MERAGO One

Privacy Policy

Effective date: July 10, 2026  ·  Last updated: July 10, 2026

Applies to: the MERAGO One mobile app, the “Ask Belinda” companion, and related MERAGO One websites and services (the “Service”).

A quick summary

We built MERAGO One to help you understand and organize your health — not to diagnose you. Here’s the short version; the full policy follows.

  • What we handle: the health information you choose to add (records, notes, reminders, your profile), your messages to Ask Belinda, your account details, and technical/usage data.
  • Why: to run the features you use, to let Ask Belinda explain your information in plain language, to keep your data secure, and to operate, improve, and develop the Service.
  • Ask Belinda is informational. It helps you read and organize your own information and learn general health facts. It does not provide a diagnosis, and Merago.One is not a medical device or a replacement for a clinician.
  • Your health data is sensitive, and we treat it that way. Where the law requires it, we rely on your explicit consent, which you can withdraw.
  • We do not sell your health data, and we do not use it for targeted advertising.
  • We do not let third-party AI providers use your identifiable health data to train their own general-purpose models without your consent.
  • We may use de-identified and aggregated data to operate, improve, and develop MERAGO One and Ask Belinda.
  • You’re in control. The in-app Privacy Dashboard lets you view, correct, export, and delete your data, and manage sharing and consents.
  • Sharing only happens when you ask for it — for example through Secure Sharing, Trust Circle, or connecting to a provider.

1. Who we are

The Service is provided by Merago Healthcare Pvt. Ltd., Bengaluru, India, a Bengaluru, India based company registered with the Registrar of Companies (“Merago”, “we”, “us”, “our”). For the purposes of applicable data-protection laws, Merago is the controller of the personal data described in this policy, except where a regional group entity is named as controller for a specific market in Section 14.

Read this together with our Terms of Service, any telehealth or clinical consent presented to you at the time, any privacy notice a clinical partner provides, and any separate consumer-health-data notice we make available. Where a more specific notice conflicts with this policy for the data it covers, that notice controls for that data.

How to reach us about privacy:

2. Scope and important notices

Availability varies by country. MERAGO One is rolled out market by market. Some features, and in some cases the app itself, may not be available in your country yet, and the way your data is handled follows the rules of the market you use the Service in. Where a market requires data to be stored locally, we host it accordingly (see Section 10).

Not a medical device; not medical advice. MERAGO One and Ask Belinda provide health information for educational and wellness purposes only. They do not diagnose, treat, or prescribe, and they are not a substitute for professional medical advice, examination, or treatment. Always consult a qualified clinician about your health. In an emergency, contact your local emergency services.

3. Clinical services and providers

MERAGO One is not, by itself, a doctor, telehealth provider, pharmacy, or health plan.

Where the app lets you connect to care — for example through My Doctor, Find Care Nearby, or a consultation — those clinical services are provided by MeragoHealth entities / independent licensed clinicians / partners identified to you before the service. MERAGO One provides the technology, coordination, and support that help you reach them.

The treating clinician or partner is responsible for clinical decisions, including diagnosis, treatment, prescribing, follow-up, and medical-record obligations. MERAGO One does not control or direct their medical judgment.

Where a clinician or partner provides its own privacy notice for the records it holds, that notice governs those records; if it conflicts with this policy for that information, that notice controls.

4. The information we collect

4.1 Information you provide

4.2 Information we collect automatically

4.3 Information from third parties

We do not collect more than we need for the purposes in Section 6.

5. Health and other sensitive data

Most of what MERAGO One handles is health data, which data-protection laws treat as a special/sensitive category requiring extra protection. This can include the information you add, health-related inferences (such as trends across your own results), and details about the care you look for.

Where the law requires a specific condition to process this data, we rely on your explicit consent, which you give when you add health information or use a feature that requires it. In some situations we may also rely on other legal grounds recognized by law — for example, to protect your or another person’s vital interests in an emergency (Emergency Info), or where you have manifestly made information public.

You can withdraw consent at any time through the Privacy Dashboard or by contacting us. Withdrawing consent doesn’t affect processing already carried out, and some features won’t work without the data they depend on.

6. How we use your information, and our legal bases

We use your information for the purposes below. Where the EU/UK GDPR or a similar law applies, the legal basis is shown in the third column.

PurposeWhat this involvesLegal basis (GDPR-style)
Provide the ServiceCreate your account; run the features; sync your data across devicesPerformance of a contract
Handle health data in featuresStore and display your records, profile, notes, reminders, emergency infoExplicit consent (Art. 9)
Ask BelindaProcess your questions and information to explain and organize itExplicit consent; contract
Improve MERAGO One & Ask BelindaEvaluate quality/safety; develop features; improve our systems (see Section 7)Consent (health data); legitimate interests (other)
Sharing you initiateSecure Sharing, Trust Circle, connecting to a providerConsent / contract
Emergency InfoMake critical details available to help you in an emergencyVital interests; consent
Location featuresFind Care NearbyConsent (device permission)
Security & fraud preventionProtect accounts and the Service; bot-mitigationLegitimate interests; legal obligation
Communicate with youService messages and support; opt-in updatesContract; consent (marketing)
Comply with lawMeet legal and regulatory obligationsLegal obligation

We do not use your health data for advertising, and we do not sell it.

7. Ask Belinda, AI processing, and product improvement

What Ask Belinda does. Ask Belinda uses automated language technology to help you understand and organize your own information and to answer general health questions in plain language. It can show you your own results and trends and explain what a marker generally measures. Any “out of range” flags it shows come from your lab’s own report, attributed to the lab — Ask Belinda does not create its own diagnosis or clinical verdict.

What it doesn’t do. Ask Belinda does not diagnose, does not make decisions that produce legal or similarly significant effects about you, and does not replace a clinician. When something needs professional judgment, it points you toward a qualified clinician.

7.1 Using data to improve MERAGO One and Ask Belinda

We use information to operate, monitor, evaluate, improve, and develop the Service and its AI features — for example to measure response quality and safety, reduce errors, test prompts and guardrails, and build new features. Where this involves your health data, we do so on the basis of your consent or as otherwise permitted by law.

7.2 De-identified, aggregated, and synthetic data

We may de-identify, aggregate, pseudonymize, derive, or synthesize data from information collected through the Service, and use it for analytics, research, development, safety evaluation, and improving and training our own systems. Where health data is de-identified, we do so in a manner permitted by applicable law. Data that no longer identifies you may be retained indefinitely.

7.3 Third-party AI providers and subprocessors

We may use vetted technology providers — including AI, cloud, analytics, and security providers — to process information as our processors under contract. They may process your data only to provide services to us. We do not allow third-party AI providers to use your identifiable health data to train their own general-purpose models without your consent. This does not limit our own use of de-identified or aggregated data to improve MERAGO One as described above.

7.4 Human review

Authorized Merago personnel, contractors, or reviewers may access limited information where needed to provide support, evaluate quality and safety, debug systems, investigate abuse, or comply with law. We limit access based on role and business need. You can use most of MERAGO One without Ask Belinda if you prefer.

8. When we share information

We share personal data only as described here:

Government and law-enforcement requests. We do not voluntarily disclose your health data to government or law-enforcement agencies except as required or permitted by law.

We do not sell your personal data, and we do not share health data with advertisers or data brokers.

9. Fitcoins

Fitcoins are non-cash engagement points that recognize healthy habits and promote good health. They have no monetary value, cannot be exchanged for cash, and are not a payment instrument, e-money, or financial product. We process only the activity needed to award and display them and use them as marketing and sales discounts for the services we provide.

10. International data transfers

We operate across multiple regions, so your data may be processed in a country other than your own. When we transfer personal data across borders, we use a lawful transfer mechanism, such as:

Local hosting. In markets that require health or personal data to remain in-country (e.g., India), we host and process that data locally and restrict transfers accordingly. You can ask us which safeguards apply to your data using the contacts in Section 1.

11. How long we keep your information

We keep personal data for as long as your account is active and as needed to provide the Service, then for as long as necessary to meet legal, regulatory, security, or dispute-resolution requirements. When data is no longer needed, we delete it or irreversibly de-identify it. You can delete your data or account at any time through the functionality provided in the Services; some records may be retained where the law requires.

Data categoryGeneral retention approach
Account & profileKept while your account is active and for a reasonable period after closure, unless the law requires longer.
Health content you addKept to provide continuity, personalization, safety, and support, then as needed for legal, security, and dispute purposes.
Clinical / telehealth recordsHeld by the treating clinician or partner (and by us where applicable) for the period medical-record and other laws require.
Payment & tax recordsKept as required for accounting, tax, and audit obligations, where any paid features apply.
Security, diagnostic & usage logsKept for a limited period for security, debugging, analytics, and reliability, unless needed longer.
De-identified & aggregated dataMay be kept indefinitely and used for analytics, research, development, and improving our systems, as it no longer identifies you.

12. How we protect your information

We use technical and organizational measures appropriate to the sensitivity of health data, including encryption in transit and at rest, access controls and least-privilege access, authentication and bot-mitigation on pre-login surfaces, network protections, logging and monitoring, vendor due diligence, and staff confidentiality obligations.

No system is perfectly secure. You are responsible for keeping your login credentials confidential and for using secure devices and networks when you access the Service.

13. Security incidents and breach notification

If we discover a security incident that requires notice under applicable law, we will notify affected users, regulators, partners, and others as required, within the timeframes the law sets. We provide public, substitute, or media notice only where the law requires.

14. Your rights and region-specific disclosures

Depending on where you live, you have some or all of these rights: to access your data, correct it, delete it, restrict or object to processing, withdraw consent, receive a portable copy, appeal a denied request where the law provides, and lodge a complaint with your data-protection authority. The easiest way to exercise most of these is the in-app Privacy Dashboard; you can also contact us using Section 1.

We may need to verify your identity before acting on a request, and you may use an authorized agent where the law allows. We respond within the timeframes required by law and will not discriminate against you for exercising your rights.

14.1 India — Digital Personal Data Protection Act, 2023

14.2 Markets pending launch

Other markets — including those requiring in-country data residency — are not yet live. When we launch there, market-specific terms and local hosting will apply, and this policy will be updated accordingly.

15. Children’s privacy

MERAGO One is intended for adults. Where the Service is made available to minors, we require verifiable parental or guardian consent in line with local law (for example, under-18 in India). We do not knowingly process a child’s data without the required consent, and we do not direct advertising at children or profile them for marketing. If you believe a child has provided data without proper consent, contact us and we will take appropriate steps.

16. Cookies and the website

Our websites use cookies and similar technologies that are strictly necessary to operate the site, and — only with your consent where required — analytics or preference cookies.

17. Changes to this policy

We may update this policy to reflect changes in the Service, technology, or law. If a change is material, we will provide prominent notice (for example, in the app) and, where required, obtain your consent. The “Last updated” date at the top shows the latest version.

18. Contact us

Questions, requests, or complaints about privacy:

Depending on where you live, you may also contact your data-protection authority or another regulator about our privacy practices.