Skip to content
Infirmy

Privacy policy

What Infirmy collects, where it is kept, who can see it, and how to have it deleted. Written as a description of what this site actually does.

Last updated: 2026-09-12

This document is published in English only, and the English text is the one that applies. If you need it explained in your own language, write to us and a person will.

What this covers

Infirmy is a marketplace that connects patients travelling for treatment with hospitals and medical facilitators in India. This policy describes what infirmy.com collects, where it is kept, who can see it and what you can ask us to do about it. It describes the site as it is actually built today, not as we intend it to work later.

Infirmy has not opened. No hospital or facilitator on this site has been verified yet, and no patient case has yet been shown to any provider.

The operator of this site is Parve Technologies.

What the case form collects, and why it is health data

If you post a case, the form asks for the condition or diagnosis that needs treating. That is information about your health, and in some countries — including under the EU General Data Protection Regulation and India's Digital Personal Data Protection Act — it is a special or sensitive category that carries extra protection. We treat everything you write in that form on that basis.

A posted case stores:

  • the condition or diagnosis you describe, in your own words
  • the treatment area, and any specific treatment you say a doctor advised
  • who the case is for — yourself, a family member, or someone you are helping
  • when you hope to travel, and the budget range you selected
  • the city you are travelling from and your preferred city in India
  • any free-text clinical notes you add
  • your name, and your email address and/or phone number
  • the language you asked to be answered in
  • the fact that you ticked the consent box, and the date and time we received the case

We keep both the individual fields and a copy of the whole submission as a single JSON record, so that a later change to the form cannot quietly drop something you told us.

We do not ask for, and the form does not have a field for, your passport number, your date of birth, your government identifiers, or your payment details.

We do not accept medical files

You cannot send us a scan, an X-ray, a laboratory result or any other medical document through this website. The case form has no file upload, and we operate no file storage of any kind. We hold no medical images or documents belonging to anybody.

This is deliberate. Medical images and test results are special-category health data, and we are not yet able to hold them to the standard that would require. Until we are, we would rather not have them at all.

From the medical part of the form we store only the text you type: your description of your condition and any clinical notes you add. A hospital that responds to your case will ask you for documents directly, and you would send them to that hospital, not to us.

An earlier version of this form showed an attachment area and then told you your files had been uploaded. They had not been — the file contents never left your browser, and only the file names were stored. That attachment area has been removed rather than fixed, for the reason above. If you posted a case and were told files had been uploaded, assume no file of yours ever reached us.

The other two forms

The provider application, for hospitals and facilitators, stores the organisation name and type, its city, registration and accreditation details as you enter them, specialties, patient volume, languages, and a named contact with their role, email address and phone number. This is business information about an organisation, not patient health data.

The search alert form stores only the treatment, city and budget you were looking for, and the email address you gave, so that we can tell you when there is something to show you.

Both are stored the same way as a case, with the date and time received.

Accounts, passwords and the session cookie

You can browse Infirmy and post a case without an account. If you create one, we store your email address (lower-cased), your name, whether you registered as a patient or as a provider, your preferred language, and optionally your organisation name and phone number.

We never store your password. We store a PBKDF2-SHA256 hash of it, with a random per-account salt and 100,000 iterations. A copy of our database does not contain anyone's password.

When you sign in we set one cookie, named infirmy_session. It holds a random 256-bit token and nothing else — no name, no email, no identifier we could read from it. The cookie is httpOnly (JavaScript on the page cannot read it), SameSite=Lax, marked Secure in production, and it expires after 30 days. Our database stores only a SHA-256 hash of that token, so a leaked copy of the sessions table is not a set of usable logins.

That cookie is strictly necessary to keep you signed in. It is the only cookie this site sets, and if you are not signed in, this site sets no cookies at all.

Signing out deletes the cookie and the session record. Changing your password signs out every other device on the account. There is no password reset yet — see below for whether Infirmy sends email at all.

We do not send email yet

Infirmy has no outbound mail service. That has two consequences you should know about. First, we cannot verify that an email address belongs to you, so nothing on this site treats an email address as proof of identity — a posted case is linked to an account only when you were signed in at the moment you posted it, never by matching addresses afterwards. Second, there is no confirmation message, no password reset link, and no automatic reply. If you post a case, keep the reference number you are shown.

What your own browser stores

If you post a case without being signed in, your browser keeps the reference number locally so that the dashboard can show it back to you. If you save a hospital to your shortlist, that is kept locally too. This information stays on your device and is not sent to us. It is labelled "this browser only" where it appears, and clearing your browser data removes it.

One more marker is kept for the length of the browser tab's session, to record that you have already been counted as having started the case form so that we do not count you five times. It holds nothing about you and disappears when you close the tab.

Analytics

We currently run no analytics on this site and count no visits. We do not use Cloudflare Web Analytics, Google Analytics, an advertising pixel, or a session-recording tool. Nothing tracks which pages you view, so there is nothing to consent to and no cookie banner.

Separately, each time someone moves past the first question on the case form, their browser asks us to record one thing: that a form was started, the language of the page, and the time. That request is allowed to carry only those three facts — never an identifier, an address, or anything you typed — and we do not know, and this document does not promise, that every such request is successfully tallied; nothing about posting your case depends on it either way. If it is being tallied, we use it together with how many cases are actually finished, to tell whether the form is too long.

If we turn on Cloudflare Web Analytics, or any other tool that counts visits, we will describe it here before we do, not after.

Where it is stored, and who processes it

Infirmy runs on Cloudflare. The site itself is a Cloudflare Worker, and everything described above is stored in Cloudflare D1, Cloudflare's hosted SQL database. Cloudflare processes this data on our instructions in order to host the service.

Apart from Cloudflare, this site loads no third-party scripts and sends your data to no other company. Fonts are served from our own domain, not from a font provider.

Infirmy is operated from India and the hospitals on it are in India, but the database itself runs on Cloudflare D1 in the APAC region, currently served from Singapore, with no regional restriction set on where it may run. If you are in the European Union or the United Kingdom, that is a transfer outside your region regardless of which of these countries your data is stored in.

Who sees your case

The point of Infirmy is to show your case to hospitals that can treat you, and that happens in two steps rather than one.

Step one. A hospital an operator has verified can see a summary of your case in its lead inbox: the treatment area you chose, the city in India you chose, your budget band, your timeline, and how recently you posted. It does not see your name, your email address, your phone number, the country or city you would travel from, what you wrote about your condition, the treatment you said you were advised to seek, or anything you wrote about your tests and history. Those fields are not sent to the inbox at all.

Step two. A hospital that wants to read the whole case has to ask. We show you the organisation's name and ask you to agree to that organisation specifically. If you agree, that one hospital receives your name, your email address and phone number, the city and country you would travel from, everything you wrote about your condition and your history, and the language you want to be answered in. No other hospital receives anything through that agreement. If you do not agree, nothing further is sent and your case stays open to other hospitals as a summary.

You can withdraw that agreement at any time, in the same place you gave it. Withdrawing stops the hospital reading your case here from that moment. It cannot undo a disclosure that already happened, so if a hospital has already contacted you, ask them to delete what they hold as well — and tell us, and we will ask them too.

We keep a record of each agreement: which case, which organisation, the exact sentence you were shown, the language it was shown in, when you agreed, and when you withdrew. That record exists so that we can show what you were actually asked, rather than describe it afterwards.

As the site stands today, no provider account has been approved, so no real posted case is visible to anybody outside Infirmy. The provider lead inbox shows demonstration data only.

We do not sell personal data, and we do not share it with advertisers or data brokers. We may disclose information where the law requires it.

Provider accounts are approved by a person, by hand, before they could ever see a real lead. Registering as a provider is a claim, not a credential, and an unapproved provider account sees the same demonstration inbox that a passer-by sees.

How long we keep it

We keep a posted case until you ask us to delete it. We have not yet set a fixed retention period, and we would rather say so than publish a schedule we do not follow.

Your own expired login sessions are cleared out the next time you sign in. We do not yet run a scheduled sweep for accounts that never come back, so a session row can otherwise sit past its expiry date unused. Everything else stays until it is deleted on request.

Asking us to delete your case, and your other rights

You can ask us to delete your case at any time, and we will. Write to privacy@infirmy.com with the reference number you were given. Deletion is done by hand: we mark the record deleted first, so that a mistake can be undone, and remove it permanently once you confirm.

You can also ask us for a copy of what we hold about you, ask us to correct it, or withdraw your consent. There is no self-service button for any of this yet — every request is handled by a person, at the same address.

Depending on where you live, the law may give you further rights, including the right to complain to a data protection authority. Being in the European Union, the United Kingdom or India gives you rights under, respectively, the GDPR, the UK GDPR and the Digital Personal Data Protection Act, 2023.

Our lawful basis for holding your case is your consent, which you give explicitly on the form and can withdraw. Our basis for the login cookie is that it is strictly necessary to provide the account you asked for.

Grievance Officer

India's IT Rules, 2021 require us to name a Grievance Officer you can complain to about content or conduct on this site, and to state how quickly we respond.

Grievance Officer: Pratik Bhoir.

Write to privacy@infirmy.com to reach them. We acknowledge a complaint within 24 hours of receiving it, and aim to resolve it within 7 days.

This is a separate route from the data-rights request above, though you can use the same address for both — write to us about a deletion, correction or access request the way that section describes, and about anything else through this one.

Children

Infirmy does not accept a case for a patient under 18, and the case form asks and checks this before anything else about the case is collected.

This is a deliberate choice, not an oversight. India's Digital Personal Data Protection Act lets a data fiduciary hold a child's personal data only with verifiable consent from a parent or guardian — evidenced by an identity-and-age check we have no way to perform on a website form. An adult ticking a box that says "I am the parent or guardian" is not that, and the Act's one healthcare carve-out from this rule applies only to a clinical establishment or a registered healthcare professional, not to a marketplace like Infirmy. Rather than hold a child's health information under a promise of consent we could not actually verify, we do not collect it at all.

If the patient turns out to be under 18 partway through a conversation that started here, we still hold nothing about them beyond what this policy already describes for the adult who posted the case.

Changes and contact

If we change how we handle your information, we will change this page and the date at the top of it. For anything in this policy, write to privacy@infirmy.com.