This Privacy Policy explains how Pythesis ("Pythesis", "we", "us") collects, uses, stores, shares and protects your personal data when you use the Pythesis web application available at pythesis.in / pythesis.com (the "Service"). We are committed to compliance with India's Digital Personal Data Protection Act, 2023("DPDPA") and other applicable laws.
1. Who is the data fiduciary?
Pythesis is operated by Abhishek Kawdiya, the data fiduciary for the purposes of the DPDPA. Grievance contact: support@pythesis.in.
2. What personal data we collect
2.1 Account data
- From Google Sign-In: your name, email address, and profile photo URL.
- Profile (optional): mobile number (for OTP verification), institution, department, year of postgraduation.
2.2 Project data you provide
- Study title, topic, objectives, methodology, target population.
- Uploaded files: Excel/CSV datasets, protocol PDFs/DOCX, optional university template.
- Edits you make to plans, settings, variables, chart selections, and generated text.
2.3 Generated artefacts
- Generated DOCX/PDF thesis, protocol forms, charts, downloaded reference PDFs, citation list.
2.4 Usage and technical data
- IP address, browser/device type, timestamps of actions (for security and abuse prevention).
- Session cookies created by Supabase Auth (used to keep you signed in).
- Payment metadata (Razorpay order ID, payment ID, signature). We do not store your card or UPI details.
3. Patient data — how we handle clinical Excel uploads
We understand the sensitivity of patient data. Our handling is built around it:
- You are expected to upload data that is already de-identified per your Institutional Ethics Committee's requirements (no names, hospital IDs, contact numbers).
- Even so, our pipeline runs a Python-only de-identification scan that detects and removes residual identifiers before any AI model is called.
- Cleaning, statistical analysis and chart generation are performed by deterministic Python code on your data. The data itself is never sent to a Large Language Model in raw form.
- What is sent to AI models for the literature review and writing steps is your study's configuration (title, design, aggregated results) and abstracts of external published papers — not your row-level data.
4. Why we process your data (purposes & legal basis)
- To provide the Service (DPDPA "specific purpose" consent + legitimate use for service performance): generating your protocol/ROL/thesis, storing your project, providing downloads.
- To bill you (contractual necessity): processing payments via Razorpay, issuing receipts.
- To secure the Service (legitimate use): rate-limiting, fraud and abuse detection, session enforcement.
- To communicate: transactional emails about your account, generation completion, receipts.
- To improve the Service: aggregate, non-identifying usage statistics. We do not use your project content to train AI models.
5. Who we share your data with (data processors)
We share the minimum data necessary with the following third parties, each bound to confidentiality and security obligations:
- Supabase (auth + database + file storage) — Mumbai (ap-south-1) region. Hosts your account, project metadata, and uploaded files inside India.
- Railway (backend compute) — currently Singapore (ap-southeast-1). Processes your requests in transit. We plan to migrate to an India region as we scale.
- Vercel (frontend hosting + CDN) — global edge network.
- Amazon Web Services / Bedrock (AI inference) — when AI assistance is invoked, study context and external paper abstracts are sent to AWS Bedrock-hosted models. Patient row-level data is never sent.
- Razorpay (payments) — for processing purchases and refunds, subject to their privacy policy.
- Academic data sources — PubMed, Europe PMC, OpenAlex, Semantic Scholar, Unpaywall: we query these with your study topic to fetch citations; no personal data is sent.
- Google (OAuth identity provider) — when you sign in with Google.
6. Cross-border data transfers
We aim to keep your data within India wherever possible. Your account, files and database records sit in ap-south-1 (Mumbai). AI inference and backend compute may currently take place outside India (in regions noted above). We are working to bring backend compute into India as the user base grows. By using the Service you acknowledge and consent to these transfers.
7. How long we keep your data (retention)
- Active accounts: data is retained for as long as your account is active.
- Deleted projects: removed from primary storage within 7 days.
- Closed accounts: all personal data deleted within 90 days, except minimal records we are required to retain for tax / audit / dispute defence purposes (e.g., GST-relevant payment records).
- Backups: may persist up to 30 days after deletion.
8. Your rights under the DPDPA
You have the right to:
- Obtain a summary of personal data we process about you.
- Request correction, completion or updating of inaccurate data.
- Request erasure of your personal data (subject to legal retention obligations).
- Nominate another individual to exercise your rights in the event of death or incapacity.
- Withdraw consent at any time (this may end your ability to use the Service).
- Grievance redressal — raise complaints to our Grievance Officer.
To exercise any right, write to support@pythesis.in. We aim to respond within 30 days.
9. Security
We use TLS for all network traffic, JWT-based session authentication, password-less Google Sign-In, single-active-session enforcement, role-based access in our database, encryption at rest for stored files, and request-scoped authorisation on every API call. No system is ever perfectly secure — but we take reasonable steps to protect your data.
10. Cookies and similar technologies
We use only essential cookies required for authentication (Supabase session cookies stored in your browser's localStorage). We do not run third-party advertising trackers or cross-site analytics.
11. Children
Pythesis is intended for postgraduate medical and dental students aged 18 and above. We do not knowingly collect data of minors. If you believe a child has provided us data, contact us and we will delete it.
12. Changes to this Policy
We may update this Policy from time to time. When we make material changes, we will notify you by email or via a prominent in-app notice. The "Last updated" date at the top reflects the latest revision.
13. Contact
Email: support@pythesis.in
Grievance Officer: Abhishek Kawdiya, contactable at the same email address.