Skip to content

Privacy Policy

Last updated 26 July 2026 · Enaro

Welcome to Enaro. We build automated tools to help you understand your laboratory reports. Because we handle sensitive medical information, our privacy posture is built on strict data ownership, minimal retention, and transparency about exactly what we do.

Our core guarantee: Enaro will never sell, rent, or trade your personal information to data brokers or advertisers. Your identity is strictly yours. Separately, and only with your explicit consent obtained at the point of your first upload (see “What we collect and why” below), we may use a de-identified version of your data — with anything that could identify you permanently removed — for our own internal system improvement and analytics, and potentially to share with external trusted research or analytics partners in the future under the same non-identification protections. No such external-sharing arrangement exists today; this describes what your consent covers if and when one is built, not a claim that it's already happening.

This policy applies to users in India, the Philippines, Singapore, and internationally.

Definitions

To keep this policy clear, we use these terms consistently throughout:

  • Personal Information: any data capable of identifying you, directly or indirectly.
  • Health Data: a sensitive sub-category of Personal Information covering your physical or mental health (e.g. lab biomarkers, conditions).
  • Uploaded Reports (Source Documents): the raw PDFs/images you upload. You retain full ownership of these.
  • Derived Data: the charts, insights, timelines, and UI elements we generate — Enaro's intellectual property.
  • De-identified Data: data with all direct and indirect identifiers permanently stripped, so it can no longer identify you. Legally, this is no longer Personal Information.
  • Aggregated Data: De-identified Data pooled across multiple users for statistical modelling.
  • Trusted Service Providers: third-party infrastructure and API partners bound by confidentiality/data-protection terms, used only to deliver the service itself.
  • Trusted Research/Analytics Partners: external organisations we may, in the future, share De-identified or Aggregated Data with for research or analytics — distinct from Trusted Service Providers. No such partnership exists today.

What we collect and why

We rely on your explicit, affirmative consent to process your Health Data, captured via two separate gates rather than one bundled sign-up screen: general account consent at sign-up, and Health Data consent at a dedicated gate immediately before your first upload. We don't rely on pre-checked boxes or implied consent for sensitive information.

Data categorySpecific data typeProcessing purpose(s)Legal basis
Account DataName, email address, authentication credentials, 18-or-older self-attestation.To create and secure your account, provide support, and send critical service notices.Explicit consent (at sign-up)
Health Data (uploaded reports)PDF/image lab reports containing biomarkers, test results, and medical facility details.
  1. Automated processing to extract data, normalise biomarkers, and generate your health timeline.
  2. Internal use: to permanently strip identifiers and create De-identified Data for our own system improvement and aggregate analytics.
  3. Potential external sharing: to license or share De-identified/Aggregated Data with Trusted Research/Analytics Partners in the future (no such arrangement exists today).
Explicit consent (a single Just-in-Time gate covering all three purposes above)
Technical DataIP address, device type, app interaction logs.To detect security threats, prevent fraud, ensure platform stability, and operate the service securely.Necessary to operate and secure the service
Marketing DataEmail address (if separately opted in).To send newsletters, feature updates, or partner offers.Explicit consent (separate, optional, never required to use the service)

Why the three Health Data purposes above share one consent gate, not three: this is a deliberate choice to obtain broad consent once, at the moment of your first upload, rather than asking again later if we build new internal-analytics or partner-sharing capabilities that fit the same description. If we ever expand processing beyond what's itemised here, we will still ask for fresh, separate consent.

How we use AI and automated processing

Enaro uses automated processing to deliver its core service. When you upload a report, our systems automatically extract the text, route it to our analysis pipelines, and construct your health timeline.

  • We use enterprise-grade AI APIs. We do not use your personal information or Health Data to train public, foundational AI models (such as public versions of ChatGPT or Gemini).
  • We actively use De-identified and Aggregated Data to evaluate our extraction accuracy, improve our OCR routing, and refine our internal analytical models. Because you consent to the creation of this De-identified Data at the time of upload, we may continuously use it for system improvement without prompting you again.

Data sharing & trusted service providers

We don't build our own data centres or foundational OCR models. To provide Enaro, we securely transmit your data to Trusted Service Providers — secure cloud hosting, enterprise AI and document processing APIs, and secure email/transactional gateways. We do not publicly name specific AI or OCR vendors here, so our engineering team can upgrade or switch infrastructure as technology improves; every provider is contractually prohibited from using your raw Health Data for their own independent purposes, marketing, or public model training, and only receives the exact fragment of data needed to perform its function.

One Trusted Service Provider we do name: we use PostHog for product analytics (see our Cookie Policy). Unlike our AI/OCR sub-processors above, PostHog never receives your uploaded reports, biomarker data, or any Health Data — only anonymous marketing-site behavior and, once you're signed in, which app features you click.

Separately, and only ever in De-identified or Aggregated form, we may in the future share data with external Trusted Research/Analytics Partners, per the consent described above. No such partnership exists today; if one is established, any such partner would be contractually bound to the same non-identification and no-resale protections described throughout this policy.

Cross-border data transfers

Enaro is a global platform initially serving users in India, the Philippines, and Singapore. To ensure high availability and security, your data may be transmitted to, stored, and processed in secure cloud infrastructure regions outside your country of residence (such as Singapore or the United States), protected by standard contractual clauses and technical safeguards. A formal data-residency strategy is a genuinely open item we're tracking as a blocking pre-launch task requiring qualified legal counsel, not something we're representing as fully resolved here — see our Data & Privacy page for the fuller, more current treatment of this specific question.

Data retention & deletion

  • We retain your Personal Information and Uploaded Reports for as long as your account is active.
  • You can request deletion at any time from Settings. This immediately signs you out everywhere and blocks further login. Your data is then retained for 30 days — to protect against accidental or malicious deletion requests — before being permanently and irreversibly removed. There is currently no self-service way to cancel a pending deletion request during this window; contact us below if you need to.
  • De-identified and Aggregated Data — including any already shared with a Trusted Research/ Analytics Partner, if that capability exists at the time — generated prior to your deletion request is permanently retained, since it cannot be linked back to you and survives account deletion and consent withdrawal alike.

Your rights & consent withdrawal

Depending on your jurisdiction, you may have rights to access, rectify, or erase your personal data — see Data & Privacy for how we approach the Philippines Data Privacy Act, India's Digital Personal Data Protection Act, and GDPR principles.

You may withdraw your consent for Health Data processing at any time, via a self-serve toggle in your account settings — exactly as easy as granting it. Withdrawing immediately halts future automated processing (disabling new uploads until you consent again). It does not retroactively invalidate processing that occurred prior to your withdrawal, nor does it require extracting your De-identified Data from existing statistical models or any partner arrangement already in place at the time.

Minors

Enaro is built strictly for adults. You must be at least 18 to create an account and upload reports — enforced via a self-declared attestation at sign-up, not independent age verification. We do not knowingly collect or process the Health Data of minors; an account found to belong to a minor will be immediately terminated and its data permanently deleted.

Future changes to this policy

We may update this policy as Enaro's capabilities evolve. If we introduce new features that require processing your personal information for purposes genuinely beyond what's itemised above (for example, sharing raw, identifiable Health Data with a third party, which is not what our Health Data consent covers), we will notify you and explicitly seek your fresh, separate consent before proceeding.

About this policy

This policy describes our current design intent and practices, not a certified legal compliance guarantee — see our Security and Data & Privacy pages for related detail, and our Cookie Policy for what cookies we use. [PLACEHOLDER — requires legal review] This policy has not yet been reviewed by legal counsel and does not constitute a claim of compliance with any specific data protection law.

Contact

Questions about this policy can be sent to hello@enaro.care.