
Privacy Policy
Privacy Policy
Effective date: July 14, 2026 · www.docz.com/privacy-policy
This Privacy Policy explains how Docz collects, uses, discloses, and protects information in connection with the Docz physician-only collaboration platform.
1. Scope
Docz is intended for licensed physicians and approved medical professionals. It is not a patient-facing service. This Privacy Policy applies to information collected through the Docz app, website, admin tools, and related services.
2. Information We Collect
Account Information
We may collect name, email address, phone number, authentication information, specialty, professional affiliation, NPI or license-related information, verification status, profile photo, biography, and other account details.
Professional Verification Information
We collect and process professional credential information to determine whether an account should be approved, rejected, suspended, or reviewed.
User Content
We collect content users submit, including curbsides, comments, replies, images, votes, feedback, DoczAI interactions, and profile content.
Usage Information
We may collect app activity, device information, logs, IP address, timestamps, crash data, diagnostic information, notification activity, and interaction data such as views, comments, replies, and helpful votes.
PHI and Sensitive Content
Users are instructed not to submit patient-identifying information. If users submit content that may contain PHI or other sensitive information, Docz may process that content for moderation, safety review, audit, and service operation. If an administrator confirms that content contains PHI, the flagged text is removed or redacted and is not retained in our audit records — audit logs retain only the fact and timing of the moderation action, not the flagged content itself.
3. How We Use Information
We use information to create and manage accounts; verify professional eligibility; provide the app and community features; display curbsides, replies, profiles, and notifications; operate DoczAI summaries and context features; detect and review potential PHI; moderate content and enforce policies; maintain security and prevent abuse; provide support; improve reliability; and comply with legal and professional obligations.
4. DoczAI and Automated Processing
DoczAI may process user-submitted curbsides, replies, and related discussion content to generate summaries, contextual responses, and source-oriented outputs. DoczAI output is not medical advice and must be independently verified by users.
5. Sharing and Disclosure
We may share information with other verified users as part of app functionality; with service providers who help operate Docz; with administrators and moderators for verification, safety, and support; when required by law, legal process, or professional obligation; to protect the rights, safety, security, and integrity of the service; and in connection with a business transaction such as a merger, acquisition, financing, or asset transfer. We do not sell personal information.
Service Providers (Sub-processors)
Docz uses the following named service providers. Each receives only the data necessary to perform its function:
Supabase — hosting, database, authentication, and file storage. Has access to data stored by the app.
Anthropic — AI summary and response features (DoczAI). Receives post and comment text and author names; does not receive images.
Resend — transactional email delivery. Receives name and email address only, not message content.
Apple Push Notification service — push notification delivery. Receives generic notification copy only, not post or comment content.
NPPES / CMS NPI Registry — professional license and NPI verification lookup.
6. Data Storage and Security
Docz uses technical and organizational measures designed to protect information. No system can guarantee complete security. Users are responsible for de-identifying clinical content before posting.
7. Data Retention
Docz retains information as needed to operate the service, maintain audit logs, comply with legal obligations, resolve disputes, enforce agreements, and support safety and moderation workflows.
Deleting your account is immediate and permanent. Your profile is anonymized (name, email, phone, NPI, and other identifying fields are removed), your uploaded photos are purged from storage, and your login credentials are deleted. We retain only a minimal, de-identified record that an account deletion occurred and when, for security and audit purposes. This cannot be undone.
8. Your Choices
You may update profile information, manage notification settings, and contact support with privacy questions. Account deletion is permanent and irreversible, as described in Section 7 — there is no separate, reversible "deactivation." You may also request a copy of the personal information Docz holds about you by contacting support; data access and export requests are currently fulfilled manually by the support team.
9. Not a HIPAA-Covered Repository
Docz has not entered into Business Associate Agreements with its service providers and is not intended to be a HIPAA-covered repository for protected health information. Users must not submit PHI. The PHI detection and moderation described here are a safety net, not a substitute for user de-identification.
10. Professional and Institutional Obligations
Users remain responsible for complying with HIPAA, state privacy laws, licensing board rules, employer policies, institutional policies, and other professional obligations that apply to their use of Docz.
11. Children's Privacy
Docz is not intended for children or patients. Users must be approved medical professionals.
12. International Users
Docz may process information in the United States or other locations where service providers operate.
13. Changes to This Policy
Docz may update this Privacy Policy from time to time. Continued use after updates means the updated policy applies.
14. Contact
Questions about privacy or this policy: israelzyskind@yahoo.com.
There are no published blog posts yet.
