Last updated: March 15, 2026
About This Policy
This Privacy Policy explains how MediXGPT (“we”, “us”, “our”) collects, uses, stores, and shares your personal data when you use our AI-powered medical education platform at medixgpt.com. Please read it carefully. By creating an account or using the Platform, you acknowledge that you have read and understood this Policy.
We collect information you provide directly, information generated as you use the Platform, and technical information sent by your device. Below is a detailed breakdown.
When you register, we collect the information necessary to create and manage your account:
As you interact with the Platform, we automatically record information about your activity:
The core function of MediXGPT involves sending messages to AI language models. When you use the chat features, we store:
Important: Do not include real patient names, dates of birth, identification numbers, contact details, or any other information that could identify a living individual in your chat messages. MediXGPT is not designed to process protected health information (PHI) and you must not submit it.
If you use file upload features (DICOM images, lab report PDFs, reference documents), we store:
Payments are processed entirely by Razorpay, a PCI-DSS compliant payment gateway. We do not receive or store your full card number, CVV, or bank account credentials. We do retain:
When you access MediXGPT, your browser or device automatically transmits technical information:
We use the data described above for specific, limited purposes. We do not sell your personal data to any third party.
MediXGPT does not operate its own large language models. When you submit a query, your message text (and any attached context such as a system prompt, conversation history, or uploaded file content) is transmitted over an encrypted connection to OpenRouter, an AI model routing service, which then forwards the request to one of the underlying model providers (such as OpenAI, Anthropic, Google DeepMind, Meta, Mistral AI, or others depending on the model you select).
Third-party AI providers do not receive your name, email address, account ID, or payment information as part of the inference request. However, your IP address may be visible to OpenRouter at the network level.
Each provider in the AI processing chain has its own privacy policy and data handling practices. By using MediXGPT you acknowledge that your query content is subject to the terms of OpenRouter and the applicable downstream model provider. We recommend reviewing their policies:
MediXGPT does not represent that OpenRouter or any downstream AI model provider is compliant with HIPAA, the Indian Digital Personal Data Protection Act (DPDPA) 2023, the General Data Protection Regulation (GDPR), or any other specific regulatory framework with respect to the processing of your queries. We do not enter into Business Associate Agreements (BAAs) with AI providers on your behalf. This is a further reason why you must never submit real patient data or protected health information to the Platform.
Beyond AI model providers, MediXGPT integrates the following services, each of which may process certain data:
When you upload a DICOM file through the chat interface, the following steps occur:
The automated DICOM anonymization provided by MediXGPT is a best-effort process and does not guarantee complete de-identification. Private DICOM tags, burned-in text within pixel data, unusual tag structures, and non-standard DICOM implementations may not be fully sanitized. You are solely and entirely responsible for ensuring that any DICOM file or medical image you upload has been properly de-identified before upload, in accordance with applicable law and your institutional data governance policies. Do not rely on MediXGPT's anonymization as the sole safeguard.
By uploading a DICOM file or any medical image, you represent and warrant that:
Uploaded files are stored in Vercel Blob. Files are retained for the duration of your account and for a reasonable period thereafter. You may request deletion of specific files or all uploaded content by contacting ayush@medixgpt.com. Vercel Blob stores data in data centers operated by Vercel and their cloud infrastructure partners.
All data transmitted between your browser and MediXGPT's servers is encrypted using TLS 1.2 or higher. All connections to third-party services (database, blob storage, AI providers, payment processor) use encrypted connections. We do not transmit personal data over unencrypted channels.
Neon encrypts database storage at rest using AES-256. Vercel Blob encrypts stored objects at rest. Passwords are hashed using bcrypt with an appropriate work factor before storage; we cannot recover your plain-text password.
We implement technical and organizational security measures appropriate to the sensitivity of the data we process, including:
No security measure is perfect. We cannot guarantee absolute security of your data. In the event of a data breach affecting your personal information, we will notify affected users and relevant authorities as required by applicable law.
MediXGPT uses HTTP-only, secure, same-site cookies to maintain your authenticated session. These cookies are strictly necessary for the Platform to function and cannot be disabled without preventing you from logging in. They are automatically deleted when your session expires or you sign out.
Some user preferences (such as selected AI model, response length setting, and UI theme) are stored in your browser's localStorage. This data remains on your device and is not transmitted to our servers except when needed to initialize a request.
We may use privacy-respecting analytics tools to collect aggregate data about how the Platform is used. Where such tools are used, we configure them to:
We do not use advertising trackers, retargeting pixels, or third-party behavioral profiling cookies. We do not share your data with advertising networks, data brokers, or marketing platforms for advertising purposes.
We retain your personal data, chat history, and uploaded files for as long as your account exists. This allows you to access your conversation history and settings across devices and sessions. You may delete individual chat sessions at any time from within the Platform.
You may request deletion of your entire account and associated personal data at any time by emailing ayush@medixgpt.com with the subject line “Account Deletion Request” from the email address registered to your account. We will process your request within 30 days. Upon deletion:
Notwithstanding the above, we are required by applicable financial and tax regulations to retain billing records (subscription transactions, payment IDs, amounts, and dates) for a period of seven years from the date of the transaction. These records contain minimal personal data (email address and transaction details) and are kept in restricted-access storage.
If your account has been inactive (no login) for a continuous period of 24 months, we may send you a notice and subsequently delete your account and associated data if you do not respond or log in within 30 days of the notice. We will always notify you before taking this action.
MediXGPT is not directed at or intended for use by individuals under the age of 18. We do not knowingly collect personal data from anyone under 18 years of age. If you are under 18, you must not create an account or use the Platform.
If we become aware that we have inadvertently collected personal data from an individual under 18, we will delete that data promptly. If you believe a minor has created an account on MediXGPT, please contact us at ayush@medixgpt.com and we will investigate and take appropriate action.
MediXGPT is operated from India. However, the third-party infrastructure and service providers we rely on are global companies whose servers may be located in countries other than India, including the United States, the European Union, and elsewhere.
By using MediXGPT, you acknowledge and consent to the transfer of your personal data to countries outside India, including countries that may not provide the same level of data protection as India. Such transfers are made pursuant to:
Where feasible, we configure services to minimize unnecessary cross-border data flows (for example, by selecting data center regions closest to our primary user base).
Depending on your jurisdiction and applicable law, you may have some or all of the following rights with respect to your personal data:
You have the right to request a copy of the personal data we hold about you. We will provide this in a structured, commonly used format within 30 days of a verified request.
If the personal data we hold is inaccurate or incomplete, you have the right to request correction. You can update most account information directly from your profile settings. For information you cannot update yourself, contact us and we will make the correction within a reasonable time.
You have the right to request deletion of your personal data, subject to limitations described in Section 7 (Data Retention & Deletion). We will honor deletion requests that do not conflict with our legal obligations or legitimate business interests.
You may request an export of your chat history and account data in a machine-readable format (JSON). The Platform also provides an in-app export feature for individual conversations. Contact us to request a comprehensive data export.
Where our processing of your data is based on consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal. Withdrawing consent to essential processing (such as authentication session cookies) will prevent you from using the Platform.
To exercise any of the rights above, contact us at ayush@medixgpt.com from the email address registered to your account. We may need to verify your identity before processing your request. We will respond within 30 days; if your request is complex or numerous, we may extend this period by a further 30 days with notice.
MediXGPT is subject to the Digital Personal Data Protection Act, 2023 (“DPDPA”) of India. We process personal data of Indian residents in compliance with the obligations applicable to Data Fiduciaries under the DPDPA.
We process your personal data on the following grounds under the DPDPA:
MediXGPT is not designed or registered to process sensitive personal data or special category data under the DPDPA, including health and medical information about identifiable individuals. The Platform is an educational tool and you must not submit any data that constitutes health data of a real person. Any health information you share must pertain to hypothetical or anonymized educational scenarios only.
In our role as Data Fiduciary under the DPDPA, we commit to:
We may update this Privacy Policy from time to time to reflect changes in our data practices, new features, legal requirements, or feedback. The “Last updated” date at the top of this page will reflect the date of the most recent revision.
For material changes — such as changes to the categories of data we collect, the purposes for which we use it, or the third parties with whom we share it — we will provide notice by:
Continued use of the Platform after the effective date of a revised Policy constitutes your acceptance of the changes. If you do not agree to the revised Policy, you must stop using the Platform and may request account deletion as described in Section 7.
If you have questions, concerns, or requests relating to this Privacy Policy or the way we handle your personal data, please reach out to us:
Privacy, Technical & Account
ayush@medixgpt.com
Data access, deletion, corrections, security
Medical Content
pranjal@medixgpt.com
Content accuracy, educational concerns
We aim to acknowledge all privacy-related inquiries within 3 business days and to resolve them within 30 days. For data breach notifications or urgent security matters, please mark your email subject line with “URGENT — Privacy”.
Postal address: MediXGPT, India. For legal service and formal notices, please use the email address above and we will provide a physical address upon request.