Privacy Policy
Last updated: 6 July 2026
This Privacy Policy explains how Nimo (“Nimo”, “we”, “us”, “our”), operated by Asif Asharaf, sole proprietor, trading as “Nimo”, collects, uses, stores, shares, and protects personal data in connection with the gonimo.in software and services (the “Service”). The Service helps independent doctors and clinics manage patients, appointments, clinical notes, and prescriptions.
Our role under the DPDP Act. When a clinic uses Nimo, the clinic is the Data Fiduciaryfor its patients’ personal and health data under India’s Digital Personal Data Protection Act, 2023 (the “DPDP Act”) and decides why and how that data is processed. Nimo acts as a Data Processor, processing patient data only on the clinic’s documented instructions to provide the Service. For the account data of doctors and staff who sign up directly, Nimo is the Data Fiduciary. This policy should be read with our Terms of Service.
1. Data we collect
- Account data (doctors, clinic owners, staff): name, mobile number, role, optional recovery email, and authentication credentials.
- Patient data entered by the clinic: name, age or date of birth, sex, contact details, emergency contact, and clinical information such as visit notes, vitals, allergies, diagnoses, and prescriptions. This is sensitive health data.
- Consultation audio, only when a doctor uses the recording feature, which is transcribed into a draft clinical note (see Section 3).
- Appointment and operational data: bookings, schedules, and (if connected) Google Calendar free/busy and event data.
- Usage, log, and device data needed to operate and secure the Service. We design our logs not to contain patient names, mobile numbers, dates of birth, or clinical content; we reference records by internal identifiers only.
2. How and why we use data
We process data to:
- authenticate users and secure accounts;
- store and display patient records to the clinic’s own authorised staff;
- transcribe and summarise visits and suggest prescriptions (AI features);
- generate prescriptions, documents, and printable records;
- send transactional messages such as login and password-recovery codes;
- provide support, prevent abuse, and keep the Service reliable; and
- comply with applicable law.
We do not sell personal data, we do not use patient or clinical data for advertising, and we do not permit our AI sub-processors to use clinic or patient data to train their models.
3. AI transcription & sub-processors
We use the following sub-processors, each under their own data-protection terms, strictly to deliver the Service:
- Supabase — database, authentication, and file storage (patient records, accounts).
- Groq and Google (Gemini) — AI transcription and summarisation. When a doctor uses the recording feature, the consultation audio and the resulting transcript are sent to these providers to produce a draft note. These services may process data outside India.
- Resend — delivery of transactional emails (e.g. login and recovery codes).
- Vercel — application hosting and performance analytics.
We maintain this list as our sub-processors change and remain responsible for their handling of data processed on our behalf.
4. Google user data (Google Calendar)
A doctor may optionally connect their own Google Calendar to Nimo from Settings › Practice › “Connect Google Calendar”. Connection is done through Google’s standard OAuth consent screen, where the doctor explicitly grants access. If connected, Nimo uses the Google Calendar API (the calendar.events scope) to:
- read the connecting doctor’s busy intervals (free/busy) so the patient booking page does not offer time slots that clash with existing calendar events; and
- create, update, and cancel calendar eventson that doctor’s own calendar to mirror appointments booked, rescheduled, or cancelled in Nimo.
We access only the calendar of the doctor who connected their account, and only for the scheduling purposes above. Google OAuth tokens are encrypted at rest and are never shared with other clinics or third parties. We do notsell Google user data, use it for advertising, or use it to train AI or machine-learning models. A doctor can disconnect Google Calendar at any time from the same settings page, which revokes Nimo’s access and deletes the stored tokens.
Limited Use.Nimo’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
5. Data location & cross-border transfers
Data is stored and processed with the providers above. Some processing — notably AI transcription — occurs outside India. We transfer only the minimum data needed for the feature in use, and we will not transfer personal data to any country or territory restricted for such transfers by the Central Government under the DPDP Act.
6. Retention & deletion
We retain personal data for as long as the relevant account is active and as needed to provide the Service. Consultation audio is used to produce the transcript and is not retained by us as a permanent recording. A clinic (as Data Fiduciary) may request export or deletion of its data by contacting us; we will action verified requests within a reasonable period, subject to (a) the clinic’s own medical record-keeping obligations, and (b) any legal requirement for us to retain certain records. On account closure we delete or return data within a reasonable period.
7. Security
Each clinic’s data is isolated from every other clinic at the database layer (row-level security), and access is restricted to that clinic’s own authorised staff by role. We use encrypted connections, least-privilege access, and reasonable security safeguards. No method of transmission or storage is perfectly secure. In the event of a personal-data breach, we will notify the affected clinic and the Data Protection Board of India as required by the DPDP Act, and cooperate in the clinic’s notification to affected individuals.
8. Consent & legal basis
Clinics are responsible for having a lawful basis (including obtaining patient consent where required) before entering patient data into Nimo, and for obtaining patient consent to recording where the recording feature is used. By using the Service, clinic users confirm they have such basis. Doctors and staff who create accounts consent to our processing of their account data as described here.
9. Your rights
As provided under the DPDP Act, data principals may:
- access and obtain a summary of their personal data we process;
- request correction, completion, updating, or erasure of their data;
- nominate another individual to exercise rights in case of death or incapacity; and
- raise a grievance (see Section 12).
Because the clinic controls patient records, patients should contact their clinic to exercise rights over their clinical data; we will assist the clinic as its processor. Doctors and staff may contact us directly about their own account data.
10. Children’s data
The Service is intended for use by healthcare professionals, not by children. Where a clinic records data about a minor patient, the clinic is responsible for obtaining verifiable consent from a parent or lawful guardian as required by the DPDP Act.
11. Cookies
We use only essential cookies and similar technologies necessary to keep you signed in and to operate the Service securely. We do not use advertising or cross-site tracking cookies.
12. Contact & grievance redressal
For any privacy question, request, or grievance, contact our Grievance Officer:
Asif Asharaf — Asif Asharaf, sole proprietor, trading as “Nimo”
[Add registered business address], India
asifxceed@gmail.com
We aim to acknowledge grievances promptly and resolve them within the timelines required by law. If you are not satisfied, you may escalate to the Data Protection Board of India.
13. Changes to this policy
We may update this policy as the Service or the law evolves. We will revise the “last updated” date above and, for material changes, take reasonable steps to notify account owners. Continued use after an update means you accept the revised policy.