy