Privacy
Last updated: 1 October 2026
Current service status
This is a private preview. Do not submit real patient data during evaluation. Before public intake opens, the operator must publish its legal identity, privacy contact and applicable service terms.
Information collected and purpose
The enquiry form requests your name, email, residence, optional phone, a short health summary, requested service, preferred hospital, travel window and language. We use this to review and coordinate your enquiry. We do not collect passports, payment details or full medical files in this form.
Consent and sharing
Contact consent and explicit health-data consent are separate. Data is not automatically sent to hospitals, translators or advertisers. Any later disclosure to a care provider needs a separate agreement on recipient, purpose and information shared.
Account emails
When email verification is enabled, Our shared email service, or Resend when configured, receives your email address and an account verification or password-reset link to deliver the requested message. These emails contain no health information. Names and email addresses are encrypted in our database; one-time tokens are stored only as hashes and expire after 30 minutes. Resetting a password signs out existing sessions.
Google sign-in
When available and selected, Google provides a verified email address, name and account identifier to create or link your account. We encrypt your name and email and store a keyed hash of the Google identifier. We do not store Google passwords or access tokens, and do not send your health enquiries to Google for sign-in. Existing accounts with the same email must first sign in with their password and explicitly link Google in Account security.
AI navigation and care files
With explicit consent, we encrypt and save care profiles, travel dates, hospital favourites, redacted reports and AI conversations. Care profiles expire 90 days after their last update; reports and AI records expire 90 days after submission. Only the account holder and allowlisted administrators may review them. Users can download reports or delete records in My care file. Clearing the chat screen only clears that screen. AI requests separately send the consented conversation and reports to the provider shown in the AI form; a report uploaded in My care file is not sent to AI. OpenRouter requests require the chosen provider, no collection and zero-retention routing. Provider policies apply; this is navigation, not a diagnosis. Data never enters advertising trackers or browser storage.
Service orders and payments
When checkout is enabled, card details are entered on Stripe’s hosted payment page. We store your account ID, service code, amount, currency, payment status, checkout reference and accepted terms URL. We do not send health summaries, names or account email addresses to Stripe. Order metadata is kept separately from the 90-day enquiry records and remains for reconciliation until the operator deletes it. Card data is not stored by this website.
Storage and access
Enquiry details are encrypted in the database. Signed-in patients can read their own linked enquiries; explicitly authorised administrators can review enquiries. Hosting and database infrastructure use Railway for the Railway deployment, and Cloudflare for the original Sites preview; this preview does not promise storage in a specific country. We do not use advertising trackers or store health summaries in browser storage.
Retention and deletion
Records older than 90 days are purged when a new enquiry is saved or an administrator opens the list. During an inactive period they may remain until the next operation. Administrators can delete an enquiry earlier. Keep your reference number to request access, correction or deletion through the operator’s published privacy contact once the public service opens. Provider backups follow the provider’s own retention policy.
Image credits
Shanghai skyline — kishjar?, CC BY 2.0. Resized and cropped for display.