DoctoPalDoctoPal
DashboardHealth AssistantInteraction CheckerCalendar
Medical Disclaimer: DoctoPal is an educational wellness tool and does not provide medical diagnosis or treatment. All recommendations are based on published scientific research. Always consult your healthcare provider before starting any supplement or making changes to your medication.

DoctoPal — Health Information Tool

Not a medical device. Does not diagnose or treat.

DoctoPal
© 2026 DoctoPal. All rights reserved

Evidence Meets Nature. AI Meets You.

Privacy Notice|Terms of Service|Security|Intended Purpose|Distance Sales Agreement|Subscription Agreement|About|info@doctopal.com

Evidence-based integrative medicine · Backed by peer-reviewed research

DoctoPal

Loading your health companion...

Security

The security of your health data is our top priority. Here are the security layers that keep you safe.

Data Encryption

All your health data is encrypted in transit with TLS 1.3 and at rest with industry-standard AES-256. With Supabase Row Level Security (RLS) policies, every user can access only their own data — even our own engineers cannot read your records without your permission.

KVKK & GDPR Compliance

Full compliance with Turkey's Law No. 6698 (KVKK) and the EU's GDPR. You can export all of your data at any time, and deleting your account permanently erases every piece of personal information. Sensitive health data is processed only with your explicit consent and you can revoke it whenever you want.

AI Safety

Our 5-layer AI safety system protects every response: emergency keyword detection, drug–herb interaction checks, contraindication scanning, dosage limit enforcement, and a transparency score on every output. The AI never makes a medical diagnosis — it provides information, and each answer is delivered with a reliability score so you know how confident the system is.

Authentication & Access

Secure session management is powered by Supabase Auth. You can sign in with Google or Facebook OAuth, or email and password — your password is never stored in plain text. Cloudflare Turnstile bot protection blocks automated attacks before they reach your account.

Infrastructure Security

We run on Vercel's edge network with a Supabase PostgreSQL database hosted in the EU. Built-in DDoS protection, automatic daily backups, and isolated serverless functions keep the platform stable and resilient against attacks.

Access Control

Every API endpoint requires authentication and is scoped to the logged-in user. Rate limiting (10 requests/minute on sensitive endpoints) blocks abuse, and all admin actions are logged in an audit trail you can request at any time.

Data Minimization

We collect only what is necessary for the service to work. Your data is retained while your account is active and is permanently erased when you delete your account. AI requests are anonymized — your name, email, ID, phone, and address are stripped before being sent to any external model.

Input Validation

All user inputs are sanitized at the API boundary. We protect against XSS, SQL injection, prompt injection, and other OWASP Top 10 threats with both library-level guards and our own AI-specific filters.

Error Monitoring

Real-time error monitoring and performance tracking with Sentry catches issues before they affect you. Security events are reported instantly to our team, and personal data is scrubbed from logs to keep your information private.

Data Transfers and Standard Contractual Clauses (SCC)

International data transfer per KVKK Article 9

DoctoPal processes user data with the following service providers:

  • •Supabase (İrlanda/AB) — Data storage and database management
  • •Anthropic Claude API (ABD) — AI analysis (anonymized data only)
Standard Contractual Clauses (SCC) have been signed with both providers in accordance with KVKK Art.9. The agreements were notified to the KVKK Board within 5 business days. Data sent to the AI API does not contain names, emails, national ID numbers, phone numbers, addresses, or user IDs. Only anonymized medical parameters (age range, gender, medication list, allergy information) are transmitted.

Anonymization and Re-identification Risk Analysis

Compliant with KVKK Generative AI Guide (November 2025)

Anonymization process:

  • •Identity information (name, email, national ID, phone, address, user ID) is completely removed
  • •Age is converted to age range (e.g., 22 → "18-24")
  • •City/location information is not transmitted
  • •Every anonymization operation is logged and auditable

Re-identification risk assessment:

The data set sent to AI (age range + gender + medication list + allergies) cannot be used to directly identify an individual because:

  • •No direct identifiers (name, email, national ID) are transmitted
  • •Age is transmitted as a range, not exact
  • •No location/address information is transmitted
  • •Thousands of people in Turkey share similar medication combinations

Data Breach Response Plan

Steps we follow in case of a data breach, per KVKK Article 12:

  1. 1. Detect the breach and determine its scope
  2. 2. Contain the breach and secure the system
  3. 3. Notify the KVKK Board within 72 hours (kvkk.gov.tr)
  4. 4. Inform affected users
  5. 5. Document the breach report
  6. 6. Update preventive measures

KVKK Board Contact

ihlalbildirim.kvkk.gov.tr

ALO 198

kvkk@kvkk.gov.tr

Notification deadline: 72 saat / 72 hours

DoctoPal Security

security@doctopal.com

contact@doctopal.com

Found a security vulnerability? Please report it to us.

security@doctopal.com