Your information and choices
Privacy Notice
DoctorAI is a health organisation and education service, not a healthcare provider. This notice explains what information the website and mobile app use, why it is needed, and how you can control it.
Information you choose to provide
This can include medications, appointments, measurements, symptoms, health notes, documents, research topics and questions sent to DoctorAI. Do not add information you do not want processed by the service.
Account information
If you sign in with Google, DoctorAI receives the account identifier, email address, name and profile image Google provides. DoctorAI does not receive your Google password.
Device and account storage
Unsigned-in hub information can remain in browser or app storage on that device. When you sign in and secure storage is available, approved hub information is encrypted before being stored for your DoctorAI account.
Documents
Private document uploads require sign-in and configured secure storage. Files are encrypted before storage. DoctorAI fails closed when secure document storage is unavailable.
AI processing
When you select Send, your message is sent to the configured AI provider to generate a response. If you switch on Health Memory, the approved details selected there may also be sent with your question. A medication-label photo is sent to OpenAI for text extraction only after you check the separate scan-consent box. DoctorAI sets the OpenAI Responses API store option to false for this scan, but OpenAI says API content may still appear in abuse-monitoring logs for up to 30 days by default. We have not confirmed a shorter-retention exception for DoctorAI's API project; do not assume zero retention. OpenAI says API data is not used to train its models by default. DoctorAI cannot delete OpenAI's provider logs directly. See OpenAI API data controls. You review extracted details before saving them. Label scanning does not check medication safety. AI output can be wrong and is not a diagnosis or treatment recommendation.
Medication database checks
NZF/NZULM product searches and interaction checks are currently disabled. If activated after written provider approval, a product search sends the single medicine name or package barcode entered in the browser to the DoctorAI server, which forwards it to NZF/NZULM only after separate consent. An interaction check sends one confirmed product-ID entry per saved medicine (blank for unmatched items) from the browser to the DoctorAI server. DoctorAI calculates the unmatched count and forwards only unique, confirmed NZMT product IDs to NZF/NZULM after a separate one-time consent; medication names, doses, schedules, free-form notes, scan images, allergies, conditions, and symptoms are not forwarded to NZF/NZULM. Provider request logging, retention, cross-border handling, and display rights must be confirmed before activation. The disabled DrugBank ingredient-level screening prototype requires a signed licence for consumer safety use, written New Zealand ingredient-scope confirmation, approved modules, and credentials. If activated, DoctorAI receives matched ingredient and health-risk identifiers, internal medication IDs, and unmatched counts, then sends only provider-required ingredient and risk identifiers to DrugBank. Medication names, doses, schedules, notes, and scan images are not sent to DrugBank. DrugBank logs API requests. This is ingredient-level, not New Zealand product-level, screening; unmatched or incomplete records remain unchecked. A database result does not establish that a medicine is safe for you.
Billing
Stripe processes subscription checkout, billing and promotion codes. DoctorAI sends Stripe account and plan details needed for billing, but does not send your health-hub content or medical documents.
Other service providers
DoctorAI may use Vercel for hosting and server functions, Google for sign-in, Stripe for billing, OpenAI for requested AI features and consented medication-label text extraction, Europe PMC for research search, and Resend for authorised account emails. NZF/NZULM may be used for medicine catalogue matching and interaction checks only after written provider approval and separate user consent. The DrugBank ingredient-level safety prototype is disabled; it requires a signed consumer-use licence, written New Zealand scope confirmation, approved modules, and credentials before it can be used. Any other licensed provider used for allergy, condition, or adverse-effect screening will be named here before activation. Each provider processes information needed for its role, as described above.
Optional public-resource page counts
The medication list template and appointment checklist offer optional, cookie-free Vercel Web Analytics page counts. Counting starts only after you choose “Allow for this visit” on that page. “No thanks”, Global Privacy Control and Do Not Track keep it off. Your choice lasts for that page visit and is not saved. Every counted visit reports the same generic canonical resource URL. The pages and analytics script use a no-referrer policy, so they do not send the referring-page URL. This feature does not collect medicine entries, appointment checklist entries, Health Hub content, names or account identifiers, and it does not record button use. It adds no analytics code to the Health Hub. Vercel may derive aggregate browser, device and location statistics from incoming requests, using visitor hashes that expire after 24 hours rather than analytics cookies. Counting can fail or be blocked, so these are partial page counts, not completed sign-ups or purchases. See Vercel Web Analytics privacy details.
Retention and deletion
You can export or delete hub information from Privacy controls. When signed in, deletion checks your account document list and removes private documents and the account copy before clearing your local record. If any step fails, deletion is reported as incomplete; some files may already be removed. Retry while signed in and connected. Deleting while signed out does not delete an account copy.
Security
DoctorAI uses signed sessions, access controls, encrypted server storage and restricted staff routes. No online service can guarantee absolute security, so use a protected device and sign out on shared devices.
Your choices
- Use the hub without adding optional health information.
- Choose whether to sign in and sync.
- Review information before sending it to AI.
- Export or delete saved hub information.
- Contact support about account or privacy requests.
Children and emergencies
The current paid founding-member beta is for adults aged 18 or older. Do not use it to store or manage another person's health information. DoctorAI is not an emergency service or a substitute for a qualified clinician. If you may be in immediate danger, contact your local emergency service.
Contact
For privacy, account or deletion questions, email support@doctoraiworld.com. The notice will be updated when data practices materially change.
