Privacy Policy
Derrick is a women's health network. People trust it with health questions, so this page is written plainly rather than defensively. Last updated 8 August 2026.
1Who we are
Derrick ("we", "us") operates this website and connects patients in India with verified women's health doctors. For any privacy question, or to exercise any right described below, write to info@derrickgynohub.com.
2What we collect
If you are a patient
- Account: your name, email address and a password you choose.
- Contact: a mobile number, so a clinic can call you back. It is not used to sign in.
- Enquiries and appointment requests: your city, the doctor or speciality you asked about, and whatever you write in the message.
- Community questions: anything you post on Ask a Doctor. These are shown publicly and are not attached to your name.
- Optional profile photo, if you upload one.
If you are a doctor
- Professional identity: name, qualifications, medical council registration number and council, year of registration, years of experience.
- Verification documents: degree and post-graduate certificates, council registration proof and a government photo ID.
- Practice details: clinic name, address, timings, contact number, specialities and services.
- Photographs you upload of yourself and your clinic.
Automatically
- IP address, used only to rate-limit sign-in attempts and one-time codes so accounts cannot be attacked by brute force.
- Approximate location, only if you grant browser permission, and only to sort doctors by distance. It is not stored on our servers.
We do not run advertising or analytics trackers, we do not build advertising profiles, and we do not buy personal data from anyone.
3How your credentials are protected
- Passwords are hashed with bcrypt (cost factor 12) before they are stored. We hold the hash, not your password. Nobody at Derrick can read it, and it cannot be reversed — which is why a forgotten password must be reset rather than recovered.
- One-time email codes are hashed too, expire after ten minutes, are single-use, and are destroyed after five incorrect attempts. Requests are rate-limited per address and per network.
- Sessions are signed tokens held in
httpOnly,secure,sameSite=laxcookies, so page scripts cannot read them. Patients, doctors and administrators each get a separate cookie — one role can never reach another's area. - All traffic is encrypted in transit over HTTPS.
4Where it is stored
- Database: MongoDB Atlas, on access-controlled managed infrastructure, reachable only by this application with credentials that are never exposed to your browser.
- Images: profile and clinic photographs are held on Cloudinary and served publicly, because they appear on public profiles anyway.
- Verification documents are treated differently.They are stored with authenticated delivery, so a direct link returns an error rather than the file. They are streamed only through a route that re-checks an administrator's session on every single request. No shareable link to a doctor's ID or certificate is ever produced.
- Email is sent over an authenticated SMTP connection for verification codes, password resets and account notices.
5What we never do
- We do not sell, rent or trade your personal data. Not to advertisers, insurers, pharmaceutical companies, data brokers or anyone else.
- We do not charge patients for anything, and we never ask a patient for card or bank details. Any message claiming otherwise is not from us.
- We do not share a patient's enquiry with doctors other than the one it is routed to.
- We do not publish a doctor's verification documents, and other doctors never see them.
- We do not use your health questions to train advertising or recommendation profiles.
6Who can see what
- The doctor an enquiry is assigned to sees your name, city, phone number and message — that is how they call you back.
- Our verification team sees doctors' documents, solely to run the 5-step check.
- The public sees a doctor's professional profile and approved patient reviews. Reviews show only the display name given.
- Service providers — our database, image storage and email providers — process data strictly to run the service, and cannot use it for their own purposes.
- Authorities, only where the law requires it.
7Cookies
Derrick sets three cookies and none of them track you:
- Session cookie — keeps you signed in. Removed when you log out.
- Language preference — remembers the language you picked.
- Cookie acknowledgement — so the notice does not reappear on every visit.
There are no advertising, analytics or social-media cookies, and no third party sets a cookie on this site.
8How long we keep it
- One-time codes: ten minutes, then deleted automatically.
- Accounts: for as long as the account exists. Ask us to delete it and we will.
- Enquiries and appointment records: kept while they are needed for the clinic relationship, then removed.
- Verification documents: kept while a doctor is listed, so their status can be re-checked, and deleted when the listing ends.
9Your rights
You can ask us to show you what we hold about you, correct anything wrong, delete your account and its data, or stop using it in a particular way. Write to info@derrickgynohub.com and we will respond within 30 days. You do not need an account to make a request, and asking costs nothing.
10Children
Derrick is intended for adults. If you are under 18, please use it with a parent or guardian. We do not knowingly create accounts for children, and we delete any we find.
11Changes
If this policy changes we will update the date at the top, and for anything significant we will say so on the site. Continuing to use Derrick after a change means you accept it.
