Privacy notice
How accounts, shortlists and enquiries are collected, stored and deleted.
Accounts and shortlists
Creating an account saves your email, name, selected topics and preferences. Profiles and shortlists are encrypted with AES-256-GCM in a database in the server data directory; passwords use salted scrypt hashes. Your shortlist is not automatically sent to a hospital.
Enquiries and receipts
After you submit and accept this notice, your name, contacts, general topic, preferred timing and notes are sent to this website’s server and encrypted in its data-directory database. Signed-in submissions link to your account and appear under My enquiries. URLs use a reference only, without your name or email.
Keep the first enquiry general
Additional notes are limited to 320 characters. Leave out medical records, test results, identity numbers, precise addresses and other sensitive medical information. Use the provider’s specified secure channel for documents it requests later.
Sessions and sign-in
Before sign-in, selected topic IDs stay in this tab’s session storage. Sign-in uses an essential HttpOnly, SameSite=Strict cookie. Sessions have a 12-hour maximum and expire after 2 hours without API activity. Sign-out deletes the server session. Security checks use a CSRF token tied to a session or pre-session.
Managing and deleting information
Your account supports profile edits, shortlist removal and account deletion. Deletion removes account details, interests, associated enquiries and sessions. Enquiry references help locate submissions. Before launch, the operator must define verification and deletion channels for anonymous enquiries and specific retention periods.
Local mock outbox
In development, enquiry confirmations and password-reset instructions are written only to the server data directory’s mock outbox. No real email, text or instant message is sent. It contains recipients and message text and is visible only through an explicitly enabled local development page. Test information should be cleaned up after demonstrations.
Security logs and rate limits
The server keeps necessary rate-limit information and error logs to prevent abuse. Passwords, master keys and reset tokens are not placed in ordinary logs. Development data serves flow verification. Access controls, retention, backups and the operator must be defined before launch.
Analytics and third parties
There is no third-party analytics, advertising tracking, external font or CDN, and no analytics cookie. Official-source links open those websites only when you click; this website does not request them in the background.