Health data, handled as health data.
Clinical records are the most sensitive data a person has. Here is exactly where yours sits, who can reach it, and what we will not do with it.
Where the data lives
Patient records are stored in the treating doctor’s own account on Google Cloud infrastructure, in the asia-south1 region. Data is encrypted in transit (TLS 1.3) and at rest.
Who can reach it
Each doctor’s data is isolated by account. No other doctor can see it. Access is authenticated through Firebase Auth, and account activation is limited to BMDC-registered physicians.
What we will not do
We do not sell patient data. We do not share it with third parties. We do not use identifiable patient records to advertise, and we do not hand them to anyone without a lawful requirement.
Audit trail
Every safety alert that a doctor overrides is written to an audit log with the rule that fired. Clinical accountability needs a record, not a silent dismissal.
Moving toward the EU
We are not GDPR-compliant today, because we do not yet operate in the EU. Any EU deployment will run on EU-region hosting with data residency inside the Union, and a GDPR programme — lawful basis, processor agreements, data subject rights, retention policy and a DPIA for health data — is planned before launch there.
Regulatory position
Carenika documents and warns; the physician decides and signs. That keeps it a clinical documentation and decision-support tool rather than a diagnostic device. We intend to take formal classification advice before any EU clinical launch.
Carenika does not practise medicine.
Carenika provides clinical documentation and decision support. It generates drafts and raises warnings. It does not diagnose, it does not prescribe, and it does not treat. Every note, every prescription and every alert is reviewed by the treating physician, who remains fully responsible for the clinical decision and for the care of the patient.
Carenika