Effective Date: 12 May 2026
Last Updated: 12 May 2026
Public URL (for app stores): https://neemandtulsi.com/delete-thrivehub-account/
Companion to: Privacy Policy · Data Retention Policy · Data Deletion Policy
This page is your official channel for requesting deletion of your ThriveHub account and the personal data we hold about you. It also serves as the public URL that Google Play and the Apple App Store require app developers to publish for account-deletion requests.
How to Delete Your Account — Step by Step
Step 1: Open your email app and compose a new email to privacy@neemandtulsi.com using the email address registered on your ThriveHub account.
Step 2: Set the subject line to: Delete my account
Step 3: In the email body, include the following details:
- the phone number on the account (so we can locate it across regions);
- which country’s tenant you used — India (Bharat) / United States (Americas);
- whether you want full deletion or item-level deletion;
- whether any pending invoices, ABDM consents, or active visits should be cancelled.
Step 4: Send the email. We will reply within 2 business days with a verification OTP and a unique Request ID. Your request will not be processed until your identity is verified.
That’s it. Once verified, your account deletion will proceed within 30 days.
1. Your Right to Delete
You may ask Vitalytics to delete:
- your entire ThriveHub account and the data linked to it, or
- specific items (a single document, a dependent profile, a saved address, a payment instrument, a consent grant).
Your right to delete is recognised under, among others, the Digital Personal Data Protection Act, 2023 (India, §13); the EU/UK GDPR (Article 17); the California Consumer Privacy Act / CPRA (§1798.105); other US-state privacy laws (CO, CT, VA, UT); the HIPAA Privacy Rule (45 CFR §164.524 / §164.526); the UAE PDPL (Art. 14); and the ABDM Health Data Management Policy.
2. What Happens After You Submit a Request
- Acknowledgement — within 24 hours. You receive an automated email with a unique Request ID and a link to track status.
- Identity verification — within 3 business days. We verify it is really you using an OTP, knowledge-based questions, or a video check. Without verification we cannot process the request.
- Pre-deletion checks — within 7 business days. We check for active visits, pending claims, and legal holds.
- Soft delete and cool-off — Day 7 to Day 14. Your account is hidden, sign-in disabled, push notifications stopped, and telemedicine bookings cancelled. During this period you may write to us to cancel the request.
- Hard delete from primary systems — Day 30.
- Propagation to backups — Day 60 at the latest. Backups continue to hold encrypted bytes for up to 35 days plus 1-year cold archive; records become inaccessible from the day of hard delete.
- Notification — within 30 days of completion. You receive a final email confirming what was deleted, what was retained (with the legal basis), and the date.
Target end-to-end timeline: 30 days from a verified request, which is within both Google Play’s 30-day account-deletion requirement and Apple’s account-deletion-link requirement.
3. What We Delete and What We Must Retain
When you request full deletion we delete the items below on Day 30. Items marked as retained are kept for the period shown in our Data Retention Policy because retaining them is required by law or essential for legitimate interests.
3.1 Deleted on Day 30
- Login credentials, password hash, security stamp
- Profile (name, DOB, gender, contact, photo, language, timezone)
- Addresses and address-proof documents
- Driving licence / identity-proof photos
- Push tokens (APNs / FCM)
- Communication preferences and consents
- Linked ABHA number and ABHA address (we also notify the gateway to revoke active consent artefacts)
- Dependents you created (unless a dependent is a real adult patient who has their own account)
- Saved payment instruments (Razorpay/Stripe customer reference)
- App-level diagnostic identifiers
- AI-assistance preferences
3.2 Retained, Then Deleted Later (Legal Floor — Medical App Requirements)
As a medical application, ThriveHub is legally required to retain certain records even after account deletion. Retained data is locked, read-only, restricted to a small set of audit-logged accounts, and not used for any purpose other than the legal/regulatory reason that justifies retention.
| Item | Why Retained | For How Long |
|---|---|---|
| Medical record (consultations, prescriptions, vitals, lab/imaging, care plans, telemedicine recordings) | Patient safety; medical-records law (IMC Regs 1.3.1, Clinical Establishments Act, US state laws) | India OPD: 3 years from last visit; India IPD: 3 years from discharge; US: state floor (typically 6–10 years; for minors, until age of majority + 6 years) |
| Pharmacy & prescription dispensing records | Drugs & Cosmetics Rules, Rule 65 | 2 years (India); HHS rules (US) |
| Invoices, GST records, payment records, refund records | Companies Act §128; CGST §36; IRS | 8 financial years (India) / 7 years (US) |
| ABDM consent artefacts (proof you granted/revoked consent) | ABDM HDM Policy, audit | Life of consent + 7 years |
| Audit logs (FHIR AuditEvent, access logs) | HIPAA 6 years; ABDM; security | 7 years from event |
| Record of your deletion request itself | Proof to regulator that we honoured your request | 7 years |
| Any record under legal hold (court order, ongoing investigation, insurance claim, malpractice claim) | Court / regulator | Until the hold is lifted |
| Anonymised aggregates derived earlier | Cannot be re-identified | Indefinite (irreversibly anonymised) |
3.3 Items We Cannot Unilaterally Delete
- Records held by your healthcare provider’s clinic in its own systems — paper charts, scanned PDFs in their on-premise EMR, copies on personal devices. To delete those, contact your clinic’s records officer.
- ABDM records held by third-party HIPs that you previously shared with. Your in-app ABDM consent screen lets you revoke each grant.
- Records that Apple App Store or Google Play have collected about you — governed by Apple’s and Google’s own privacy policies.
4. Item-Level Deletion
You can request deletion of the following without deleting your whole account, by emailing [EMAIL]:
- a dependent profile;
- a saved address;
- a saved payment instrument;
- a document you uploaded (ID proof, prescription photo, lab report);
- a communication-channel opt-in
- an ABDM consent grant;
- an AI-assistance preference.
For clinical entries created by your practitioner (consultations, prescriptions, lab orders), Indian medical-records law and [ADDRESS] state law require the practitioner to retain them. You can ask the practitioner to correct them, or ask us to make a note of your objection alongside the record.
5. Cancelling a Deletion Request
You may cancel your deletion request at any time during the cool-off period (Day 7 to Day 14) by emailing privacy@neemandtulsi.com with the subject “Cancel deletion — [Your Request ID]”. Once the hard delete is executed on Day 30, cancellation is no longer possible.
6. If We Refuse or Delay
We may deny or partially fulfil a request only on the grounds permitted by law, including:
- we are unable to verify your identity after reasonable attempts;
- the deletion would prevent us from completing a transaction you initiated;
- a legal hold applies;
- retaining the data is required to comply with a legal obligation (see Section 3.2);
- the request is “manifestly unfounded or excessive” (GDPR / DPDP).
Where we refuse or partially fulfil, we will tell you the reason, the legal basis, and your right to escalate within the same 30-day response window.
7. Right to Escalate
| Audience | Where to Go |
|---|---|
| Vitalytics Grievance Officer (mandatory first step in India) | dpo@neemandtulsi.com — we acknowledge within 24 hours and resolve within 30 days |
| Data Protection Board of India | https://dpb.gov.in |
| US Department of Health & Human Services, Office for Civil Rights | https://www.hhs.gov/ocr |
| California Privacy Protection Agency | https://cppa.ca.gov |
| UK Information Commissioner’s Office | https://ico.org.uk |
| EU Supervisory Authority | The data protection authority of your EU member state |
| UAE Data Office | https://u.ae |
8. Re-Registration
After full deletion, you may re-register at any time. We will treat you as a new user and will not be able to restore the deleted record. If you re-register with the same identity, we may relink your historical clinical record where it is still within the medical-records retention window and you reauthorise the link.
9. Special Situations
- Deceased users (India). Under DPDP §15, a nominee identified by you may be authorised to delete your data on your behalf after death. The medical record is retained for the period required by law.
- Deceased users (US). Personal representative under HIPAA §164.502(g) may request deletion. Medical-record retention period continues to apply.
- Minors transitioning to adult accounts. When a dependent reaches the age of majority, they may convert the dependent profile into a full account. The medical record continues; the parent’s access can be revoked.
- Account take-over / security incident. If you believe somebody has deleted your account fraudulently, write to security@neemandtulsi.com within 30 days of the deletion email. If we can verify, we will restore from cool-off or the most recent backup.
10. Audit Log
Every deletion request is recorded as an immutable event with:
- request ID,
- timestamp,
- channel (in-app / web / email),
- scope (full / partial),
- identity-verification method used,
- requested by (data subject / authorised representative / legal heir),
- completion timestamp,
- propagation timestamp to backups.
This log is retained for 10 years and is available on request to data-protection regulators.
11. Contact
| Purpose | Contact |
|---|---|
| Account deletion requests | privacy@neemandtulsi.com |
| Deletion status / follow-up | privacy@neemandtulsi.com (include your Request ID) |
| Grievance Officer / Data Protection Officer | dpo@neemandtulsi.com |
| Security / suspected fraudulent deletion | security@neemandtulsi.com |
| Postal | Vitalytics Professional Services Pvt. Ltd., A-38 Citizen Society, Ellora Park, Vadodara, Gujarat – 390023, India |
© 2026 Vitalytics Professional Services Private Limited. ThriveHub is a registered trademark of Vitalytics Professional Services Private Limited.
Important — this document is a working draft prepared by the engineering team for legal review. Counsel should review the legal-floor citations and the listed timelines for each jurisdiction before publication.
