Skip to main content

Policy

Privacy policy

What we collect, why we collect it, who sees it, and how long we keep it.

Effective

1. Scope

This policy covers information we collect through this website and the account portal. Our handling of medical and health information specifically is described in more detail in our privacy practices for health information, which should be read alongside this policy.

2. Information we collect

  • Account information: name, email address, phone number, password (stored only as a bcrypt hash, never in readable form).
  • Service information: branch, service dates, discharge type, and — where you choose to provide it — the last four digits of a VA file number, used solely to match records you upload.
  • Case information: the condition you select, your intake answers, and the documents you upload.
  • Payment information: we receive a payment identifier, the card brand, and the last four digits from Stripe. We never receive or store your full card number.
  • Technical information: IP address, browser user agent, and timestamps, recorded in our audit log for security purposes.

3. Why we use it

We do not use your information for behavioural advertising, and we do not sell it. Ever, to anyone.

  • To create and administer your account.
  • To enable a physician to review your records and prepare a medical opinion.
  • To schedule and conduct your consultation.
  • To take payment and issue receipts.
  • To send you transactional updates about your case.
  • To detect and investigate fraud, abuse, and unauthorised access.
  • To comply with legal and regulatory obligations.

4. Who can see it

Access is restricted by role and enforced in the application, not merely by policy.

  • You can see everything relating to your own account and cases.
  • The physician assigned to your case can see that case, and only that case.
  • Administrators can see cases in order to support them, under a minimum-necessary standard.
  • Every access to a document is recorded in an audit log identifying who opened it and when.

5. Service providers

We use a small number of providers to run the service. Each receives only what it needs:

  • Amazon Web Services — document storage and transactional email, hosted in the United States.
  • MongoDB Atlas — database hosting.
  • Stripe — payment processing. Stripe receives your name, email, and billing address; we receive no card data.

6. How we protect it

  • Encryption in transit using TLS on every connection.
  • Encryption at rest for all stored documents and database contents.
  • A second layer of application-level AES-256-GCM encryption on intake narratives, clinical notes, case messages, and consultation links, so that content is unreadable even with direct database access.
  • Documents reachable only through short-lived signed links, never from a public URL.
  • Role-based access control, enforced server-side on every request.
  • Audit logging of every access to case data.
  • Automatic account lockout after repeated failed sign-in attempts, and short session lifetimes.

7. How long we keep it

Your completed opinion remains available in your account for as long as your account is open. Supporting records are retained for the period appropriate to medical records retention standards and then securely destroyed.

Audit logs are retained for a minimum of six years, because their purpose is to allow investigation of access long after the fact.

You may ask us to delete your account and associated records. We will do so except where retention is required by law or necessary to resolve a dispute.

8. Your choices

Residents of certain states have additional statutory rights, including the right not to be discriminated against for exercising them. Contact us and we will honour any right that applies to you.

  • Access a copy of the information we hold about you.
  • Correct information that is inaccurate.
  • Ask us to delete your account and records, subject to what we must retain.
  • Opt out of non-transactional email. Transactional messages about your case cannot be turned off while a case is open.

9. Children

The service is not directed at anyone under 18 and we do not knowingly collect information from children. If we learn we have, we delete it.

10. Cookies

We use only the cookies necessary to keep you signed in and to protect against cross-site request forgery. We do not use advertising or cross-site tracking cookies, so there is no consent banner to dismiss.

11. Changes

We will post any update here and, where the change is material, notify account holders by email.