/ trust

At , trust is not a marketing promise — it is something you can point to in the product. Under every heading below we set out what we do, what we do not yet do, and what is not ours to decide.

01 / 10

How your health data is protected

Your data is encrypted in transit, and encrypted a second time with a separate key before it is written to our servers. Reports and images you upload arrive at storage already encrypted — the storage provider only ever sees the encrypted form. Your data is stored and processed in the European Union (Frankfurt).

What we don't claim

This is not "end-to-end encryption". The key is managed on our servers — because clinical summaries, interpretation and the doctor's view all require the data to be processed on the server. A truly end-to-end encrypted system could not offer those functions.

03 / 10

Who can see what

Access follows your role: patients see only their own records · a doctor only if verified and assigned to the case · a partner doctor cannot reach the patient database at all, and personal names are masked in the question forwarded to them · coordinators and agencies see logistics, not clinical records. When your post-operative follow-up ends, clinical staff access closes and the record stays with you alone; you can reopen it whenever you wish.

04 / 10

Doctor verification

Before a doctor becomes visible or receives any patient assignment, they upload their professional documents — diploma, specialty certificate and professional liability insurance — and these are reviewed and approved. An unapproved doctor's profile is never published.

What we don't claim

We do not say "accredited doctor" — what we verify is the existence and validity of the documents.

05 / 10

Video, documents and sharing

Your consultations are not recorded. Video and audio are encrypted with WebRTC; when a direct connection cannot be established, the relay server that steps in carries only encrypted traffic and cannot see its content. When you share your records, you choose which categories are visible; you can set an expiry, add a password, disable downloads, and revoke the link at any moment. Every access is logged.

06 / 10

Audit and access history

Every meaningful access to your clinical data is written to a chain that cannot later be deleted or altered, and that can be independently verified.

The limit

The audit log is designed not to block the application — if an entry cannot be written, the operation still completes. High-frequency technical events such as signalling are deliberately not logged.

07 / 10

Retention and deletion

You can delete your account and your personal data. When you do, your e-mail, name, phone number, profile and notifications are genuinely deleted, your share links are revoked, and signing in becomes impossible. Your health records must be kept for the statutory retention period of 20 years — but they close to access (no one can open them: not doctors, not coordinators, not administrators, and not you) and they are destroyed automatically when the period ends. Two things are kept on purpose: your consent records, which prove the legal basis for what we hold — at the end of the retention period their personal content (IP, device details) is destroyed and the record remains as an anonymous verification link, and the access history, a tamper-evident chain that carries no identifying data and whose deletion would break the chain.

What we don't claim

Deletion is not performed by destroying a key ("crypto-shredding") but by physically deleting the record.

08 / 10

International transfer and service providers

Storage and processing take place in the European Union (Frankfurt). The limited cases that leave the EU:

  • AI pre-assessment and clinical summary (Anthropic, USA): your name is not sent — a placeholder is used; the clinical content is sent because it is the substance of the task.
  • Simultaneous interpretation (Google, USA): the audio of your visit is processed for interpretation, subject to separate explicit consent; without that consent it does not run.
  • Connection relay (Cloudflare): carries encrypted media only.
  • Signalling (Ably) and rate limiting (Upstash): no health data is sent.

09 / 10

Clinical responsibility

Diagnosis, treatment and medical decisions belong to qualified healthcare professionals. supports assessment, coordination and communication; it does not replace your doctor. A second opinion is not binding.

10 / 10

Report a privacy or security concern

If you have a concern about your data, or a security finding, tell us.

⚖️ Draft

The data controller's contact address has not been published yet; this section will be updated once it is final. We are not inventing an address in the meantime.

Ready when you are.