Privacy Policy
What we collect when you search, what we strip out before any AI sees it, how long we keep it, and what you can ask us to do with it.
Last updated
The short version
You can search without an account and without telling us who you are. We automatically strip emails, phone numbers, Aadhaar, PAN and card numbers out of your search text before storing it or sending it to an AI service — though that cannot catch personal details written in plain language, so please describe what you need rather than who you are.
We erase search text after 90 days, we never sell data, we run no advertising trackers, and we do not want your medical records.
Who we are
CureWeave is a healthcare provider discovery service. You describe what you are looking for in your own words, and we match you with practitioners who fit — physiotherapists, psychologists, nutritionists, Ayurveda practitioners and similar.
CureWeave is the data fiduciary for the personal data described in this policy. This policy covers the CureWeave website and the search service on it. It does not cover the practices of the providers you find through us — once you contact a provider directly, their own privacy practices apply to that conversation.
What this service is not
We are a directory, not a clinic.
CureWeave does not diagnose conditions, recommend treatments, or provide medical advice of any kind. Nothing here is a substitute for a consultation with a qualified practitioner.
If you are experiencing a medical emergency, stop and call your local emergency number or go to the nearest hospital. Do not use this site to seek urgent help.
This matters for your privacy as much as for your safety. Because we never provide clinical care, we have no reason to hold a medical record — and we deliberately do not keep one. We do not ask for, and you should not send us, diagnoses, test results, prescriptions, or any other clinical record.
What we collect
We collect as little as the service can work with. There are four kinds of data, and most visitors only ever generate the first two.
- Your search text
- The sentence you type into the search box, after automatic redaction (see section 4). We keep it so we can tell whether search is actually helping people — how often it returns nothing useful, which needs go unmet.
- A session identifier
- A random ID for your browsing session, used to keep a multi-turn conversation coherent and to enforce rate limits that stop automated abuse. It is not linked to your identity unless you are signed in.
- Account details
- Only if you create an account: your email address, your name if you give one, and — for practitioners — the profile you choose to publish. We use Google Sign-In as an option; if you use it, we receive your email address and name from Google, nothing more.
- Technical logs
- Standard server and error logs — IP address, browser type, timestamps, and error traces — kept to keep the service running and to investigate faults.
We do not collect health records, insurance details, government identity numbers, or payment card details. We have no advertising trackers, and we do not sell or rent personal data to anyone, for any purpose.
How AI is used, and what we strip before it sees anything
To understand a sentence like “an online psychologist in Bangalore who speaks Kannada, under ₹2,000”, we send your search text to a third-party AI service (see section 6). The AI is used only to interpret language into structured filters — city, budget, language, type of care. It never chooses or ranks the providers you see; that is done by our own rules, which is why we can always explain why a result appeared.
Before your text leaves our servers, it passes through an automatic redaction step that finds and removes common personal identifiers, replacing them with a placeholder:
- Email addresses
- Indian mobile numbers, including formats like +91 98765 43210 and 98765-43210
- Aadhaar numbers, including the printed 1234 5678 9012 grouping
- PAN numbers, upper or lower case
- Payment card numbers, 13 to 19 digits, spaced or hyphenated
The redacted version is what we send to the AI service, and the redacted version is what we store. The original text is never written to our database.
What redaction cannot catch
This redaction works by recognising the shape of an identifier. It is reliable for the formats listed above, and it cannot catch personal details expressed in ordinary language — “I live near Indiranagar metro”, “my daughter’s therapist”, or a description specific enough to identify you. Text like that is sent to the AI service as written.
We are telling you this plainly rather than burying it, because it changes what you should type. Describe what you need, not who you are. You never have to identify yourself to search, and the service works just as well when you do not.
Why we use it, and on what basis
Each kind of data has one purpose, and we do not repurpose it later:
- To answer your search
- Your search text and session ID, for as long as the conversation lasts. Without this there is no service.
- To improve search quality
- Redacted search text in aggregate, to find what people ask for and cannot find.
- To keep the service up
- Session IDs for rate limiting, and technical logs for diagnosing faults and abuse.
- To run your account
- Your email and profile, if you created an account — including verification and password-reset email.
Where the law requires your consent, we rely on the consent you give when you create an account and accept this policy. Searching without an account relies on the legitimate need to provide the service you have asked for. You can withdraw consent at any time by deleting your account, as described in section 8.
Where your data is stored
Our database and stored files are hosted in Tokyo, Japan (ap-northeast-1). Our other providers — the AI service, error monitoring, email delivery and hosting — operate globally, so processing your data involves transfers outside India.
We are stating the actual location rather than an intention. If you are in India and would prefer your data to be held in India, that is a change we are able to make, and telling us at cureweave@gmail.com is the fastest way to weight that decision.
Redaction (section 4) is what limits the exposure of any cross-border transfer: the text that crosses a border has had recognisable identifiers removed from it first.
How long we keep it
- Search text
- The text of a search, and our structured reading of it, is automatically erased 90 days after the search. The anonymous counts — how many results came back, whether the search failed — are kept indefinitely so we can measure whether search is improving.
- Rate-limit records
- Deleted automatically once they are more than 2 hours old.
- Account data
- Kept while your account is open, and deleted when you delete it.
- Practitioner profiles
- Kept while the listing is active, since the point of a profile is to be found.
- Technical logs
- Short-lived, and retained per our infrastructure providers’ standard log windows.
Both erasure jobs run automatically every day. They are not a promise about what we intend to do by hand.
Your rights
Under the Digital Personal Data Protection Act, 2023, and as a matter of how we think this should work regardless of where you live, you have the right to:
- Know what personal data we hold about you and how it is being processed
- Have inaccurate or incomplete data corrected
- Have your data erased
- Withdraw consent you previously gave
- Nominate someone to exercise these rights if you are unable to
- Raise a grievance and get an answer
If you have an account, you can delete it yourself at any time from your profile page. Deleting your account removes your profile and disconnects your past searches from you, so the remaining records can no longer be traced back to you.
For anything else — a copy of your data, a correction, or a question about this policy — write to cureweave@gmail.com. We answer within 30 days, and usually much sooner.
Children
This service is not directed at children, and we do not knowingly collect personal data from anyone under 18. A parent or guardian is welcome to use it to find care for a child, and if you do, please describe the need without identifying the child. If you believe a child has given us personal data, write to cureweave@gmail.com and we will delete it.
How we protect it
Every layer of the service checks permissions independently, rather than trusting the layer above it. In practice that means database rules restrict each account to its own rows, administrative credentials never reach your browser, all traffic is encrypted in transit, and search text is redacted before it is stored or sent onward.
No system is perfectly secure, and we would rather say so than imply otherwise. If you find a vulnerability, please report it to cureweave@gmail.com — we will not pursue action against anyone who reports a genuine issue in good faith and gives us a reasonable chance to fix it.
Changes to this policy
When we change this policy we update the date at the top. If a change materially affects your rights — new categories of data, a new purpose, a longer retention period — we will tell account holders by email before it takes effect, rather than relying on you to re-read the page.
Contact and grievances
For privacy questions, to exercise any right in section 9, or to raise a grievance: cureweave@gmail.com.
For anything else: cureweave@gmail.com.
If we have not resolved your grievance to your satisfaction, you may escalate it to the Data Protection Board of India.
See also our Terms of Service, or return to search.