What this covers
Infirmy is a marketplace that connects patients travelling for treatment with hospitals and medical facilitators in India. This policy describes what infirmy.com collects, where it is kept, who can see it and what you can ask us to do about it. It describes the site as it is actually built today, not as we intend it to work later.
Infirmy has not opened. No hospital or facilitator on this site has been verified yet, and no patient case has yet been shown to any provider.
The operator of this site is Parve Technologies.
What the case form collects, and why it is health data
If you post a case, the form asks for the condition or diagnosis that needs treating. That is information about your health, and in some countries — including under the EU General Data Protection Regulation and India's Digital Personal Data Protection Act — it is a special or sensitive category that carries extra protection. We treat everything you write in that form on that basis.
A posted case stores:
- the condition or diagnosis you describe, in your own words
- the treatment area, and any specific treatment you say a doctor advised
- who the case is for — yourself, a family member, or someone you are helping
- when you hope to travel, and the budget range you selected
- the city you are travelling from and your preferred city in India
- any free-text clinical notes you add
- your name, and your email address and/or phone number
- the language you asked to be answered in
- the fact that you ticked the consent box, and the date and time we received the case
We keep both the individual fields and a copy of the whole submission as a single JSON record, so that a later change to the form cannot quietly drop something you told us.
We do not ask for, and the form does not have a field for, your passport number, your date of birth, your government identifiers, or your payment details.
We do not accept medical files
You cannot send us a scan, an X-ray, a laboratory result or any other medical document through this website. The case form has no file upload, and we operate no file storage of any kind. We hold no medical images or documents belonging to anybody.
This is deliberate. Medical images and test results are special-category health data, and we are not yet able to hold them to the standard that would require. Until we are, we would rather not have them at all.
From the medical part of the form we store only the text you type: your description of your condition and any clinical notes you add. A hospital that responds to your case will ask you for documents directly, and you would send them to that hospital, not to us.
An earlier version of this form showed an attachment area and then told you your files had been uploaded. They had not been — the file contents never left your browser, and only the file names were stored. That attachment area has been removed rather than fixed, for the reason above. If you posted a case and were told files had been uploaded, assume no file of yours ever reached us.
The other two forms
The provider application, for hospitals and facilitators, stores the organisation name and type, its city, registration and accreditation details as you enter them, specialties, patient volume, languages, and a named contact with their role, email address and phone number. This is business information about an organisation, not patient health data.
The search alert form stores only the treatment, city and budget you were looking for, and the email address you gave, so that we can tell you when there is something to show you.
Both are stored the same way as a case, with the date and time received.
Accounts, passwords and the session cookie
You can browse Infirmy and post a case without an account. If you create one, we store your email address (lower-cased), your name, whether you registered as a patient or as a provider, your preferred language, and optionally your organisation name and phone number.
We never store your password. We store a PBKDF2-SHA256 hash of it, with a random per-account salt and 100,000 iterations. A copy of our database does not contain anyone's password.
When you sign in we set one cookie, named infirmy_session. It holds a random 256-bit token and nothing else — no name, no email, no identifier we could read from it. The cookie is httpOnly (JavaScript on the page cannot read it), SameSite=Lax, marked Secure in production, and it expires after 30 days. Our database stores only a SHA-256 hash of that token, so a leaked copy of the sessions table is not a set of usable logins.
That cookie is strictly necessary to keep you signed in. It is the only cookie this site sets, and if you are not signed in, this site sets no cookies at all.
Signing out deletes the cookie and the session record. Changing your password signs out every other device on the account. There is no password reset yet — see below for whether Infirmy sends email at all.
We do not send email yet
Infirmy has no outbound mail service. That has two consequences you should know about. First, we cannot verify that an email address belongs to you, so nothing on this site treats an email address as proof of identity — a posted case is linked to an account only when you were signed in at the moment you posted it, never by matching addresses afterwards. Second, there is no confirmation message, no password reset link, and no automatic reply. If you post a case, keep the reference number you are shown.
What your own browser stores
If you post a case without being signed in, your browser keeps the reference number locally so that the dashboard can show it back to you. If you save a hospital to your shortlist, that is kept locally too. This information stays on your device and is not sent to us. It is labelled "this browser only" where it appears, and clearing your browser data removes it.
One more marker is kept for the length of the browser tab's session, to record that you have already been counted as having started the case form so that we do not count you five times. It holds nothing about you and disappears when you close the tab.
Analytics
We currently run no analytics on this site and count no visits. We do not use Cloudflare Web Analytics, Google Analytics, an advertising pixel, or a session-recording tool. Nothing tracks which pages you view, so there is nothing to consent to and no cookie banner.
Separately, each time someone moves past the first question on the case form, their browser asks us to record one thing: that a form was started, the language of the page, and the time. That request is allowed to carry only those three facts — never an identifier, an address, or anything you typed — and we do not know, and this document does not promise, that every such request is successfully tallied; nothing about posting your case depends on it either way. If it is being tallied, we use it together with how many cases are actually finished, to tell whether the form is too long.
If we turn on Cloudflare Web Analytics, or any other tool that counts visits, we will describe it here before we do, not after.
Where it is stored, and who processes it
Infirmy runs on Cloudflare. The site itself is a Cloudflare Worker, and everything described above is stored in Cloudflare D1, Cloudflare's hosted SQL database. Cloudflare processes this data on our instructions in order to host the service.
Apart from Cloudflare, this site loads no third-party scripts and sends your data to no other company. Fonts are served from our own domain, not from a font provider.
Infirmy is operated from India and the hospitals on it are in India, but the database itself runs on Cloudflare D1 in the APAC region, currently served from Singapore, with no regional restriction set on where it may run. If you are in the European Union or the United Kingdom, that is a transfer outside your region regardless of which of these countries your data is stored in.
How long we keep it
We keep a posted case until you ask us to delete it. We have not yet set a fixed retention period, and we would rather say so than publish a schedule we do not follow.
Your own expired login sessions are cleared out the next time you sign in. We do not yet run a scheduled sweep for accounts that never come back, so a session row can otherwise sit past its expiry date unused. Everything else stays until it is deleted on request.
Asking us to delete your case, and your other rights
You can ask us to delete your case at any time, and we will. Write to privacy@infirmy.com with the reference number you were given. Deletion is done by hand: we mark the record deleted first, so that a mistake can be undone, and remove it permanently once you confirm.
You can also ask us for a copy of what we hold about you, ask us to correct it, or withdraw your consent. There is no self-service button for any of this yet — every request is handled by a person, at the same address.
Depending on where you live, the law may give you further rights, including the right to complain to a data protection authority. Being in the European Union, the United Kingdom or India gives you rights under, respectively, the GDPR, the UK GDPR and the Digital Personal Data Protection Act, 2023.
Our lawful basis for holding your case is your consent, which you give explicitly on the form and can withdraw. Our basis for the login cookie is that it is strictly necessary to provide the account you asked for.
Grievance Officer
India's IT Rules, 2021 require us to name a Grievance Officer you can complain to about content or conduct on this site, and to state how quickly we respond.
Grievance Officer: Pratik Bhoir.
Write to privacy@infirmy.com to reach them. We acknowledge a complaint within 24 hours of receiving it, and aim to resolve it within 7 days.
This is a separate route from the data-rights request above, though you can use the same address for both — write to us about a deletion, correction or access request the way that section describes, and about anything else through this one.
Children
Infirmy does not accept a case for a patient under 18, and the case form asks and checks this before anything else about the case is collected.
This is a deliberate choice, not an oversight. India's Digital Personal Data Protection Act lets a data fiduciary hold a child's personal data only with verifiable consent from a parent or guardian — evidenced by an identity-and-age check we have no way to perform on a website form. An adult ticking a box that says "I am the parent or guardian" is not that, and the Act's one healthcare carve-out from this rule applies only to a clinical establishment or a registered healthcare professional, not to a marketplace like Infirmy. Rather than hold a child's health information under a promise of consent we could not actually verify, we do not collect it at all.
If the patient turns out to be under 18 partway through a conversation that started here, we still hold nothing about them beyond what this policy already describes for the adult who posted the case.
Changes and contact
If we change how we handle your information, we will change this page and the date at the top of it. For anything in this policy, write to privacy@infirmy.com.
