Privacy policy
What we collect
- Visitors: search terms and locations (not tied to you), and the name, contact details, and short message you choose to send in an appointment request. We ask you not to include health information.
- Clinicians: account details, license and identity documents (stored encrypted), profile content, and billing handled by Stripe.
- Technical: standard server logs and, if you consent, analytics cookies.
How we use it
To run the directory, verify clinicians, send appointment requests to the clinician you chose, and improve coverage in places patients search. We do not sell personal information.
Your rights
You can ask for a copy of your data, ask us to delete it, or ask us to remove an unclaimed profile of you at doctordirectory.ai/privacy-requests. We confirm every request by email and act quickly, usually the same day and always within 30 days. Signed-in clinicians and sponsors can download or delete their data instantly from the Account page.
We do not sell or share personal information, so there is nothing to opt out of under the CCPA "do not sell or share" right; the right is honored by default. California, EU, and UK residents have the same rights as everyone else here: access, correction, deletion, portability, and the right to complain to your data protection authority.
Clinicians in the public registry can request removal of an unclaimed profile at any time, and removed records are never re-imported.
How long we keep things
Accounts and profiles: until you delete them. Appointment requests: 24 months, then deleted. "Notify me" requests: until you unsubscribe or we email you about a match, whichever is later, plus 12 months. Unclaimed registry profiles: six months from import unless claimed. Server logs and rate-limit counters: 30 days. Records we must keep for billing or legal reasons (invoices, deletion receipts) are kept only as long as the law requires.