In every region

One set of safeguards, whichever law applies.

Clinic and patient records are stored on Amazon Web Services in the Asia Pacific (Mumbai) region, India. The same controls protect every clinic, and each regional statement maps them to the provisions of its law.

Encryption at rest
Patient and clinic records are held in a managed PostgreSQL database on Amazon RDS, encrypted at rest with AES-256. The storage volumes of the application servers are encrypted in the same way.
Encryption in transit
Every connection between a browser or the MolarPlus mobile app and the MolarPlus service is encrypted with TLS.
Network isolation
The production database accepts no connections from the public internet. It can be reached only from the MolarPlus application servers.
Role-based access
The clinic owner decides, section by section, what each staff member can see and do. Staff are given access to the information their work requires and nothing more.
Authentication
Every user signs in with an individual account. Passwords are stored only as bcrypt hashes, sign-in and sign-up are verified with one-time codes, and repeated attempts are rate limited.
Audit trail
Actions taken within a clinic account are recorded in an activity log, which the clinic owner can review and export.
Private document links
Documents, prescriptions and reports are kept in private object storage and are opened only through signed links that expire shortly after they are issued.
Backups and recovery
The database is backed up automatically every day, with point-in-time recovery available across a rolling seven-day window.
Portability
A clinic owner can download a complete archive of the clinic’s data at any time and export patient records as a spreadsheet, without contacting MolarPlus.
Sub-processors

Every provider that handles clinic data.

MolarPlus uses the following service providers to deliver the service. Some process data outside India, including in the United States. Under their commercial terms, Anthropic and OpenAI do not use data submitted through their APIs to train their models. MolarPlus will update this register before engaging a new provider that handles patient data.

Amazon Web Services
Application hosting and database, in the Mumbai region
All clinic and patient records
Cloudflare
Object storage for files
Documents, prescriptions, reports and invoices
Anthropic
AI-assisted clinical note drafting and handwriting extraction
Only the content a clinician submits to these features
OpenAI
AI analysis within practice reports
Report data a clinic chooses to generate
MSG91
SMS and WhatsApp message delivery
Patient name, phone number and message content
Meta Platforms
WhatsApp Business messaging
Patient name, phone number and message content
WA Reach
WhatsApp messages from a clinic’s own number, where the clinic connects one
Patient name, phone number and message content
Zoho (ZeptoMail)
Transactional email
Recipient email address and message content
Sentry
Error monitoring
Technical diagnostics, which may include user identifiers
PostHog
Product usage analytics
Usage events of clinic staff
Cashfree Payments
Subscription billing in India
Billing details of the clinic
Dodo Payments
Subscription billing outside India
Billing details of the clinic
Google
Optional sign-in and Google Business Profile integration
Account email and profile details the clinic authorises
Shared responsibility

What MolarPlus secures, and what the clinic decides.

MolarPlus is responsible for the security of the service: the infrastructure, the application and the safeguards described on this page.

The clinic is responsible for how it uses the service: obtaining patient consent, deciding which staff may see what, keeping sign-in details private, and keeping records for the period its professional regulator requires.

Privacy and grievance contact
Grievance Officer, MolarPlus
Telephone: +91 9594078777
Sky Loft, opposite Golf Course, Shastrinagar, Yerawada, Pune, Maharashtra 411006, India

© 2026 MolarPlus Powered by Upclick labs (OPC) Pvt. ltd.