Legal

Privacy Policy

Effective: 1 February 2026

This Privacy Policy explains how RIF Master, operated by Dr. Mona Shroff, MD, collects, uses and protects information when you use the Service.

1. Information we collect

  • Account data: your name, email address and hashed password.
  • Payment data: UPI transaction reference, Razorpay order/payment IDs, and the paid amount. Your full card, UPI PIN or bank credentials are never seen or stored by us — they are handled exclusively by Razorpay.
  • Clinical case data: patient labels (which you are asked to keep as initials / codes), clinical flags you tick in the workflow, generated protocol content, outcome and optional notes.
  • Technical data: session tokens, IP address, browser user-agent, and audit timestamps.

2. What we do NOT ask you to store

The Service is designed to work with de-identified case codes (e.g. initials, hospital ID) and does not require you to enter patient names, contact details, or Aadhaar / identifier numbers. Please do not upload directly identifying patient information into the Service.

3. How we use it

  • To operate the Service — authenticate you, save your cases, generate PDFs and cohort insights.
  • To process your one-time lifetime access payment through Razorpay.
  • To send transactional email (activation confirmation, monthly digest to the Owner) via Resend when configured.
  • To improve the Service — aggregate factor frequency and success-rate analytics are computed within your own workspace only, and are never shared across clinicians without explicit prior consent.

4. Data storage & security

Data is stored in MongoDB under strict access controls. Passwords are hashed with bcrypt; session tokens are stored as httpOnly, secure cookies (with an authenticated-header fallback for browsers that block third-party cookies). Transport to and from the Service is over HTTPS.

5. Sharing

We share information only with the sub-processors necessary to operate the Service:

  • Razorpay — payment processing
  • Resend — transactional email delivery (when configured)
  • MongoDB Atlas — encrypted-at-rest database hosting
  • Hosting infrastructure (Emergent, AWS, Cloudflare)

We do not sell, rent, or trade personal information. We may disclose information if compelled by valid legal process (court order, regulator).

6. Your rights

You may at any time:

  • Access and export your saved cases (available in the Service; a CSV is downloadable by the Owner too).
  • Delete individual cases yourself, or request full account deletion by emailing us.
  • Correct your account name/email through the Owner.

7. Retention

Case and account data are retained for as long as your account remains active. On account deletion, data is anonymised within 30 days and any residual backups are purged within 90 days.

8. Children

The Service is not directed at children under 18 and no such data is knowingly collected.

9. Contact & grievances

Data-protection queries and access / erasure requests can be sent to drmonashroff@gmail.com. As required by the Information Technology (Reasonable Security Practices) Rules, 2011, our Grievance Officer is Dr. Mona Shroff, reachable at the same email address; we aim to acknowledge grievances within 48 hours and resolve them within 30 days.

10. Changes

Material changes to this policy will be flagged on the login page and via email at least 30 days before they take effect.