Applies to: the MERAGO One mobile app, the “Ask Belinda” companion, and related MERAGO One websites and services (the “Service”).
A quick summary
We built MERAGO One to help you understand and organize your health — not to diagnose you. Here’s the short version; the full policy follows.
- What we handle: the health information you choose to add (records, notes, reminders, your profile), your messages to Ask Belinda, your account details, and technical/usage data.
- Why: to run the features you use, to let Ask Belinda explain your information in plain language, to keep your data secure, and to operate, improve, and develop the Service.
- Ask Belinda is informational. It helps you read and organize your own information and learn general health facts. It does not provide a diagnosis, and Merago.One is not a medical device or a replacement for a clinician.
- Your health data is sensitive, and we treat it that way. Where the law requires it, we rely on your explicit consent, which you can withdraw.
- We do not sell your health data, and we do not use it for targeted advertising.
- We do not let third-party AI providers use your identifiable health data to train their own general-purpose models without your consent.
- We may use de-identified and aggregated data to operate, improve, and develop MERAGO One and Ask Belinda.
- You’re in control. The in-app Privacy Dashboard lets you view, correct, export, and delete your data, and manage sharing and consents.
- Sharing only happens when you ask for it — for example through Secure Sharing, Trust Circle, or connecting to a provider.
1. Who we are
The Service is provided by Merago Healthcare Pvt. Ltd., Bengaluru, India, a Bengaluru, India based company registered with the Registrar of Companies (“Merago”, “we”, “us”, “our”). For the purposes of applicable data-protection laws, Merago is the controller of the personal data described in this policy, except where a regional group entity is named as controller for a specific market in Section 14.
Read this together with our Terms of Service, any telehealth or clinical consent presented to you at the time, any privacy notice a clinical partner provides, and any separate consumer-health-data notice we make available. Where a more specific notice conflicts with this policy for the data it covers, that notice controls for that data.
How to reach us about privacy:
- Email: privacy@merago.one
- Data Protection Officer: dpo@merago.one (where appointed — see Section 14)
2. Scope and important notices
Availability varies by country. MERAGO One is rolled out market by market. Some features, and in some cases the app itself, may not be available in your country yet, and the way your data is handled follows the rules of the market you use the Service in. Where a market requires data to be stored locally, we host it accordingly (see Section 10).
Not a medical device; not medical advice. MERAGO One and Ask Belinda provide health information for educational and wellness purposes only. They do not diagnose, treat, or prescribe, and they are not a substitute for professional medical advice, examination, or treatment. Always consult a qualified clinician about your health. In an emergency, contact your local emergency services.
3. Clinical services and providers
MERAGO One is not, by itself, a doctor, telehealth provider, pharmacy, or health plan.
Where the app lets you connect to care — for example through My Doctor, Find Care Nearby, or a consultation — those clinical services are provided by MeragoHealth entities / independent licensed clinicians / partners identified to you before the service. MERAGO One provides the technology, coordination, and support that help you reach them.
The treating clinician or partner is responsible for clinical decisions, including diagnosis, treatment, prescribing, follow-up, and medical-record obligations. MERAGO One does not control or direct their medical judgment.
Where a clinician or partner provides its own privacy notice for the records it holds, that notice governs those records; if it conflicts with this policy for that information, that notice controls.
4. The information we collect
4.1 Information you provide
- Account and profile: name, email, phone number, password, country/language, and optional details such as date of birth, sex, height/weight, and preferences.
- Health information you add (sensitive data — see Section 5):
- My Health Profile: conditions, allergies, medications, vitals.
- My Medical Records: documents, lab reports, images, and files you upload.
- Belinda Notes: symptoms, questions, and notes you record.
- Medicine Reminders: medicines and schedules you set.
- Emergency Info: critical details you choose to make available in an emergency.
- Messages to Ask Belinda: the questions you ask and the content you share in the chat.
- Contacts you choose to add for Trust Circle (family or carers) or Secure Sharing (a clinician or recipient), including their name and contact details. Please only add others’ details where you’re entitled to.
- Payment information: MERAGO One is free to use. If we introduce optional paid features, payment is handled by our payment processors and card details will not be stored by us.
4.2 Information we collect automatically
- Device and technical data: device model, OS, app version, language, time zone, identifiers, and crash/diagnostic logs.
- Usage data: features used, actions taken, and interaction events, used to operate and improve the Service.
- Approximate location: to power any of our location based services, only with the permission you grant through your device. You can turn this off in device settings.
- Security and bot-mitigation signals: on sign-up, log-in, and forms we may use bot-detection tools that receive your IP address, request headers, and browser/device characteristics to tell human visitors from bots. These tools do not receive your account content or health information.
4.3 Information from third parties
- Care providers, labs, or partners you connect to (e.g. via My Doctor / My GP or Find Care), where you initiate the connection.
- User-authorized sources, such as medical records, wearables, or lab data you choose to link.
We do not collect more than we need for the purposes in Section 6.
5. Health and other sensitive data
Most of what MERAGO One handles is health data, which data-protection laws treat as a special/sensitive category requiring extra protection. This can include the information you add, health-related inferences (such as trends across your own results), and details about the care you look for.
Where the law requires a specific condition to process this data, we rely on your explicit consent, which you give when you add health information or use a feature that requires it. In some situations we may also rely on other legal grounds recognized by law — for example, to protect your or another person’s vital interests in an emergency (Emergency Info), or where you have manifestly made information public.
You can withdraw consent at any time through the Privacy Dashboard or by contacting us. Withdrawing consent doesn’t affect processing already carried out, and some features won’t work without the data they depend on.
6. How we use your information, and our legal bases
We use your information for the purposes below. Where the EU/UK GDPR or a similar law applies, the legal basis is shown in the third column.
| Purpose | What this involves | Legal basis (GDPR-style) |
|---|---|---|
| Provide the Service | Create your account; run the features; sync your data across devices | Performance of a contract |
| Handle health data in features | Store and display your records, profile, notes, reminders, emergency info | Explicit consent (Art. 9) |
| Ask Belinda | Process your questions and information to explain and organize it | Explicit consent; contract |
| Improve MERAGO One & Ask Belinda | Evaluate quality/safety; develop features; improve our systems (see Section 7) | Consent (health data); legitimate interests (other) |
| Sharing you initiate | Secure Sharing, Trust Circle, connecting to a provider | Consent / contract |
| Emergency Info | Make critical details available to help you in an emergency | Vital interests; consent |
| Location features | Find Care Nearby | Consent (device permission) |
| Security & fraud prevention | Protect accounts and the Service; bot-mitigation | Legitimate interests; legal obligation |
| Communicate with you | Service messages and support; opt-in updates | Contract; consent (marketing) |
| Comply with law | Meet legal and regulatory obligations | Legal obligation |
We do not use your health data for advertising, and we do not sell it.
7. Ask Belinda, AI processing, and product improvement
What Ask Belinda does. Ask Belinda uses automated language technology to help you understand and organize your own information and to answer general health questions in plain language. It can show you your own results and trends and explain what a marker generally measures. Any “out of range” flags it shows come from your lab’s own report, attributed to the lab — Ask Belinda does not create its own diagnosis or clinical verdict.
What it doesn’t do. Ask Belinda does not diagnose, does not make decisions that produce legal or similarly significant effects about you, and does not replace a clinician. When something needs professional judgment, it points you toward a qualified clinician.
7.1 Using data to improve MERAGO One and Ask Belinda
We use information to operate, monitor, evaluate, improve, and develop the Service and its AI features — for example to measure response quality and safety, reduce errors, test prompts and guardrails, and build new features. Where this involves your health data, we do so on the basis of your consent or as otherwise permitted by law.
7.2 De-identified, aggregated, and synthetic data
We may de-identify, aggregate, pseudonymize, derive, or synthesize data from information collected through the Service, and use it for analytics, research, development, safety evaluation, and improving and training our own systems. Where health data is de-identified, we do so in a manner permitted by applicable law. Data that no longer identifies you may be retained indefinitely.
7.3 Third-party AI providers and subprocessors
We may use vetted technology providers — including AI, cloud, analytics, and security providers — to process information as our processors under contract. They may process your data only to provide services to us. We do not allow third-party AI providers to use your identifiable health data to train their own general-purpose models without your consent. This does not limit our own use of de-identified or aggregated data to improve MERAGO One as described above.
7.4 Human review
Authorized Merago personnel, contractors, or reviewers may access limited information where needed to provide support, evaluate quality and safety, debug systems, investigate abuse, or comply with law. We limit access based on role and business need. You can use most of MERAGO One without Ask Belinda if you prefer.
8. When we share information
We share personal data only as described here:
- At your direction: through Secure Sharing (to a clinician or recipient you choose), Trust Circle (family/carers you invite), or when you connect to a provider via My Doctor / My GP.
- Care directory / telemedicine partners: where you use Find Care Nearby or choose to consult a provider, subject to that partner’s terms and privacy practices.
- Legal, safety, and rights protection: where required or permitted by law or to protect the rights, safety, and security of you, others, or Merago.
Government and law-enforcement requests. We do not voluntarily disclose your health data to government or law-enforcement agencies except as required or permitted by law.
We do not sell your personal data, and we do not share health data with advertisers or data brokers.
9. Fitcoins
Fitcoins are non-cash engagement points that recognize healthy habits and promote good health. They have no monetary value, cannot be exchanged for cash, and are not a payment instrument, e-money, or financial product. We process only the activity needed to award and display them and use them as marketing and sales discounts for the services we provide.
10. International data transfers
We operate across multiple regions, so your data may be processed in a country other than your own. When we transfer personal data across borders, we use a lawful transfer mechanism, such as:
- Adequacy decisions, where the destination is recognized as providing adequate protection;
- Standard Contractual Clauses (EU) / the International Data Transfer Agreement or Addendum (UK), with supplementary safeguards where needed;
- the EU–US / UK / Swiss Data Privacy Framework, where and to the extent we are certified; and
- your explicit consent, where permitted.
Local hosting. In markets that require health or personal data to remain in-country (e.g., India), we host and process that data locally and restrict transfers accordingly. You can ask us which safeguards apply to your data using the contacts in Section 1.
11. How long we keep your information
We keep personal data for as long as your account is active and as needed to provide the Service, then for as long as necessary to meet legal, regulatory, security, or dispute-resolution requirements. When data is no longer needed, we delete it or irreversibly de-identify it. You can delete your data or account at any time through the functionality provided in the Services; some records may be retained where the law requires.
| Data category | General retention approach |
|---|---|
| Account & profile | Kept while your account is active and for a reasonable period after closure, unless the law requires longer. |
| Health content you add | Kept to provide continuity, personalization, safety, and support, then as needed for legal, security, and dispute purposes. |
| Clinical / telehealth records | Held by the treating clinician or partner (and by us where applicable) for the period medical-record and other laws require. |
| Payment & tax records | Kept as required for accounting, tax, and audit obligations, where any paid features apply. |
| Security, diagnostic & usage logs | Kept for a limited period for security, debugging, analytics, and reliability, unless needed longer. |
| De-identified & aggregated data | May be kept indefinitely and used for analytics, research, development, and improving our systems, as it no longer identifies you. |
12. How we protect your information
We use technical and organizational measures appropriate to the sensitivity of health data, including encryption in transit and at rest, access controls and least-privilege access, authentication and bot-mitigation on pre-login surfaces, network protections, logging and monitoring, vendor due diligence, and staff confidentiality obligations.
No system is perfectly secure. You are responsible for keeping your login credentials confidential and for using secure devices and networks when you access the Service.
13. Security incidents and breach notification
If we discover a security incident that requires notice under applicable law, we will notify affected users, regulators, partners, and others as required, within the timeframes the law sets. We provide public, substitute, or media notice only where the law requires.
14. Your rights and region-specific disclosures
Depending on where you live, you have some or all of these rights: to access your data, correct it, delete it, restrict or object to processing, withdraw consent, receive a portable copy, appeal a denied request where the law provides, and lodge a complaint with your data-protection authority. The easiest way to exercise most of these is the in-app Privacy Dashboard; you can also contact us using Section 1.
We may need to verify your identity before acting on a request, and you may use an authorized agent where the law allows. We respond within the timeframes required by law and will not discriminate against you for exercising your rights.
14.1 India — Digital Personal Data Protection Act, 2023
- Consent: we process your personal data based on your consent for specified purposes, with notice in clear language.
- Grievance Officer: The Grievance Officer, Merago One. Email: grievance@merago.one
- Children: we process data of anyone under 18 only with verifiable parental/guardian consent, and we do not undertake tracking, behavioral monitoring, or targeted advertising directed at children.
14.2 Markets pending launch
Other markets — including those requiring in-country data residency — are not yet live. When we launch there, market-specific terms and local hosting will apply, and this policy will be updated accordingly.
15. Children’s privacy
MERAGO One is intended for adults. Where the Service is made available to minors, we require verifiable parental or guardian consent in line with local law (for example, under-18 in India). We do not knowingly process a child’s data without the required consent, and we do not direct advertising at children or profile them for marketing. If you believe a child has provided data without proper consent, contact us and we will take appropriate steps.
16. Cookies and the website
Our websites use cookies and similar technologies that are strictly necessary to operate the site, and — only with your consent where required — analytics or preference cookies.
17. Changes to this policy
We may update this policy to reflect changes in the Service, technology, or law. If a change is material, we will provide prominent notice (for example, in the app) and, where required, obtain your consent. The “Last updated” date at the top shows the latest version.
18. Contact us
Questions, requests, or complaints about privacy:
- Email: privacy@merago.one
- DPO / Grievance Officer / regional representatives: see Section 14
- Post: Merago Healthcare Pvt. Ltd., Bengaluru, India, 3rd Floor, A-Wing, #303, Mittal Tower, M G Road, Bengaluru 560001 Karnataka, India.
Depending on where you live, you may also contact your data-protection authority or another regulator about our privacy practices.