Placeholder
Privacy
This deployment is a demonstration. It holds no real patient data and collects nothing about visitors beyond what is needed to keep a session open.
What the demo stores
- A session cookie, so the read-only demo identity survives a page refresh. It expires after eight hours.
- A preference cookie recording whether you collapsed the navigation rail.
- Nothing else. There is no analytics script, no third-party tag, and no advertising identifier — the Content-Security-Policy on every response blocks outbound requests to other origins.
The clinical data you see
Every patient, clinician, appointment, transcript and note in this application is synthetic and generated from a fixed seed. None of it corresponds to a real person or a real encounter.
What is not claimed
No compliance with HIPAA, the DPDP Act, GDPR or any other framework is claimed. A real deployment handling real health information would need controls this project does not implement.