Legal

Privacy policy

Chaare holds information about your mental health. This page sets out, in plain language, exactly what we collect, who can see it, how long we keep it and what you can ask us to do with it.

Last updated

1. Who we are

Chaare is a mental well-being platform that connects people with qualified therapists for counselling sessions. This policy explains what personal data we collect when you use chaare.in, why we collect it, who else can see it, and the choices you have.

For the purposes of India’s Digital Personal Data Protection Act, 2023 (the DPDP Act), Chaare is the Data Fiduciary for the data described here, and you are the Data Principal. You can reach us at enquiries@chaare.com, on +919895005083, or by post at Pukalakkat Tower, Cochin, Kerala, 682024.

2. What we collect

We collect only what the service needs in order to work.

  • Account details. Your name, email address, mobile number and a password, which we store only as a one-way hash and never in readable form. You may also upload a profile photo.
  • Booking details. The therapist and time slot you choose, the session type, and anything you write in the optional “what’s on your mind” note attached to a booking.
  • Session records. Notes your therapist writes about a session, and any feedback or rating you leave afterwards.
  • Enquiries. If you use the contact form, the name, email, mobile number and message you submit.
  • Therapist credentials. If you register as a therapist: your biography, qualifications, specialisations, years of experience, and the licence document you upload for verification.
  • Technical data. Standard server logs, and short-lived one-time codes and session tokens needed to sign you in securely.

Some of this — your booking notes and your therapist’s session notes — is health-related information. We treat it as the most sensitive data we hold and restrict it accordingly, as set out below.

3. Why we use it

  • To create and secure your account, and to verify your mobile number by one-time code.
  • To show you therapists, take your booking and confirm it to you and your therapist.
  • To connect you with a first responder over WhatsApp when a booking needs a human hand-off.
  • To let your therapist prepare for and record your session.
  • To answer enquiries you send us.
  • To verify that therapists on the platform hold the credentials they claim.
  • To keep the service secure, diagnose faults and prevent abuse.

We do not sell your personal data. We do not use your data to train advertising profiles, and we do not use the contents of your session notes for marketing of any kind.

4. Who can see it

  • Your therapist sees your name, contact details, the sessions you have booked with them, and the notes you choose to add to a booking.
  • You see your own bookings and any feedback you have left. Notes a therapist writes for their own clinical record and feedback you write about a therapist are kept separate and are never shown to the other party in the same view.
  • Chaare staff and support operators can look up a booking and the contact details attached to it in order to help with scheduling or a first-responder hand-off. Access is limited to the specific permissions an administrator has granted them, and booking changes are recorded in an audit log.
  • Service providers who operate parts of the platform on our behalf: our hosting and database provider, an SMS provider for one-time codes, an email provider for transactional messages, and WhatsApp for the first-responder hand-off. They act on our instructions and may not use your data for their own purposes.
  • Authorities, where we are legally required to disclose information, or where there is a serious and immediate risk to someone’s life or safety.

5. How we protect it

Traffic to and from the site is encrypted in transit. Passwords are stored only as salted one-way hashes. Sign-in uses short-lived access tokens held in memory rather than in browser storage, with refresh tokens in HTTP-only cookies that JavaScript cannot read. Sign-in, registration and password-reset endpoints are rate-limited to frustrate automated attacks.

Access to personal data inside Chaare is granted by role and by explicit permission, not by default. No system is perfectly secure, so if a breach ever affects your personal data we will notify you and the Data Protection Board of India as the DPDP Act requires.

6. How long we keep it

  • Account and booking records are kept while your account is open, and for as long afterwards as we are required to retain them for legal, tax or clinical-record purposes.
  • Session notes are kept as part of the clinical record for the period required of a mental-health practitioner.
  • Enquiries sent through the contact form are kept until they have been dealt with and for a reasonable period after, so we can pick up a conversation you resume.
  • One-time codes and session tokens expire within minutes to days and are then discarded automatically.

When data is no longer needed for any of these purposes, we delete it or irreversibly anonymise it.

7. Your rights

Under the DPDP Act you have the right to:

  • ask what personal data we hold about you and get a summary of how it is processed;
  • have inaccurate or incomplete data corrected, and out-of-date data updated;
  • ask us to erase your personal data where it is no longer needed for the purpose it was collected for;
  • withdraw consent you previously gave, without affecting anything done before you did;
  • nominate someone to exercise these rights on your behalf if you die or become incapacitated;
  • complain to us, and then to the Data Protection Board of India if we do not resolve it.

Some data must be retained even after a deletion request — clinical session records, for instance — and we will tell you when that applies and why.

8. Children and guardians

Accounts on Chaare are for people aged 18 and over. Where counselling involves someone under 18, the account must be held and the booking made by a parent or legal guardian, who provides consent on the child’s behalf. We do not knowingly create accounts directly for children, and we do not use children’s data for tracking or behavioural advertising. If you believe a child has registered without a guardian, tell us and we will remove the account.

9. Cookies

Chaare sets only the cookies it needs to keep you signed in and to remember your role between visits. These are strictly necessary cookies: without them, sign-in does not work. We do not set advertising or cross-site tracking cookies.

10. Changes to this policy

If we change how we handle personal data, we will update this page and move the “last updated” date at the top. Where a change materially affects your rights, we will also tell you directly through the platform or by email.

11. Contacting us

Questions about this policy, or a request to exercise any of the rights above, can go to our grievance contact at enquiries@chaare.com or +919895005083. Our postal address is Pukalakkat Tower, Cochin, Kerala, 682024. We aim to respond within 30 days.

See also our Terms of Service, which govern your use of the platform.