Skip to content

Data & Privacy

Last updated 25 July 2026 · Enaro

Enaro is built first for users in the Philippines, Southeast Asia, and India. This page describes how our data practices are structured to accommodate the region's data protection frameworks. It is not a certification of compliance — see the note at the end of this page.

Frameworks we're structured around

  • Philippines Data Privacy Act (RA 10173) — health information is treated as sensitive personal information, with corresponding access and processing safeguards.
  • India's Digital Personal Data Protection Act — we design around purpose-limited processing and user-controlled deletion.
  • GDPR principles — used as a general baseline (data minimisation, encryption, user rights to access/export/delete), even where GDPR does not directly apply.

What this means in practice

  • Your health data is encrypted in transit and at rest.
  • Access to your records is isolated per account at the database level.
  • You can export or delete your data at any time from Settings.
  • We do not sell personal health information.

Data residency

[PLACEHOLDER — requires legal review] A formal data-residency strategy — including where data is physically stored and processed relative to the Philippines and India — is a genuinely open item, tracked internally as a blocking item before onboarding real users at scale, and requires review by qualified legal counsel rather than an engineering decision alone.

No compliance certification claimed

Enaro does not currently hold, and does not claim, formal certification under any of the frameworks listed above. This page describes our design intent and current practices, not a legal compliance guarantee.