Niro

Trust Centre

Your health record is among the most sensitive information you own. This page explains, in plain language, how Niro protects it.

Who Controls Your Data

Authentication

Verification of Professionals

Encryption

Data Residency and Processing

Referrals

Observations Taken Before a Consultation

Limits on Document Reading

Niro can read a photograph of a laboratory report, a prescription or a clinic note and offer you the details it finds, saving you the typing.

Paying for Niro Premium

The heart of Niro is free — your record, your appointments, video consultations and home care. Niro Premium adds reading documents with AI, keeping photographs of your reports, and creating and managing your family's records. It costs LKR 1,999 a year by bank transfer, or LKR 199 a month by card.

If you pay by bank transfer, you upload a photograph of the receipt. We read it with the same AI that reads a lab report — only to check the amount, date and reference — and we match it against our own bank statement. The receipt is kept only until your payment is confirmed and is deleted within 90 days; it is never shown to a clinician or anyone else. Your card number is never seen by us: card payments go through PayHere.

When a paid period ends, Premium features stop — but nothing already in your record, including a document or a family member's record, is ever removed or hidden.

Institutions pay separately for the channelling plan — from LKR 2,000 a month by the size of the practice, first month free, by bank transfer with a receipt uploaded in their portal. Pharmacies, laboratories, radiology centres and allied health portals are free. An institution's plan is never charged to its patients, and a lapsed plan never touches a patient's record or their existing bookings.

Access Controls

The Audit Log

Every grant of access to a record is logged with who, when, what scope and why, and the patient can read their own log.

We are precise about what this is. It records authorisation, not page views: once a party has been let in, they read the record straight from their device to the database, and our servers are not in that path. We would rather tell you exactly what we know than imply a level of surveillance we do not have.

The log is written by our servers only. Nobody — including the patient — can write or alter it.

Home Care Access

A carer sees a patient's record only while an accepted visit stands, and only the safety set: allergies, current medicines, current conditions, and the prescription behind anything a nurse has been asked to give.

They cannot read consultation notes, past visits or investigation results, and they cannot write anything into the medical record at all. What happened during a visit is recorded on the visit, not in the chart — a companion is not an author of clinical notes.

Every state change to a visit — accepted, declined, checked in, checked out, cancelled — goes through our servers rather than being written by either party's device. So does the price, which is taken from the carer's own published rates at the moment the visit is requested and fixed there. A carer cannot mark a visit complete they did not attend, and cannot raise the price on the way out.

A carer's eligibility to appear at all — verified, insured with an unexpired policy, agreement accepted, prices set, available — is recomputed by our servers on every change and swept nightly, because an insurance policy expiring is not an event anything writes.

Identity and Sign-In

Sign-in is by one-time code to a Sri Lankan mobile number, or for people abroad, to an email address, after which the device's own fingerprint or face unlocks the app.

Biometrics never leave the device. What we hold is a public key; the private key stays in the device's secure hardware, and we could not extract a fingerprint or face from what we store.

Identity verification — required before anyone can act on another person's record — is a document reviewed by a person. The trust level it produces is stored where its own subject cannot write it. A trust level the user can edit is not a trust level.

One-time code requests are rate-limited per number, per address and per source, with a daily ceiling, so that the code channel cannot be used to exhaust our sending credit or to harass a number.

Payments

Card details are entered inside PayHere's checkout and never reach Niro. We do not receive, process or store a card number.

A payment only becomes real when PayHere's own server tells ours it has, over a signed notification we verify. A client saying "I paid" is not accepted as evidence of payment by anything in the system.

Every payment is recorded with what it was for and what became of it. A payment that never resulted in the consultation or visit it was for is marked as owing a refund, so that the ledger stays honest even while refunds are issued by hand.

Vendor Security

What We Never Do

Data Lifecycle

Incident Response

Compliance

Security Contact