Last updated 2 October 2026
Rubrix privacy notice
Rubrix is clinic software for homeopathic doctors in India, made by PickleBook. This notice explains what data Rubrix holds about clinics, their doctors and staff, and their patients; who decides what happens to it; where it is stored; how long it is kept; and how to raise a concern. It covers Rubrix only. PickleBook’s other products have their own notices.
1. Who we are
PickleBook is a sole proprietorship of Suraj Bansode in India. You can reach us at picklebook.hq@gmail.com.
2. Who is responsible for patient data
- Patient records belong to the clinic. The clinic decides what to record about its patients and why, so the clinic is the data fiduciary under India’s Digital Personal Data Protection Act, 2023. PickleBook is the clinic’s data processor: we store and process patient data only to provide Rubrix to that clinic, and only on its instructions. Each clinic signs a data-processing agreement with us.
- For the clinic’s own account (the doctors’ and staff’s logins and the clinic’s plan), we decide how that data is used, so we are its data fiduciary.
3. What Rubrix holds
- About doctors and staff: name, email, phone, User ID, password (stored only as a one-way hash), role, and for doctors their registration number, council and qualification (needed on every prescription).
- About patients, as entered by the clinic: name, age or date of birth, sex, phone, address, occupation and other details on the case sheet; health information such as complaints, history, examination findings, investigations, diagnosis, mental and emotional characteristics, repertory work, prescriptions, follow-ups and diet sheets; and bills, payments and medicines dispensed. Religion is optional and is left off printed records unless the clinic chooses to include it.
- About enquiries (people who contact the clinic before becoming patients): the name, phone and notes the clinic enters.
- Security records: sign-ins and failed sign-ins, exports of patient data, changes to who can do what, and finalized prescriptions and visits, each with the time, the person, the IP address and the browser.
Health information is sensitive personal data. Rubrix is built so that each clinic sees only its own records, each person sees only what their role needs, and nothing is shared or published.
4. Why we use it
- To run Rubrix for the clinic: keep its records, appointments, prescriptions, bills and stock, and produce the documents it prints.
- To keep accounts and records secure: one-time codes for password resets, one device at a time, signing out after a period without use, and the security records above.
- To help the clinic when it asks us to (for example to import old records or fix a problem).
- To bill the clinic for its Rubrix plan.
We do not sell personal data, use it for advertising, or use patient records to train AI models. PickleBook staff do not look at a clinic’s patient records unless the clinic asks us to help with something specific, or the law requires it. Our own business figures are counts only, never patient details.
5. AI features
Rubrix has optional AI helpers: the Rubric Assistant (turns the doctor’s description of symptoms into repertory search phrases), a short case summary for the doctor, and suggested edits to a diet sheet. They work only when a doctor or staff member asks for them.
- The text is sent to an AI model (Anthropic’s Claude, through OpenRouter) whose servers are outside India. Before anything is sent, Rubrix removes the patient’s name, phone number, email, address, date of birth, OPD and case numbers and other identifiers it can detect. We ask OpenRouter to use only providers that do not store or train on this data.
- AI output is only ever a suggestion. It never chooses a remedy, never writes into a prescription or a patient’s record, and is never sent to a patient, unless the doctor reviews it and acts on it. The doctor always decides.
- A clinic that does not want AI at all can simply not use these buttons; everything else works without them.
6. Who we share it with
Only the service providers we need to run Rubrix, each for that purpose alone and under contract:
- Vercel (hosting) and Neon (database), in Singapore.
- OpenRouter and Anthropic (the AI features in section 5, outside India).
- Google (sending sign-in codes and account emails from picklebook.hq@gmail.com).
- Razorpay (paying for a Rubrix plan online, once that is switched on; it receives the payer’s details, never patient records).
So patient data is stored and processed outside India, in Singapore, and the redacted AI text goes to the AI provider. Indian law allows this for providing the service the clinic has asked for. We share data with authorities only when Indian law requires it.
7. WhatsApp and messages to patients
Rubrix does not send WhatsApp messages itself. When the clinic presses “Send on WhatsApp”, it opens WhatsApp on the clinic’s own phone or computer with a message ready to send, and the clinic sends it. The clinic is responsible for having the patient’s consent for messages the clinic starts (reminders, follow-ups), and for recording that consent.
8. How long data is kept
- Patient records: medical records have to be kept for years. Rubrix keeps a clinic’s records for the period the clinic sets (10 years unless the clinic chooses otherwise). This is a default, not a period fixed by law; the clinic remains responsible for keeping records as long as the rules that apply to it require. Patient records are never removed just because a visit is old.
- If a clinic stops using Rubrix: its records stay available to the clinic for export. At the end of the agreed period, or earlier on the clinic’s written instruction where the law allows, we return or delete them as the data-processing agreement says.
- Security records: 180 days, as India’s CERT-In directions require, then deleted.
- Doctor and staff logins: while the clinic’s account is open. A login that is switched off stays on record so that past entries still show who made them.
9. Patients’ rights
Patients can ask to see their information, correct it, or have it erased where the law allows, withdraw consent, and nominate someone to act for them.
- If you are a patient, please ask your clinic first: it controls your record and can correct it or give you a copy. You can also write to us and we will pass your request to the clinic and help it respond.
- Some information cannot be erased while the clinic must keep medical records; the clinic will explain if that applies.
- If you are a doctor or staff member, you can update your own details in Rubrix, or ask your clinic’s admin or us.
10. Security
Data is encrypted in transit; passwords are stored only as hashes; each clinic can see only its own data, and each person only what their role allows; each login works on one device at a time and signs out when left unused; exports of patient data are limited and recorded. If a breach affects personal data, we will tell the affected clinic without delay so it can inform its patients, and we will report it to CERT-In and the Data Protection Board of India as the law requires.
11. Children
Clinics treat children too. A clinic recording a child’s health information should record the parent or guardian who brings them. Rubrix accounts themselves are for doctors and clinic staff aged 18 or over.
12. Cookies
Rubrix uses only the cookies needed to keep you signed in and secure. It does not use advertising or tracking cookies inside the app.
13. Grievance officer
Suraj Bansode, PickleBook. Email: picklebook.hq@gmail.com. Phone: +91 90752 04033. We reply within 7 days and resolve complaints within the time the law allows. If you are not satisfied, you may complain to the Data Protection Board of India.
14. Changes
If we change this notice in a way that matters, we will tell clinics by email or in Rubrix before the change applies. See also the Rubrix terms of service.