At , trust is not a marketing promise — it is something you can point to in the product. Under every heading below we set out what we do, what we do not yet do, and what is not ours to decide.
01 / 10
How your health data is protected
Your data is encrypted in transit, and encrypted a second time with a separate key before it is written to our servers. Reports and images you upload arrive at storage already encrypted — the storage provider only ever sees the encrypted form. Your data is stored and processed in the European Union (Frankfurt).
What we don't claim
This is not "end-to-end encryption". The key is managed on our servers — because clinical summaries, interpretation and the doctor's view all require the data to be processed on the server. A truly end-to-end encrypted system could not offer those functions.
02 / 10
Consent and artificial intelligence
Three separate consents are taken, and none stands in for another: general data-protection consent · AI pre-assessment of your complaint · AI simultaneous interpretation of your visit. For each one we store the exact text you approved, the moment you approved it, and a chain showing it has not been altered since. No step begins before consent — the form does not open, camera permission is not requested. You can view your own consent record at any time.
Medical decisions do not belong to artificial intelligence: organises your information and suggests an appropriate specialty; diagnosis and treatment decisions are made by qualified healthcare professionals.
03 / 10
Who can see what
Access follows your role: patients see only their own records · a doctor only if verified and assigned to the case · a partner doctor cannot reach the patient database at all, and personal names are masked in the question forwarded to them · coordinators and agencies see logistics, not clinical records. When your post-operative follow-up ends, clinical staff access closes and the record stays with you alone; you can reopen it whenever you wish.
04 / 10
Doctor verification
Before a doctor becomes visible or receives any patient assignment, they upload their professional documents — diploma, specialty certificate and professional liability insurance — and these are reviewed and approved. An unapproved doctor's profile is never published.
What we don't claim
We do not say "accredited doctor" — what we verify is the existence and validity of the documents.
05 / 10
Video, documents and sharing
Your consultations are not recorded. Video and audio are encrypted with WebRTC; when a direct connection cannot be established, the relay server that steps in carries only encrypted traffic and cannot see its content. When you share your records, you choose which categories are visible; you can set an expiry, add a password, disable downloads, and revoke the link at any moment. Every access is logged.
06 / 10
Audit and access history
Every meaningful access to your clinical data is written to a chain that cannot later be deleted or altered, and that can be independently verified.
The limit
The audit log is designed not to block the application — if an entry cannot be written, the operation still completes. High-frequency technical events such as signalling are deliberately not logged.
07 / 10
Retention and deletion
You can delete your account and your personal data. When you do, your e-mail, name, phone number, profile and notifications are genuinely deleted, your share links are revoked, and signing in becomes impossible. Your health records must be kept for the statutory retention period of 20 years — but they close to access (no one can open them: not doctors, not coordinators, not administrators, and not you) and they are destroyed automatically when the period ends. Two things are kept on purpose: your consent records, which prove the legal basis for what we hold — at the end of the retention period their personal content (IP, device details) is destroyed and the record remains as an anonymous verification link, and the access history, a tamper-evident chain that carries no identifying data and whose deletion would break the chain.
What we don't claim
Deletion is not performed by destroying a key ("crypto-shredding") but by physically deleting the record.
08 / 10
International transfer and service providers
Storage and processing take place in the European Union (Frankfurt). The limited cases that leave the EU:
AI pre-assessment and clinical summary (Anthropic, USA): your name is not sent — a placeholder is used; the clinical content is sent because it is the substance of the task.
Simultaneous interpretation (Google, USA): the audio of your visit is processed for interpretation, subject to separate explicit consent; without that consent it does not run.
Connection relay (Cloudflare): carries encrypted media only.
Signalling (Ably) and rate limiting (Upstash): no health data is sent.
09 / 10
Clinical responsibility
Diagnosis, treatment and medical decisions belong to qualified healthcare professionals. supports assessment, coordination and communication; it does not replace your doctor. A second opinion is not binding.
10 / 10
Report a privacy or security concern
If you have a concern about your data, or a security finding, tell us.
⚖️ Draft
The data controller's contact address has not been published yet; this section will be updated once it is final. We are not inventing an address in the meantime.