বাংলা সংস্করণ নিচে · Read in English · সর্বশেষ হালনাগাদ: ৮ অক্টোবর ২০২৬
প্রাইভেসি পলিসি
My Dr BD (“আমরা”) আপনার স্বাস্থ্যসংক্রান্ত তথ্যকে অত্যন্ত সংবেদনশীল বলে গণ্য করি। এই পলিসিতে বলা হয়েছে আমরা কোন তথ্য সংগ্রহ করি, কেন করি, কার সাথে ভাগ করি এবং আপনার কী অধিকার আছে। এটি My Dr BD রোগী অ্যাপ, ডক্টর অ্যাপ (ডাক্তারদের জন্য) এবং এই ওয়েবসাইটের জন্য প্রযোজ্য।
১. আমরা কোন তথ্য সংগ্রহ করি
| তথ্য | কীভাবে পাই | কেন লাগে |
|---|---|---|
| মোবাইল নম্বর | সাইন-ইনের সময় আপনি দেন | আপনার অ্যাকাউন্ট চেনা ও OTP কোড পাঠানো (SMS-এর মাধ্যমে) |
| OTP কোড (৬ সংখ্যার, ৫ মিনিট মেয়াদ) | আমরা তৈরি করে আপনার নম্বরে পাঠাই | সাইন-ইন যাচাই। কোডটি আমাদের কাছে শুধু হ্যাশ করা (এক-মুখী স্ক্র্যাম্বল) অবস্থায় থাকে, পড়ার মতো অবস্থায় নয়। |
| প্রোফাইল: নাম, বয়স, লিঙ্গ, জন্মতারিখ, রক্তের গ্রুপ, অ্যালার্জি, রোগের তালিকা, ঠিকানা, জরুরি যোগাযোগ, ছবি | আপনি প্রোফাইলে লিখলে | ডাক্তারের সাথে অ্যাপয়েন্টমেন্টে প্রয়োজনীয় তথ্য দেখানো, অ্যাপের অভিজ্ঞতা ব্যক্তিগত করা (যেমন আপনার রোগ অনুযায়ী খাবারের রেটিং) |
| অ্যাপয়েন্টমেন্ট: ডাক্তার, সময়, ধরন, আপনার লেখা নোট, বাতিলের কারণ | বুকিং করলে | সেবা দেওয়া, ডাক্তারকে জানানো |
| স্বাস্থ্য রিপোর্ট PDF | আপনি একটি অ্যাপয়েন্টমেন্টের জন্য নিজে শেয়ার করলে | শুধু ওই অ্যাপয়েন্টমেন্টের ডাক্তারকে দেখানো |
| প্রেসক্রিপশন | ডাক্তার পাঠালে | আপনাকে দেখানো |
| পেমেন্টের তথ্য: পরিমাণ, পদ্ধতি (bKash, Nagad, কার্ড ইত্যাদি), লেনদেন নম্বর | পেমেন্ট করলে | পেমেন্ট নিশ্চিত করা, রিফান্ড, হিসাব। আমরা আপনার কার্ড নম্বর বা মোবাইল ওয়ালেটের পিন সংরক্ষণ করি না — তা পেমেন্ট গেটওয়ে (EPS) নেয়। |
| যোগাযোগ বার্তা | “যোগাযোগ” ফর্ম পূরণ করলে | উত্তর দেওয়া |
| ভিডিও কলের অডিও/ভিডিও | কলের সময় | ডাক্তার ও আপনার মধ্যে সরাসরি, এনক্রিপ্টেড সংযোগ। সরাসরি সংযোগ সম্ভব না হলে কল আমাদের নিজস্ব রিলে সার্ভারের মধ্য দিয়ে যায়, যা তা পড়তে বা জমা রাখতে পারে না; কলের জন্য কোনো তৃতীয় পক্ষের সার্ভার ব্যবহার হয় না। আমরা কল রেকর্ড বা সংরক্ষণ করি না। |
| অ্যাকাউন্ট কার্যকলাপ: সর্বশেষ কখন অ্যাপ ব্যবহার করেছেন | স্বয়ংক্রিয় | নিরাপত্তা ও সেবার মান |
২. যে তথ্য শুধু আপনার ফোনে থাকে
ওষুধের তালিকা ও ডোজের হিসাব, সুগার/প্রেশার/ওজনের মাপ, খাবারের লগ, দৈনিক নোট, মেডিকেল রেকর্ড ও স্ক্যান করা প্রেসক্রিপশন/রিপোর্ট আপনার ফোনেই সংরক্ষিত থাকে; আমাদের সার্ভারে পাঠানো হয় না। প্রেসক্রিপশন বা রিপোর্টের ছবি থেকে লেখা পড়া (OCR) আপনার ফোনেই হয়। আপনার ফোনের ব্যাকআপ চালু থাকলে অ্যান্ড্রয়েড এই ফোন-ডেটা (সাইন-ইনের তথ্য বাদে) আপনার নিজের Google অ্যাকাউন্টের ব্যাকআপে রাখতে পারে, যাতে নতুন ফোনে ফিরে পান; এটি আপনার ফোনের সেটিংসে নিয়ন্ত্রিত, আমরা তা পাই না, এবং আমাদের অ্যাপে “অ্যাকাউন্ট মুছুন” সেই ব্যাকআপ মোছে না (তা আপনার Google ব্যাকআপ সেটিংস থেকে মুছতে হবে)। নতুন ফোনে ফিরিয়ে আনার পর আবার SMS কোড দিয়ে সাইন-ইন করতে হবে। শুধু আপনি “ডাক্তারকে পাঠান” বেছে নিলে তৈরি করা স্বাস্থ্য রিপোর্ট PDF সেই অ্যাপয়েন্টমেন্টের জন্য আমাদের সার্ভারে যায়।
৩. কে আপনার তথ্য দেখতে পারে
- আপনার ডাক্তার: যে ডাক্তারের সাথে আপনার অ্যাপয়েন্টমেন্ট আছে, শুধু তিনি আপনার নাম, বয়স, লিঙ্গ, রক্তের গ্রুপ, অ্যালার্জি, রোগের তালিকা, ফোন নম্বর, অ্যাপয়েন্টমেন্টে আপনার লেখা নোট এবং (আপনি শেয়ার করলে) স্বাস্থ্য রিপোর্ট ও তার সাথে পাঠানো বর্তমান ওষুধের তালিকা দেখতে পান।
- My Dr BD-এর অ্যাডমিন/সাপোর্ট কর্মী: অ্যাকাউন্ট ও বুকিং পরিচালনার জন্য নাম, ফোন নম্বর, বুকিংয়ের তথ্য ও পেমেন্টের হিসাব দেখতে পারেন; কর্মীর ভূমিকা অনুমতি দিলে জন্মতারিখ, ঠিকানা ও জরুরি যোগাযোগও দেখতে পারেন। তারা আপনার স্বাস্থ্য তথ্য (রক্তের গ্রুপ, অ্যালার্জি, রোগ, রিপোর্টের বিষয়বস্তু, আপনার লেখা নোট) দেখতে পান না।
- সেবা সরবরাহকারী (আপনার তথ্য শুধু কাজের জন্য যতটুকু দরকার):
- Alpha SMS — OTP পাঠাতে: আপনার ফোন নম্বর ও কোডসহ বার্তা।
- EPS (পেমেন্ট গেটওয়ে) — পেমেন্ট নিতে: পরিমাণ এবং পেমেন্ট সম্পন্ন করতে প্রয়োজনীয় তথ্য (যেমন আপনার নাম ও ফোন নম্বর)। কার্ড বা ওয়ালেটের তথ্য EPS-এর পাতায় দেন, আমাদের কাছে আসে না।
- বাংলাদেশের হোস্টিং প্রদানকারী — আমাদের সার্ভার (ডেটাবেস ও আপলোড করা ফাইল) বাংলাদেশে অবস্থিত এই প্রদানকারীর ডেটা সেন্টারে চলে। আপনার তথ্য বাংলাদেশের সার্ভারেই সংরক্ষিত থাকে।
- Cloudflare — আমাদের ওয়েবসাইট ও সার্ভারের সামনে থেকে সুরক্ষা ও গতি দেয়; অ্যাপ ও সার্ভারের মধ্যের যোগাযোগ এর বৈশ্বিক নেটওয়ার্কের মধ্য দিয়ে (এনক্রিপ্টেড সংযোগে) যায়, তবে তথ্য সংরক্ষিত হয় না — সংরক্ষণ শুধু আমাদের বাংলাদেশের সার্ভারে।
- Google ML Kit (অ্যাপের ভেতরের সফটওয়্যার লাইব্রেরি) — প্রেসক্রিপশন/রিপোর্টের ছবি থেকে লেখা পড়া আপনার ফোনেই হয়; ছবি Google-এর সার্ভারে পাঠানো হয় না।
- আমরা আপনার তথ্য বিক্রি করি না এবং বিজ্ঞাপনের জন্য কাউকে দিই না। আইনানুগ বাধ্যবাধকতা থাকলে আদালত বা সরকারি কর্তৃপক্ষকে তথ্য দিতে হতে পারে।
৪. কতদিন রাখি
- প্রোফাইল ও অ্যাকাউন্ট: আপনি অ্যাকাউন্ট মুছে ফেলা পর্যন্ত।
- অ্যাপয়েন্টমেন্ট ও পেমেন্টের হিসাব: আইন ও হিসাব-নিকাশের প্রয়োজনে অ্যাকাউন্ট মুছলেও পরিচয় সরিয়ে (বেনামে) ৬ বছর সংরক্ষণ করা হয়, তারপর মুছে ফেলা হয়।
- শেয়ার করা স্বাস্থ্য রিপোর্ট PDF: অ্যাপয়েন্টমেন্ট বাতিল হলে বা আপনি প্রত্যাহার করলে মুছে যায়; অ্যাকাউন্ট মুছলেও মুছে যায়।
- OTP কোড: ২ দিনের মধ্যে মুছে ফেলা হয়।
- ফ্রি ট্রায়ালের রেকর্ড: অ্যাকাউন্ট মুছলেও ট্রায়ালের তারিখ ও কেনা সাবস্ক্রিপশনের মেয়াদ আপনার ফোন নম্বরের একমুখী, চাবি-যুক্ত হ্যাশের (নম্বরটি নয়) বিপরীতে অনির্দিষ্টকাল রাখা হয়, যাতে মুছে আবার নিবন্ধন করলে দ্বিতীয়বার ফ্রি ট্রায়াল না পাওয়া যায় এবং কেনা মেয়াদ হারিয়ে না যায়।
- সার্ভার লগ (যেখানে আইপি ঠিকানা ও অনুরোধের তথ্য থাকতে পারে): সর্বোচ্চ ৯০ দিন।
- ব্যাকআপ: সার্ভারের ডেটাবেসের ব্যাকআপ ১৪ দিন এবং শেয়ার করা রিপোর্ট PDF-এর ব্যাকআপ ৩৫ দিন রাখা হয়। তাই অ্যাকাউন্ট মুছলেও মুছে ফেলা তথ্য এই সময় পর্যন্ত ব্যাকআপে থেকে যেতে পারে; তারপর স্বয়ংক্রিয়ভাবে মুছে যায়।
৪ক. ডাক্তারদের তথ্য (ডক্টর অ্যাপ)
ডাক্তার নিবন্ধন করলে আমরা তাঁর নাম, ইমেইল, ফোন নম্বর, BMDC নম্বর, যোগ্যতা, বিশেষত্ব, চেম্বারের নাম ও ঠিকানা, ছবি, ফি এবং রোগী দেখার সময়সূচি নিই। পাসওয়ার্ড সরল অবস্থায় নয়, হ্যাশ করে রাখা হয়। ডাক্তারের নাম, বিশেষত্ব, যোগ্যতা, ছবি, চেম্বার ও ফি অনুমোদনের পর রোগীদের কাছে দেখানো হয়; ইমেইল, ফোন নম্বর, BMDC নম্বর ও পাসওয়ার্ড রোগীদের দেখানো হয় না। অ্যাডমিন কর্মী অনুমোদন ও পরিচালনার জন্য এই তথ্য দেখতে পান। ডাক্তার লেখা প্রেসক্রিপশন যে রোগীর জন্য লেখা, শুধু সেই রোগী (পাঠানোর পর) এবং লেখক ডাক্তার দেখতে পান।
৫. আপনার অধিকার
- প্রোফাইলের তথ্য অ্যাপ থেকেই দেখা ও সংশোধন করতে পারেন।
- শেয়ার করা রিপোর্ট যেকোনো সময় প্রত্যাহার করতে পারেন।
- অ্যাকাউন্ট ও ব্যক্তিগত তথ্য মুছে ফেলার অনুরোধ অ্যাপের মেনু → “অ্যাপ সেটিংস” → “অ্যাকাউন্ট মুছুন” থেকে করতে পারেন, অথবা এই পাতার নির্দেশনা অনুসরণ করুন।
- আপনার তথ্য সম্পর্কে প্রশ্ন বা অভিযোগ থাকলে [email protected]-এ লিখুন।
৬. নিরাপত্তা
সব যোগাযোগ এনক্রিপ্টেড (HTTPS)। পাসওয়ার্ড কখনও সরল অবস্থায় রাখা হয় না; OTP কোড হ্যাশ করে রাখা হয়। শেয়ার করা রিপোর্ট ইন্টারনেট থেকে সরাসরি খোলা যায় না, শুধু অনুমোদিত ডাক্তার দেখতে পান। কোনো সিস্টেমই শতভাগ নিরাপদ নয়; কোনো সমস্যা ধরা পড়লে আমরা দ্রুত ব্যবস্থা নেব।
৭. শিশুদের তথ্য
অ্যাপটি ১৮ বছরের কম বয়সীদের নিজে ব্যবহারের জন্য নয়। অভিভাবক শিশুর স্বাস্থ্যসেবার জন্য নিজের অ্যাকাউন্ট ব্যবহার করতে পারেন।
৮. চিকিৎসা সংক্রান্ত সতর্কতা
অ্যাপের তথ্য (যেমন খাবারের রেটিং ও রিমাইন্ডার) সাধারণ সহায়তা, ডাক্তারের পরামর্শের বিকল্প নয়। জরুরি অবস্থায় ৯৯৯-এ কল করুন বা হাসপাতালে যান।
৯. পরিবর্তন
এই পলিসি বদলালে এখানে নতুন তারিখসহ প্রকাশ করা হবে; বড় পরিবর্তন হলে অ্যাপেও জানানো হবে।
১০. যোগাযোগ
My Dr BD · ইমেইল: [email protected]
Privacy Policy
Last updated: 8 October 2026
My Dr BD (“we”) treats your health information as highly sensitive. This policy explains what we collect, why, who it is shared with and your rights. It covers the My Dr BD patient app, the Doctor App (for doctors) and this website.
1. What we collect
| Data | How we get it | Why |
|---|---|---|
| Mobile number | You enter it to sign in | To identify your account and send one-time codes (OTP) by SMS |
| OTP code (6 digits, valid 5 minutes) | We generate it and send it to your number | To verify your sign-in. We keep the code only in hashed (one-way scrambled) form, never in readable form. |
| Profile: name, age, gender, date of birth, blood group, allergies, conditions, address, emergency contact, photo | You enter it in your profile | To show your doctor what they need for an appointment, and to personalise the app (e.g. food ratings for your conditions) |
| Appointments: doctor, time, type, notes you write, cancellation reason | When you book | To provide the service and inform your doctor |
| Health report PDF | Only when you choose to share it for an appointment | Shown only to that appointment's doctor |
| Prescriptions | Sent by your doctor | To show them to you |
| Payment details: amount, method (bKash, Nagad, card…), transaction number | When you pay | To confirm payment, refunds and accounting. We do not store your card number or wallet PIN — the payment gateway (EPS) handles them. |
| Contact messages | When you use the contact form | To reply |
| Audio/video during calls | During a video consultation | A direct, encrypted connection between you and your doctor. When a direct connection isn't possible the call goes through our own relay server, which cannot read or store it; no third-party server is used for calls. We do not record or store calls. |
| Account activity: when you last used the app | Automatic | Security and service quality |
2. Data that stays on your phone
Your medicine list and dose log, blood sugar/pressure/weight readings, food log, daily notes, medical records and scanned prescriptions/reports are stored on your phone and are not sent to our servers. Reading text from photos of prescriptions or reports (OCR) happens on your phone. If your phone's backup is on, Android may keep this on-phone data (not your sign-in) in your own Google account's backup so you can restore it on a new phone; that is controlled by your phone's settings, we do not receive it, and “Delete account” in our app does not remove that backup (delete it in your Google backup settings). After restoring on a new phone you sign in again with an SMS code. Only the health report PDF you choose to “send to the doctor” is uploaded, for that appointment.
3. Who can see your data
- Your doctor: only a doctor you have an appointment with can see your name, age, gender, blood group, allergies, conditions, phone number, the note you write on the appointment and (if you share it) your health report together with the current-medicines list sent with it.
- My Dr BD admin/support staff: can see your name, phone number, booking details and payment records to run accounts and bookings; if their role allows it, also your date of birth, address and emergency contact. They cannot see your health information (blood group, allergies, conditions, report contents, notes you write).
- Service providers, only what they need:
- Alpha SMS — to send OTP codes: your phone number and the message with the code.
- EPS (payment gateway) — to take payment: the amount and what is needed to complete it (such as your name and phone number). You enter card or wallet details on EPS's page; they never reach us.
- A hosting provider in Bangladesh — our server (database and uploaded files) runs in this provider's data centre in Bangladesh. Your data is stored on servers in Bangladesh.
- Cloudflare — protects and speeds up our website and server; traffic between the app and our server passes through its global network (over encrypted connections), but the data is not stored there — storage is only on our servers in Bangladesh.
- Google ML Kit (a software library inside the app) — reading text from prescription/report photos happens on your phone; the photos are not sent to Google's servers.
- We do not sell your data or share it for advertising. We may have to disclose data to a court or authority where the law requires it.
4. How long we keep it
- Profile and account: until you delete your account.
- Appointment and payment records: kept in anonymised form even after account deletion, as needed for law and accounting, for 6 years, then deleted.
- Free-trial record: kept indefinitely. After account deletion we keep the trial dates and any paid subscription period against a one-way scrambled (keyed hash) form of your phone number — not the number itself — so that deleting and re-registering does not give a second free trial and paid time is not lost.
- Shared health report PDFs: deleted when the appointment is cancelled, when you withdraw the report, or when you delete your account.
- OTP codes: deleted within 2 days.
- Server logs (which may include IP addresses and request details): at most 90 days.
- Backups: copies of the server database are kept for 14 days and copies of shared report PDFs for 35 days. So data you delete may remain in those backups for up to that long, and is then removed automatically.
4a. Doctors' data (Doctor App)
When a doctor registers we collect their name, email, phone number, BMDC number, qualifications, speciality, chamber name and address, photo, fees and consultation hours. The password is stored hashed, never in readable form. After approval, the doctor's name, speciality, qualifications, photo, chamber and fees are shown to patients; email, phone number, BMDC number and password are not. Admin staff can see this information to approve and manage accounts. A prescription a doctor writes can be seen only by the author doctor and, once sent, the patient it was written for.
5. Your rights
- View and correct your profile in the app at any time.
- Withdraw a shared report at any time.
- Delete your account and personal data in the app: Menu → App settings → “Delete account”, or follow the instructions here.
- Questions or complaints about your data: [email protected].
6. Security
All communication is encrypted (HTTPS). Passwords are never stored in readable form and OTP codes are stored hashed. Shared reports cannot be opened from the internet — only the authorised doctor can view them. No system is perfectly secure; if we find a problem we will act quickly.
7. Children
The app is not intended for people under 18 to use on their own. A parent or guardian may use their own account for a child's care.
8. Medical disclaimer
Information in the app (such as food ratings and reminders) is general support, not a substitute for a doctor's advice. In an emergency call 999 or go to a hospital.
9. Changes
If we change this policy we will publish it here with a new date, and tell you in the app for significant changes.
10. Contact
My Dr BD · Email: [email protected]