Niramay Privacy Policy
Last updated: July 27, 2026
Niramay helps patients find participating hospitals, doctors, and clinics, view appointment availability, and request visit bookings online.
Google user data
Google sign-in is used to identify the patient account by email and keep booking access tied to the signed-in user. When a patient allows Google Drive access, booking receipts may be saved to the patient's private Google Drive app data folder so booking history can be restored across devices.
For provider and doctor accounts, Niramay uses Google Calendar access only to support appointment scheduling. With the doctor's consent, Niramay may read free/busy availability, list appointment-related calendar events for the selected schedule window, and create, update, or delete appointment or availability-block events in the doctor's Google Calendar.
The Google user data we may process includes the signed-in Google account email address, Google account identifier, Google Drive app data files created by Niramay for booking receipts, Google Calendar availability information, Google Calendar event identifiers, and appointment event details needed to create, update, cancel, or display bookings.
Patient and booking data
Patient name, phone, and local receipts are stored in the browser using encrypted local storage. Appointment details needed for a booking may be shared with the selected participating hospital, clinic, or doctor.
Sharing and disclosure of Google user data
We do not sell Google user data. We do not use Google user data for advertising, generalized analytics, or training AI or machine learning models. We disclose Google user data only as needed to provide the scheduling service, comply with law, protect users, or maintain the service.
Appointment details may be shared with the selected participating hospital, clinic, doctor, or helper so they can manage the requested booking. Calendar invitations may disclose the patient's signed-in email address to the selected doctor and other event attendees selected by the user or provider. Google user data is processed by Google services such as Google Sign-In, Google Drive, Google Calendar, Firebase, Google Cloud Functions, Firestore, and Firebase Storage to operate the app.
Data protection
Niramay uses Firebase Authentication, server-side Cloud Functions, Firestore Security Rules, Firebase Storage Rules, role-based access checks, rate limits, and HTTPS encryption in transit to protect account, booking, and scheduling data. Data stored in Google Cloud services is protected by Google Cloud's infrastructure security controls, including encryption at rest.
Patient profile details and booking receipts stored in the browser are encrypted locally before storage. Google Calendar refresh tokens for provider accounts are stored server-side and are used only by Cloud Functions for authorized scheduling operations. Access is limited to the minimum application components and authorized users needed to provide the service.
Retention and deletion
Google user data is retained only for as long as needed to provide booking history, appointment management, security, legal compliance, and operational support. Patient booking receipts saved to Google Drive app data remain in the user's own Google Drive app data folder until the user deletes them, disconnects the app, deletes the app's Drive app data, or requests deletion from Niramay where supported.
Doctor Google Calendar refresh tokens and Calendar connection metadata are retained until the doctor or provider disconnects Google Calendar, revokes Niramay access from the Google Account permissions page, removes the doctor account from the practice, or requests deletion. Appointment records and Calendar event identifiers are retained while needed for active bookings, booking history, cancellation handling, dispute resolution, security, legal compliance, and audit purposes. When a booking is cancelled through Niramay, Niramay attempts to cancel or remove the corresponding Google Calendar event where it has permission to do so.
Users can revoke Google access at any time from their Google Account permissions page. Patients may delete local browser data and Drive app data from their own account. Providers may remove or deactivate doctor and helper accounts in the provider app. Deletion requests can also be sent through the app support channel or to the operator of the hospital or clinic using Niramay.
Patients can permanently delete their account from Profile > Delete Account in the Android app, or use the public account deletion page. The flow removes the patient sign-in identity, notification record, encryption key, private Niramay Drive app-data files when permission is available, and browser-local Niramay data. Future appointments are cancelled. Historical clinic appointment records may be retained without the patient's Niramay account identifier where required for patient care, accounting, fraud prevention, legal compliance, dispute resolution, or audit.
Providers can start deletion from Settings > Delete Account in the provider app. Non-owner provider accounts are deleted immediately. Clinic owners must transfer ownership or close the clinic before their identity can be removed so staff and patient records are not orphaned.
Service limits
This service is for appointment discovery and booking requests only. It does not provide medical advice, diagnosis, treatment, emergency support, or guaranteed appointment acceptance.