Privacy Policy
Effective / Last Updated: August 7, 2026
1. Overview & App Identity
This Privacy Policy explains how CAAS Counselling App(“CAAS,” “we,” “us,” or “our”) collects, uses, protects, and discloses personal information when you use our web platform and mobile applications.
CAAS provides secure, professional online counselling and mental wellness support from verified psychologists. We are committed to maintaining the highest standards of data privacy and strict clinical confidentiality.
2. Information We Collect
We collect the minimum amount of personal and sensitive data necessary to provide a secure and effective counselling service. The categories of information collected depend on your role:
A. Student / Patient Information
- Account Profile: Full name, email address, username, profile photo, date of birth, gender, and timezone.
- Institutional Details: Roll number, department, and registration status to verify student eligibility.
- Contact Information: Phone number collected during onboarding to facilitate communication. We do not share your phone number with OTP providers or send SMS verification codes.
- Daily Check-ins: Optional wellness assessments and daily mood check-ins completed by you.
B. Psychologist Information
- Profile Details: Display name, profile photo, languages spoken, bio, experience years, specializations, availability rules, and consulting session fees.
- Qualifications & Education: License number, highest degree, area of specialization, awarding institution, and graduation year.
- Verification Documents: Uploaded identity documents (Aadhaar name and masked card number), degree certificates, professional licenses, experience letters, and bank details proof.
- Bank Payout Details: Bank name, account holder name, account type, branch name, IFSC code, PAN card number, UPI ID, and encrypted bank account numbers. Bank credentials are encrypted at rest using industry-grade cryptography (Fernet).
C. Transactional & Technical Metadata
- Appointment Records: Booking references, scheduled start and end times, chosen session channels (video or audio), fee amounts, hold expirations, and cancellation records.
- Device & Session Logs: Secure authentication tokens, IP addresses, browser/device agent info, and push notification installation tokens (such as Firebase Installation IDs).
3. Health and Counselling Data Handling
Because CAAS is a mental wellness platform, we treat all health and counselling-related information with special safeguards:
- Encrypted Session Reports: Following each completed consultation, the psychologist may write a clinical session report. This includes the presenting concern, symptoms discussed, psychologist observations, recommendations, and referral details. These reports contain sensitive health information and are encrypted at rest.
- Strict Access Controls: Session reports are accessible only by the authoring psychologist and platform administrators. Students / patients do not have access to these reports, and they are never shared with university administrators, employers, or family members.
- No Audio/Video Recordings: Consultation sessions are conducted through secure, real-time video or audio streams. We do not record, capture, or store the video or audio content of counselling sessions.
4. Security of Payments (Razorpay)
All payment transactions are processed securely through our authorized payment gateway provider, Razorpay.
CAAS does not collect, process, or store payment instrument credentials(such as credit card numbers, CVVs, online banking passwords, or UPI PINs). All sensitive payment credentials are input directly into Razorpay's secure interfaces in compliance with the Payment Card Industry Data Security Standard (PCI-DSS).
We only retain payment status, order references, refund history, and payment capture timestamps necessary to validate bookings, process cancellation refunds, and coordinate settlements in accordance with our Cancellation & Refund Policy.
5. Third-Party Service Providers
We share minimum necessary information with verified third-party subprocessors only to deliver core application functionality:
- Supabase Auth: Manages authentication identity tokens and handles secure user account registration and logins via Google Sign-In.
- Agora: Transmits encrypted real-time video and audio streams for remote consultations. Agora does not store or record consultation media.
- Razorpay: Secures and handles all payment gateways, payment captures, and refund transactions.
- Cloudflare R2 / AWS S3: Securely hosts static assets, psychologist profiles, uploaded qualifications certificates, and encrypted reports. Documents are accessed via temporary signed URLs.
- Firebase Cloud Messaging (FCM): Sends real-time appointment reminders, schedule changes, and transactional push notification alerts to your mobile device.
6. Mobile Permissions (Google Play & Apple App Store)
To facilitate consultation video calls, the CAAS mobile application requests access to the following permissions:
- CAMERA: Requested during video consultations to capture and transmit video streams to your psychologist.
- RECORD_AUDIO: Requested during audio and video calls to capture and transmit your voice.
- Notifications: Requested to deliver instant alerts for upcoming sessions, booking confirmations, or system status.
These permissions are used strictly when you actively participate in a consultation call and are never used to monitor you in the background.
7. Data Retention
We retain your personal information only for as long as your account is active, or as required to fulfill the purposes outlined in this policy (including complying with our ethical clinical records guidelines, legal obligations, resolving disputes, and enforcing agreements).
8. Account Deletion and Compliance Requests
You have the right to request deletion of your account and personal data at any time.
To submit a deletion request, please contact our compliance desk at trymindcare@gmail.com. Upon receiving your request, we will delete your account profile details and general records. Certain transaction logs, billing blocks, and clinical history may be retained in archive format where required by financial or clinical regulatory obligations.
Notice regarding Account Deletion: The CAAS web and mobile platforms do not currently feature a self-serve, in-app deletion button. Deletion requests are processed manually by our support desk within 7 working days of email receipt.
9. Data Security Wording
We employ strict industry-standard technical measures (such as HTTPS encryption in transit, Fernet database encryption at rest, secure signed URLs, and strict identity access management controls) to defend your personal information against unauthorized access, loss, or disclosure. While we take maximum precautions, no method of transmission or storage can be completely infallible.
10. Children and Minor Usage
MindCare services are intended for university students and adults. Minors under the age of 18 must obtain the consent and guidance of their parent or legal guardian before registering on the platform.
11. Emergency Service Disclaimer
CAAS does not provide crisis intervention, emergency medical treatment, or suicide helpline services. If you or someone you know is in immediate distress, danger, or experiencing self-harm urges, please call local emergency services or national helplines (such as 112 in India) immediately.
12. Contact Information
If you have any questions, feedback, or data privacy requests regarding this policy, please reach out to us at:
Email: trymindcare@gmail.com