Intake & reference tool for qualified Ayurvedic practitioners · Not a medical device · Not for diagnosis or treatment · Intended use →
MyDosha ← mydosha.org
Security & Trust

How we protect your patients' data

MyDosha handles special-category health data on behalf of Ayurvedic practitioners. We treat that as a responsibility, not a checkbox. This page sets out — in plain language — where your data lives, who can reach it, and what happens if something goes wrong.

Where your data lives

All practitioner and patient records are stored in the European Union, in a managed PostgreSQL database (Supabase, AWS eu-central-1, Frankfurt). MyDosha is operated from the EU; the operating entity is European. We do not sell data, and we do not show advertising. We do not process the Dutch BSN or any other national identification number.

EU data residency

Primary database and file storage hosted in the European Union — Supabase on AWS eu-central-1 (Frankfurt, Germany), ISO 27001 and SOC 2 Type II certified.

Encrypted in transit

HTTPS/TLS everywhere; insecure requests are upgraded. No plaintext endpoints.

Encrypted at rest

Database, file storage, and backups encrypted at rest (AES-256) by the platform.

Backups every 6 hours

Automated, validated off-platform backups four times a day, kept 90 days, with quarterly restore drills.

Who can reach the data

How the AI assistants handle your data

Our subprocessors

We rely on a small set of established providers. Each processes only what its function requires, under a data-processing agreement. International transfers, where they occur, are covered by Standard Contractual Clauses.

ProviderPurposeData it touches
SupabaseDatabase & file storage (EU)Practitioner & patient records, uploaded documents
VercelApplication hosting / deliveryRequest traffic; no database stored here
ResendTransactional emailRecipient address & message content (login codes, notifications)
AnthropicAI dossier & intake assistanceIntake text submitted for processing — not used to train models
DeepgramSpeech-to-text for dictation (EU endpoint)Dictated audio, processed in the EU and never stored by us — not used to train models
CloudflareBot protection (sign-up)Challenge token only; no patient data
StripeSubscription billingPractitioner billing details — never patient data
GitHubOff-platform storage of encrypted backup archivesDatabase backup archives, encrypted before upload with keys GitHub does not hold

Backups & recovery

The full database is backed up automatically every 6 hours. Each backup is validated for completeness (table coverage, row-count floors, referential integrity) so a half-failed dump is caught rather than silently kept. The archive is then encrypted before it leaves our infrastructure; the decryption key is held offline, so the storage provider cannot read patient data. We periodically restore a backup into a throwaway environment to confirm it actually works — an untested backup is not a backup.

Your rights & our commitments

Scope matters for safety, too. MyDosha is an intake and reference tool — not a medical device. The AI reorganises what a patient reported and surfaces curated classical references; it does not diagnose, prescribe, or screen an individual record. Keeping the software inside that boundary is itself a safety control. See the intended-use statement.

Reporting a vulnerability

If you believe you have found a security issue, please email security@mydosha.org. We aim to acknowledge reports within 48 hours and welcome responsible disclosure. Our machine-readable policy is published at /.well-known/security.txt.


This page describes our security posture in good faith and may evolve as the product does. It is informational and does not by itself form part of any contract; the binding terms are in your service agreement and DPA.

Last updated: 1 September 2026