Who we are and what this covers
This policy explains how Substrate Labs (“Substrate”, “we”, “us”) handles personal data on substrates.in and in Substrate Console, our clinic records software. The company’s registered name and address, and how to reach our Grievance Officer, are listed under Contact at the end of this page.
We follow the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 (together, “the DPDP Act”), and the Information Technology Act, 2000 and the rules made under it.
Who decides what happens to your data depends on how you use Substrate:
- On the website, and for Substrate Console accounts, we decide why and how your data is used. Under the DPDP Act we are the data fiduciary.
- For patient records, the clinic decides. The clinic is the data fiduciary and we are its data processor: we store and handle the records only to provide Substrate Console to that clinic. Patient records explains what this means for patients.
On substrates.in
Reading the site. You don’t need an account, and public pages set no cookies. We don’t use analytics, advertising or social media trackers. Like every website, ours receives your IP address and basic browser details with each request. We use the IP address for a few seconds to stop abuse, such as one address submitting a form hundreds of times, and we don’t store it in our database. Our hosting provider, Cloudflare, keeps short-lived request logs to keep the site secure and working.
Joining the waitlist. We store your email address, the date you joined, and, if you followed someone’s invitation link, the code in that link. We use your email to tell you when Substrate is ready for you and, occasionally, to share product news. Every email has an unsubscribe link. We copy your email address to WorkOS, our sign-in provider, so we can invite you when access opens.
Answering a survey. We store your answers. Leaving your name, clinic, phone number, email or a note is optional. We use your answers to understand what clinics need and what they would pay. We contact you only if you left your details, and add you to the waitlist only if you choose to. While you answer, your progress is saved in your own browser so you can pick up where you left off. It is removed when you finish.
Subscribing to status updates. We store your email address and the parts of the service you chose to follow. We send a confirmation email first, and nothing else until you confirm. After that we email you only about incidents and maintenance. Every email has a link to change or end your subscription.
Invitation links. If you arrive through someone’s invitation link, your browser remembers the code for 30 days so the right person is credited if you join later. The code stays on your device unless you join the waitlist.
Articles with embedded media. Some Newsroom articles include videos from Vimeo or charts from Observable. These load from those services when you open the article, so they receive your IP address. Vimeo videos play in Vimeo’s do-not-track mode. Images in articles are served by Sanity, the service we publish articles with.
Our emails. We don’t put tracking pixels in our emails and we don’t track whether you open them or click their links.
In Substrate Console
Your account. If you work at a clinic that uses Substrate Console, we hold your name, email address, role and the clinics you belong to. If you are a doctor, we also hold your signature image and registration details, so they can appear on letterheads and prescriptions you sign. If you choose Sign in with Google, we receive your name and email address from Google, and nothing else.
Signing in. WorkOS runs sign-in and keeps your session. Substrate Console sets one cookie, which is needed to keep you signed in. It is not used for anything else. We use your IP address briefly, in memory, to limit repeated sign-in attempts.
The audit log. Substrate Console records who did what and when: sign-ins, changes to records, signatures, document views, shares and imports. The log holds names, identifiers and times, never the clinical content itself. It lets your clinic see who accessed what, and lets us investigate security problems.
Email. We send invitations and administrative notices, such as a new sign-in to your account. We never send clinical information by email.
No AI and no automated decisions. Substrate Console does not use AI models or make automated decisions about anyone. Allergy and duplicate-medicine warnings are simple checks against what is already on file.
Patient records
Clinics use Substrate Console to keep patient records. These can include a patient’s name, sex, date of birth or age, phone number, address, emergency contact, and ABHA number and address. They also include clinical notes, prescriptions, allergies, lab results, a pinned summary, and uploaded documents such as reports and scans.
The clinic is responsible for these records. The clinic decides what to record and why, and tells its patients how their data is used. Substrate Console keeps track of which version of the clinic’s privacy notice each patient acknowledged, and who recorded it.
What we do with them. We store, secure, display and back up patient records so the clinic can use Substrate Console, under our Data Processing Terms with the clinic. We do not sell patient data, use it for advertising, use it to train AI models, or share it with anyone else, except the providers that host the service and authorities when the law requires it. Our staff look at patient records only when the clinic asks us for help, or when we need to in order to keep the service secure or meet a legal duty.
Inside the clinic. People see what their role needs. A clinic administrator cannot see clinical content unless they are also a doctor or staff member at that clinic.
Aadhaar. We never store Aadhaar numbers. If an Aadhaar number is used to verify an ABHA through the national health system, it passes through without being kept.
Ayushman Bharat Digital Mission. Linking records with ABDM is not yet available. When it is, records will be shared through ABDM only with the patient’s consent, given through ABDM’s own consent manager, and ABDM’s policies will also apply.
Signed records are not rewritten. Once a doctor signs a note or prescription it is not changed. A correction is added as a new version and the original is kept, because medical records must show what was written and when.
If you are a patient. To see, correct or delete your record, or to name someone to act for you, contact your clinic first. We help clinics answer these requests. If you cannot reach your clinic, write to our Grievance Officer and we will pass your request on. Some records may have to be kept for a period set by medical records law even if you ask for them to be deleted. If so, the clinic will tell you why.
Children and guardians. Clinics treat children and people who cannot consent for themselves. The clinic is responsible for getting consent from a parent or lawful guardian when the law requires it.
Why we use personal data
We use personal data only for the purpose it was given for:
- to run the waitlist, surveys and status emails you asked for, based on your consent
- to provide Substrate Console to you and your clinic, and to sign you in
- to keep our services secure, prevent abuse and investigate problems
- to meet our legal obligations, such as keeping records the law requires
Where we rely on your consent, you can withdraw it as easily as you gave it: unsubscribe from any email, or write to us. Withdrawing consent doesn’t affect what we did before, but we stop from then on.
Who else handles your data
We use a small number of providers to run our services. Each one handles only what it needs, under a contract that requires it to protect the data.
- Cloudflare, Inc. hosts the website and Substrate Console, including the database, uploaded documents and request logs. Patient records are stored only with Cloudflare.
- WorkOS, Inc. runs sign-in and sessions for Substrate Console, and holds the waitlist. It handles names and email addresses, never patient records.
- Google LLC provides Sign in with Google, if you choose it.
- Resend sends our emails: waitlist and status emails, invitations and administrative notices. Emails never contain clinical information.
- Sanity, Inc. hosts the articles and images on substrates.in. It receives no personal data beyond the IP address of image requests.
- Clerk, Inc. ran sign-in before WorkOS and still holds some older accounts. We are moving away from it and will delete those accounts when the move is complete.
- Vimeo and Observable receive your IP address only when you open an article that embeds their content.
We also share data when the law requires it, for example in response to a valid order from a court or government authority. If Substrate is merged into or bought by another company, your data would move with it under the same protections, and we would tell you first.
We never sell personal data.
Where your data is stored
Our database and uploaded files are stored with Cloudflare in its Asia-Pacific region, currently in Singapore. Cloudflare does not yet offer storage limited to India. WorkOS, Google and Resend process data in the United States.
The DPDP Act allows personal data to be processed outside India, except in countries the Government of India restricts. We will not transfer data to a restricted country, and we will tell clinics before we change where patient records are stored.
How long we keep it
- Waitlist: until access opens and we have invited you, or until you ask us to delete it. If you unsubscribe, we keep your address only to make sure we don’t email you again.
- Surveys: answers are kept to compare results over time. Your contact details are kept until we have followed up, or until you ask us to delete them.
- Status updates: until you unsubscribe.
- Substrate Console accounts: while your account is active. When your clinic removes you or leaves Substrate, your account is deleted as described in the Data Processing Terms.
- Patient records: as long as the clinic keeps them in Substrate Console. When a clinic leaves, it has 30 days to export its records. We then delete them within 30 days, and backups are overwritten within a further 30 days.
- Audit and processing logs: at least one year, as the DPDP Rules require, in storage that cannot be changed or deleted early.
How we protect it
- Data is encrypted in transit and at rest.
- Each person sees only what their role needs, and every sign-in, view, change and share in Substrate Console is recorded in the audit log.
- Patient data is kept out of system logs and emails.
- Signed records cannot be changed, only amended with a new version.
- The database keeps 30 days of history, so a mistake or failure can be undone.
No system is perfectly secure. If a breach affects your personal data, we will tell you and the Data Protection Board of India without delay, and send the Board a full report within 72 hours, as the DPDP Rules require. If a breach affects patient records, we tell the clinic within 24 hours and help it inform its patients and the Board.
Your rights
Under the DPDP Act you can:
- ask for a summary of the personal data we hold about you, what we do with it, and who we have shared it with
- ask us to correct, complete or update it
- ask us to delete it, unless the law requires us to keep it
- withdraw your consent at any time
- name someone to exercise these rights for you if you die or cannot act for yourself
- complain to our Grievance Officer, and then to the Data Protection Board of India if you are not satisfied with our answer
To make a request, write to our Grievance Officer using the details under Contact. We may ask you to confirm your identity first. We reply within 30 days, and never later than the 90 days the DPDP Rules allow. If you live outside India, you may have similar rights under your local law, and we handle those requests the same way.
Children
The website and Substrate Console accounts are not meant for anyone under 18, and we don’t knowingly collect their personal data. If you believe a child has given us personal data, write to us and we will delete it. Patient records of children are kept by clinics, as described under Patient records.
Cookies and your browser
We set no cookies on public pages, so there is nothing to accept. We use the following, all of them needed for the feature you are using:
- Substrate Console sign-in cookie: keeps you signed in, and ends when you sign out or your session expires.
- Invitation code: remembered in your browser for 30 days, as described above.
- Survey progress: saved in your browser until you finish the survey.
Changes to this policy
When we change this policy, we publish the new version here with its date and a line in the change history below. If a change affects how we use data you have already given us, we email waitlist members, status subscribers and Substrate Console account holders before it takes effect.
Contact
Write to our Grievance Officer with any question, request or complaint about this page or your data.
- Company
- Substrate Labs
- Registered address
- Mumbai, India
- Replies
- Privacy requests within 30 days. Complaints acknowledged within 24 hours and resolved within 15 days.
If you are not satisfied with our answer, you can complain to the Data Protection Board of India.
Change history
First published.