Intake & reference tool for qualified Ayurvedic practitioners · Not a medical device · Not for diagnosis or treatment · Intended use →
MyDosha ← mydosha.org
Security & Trust

How we protect your patients' data

MyDosha handles special-category health data on behalf of Ayurvedic practitioners. We treat that as a responsibility, not a checkbox. This page sets out — in plain language — where your data lives, who can reach it, and what happens if something goes wrong.

Where your data lives

All practitioner and patient records are stored in the European Union, in a managed PostgreSQL database (Supabase, AWS eu-central-1, Frankfurt). MyDosha is operated from the EU; the operating entity is European. We do not sell data, and we do not show advertising.

EU data residency

Primary database and file storage hosted in the European Union.

Encrypted in transit

HTTPS/TLS everywhere; insecure requests are upgraded. No plaintext endpoints.

Encrypted at rest

Database, file storage, and backups encrypted at rest (AES-256) by the platform.

Daily backups

Automated, validated daily backups with periodic restore drills.

Who can reach the data

How the AI assistants handle your data

Our subprocessors

We rely on a small set of established providers. Each processes only what its function requires, under a data-processing agreement. International transfers, where they occur, are covered by Standard Contractual Clauses.

ProviderPurposeData it touches
SupabaseDatabase & file storage (EU)Practitioner & patient records, uploaded documents
VercelApplication hosting / deliveryRequest traffic; no database stored here
ResendTransactional emailRecipient address & message content (login codes, notifications)
AnthropicAI dossier & intake assistanceIntake text submitted for processing — not used to train models
CloudflareBot protection (sign-up)Challenge token only; no patient data
StripeSubscription billingPractitioner billing details — never patient data

Backups & recovery

The full database is backed up automatically every day. Each backup is validated for completeness (table coverage, row-count floors, referential integrity) so a half-failed dump is caught rather than silently kept. We periodically restore a backup into a throwaway environment to confirm it actually works — an untested backup is not a backup.

Your rights & our commitments

Scope matters for safety, too. MyDosha is an intake and reference tool — not a medical device. The AI reorganises what a patient reported and surfaces curated classical references; it does not diagnose, prescribe, or screen an individual record. Keeping the software inside that boundary is itself a safety control. See the intended-use statement.

Reporting a vulnerability

If you believe you have found a security issue, please email security@mydosha.org. We aim to acknowledge reports within 48 hours and welcome responsible disclosure. Our machine-readable policy is published at /.well-known/security.txt.


This page describes our security posture in good faith and may evolve as the product does. It is informational and does not by itself form part of any contract; the binding terms are in your service agreement and DPA.

Last updated: 19 June 2026