Privacy policy · plain-language first
How we handle your data.
In short: your shop's data belongs to your shop. We don't sell it, don't train models on it without your written opt-in, and don't pretend deletion means anything other than deletion. This page is the longer version.
The one-paragraph version
We collect what we need to run the product, store it isolated per shop, encrypt it at rest, retain it only as long as it's useful or legally required, and delete it when you ask. We don't sell data to anyone, ever. We don't train models on your shop's transactions without your written, separately-collected opt-in. If we ever have to materially change this policy, you get notice before it takes effect.
Who this applies to
This policy covers the Pia mobile application for Android and iOS (com.piaprescience.pia) and the hey-pia.com website.
It covers everyone who uses Pia — pharmacy owners, admins, managers, staff and workers logged in under a shop's tenant — and everyone who visits this website. We are the data fiduciary under India's Digital Personal Data Protection Act, 2023. The shop's owner is the data principal for that shop's data.
What we collect
From the website
- Basic request metadata (IP, user-agent, referrer) for security and abuse prevention. Retained for 30 days.
- If you fill in a form or message us: whatever you sent us. Retained for the life of the conversation plus 12 months.
- Cloudflare Web Analytics, which counts page views and how quickly pages loaded. It sets no cookies, carries no advertising trackers, and does not follow you between sites — we see totals, never a person.
- We do not run third-party advertising trackers. We do not run a cookie banner because we're not setting cookies that would require one.
Inside the product
- Account & user data: your email address — this is your account identifier and is required — plus your name, your role (owner / admin / manager / staff / worker), an optional phone number, and your language preference.
- Shop & business data: shop name, GSTIN, address, drug license number where required, the products and batches you stock.
- Operational data: bills, purchases, customer records, supplier records, returns, ledger entries — everything the product needs to do its job.
- Conversation data: your messages to Pia, the drafts Pia produced, what you approved or edited.
- Photographs: receipts, prescriptions, or product labels you photograph so Pia can read them.
- Device & security data: a per-install device identifier and the app version, used only to enforce device approval — an unrecognised phone has to be approved by the shop owner before it can open shop data. We run no analytics, advertising, attribution or crash-reporting tools, so we collect no crash logs, no performance traces and no usage telemetry at all.
Three that deserve their own answer
Location — once, at setup, and it never reaches us. When you first set up your shop, Pia offers to fill in the shop address for you. If you allow it, your phone reads its position, converts it to a street address on the phone itself, and Pia keeps only that address. The coordinates are never sent to us and never stored. Decline it and you simply type the address instead. Location is not read at any other point, and never in the background.
Voice — used to hear you, not kept. If you tap the microphone and speak to Pia instead of typing, the recording is sent to a speech-to-text service to be turned into words — Sarvam AI, an Indian company, for ordinary clips, and Cloudflare's own transcription for longer ones. The recording is deleted from your phone in the same moment it is sent, and it is never written to our storage — it exists only for the seconds it takes to transcribe. What we keep is the resulting text, exactly as though you had typed it. Typing always does the same job.
Health-related records — your pharmacy's register, not a patient profile. Where you capture a prescription against a sale, or maintain the Schedule H1 register that the Drugs and Cosmetics Rules require, Pia stores the prescriber, the patient details recorded at the counter, and the medicines dispensed. This is your pharmacy's own regulatory record about its own customers. We never sell it, never share it, never use it for advertising, and never use it for anything other than running your shop and letting you produce the register when you are asked for it.
How we use it
- To run the product — everything above, used to do what you asked Pia to do.
- To meet legal obligations — GST filings, audit trails, drug-regulator reporting where required.
- To respond when you contact us — support, feedback, recovery from incidents.
What we don't use it for
- Training models on your shop's data without your written, separately-collected opt-in. Opt-in is never bundled with feature access.
- Selling to data brokers, advertisers, or any third party.
- Profiling individuals across pharmacies.
- Marketing to your customers without your shop's explicit instruction.
How long we keep it
| Category | Retention |
|---|---|
| Transactional data (bills, purchases, ledger) | 8 years — section 36 of the CGST Act requires 72 months from the due date of the annual return |
| Schedule H1 register entries | 3 years — required by the Drugs and Cosmetics Rules, 1945 |
| Customer records inside a tenant | For as long as the shop wants; deletable on request |
| Pia conversation history | 3 years rolling, unless you opt to shorten or extend |
| Photographs of bills and prescriptions | Kept alongside the record they belong to, so it can be checked against its original. Removed from live systems when you close the account; where the record they belong to is one the law requires us to keep, the photograph is retained with it for that period and no longer |
| Voice recordings | Not retained — deleted from the phone on send, never written to our storage |
| Server logs | 30 days |
| Account & access records after closure | 90 days, then deleted; legally-required records kept only for the periods above |
Where it lives
Your shop's records sit in their own separate database, provisioned for your shop alone — the isolation here is physical separation, not a shared table with a filter on it. That database runs on Cloudflare's infrastructure, in its Asia-Pacific region. Everything is encrypted in transit and at rest.
Who else processes it, and what they see
We use a small number of processors. This is all of them — not a representative sample.
| Processor | What it does, and what it receives |
|---|---|
| Cloudflare | Hosting, databases, file storage and background processing. Your shop's records live here. Its Workers AI service also transcribes longer voice recordings. |
| Anthropic | The Pia assistant; reading photographed supplier bills and prescriptions; reading catalogue and expense files you upload. This means the contents of those photographs and messages are sent to Anthropic to be read. Processed under a commercial agreement that does not permit your data to be used for training. |
| Sarvam AI (India) | Turning what you say to Pia into text. Receives the recording for the seconds it takes to transcribe. |
| Google Cloud — Vertex AI | Forecasting what you are likely to run out of. Receives quantities and dates. No names. |
| Google Firebase | Checking that a copy of the app is genuine before it can reach your data. Receives no shop data. |
| Expo | Building the app, delivering updates, and relaying push notifications to your phone. |
| Resend | Sending you email — sign-in codes, invitations, account notices. |
Some of these process data outside India. Where that happens, the processor is bound by contract to the standards this policy sets, and this list is the notice. We will update it here before adding a processor, not after.
Beyond that list, we share with lawful authority only — on a valid order, only the data the order specifies, and we tell you it happened unless we are legally prohibited from doing so.
Ending it
There are three separate things you might mean by “delete”, and Pia keeps them separate on purpose.
- Delete your own account. In the app: Me → Account → Delete my account. Your login, your devices, your sessions, your conversations with Pia and your personal records go. If you own a shop, we will not let you do this silently — deleting the shop is its own decision, below.
- Delete a location, or the whole shop. Owners only, in the app: Me → Workspace → Danger zone. This ends the shop's systems and removes its records from live use.
- Can't sign in? Ask us at hey-pia.com/delete-account. We verify it is you, then do it for you.
Nothing happens for 90 days. Every one of those is scheduled, not immediate: sign in at any point during those 90 days and it is cancelled, with everything put back as it was. After the 90 days, erasure begins and cannot be reversed.
What survives, and only for as long as the law says. The records we are legally required to keep — transactional and tax records under section 36 of the CGST Act, register entries under the Drugs and Cosmetics Rules — are moved to restricted storage for the periods in the table above, used for nothing else, and reachable by no one running the product day to day. Records of who did what, and of security events, are kept as an audit trail. Everything else goes.
Your staff's deletions do not erase your books. When a staff member deletes their account, their identity is removed and their name is replaced everywhere it appeared in your shop's records — but the bills they rang up remain your bills. A shop's books are not any one employee's to delete.
Your rights
Under DPDPA 2023 and as a matter of policy, every data principal has the right to:
- Access — a copy of the personal data we hold about you.
- Correction & updation — fixing anything inaccurate.
- Erasure — deletion of personal data, subject only to legal-retention exceptions we'll cite specifically.
- Withdrawal of consent — for anything where consent was the basis.
- Grievance — a working channel to raise concerns. Ours is below.
- Nomination — assign someone to exercise these rights if you can't.
The full mechanics are at our DPDPA 2023 statement, including how long we take to fulfill a request and what we charge (nothing, in almost every case).
Grievance officer
Per DPDPA 2023 and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, our designated Grievance Officer is:
Akshat Gupta, Grievance Officer
Pia Prescience Private Limited
1420, Kamini Kunj, Napier Town, Jabalpur – 482001, Madhya Pradesh, India
[email protected]
We acknowledge every grievance within a working day and resolve it within the 30 days the Act allows. If you're unsatisfied, you can escalate to the Data Protection Board of India under the Act.
Children
Pia is built for businesses. We don't knowingly collect personal data of individuals under 18 as a Pia user. If a pharmacy uses Pia to track customers who happen to be minors, that processing is governed by the shop's own customer-data obligations, not ours directly.
Changes to this policy
Material changes get email notice 30 days before they take effect. Clarifications (typos, restructure for readability) don't. Every change is timestamped at the bottom of this page; the canonical history lives in our git log.