Security & data protection
Last updated: 09 August 2026
This page describes how Pharma Mithra handles your data in the running service. It is a description of the system as deployed, not a statement of intent.
1. Where your data lives
All application data is stored and processed in India. The database, the application servers and the verification services run in the Asia Pacific (Mumbai) region — ap-south-1. We do not replicate verification data outside India.
Two processing exceptions are worth naming plainly, because they are the only places your input leaves that region:
- Optical character recognition of a photographed licence, certificate or medicine label, used to read the number so you do not have to type it. The image is processed for that purpose and is not retained as a training corpus.
- Sign-in messaging. Your mobile number is passed to our OTP delivery provider to send the code.
2. What we store
- Account: mobile number, name, business name, city, email if you give one, and your plan.
- Verification history: the identifier you checked, the result, its source and the date — this is your compliance record and it is what makes a past check evidence.
- Saved records: licences, GSTINs and FSSAI records you choose to save, with your own private notes.
- Payments: transaction references only. Card and bank details are handled entirely by our payment gateway and never reach our servers.
We do not sell your data, and we do not share your verification history with any third party. The identifiers you check are, in every case, numbers published on official government registers.
3. How long we keep it
Verification history is retained for as long as your account is open, because its value is precisely that it is dated evidence you can produce later. You can delete your account from inside the app at any time, from Settings; deletion removes your profile, saved records and verification history together, in one transaction.
4. Access and protection
- Every table carrying user data is protected by row-level security: a signed-in user can read and write only their own rows, enforced by the database rather than by the application.
- All traffic is over HTTPS. The Android app refuses plain HTTP and will not accept an invalid certificate.
- Verification endpoints identify the caller from a signed session token, never from a value supplied in the request.
- Secrets are held in the platform's secret store, not in the application code.
5. DPDP Act posture
We collect the minimum needed to run the service, use it only for the purpose you gave it for, and keep it in India. You may access, correct or delete your data, or withdraw consent, by writing to our Grievance Officer below or by deleting your account in the app. We will respond within the timelines the Act requires.
6. Reporting a security problem
If you believe you have found a vulnerability, please write to support@pharmamithra.com with enough detail to reproduce it. We will acknowledge and keep you informed, and we will not pursue action against good-faith research that avoids privacy violations and service disruption.
7. Who we are
Our registered entity details are being finalised and will be published here before we begin accepting payments. In the meantime, reach our Grievance Officer at grievance@pharmamithra.com.
See also our Privacy Policy, Terms and Refunds & Cancellation.