CureWeave

Privacy Policy

What we collect when you search, what we strip out before any AI sees it, how long we keep it, and what you can ask us to do with it.

Last updated

The short version

You can search without an account and without telling us who you are. We automatically strip emails, phone numbers, Aadhaar, PAN and card numbers out of your search text before storing it or sending it to an AI service — though that cannot catch personal details written in plain language, so please describe what you need rather than who you are.

We erase search text after 90 days, we never sell data, we run no advertising trackers, and we do not want your medical records.

Who we are

CureWeave is a healthcare provider discovery service. You describe what you are looking for in your own words, and we match you with practitioners who fit — physiotherapists, psychologists, nutritionists, Ayurveda practitioners and similar.

CureWeave is the data fiduciary for the personal data described in this policy. This policy covers the CureWeave website and the search service on it. It does not cover the practices of the providers you find through us — once you contact a provider directly, their own privacy practices apply to that conversation.

What this service is not

We are a directory, not a clinic.

CureWeave does not diagnose conditions, recommend treatments, or provide medical advice of any kind. Nothing here is a substitute for a consultation with a qualified practitioner.

If you are experiencing a medical emergency, stop and call your local emergency number or go to the nearest hospital. Do not use this site to seek urgent help.

This matters for your privacy as much as for your safety. Because we never provide clinical care, we have no reason to hold a medical record — and we deliberately do not keep one. We do not ask for, and you should not send us, diagnoses, test results, prescriptions, or any other clinical record.

What we collect

We collect as little as the service can work with. There are four kinds of data, and most visitors only ever generate the first two.

Your search text
The sentence you type into the search box, after automatic redaction (see section 4). We keep it so we can tell whether search is actually helping people — how often it returns nothing useful, which needs go unmet.
A session identifier
A random ID for your browsing session, used to keep a multi-turn conversation coherent and to enforce rate limits that stop automated abuse. It is not linked to your identity unless you are signed in.
Account details
Only if you create an account: your email address, your name if you give one, and — for practitioners — the profile you choose to publish. We use Google Sign-In as an option; if you use it, we receive your email address and name from Google, nothing more.
Technical logs
Standard server and error logs — IP address, browser type, timestamps, and error traces — kept to keep the service running and to investigate faults.

We do not collect health records, insurance details, government identity numbers, or payment card details. We have no advertising trackers, and we do not sell or rent personal data to anyone, for any purpose.

How AI is used, and what we strip before it sees anything

To understand a sentence like “an online psychologist in Bangalore who speaks Kannada, under ₹2,000”, we send your search text to a third-party AI service (see section 6). The AI is used only to interpret language into structured filters — city, budget, language, type of care. It never chooses or ranks the providers you see; that is done by our own rules, which is why we can always explain why a result appeared.

Before your text leaves our servers, it passes through an automatic redaction step that finds and removes common personal identifiers, replacing them with a placeholder:

  • Email addresses
  • Indian mobile numbers, including formats like +91 98765 43210 and 98765-43210
  • Aadhaar numbers, including the printed 1234 5678 9012 grouping
  • PAN numbers, upper or lower case
  • Payment card numbers, 13 to 19 digits, spaced or hyphenated

The redacted version is what we send to the AI service, and the redacted version is what we store. The original text is never written to our database.

What redaction cannot catch

This redaction works by recognising the shape of an identifier. It is reliable for the formats listed above, and it cannot catch personal details expressed in ordinary language — “I live near Indiranagar metro”, “my daughter’s therapist”, or a description specific enough to identify you. Text like that is sent to the AI service as written.

We are telling you this plainly rather than burying it, because it changes what you should type. Describe what you need, not who you are. You never have to identify yourself to search, and the service works just as well when you do not.

Why we use it, and on what basis

Each kind of data has one purpose, and we do not repurpose it later:

To answer your search
Your search text and session ID, for as long as the conversation lasts. Without this there is no service.
To improve search quality
Redacted search text in aggregate, to find what people ask for and cannot find.
To keep the service up
Session IDs for rate limiting, and technical logs for diagnosing faults and abuse.
To run your account
Your email and profile, if you created an account — including verification and password-reset email.

Where the law requires your consent, we rely on the consent you give when you create an account and accept this policy. Searching without an account relies on the legitimate need to provide the service you have asked for. You can withdraw consent at any time by deleting your account, as described in section 8.

Who else processes your data

We run on third-party infrastructure rather than our own hardware. Each of these processes data strictly on our instructions, and none of them is permitted to use it for their own purposes:

Supabase
Database, accounts and file storage. This is where your data lives.
OpenRouter
The AI service that interprets your search text. Receives redacted text only.
Langfuse
Records AI requests so we can monitor quality and cost. Receives the same redacted text.
Vercel
Website hosting and content delivery.
Resend
Sends account email — verification, password resets, and notices to practitioners.

Beyond these, we disclose personal data only when the law compels it, and we will tell you when we are permitted to.

Where your data is stored

Our database and stored files are hosted in Tokyo, Japan (ap-northeast-1). Our other providers — the AI service, error monitoring, email delivery and hosting — operate globally, so processing your data involves transfers outside India.

We are stating the actual location rather than an intention. If you are in India and would prefer your data to be held in India, that is a change we are able to make, and telling us at cureweave@gmail.com is the fastest way to weight that decision.

Redaction (section 4) is what limits the exposure of any cross-border transfer: the text that crosses a border has had recognisable identifiers removed from it first.

How long we keep it

Search text
The text of a search, and our structured reading of it, is automatically erased 90 days after the search. The anonymous counts — how many results came back, whether the search failed — are kept indefinitely so we can measure whether search is improving.
Rate-limit records
Deleted automatically once they are more than 2 hours old.
Account data
Kept while your account is open, and deleted when you delete it.
Practitioner profiles
Kept while the listing is active, since the point of a profile is to be found.
Technical logs
Short-lived, and retained per our infrastructure providers’ standard log windows.

Both erasure jobs run automatically every day. They are not a promise about what we intend to do by hand.

Your rights

Under the Digital Personal Data Protection Act, 2023, and as a matter of how we think this should work regardless of where you live, you have the right to:

  • Know what personal data we hold about you and how it is being processed
  • Have inaccurate or incomplete data corrected
  • Have your data erased
  • Withdraw consent you previously gave
  • Nominate someone to exercise these rights if you are unable to
  • Raise a grievance and get an answer

If you have an account, you can delete it yourself at any time from your profile page. Deleting your account removes your profile and disconnects your past searches from you, so the remaining records can no longer be traced back to you.

For anything else — a copy of your data, a correction, or a question about this policy — write to cureweave@gmail.com. We answer within 30 days, and usually much sooner.

Cookies

We use the minimum a login can be built on. There is no advertising cookie on this site and no cross-site tracking of any kind.

Sign-in cookie
Set only when you sign in, so you stay signed in. Strictly necessary — the site cannot offer accounts without it.
Session identifier
Keeps a multi-turn search coherent and enforces rate limits. Strictly necessary.

We do not currently load any analytics or advertising script. If that changes, we will ask for your consent before loading it, and update this section first.

Children

This service is not directed at children, and we do not knowingly collect personal data from anyone under 18. A parent or guardian is welcome to use it to find care for a child, and if you do, please describe the need without identifying the child. If you believe a child has given us personal data, write to cureweave@gmail.com and we will delete it.

How we protect it

Every layer of the service checks permissions independently, rather than trusting the layer above it. In practice that means database rules restrict each account to its own rows, administrative credentials never reach your browser, all traffic is encrypted in transit, and search text is redacted before it is stored or sent onward.

No system is perfectly secure, and we would rather say so than imply otherwise. If you find a vulnerability, please report it to cureweave@gmail.com — we will not pursue action against anyone who reports a genuine issue in good faith and gives us a reasonable chance to fix it.

Changes to this policy

When we change this policy we update the date at the top. If a change materially affects your rights — new categories of data, a new purpose, a longer retention period — we will tell account holders by email before it takes effect, rather than relying on you to re-read the page.

Contact and grievances

For privacy questions, to exercise any right in section 9, or to raise a grievance: cureweave@gmail.com.

For anything else: cureweave@gmail.com.

If we have not resolved your grievance to your satisfaction, you may escalate it to the Data Protection Board of India.


See also our Terms of Service, or return to search.