Privacy starts with restraint

Prototype privacy notice

This proof of concept is intentionally designed without patient-data features.

Prototype notice · Updated July 19, 2026

What this prototype does not request

This static website has no accounts, forms, checkout, uploads, comments, symptom checker, patient messaging, medication profile, or site analytics. It does not ask for names, contact details, symptoms, diagnoses, prescription details, professional-license details, photos, or other personal or health information.

Homepage and member-library search filter the three static guide cards inside your browser. Search text is carried in the URL fragment, which browsers do not send in the page request, and is not submitted to or saved by this site.

Do not send health information.

There is no patient-support inbox or secure clinical messaging channel associated with this prototype.

Video playback

The demonstration videos and poster images are served directly by the same website rather than through an embedded social-video platform. Videos do not autoplay. Your browser requests a video file when you choose to play it, and that request may appear in ordinary hosting and security logs.

Technical hosting records

Like most websites, eventual hosting and security infrastructure may create routine access logs such as request time, IP address, requested path, browser information, and response status. This source-code prototype does not define the live server’s final log fields, retention period, access controls, or deletion process.

The prototype therefore does not make a categorical “zero collection” claim and does not claim HIPAA compliance. Actual hosting and data flows must be reviewed before a final production privacy notice is published.

Planned membership

Future membership plans remain concept-stage. The member preview uses fixed, read-only sample credentials and does not authenticate anyone. This prototype does not create member accounts, accept payment, collect credentials, or verify professional licenses. Those workflows would require separate privacy, security, retention, identity-verification, and access-control decisions before launch.

Before production

A production notice must be reviewed against the deployed host, media delivery, logs, cookies, analytics, payment processing, authentication, license verification, support channels, and every feature that handles personal information. Patient profiles and patient messaging remain outside this proof of concept.

For general background, see the HHS overview of the HIPAA Privacy Rule. Applicability to the eventual business model requires qualified legal and privacy review.