01
Your verification document can never become public
A patient post has to be backed by a discharge summary or a bill, so that a moderator can confirm the
operation actually happened. That document is opened once, by a person, for that purpose. There is no
approval level, no setting and no combination of flags that makes it public, because a bill names a
hospital and this site never publishes hospital names.
This is not a policy we remember to follow. The function that records a moderator's decision sets
visibility itself, per file type, so approving a document marks it “believed” and leaves it
private — the code has no branch that could publish one.
02
Nothing you upload has a web address
Uploaded files are not stored anywhere a browser can reach. They live outside the public site, behind a
server-level denial, and the only way any of them is ever sent is through a script that re-checks who
you are and what has been approved on every single request.
So a link is never a key. If a photograph is un-approved, it stops being served immediately, including
to someone who already had the address. And because filenames are random rather than sequential,
guessing one returns the same 404 a stranger gets for a file that does not exist — we deliberately
do not distinguish the two, because “this exists but you may not see it” is itself a
disclosure.
03
The hidden data in your photo is removed before we store it
A photograph taken on a phone usually carries the GPS coordinates of the place it was taken, which for a
photo of a bill is normally someone's home, along with the device, its serial and the exact time. Most
sites strip that when displaying an image, which means the original still sits on their disk.
We strip it on the way in. The copy written to disk is rebuilt without those blocks, so the data is not
in our possession at all and cannot leak later — not through a bug, not through a backup, and not
to us. If we cannot rebuild a file cleanly, we refuse it instead of storing it as it came.
04
The filename you sent is thrown away
“Ramesh_Kumar_discharge_summary.pdf” identifies a patient in the filename alone. Every
stored file is renamed to a random string before it is written, and what you called it is never
recorded. Downloads a moderator makes are named from that random string too.
05
Every photograph is approved one at a time
Approving a post does not approve its pictures. Each image is judged separately, and the check is mostly
about the edges of the frame rather than the subject: a wristband, a face in the background, a name
board, a letterhead, a department sign. Any of those is a rejection.
We refuse formats we cannot handle honestly. SVG can carry script. HEIC and WebP we cannot rewrite with
confidence, and accepting them would mean storing metadata we told you we removed, so they are declined
rather than quietly passed through. JPG, PNG and PDF only.
06
Anonymous is the default, and verifying does not undo it
Sending a document proves an operation happened. It does not attach your name to what is published. The
anonymous box is ticked when the form loads, sending proof does not untick it, and if the box is missing
from a submission for any reason we read that as anonymous rather than as consent.
Doctors can publish without their name too. Saying that your own specialty operates more often than the
evidence supports carries a professional cost, and the tip is worth more than the byline. The badge
means we checked a register, not that we published who was on it.
07
Identifiers are removed before storage, not before display
Email addresses, phone numbers, long ID runs, Aadhaar-style groupings, links and social handles are
stripped out of what you write as it is saved. They never reach the file. A leak of our moderation queue
could not expose a contact detail, because the contact detail was never written down.
The forms also do not ask for the things that identify people indirectly. No hospital, no city, no exact
date, no prescription box. A procedure plus a date plus a place can single out one person in a small
town, so we do not hold that combination.
08
A person reads everything, and nothing publishes itself
There is no automatic publishing on this site. Text that appears to name a facility or a clinician is
flagged for the moderator before they read the story, so the naming risk is seen first rather than
discovered last. Abuse, personal attacks, unverified allegations, prescriptions and dosages, and
anything reading as advertising are all removed.
Ask us and your submission or any single photograph is deleted, and an approved image stops being
served immediately rather than at the next cache expiry.
09
What the site holds about your account
A name, an email, a hashed password, and whichever of patient or doctor you chose. Passwords are hashed,
never stored or recoverable. We do not ask for your full medical records, your prescriptions, your scans
or an ID proof, and there is nowhere on this site to send them.
The site runs no JavaScript at all, which means no analytics scripts, no trackers, no third-party tags,
and no advertising pixels — there is no code from anyone else running while you read. Nothing is
sold or shared.
10
No hospital can buy anything here
Not a mention, not a better mention, not the removal of one. No advertising, no sponsorship, no
affiliate arrangement, no booking commission, no paid placement. The one paid programme is hospital
certification, where the fee buys the survey and not the result, and below 90% nothing is published.
How certification works.
11
This is education, not diagnosis
Doctor tips and library pages are written to make you better at the conversation with the clinician who
can actually examine you and read your reports. They do not replace that consultation, and they cannot
help in an emergency.