Privacy Policy
Draft — last updated 10/9/2026. This has not yet been reviewed by legal counsel and should not be relied on as a final compliance document.
1. What we collect
When you create a patient account, we collect your name, email, and — once you complete onboarding — your cancer type, treatment status, and the symptoms you tell us about. This is health information. When you create a practitioner account, we collect your professional credentials, license information, and the specialty and rate information you provide.
2. Where we are with HIPAA
We are pre-launch, and we are not yet taking patients' health information on the live site. Before we do, the services that would store or process it (our database and hosting providers, and our insurance-eligibility provider) will be under business associate agreements, and these policies will have been reviewed by a lawyer. Until then, the live site refuses health information rather than collecting it on a promise.
Practitioners on the network are independent, licensed professionals and may themselves be covered by HIPAA. State health-privacy laws can also apply to us whatever HIPAA's status. We will update this section, with the date, when that changes.
3. How we use it
We use your information to match you with relevant practitioners, facilitate booking and payment for appointments, verify practitioner credentials (including checking the public NPPES registry), and let you track your symptoms over time. We do not sell your health information.
4. Who we share it with
Practitioners you book with see the health information relevant to your visit. Payments are processed by Stripe; we share only the amount and appointment reference, not your health details. Our infrastructure providers (currently Neon for our database and Vercel for hosting) process data on our behalf but do not use it for their own purposes.
5. Your rights
You can request a copy of your data, request correction of inaccurate information, or request deletion of your account at any time by contacting us. Some records (appointment and payment history) may be retained after deletion where we have a legal or record-keeping obligation to do so — see our Terms of Service for details.
6. Security
Passwords are hashed, never stored in plain text. We support optional two-factor authentication. Accounts are automatically locked after repeated failed login attempts. Data is encrypted in transit and at rest by our infrastructure providers.
7. Contact
Questions about this policy can be sent to the contact address listed on our site.