HomePrivacy Policy & Patient Data Rights
Patient Rights & Security Standards

Privacy and Trust by Design

DrGodly is designed to support patients and clinicians while maintaining the highest technical standards of data isolation, explicit consent, and healthcare security.

Last Updated: September 2026 • Version 2.4
Healthcare Safety & Clinical Scope Notice

DrGodly provides AI-powered healthcare intelligence designed to organize and contextualize medical information. AI outputs are assistive tools for clinical decision support and patient preparation; they do not replace emergency medical care or professional clinical judgment. If you are experiencing emergency symptoms (e.g. acute chest pain, shortness of breath, sudden numbness), please immediately contact local emergency services (911).

1. Patient-Controlled Health Information & Consent

Every record, lab result, and symptom description in DrGodly belongs strictly to the patient. You retain explicit, granular control over what information is visible to clinicians. No healthcare professional can inspect your history without your active, affirmative consent, and you can revoke individual clinician access permissions instantly via your account security dashboard.

2. Secure Authentication & Identity Verification

Access to DrGodly accounts requires robust multi-factor authentication (MFA), including support for WebAuthn, FIDO2 hardware tokens, and biometric device authentication. Doctor accounts undergo mandatory National Provider Identifier (NPI) verification and state medical license credentialing before gaining platform access.

3. Cryptographic Data Protection & Key Management

All data at rest is encrypted using military-grade Advanced Encryption Standard (AES-256) with unique cryptographic envelope keys per tenant. All communications between your device, our servers, and video consultation feeds operate across Transport Layer Security (TLS 1.3) with strict forward secrecy and HTTP Strict Transport Security (HSTS).

4. Role-Based Data Access Controls & Least Privilege

Our engineering infrastructure strictly adheres to the principle of least privilege. Internal engineers cannot view unencrypted patient health records. Technical access to underlying infrastructure requires hardware-backed authentication, ephemeral access approvals, and time-bounded sessions.

5. Comprehensive Audit Logging & Traceability

Every viewing, edit, export, or transmission of protected health data is recorded in an immutable, append-only audit trail. Patients can request a complete disclosure log of every individual and clinical entity that has viewed any segment of their records.

6. Data Retention, Export & Cryptographic Deletion

You have the right to request the complete deletion of your account and medical history at any time. Upon verified deletion request, personal data is cryptographically shredded across all active production storage systems within 30 days, subject only to mandatory clinical record retention laws that may apply to completed clinical encounters.

7. Clinical Document Ingestion Security

Uploaded laboratory panels, discharge summaries, and external clinic PDFs are scanned for malware within isolated sandbox environments prior to processing. OCR extraction takes place in isolated memory environments without caching unencrypted binary payloads to insecure shared storage.

8. AI Processing & Zero-Retention Architecture

DrGodly AI processes patient narratives and medical documents solely for the purpose of organizing context and generating clinical decision support during your consultation. Patient health records are NEVER used to train public or foundational third-party AI models. We enforce zero-retention data policies with our dedicated compute partners.

9. Doctor-Led Care & Clinical Decision Support Safeguards

DrGodly is an intelligence and documentation tool designed to support patients and clinicians. It does not issue autonomous diagnoses, order prescriptions independently, or substitute for physician clinical judgment. A licensed human doctor leads every encounter, reviews pre-visit summaries, and retains ultimate authority over patient diagnosis and treatment.

Exercise Your Patient Privacy Rights

You may request an export of your longitudinal clinical record or submit a data deletion request at any time through your account portal or by contacting our dedicated data protection officer.