This describes what this website actually does with your information — not what a template says a clinic website usually does. Where the honest answer is “this site cannot do that”, it says so.
Last reviewed: 8 September 2026 · Shree Ganesh Homoeopathic & Ayurvedic Clinic, Satara · Maharashtra Council of Homoeopathy — Registration No. 34210
The Guided Case Intake, the patient register and the recorder all use your browser’s own storage (IndexedDB). That covers:
What this genuinely means, stated plainly: data in a browser profile is about as private as the device it sits on. Anyone with access to that computer or phone, that browser profile, or an unlocked screen may be able to reach it. Clearing your browser data, using a different browser, or using private/incognito mode will lose it. The passcode on the patient record keeps a casual passer-by out of the interface; it is not disk encryption, and it does not make the device secure by itself.
This is not a cloud medical record, a hospital database, or a cross-device patient file, and this site does not describe it as one.
1. The enquiry form and WhatsApp button.
The contact form does not submit to any server. It opens your own email app with a message pre-filled — name, phone, an optional email address, the subject you chose and what you wrote — and nothing is sent until you press send in your own email app. The WhatsApp button does the same through WhatsApp, which is a third-party service with its own privacy terms. Please keep detailed medical history out of both, and bring it to the consultation instead.
2. The optional AI Case-Taking Assistant.
This is the only feature that transmits health information. What you type is sent to Anthropic’s AI service, on servers outside India, so it can reply. The conversation is not written to any clinic database — it reaches the doctor only if you copy or download the case file yourself and send it. You are shown this before the chat starts and can decline; the Guided Case Intake asks the same kind of questions and sends nothing.
3. Ordinary web-server information.
Like any website, requests for pages reach the hosting provider and are handled with the normal technical information a web request carries (such as the IP address making it). This is used to serve the site and to limit abuse of the AI assistant, not to profile you.
There is no analytics script, no advertising pixel, no remarketing tag and no third-party tracker on this site. Nothing you enter in the intake is sent to any analytics service.
The only cookie the site sets is the session cookie created when the doctor signs in to the physician area. It is HttpOnly, restricted to this site, and carries no patient information. Because there are no non-essential cookies, there is no cookie banner — adding one would imply a choice that does not exist.
The clinic sees children, and the intake has a paediatric pathway. Information about a child should be entered by a parent or guardian, and the intake records that relationship.
A child’s information is handled exactly like an adult’s: it stays on your own device. It is never used for advertising, profiling or behavioural tracking of any kind — the site carries no tracking technology at all, so there is nothing that could do so.
Because your records live in your browser, they are kept for as long as you keep them, and you can remove them at any time by clearing this site’s data in your browser settings. You can also export your own case as a text or JSON file from the completion screen at any point.
The clinic cannot delete something it never received. If you have sent the clinic information by email, WhatsApp or in person — or if you are a patient of the clinic and want to know what is held about you — write to the contact below and it will be handled within one month.
You can ask what information the clinic holds about you, ask for it to be corrected, ask for it to be deleted where the clinic holds it, and object to how it is used. Use the contact below.
India’s Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 are notified, but their substantive obligations — notice, consent, children’s data, data-principal rights — commence in May 2027. The obligations in force today come from the Information Technology Act, 2000 and the Sensitive Personal Data rules made under it, which treat health information as sensitive personal data and require a published privacy notice, consent before collection, and a named grievance contact. This notice is written to satisfy those now, and to be honest under the DPDP framework when it commences.
This is a description of how the website works, written by the clinic. It is not legal advice, and it is not a claim of certification by any authority.
If you have a question or a complaint about how your information has been handled, contact the grievance officer for this website directly:
Complaints are answered within one month.