Cookie Policy
DocVerb separates patient identity from clinical documentation. Our server architecture is designed to exclude direct patient identifiers such as names, phone numbers, email addresses, dates of birth, government IDs, locations, and other demographic attributes from clinical processing, storage, and indexing. Clinical conversations are processed exclusively to extract relevant medical information for generating SOAP notes and prescriptions, without creating patient identity profiles.
Only SOAP notes, prescriptions, and a doctor-specific anonymous UID are securely stored. This UID maintains continuity of care exclusively within the same doctor–patient relationship without creating a universal patient identity.
1. Introduction and Philosophy
DocVerb is designed with data minimisation principles. We use cookies and similar tracking technologies sparingly—only what is essential for the Service to function, plus optional analytics you can control. This policy explains what cookies are, which ones we use, why, and how you can manage them.
Clinical documentation is protected using encryption and never exposed to cookie-based tracking. The treating healthcare provider remains responsible for clinical decisions; DocVerb assists with documentation and workflow.
2. UID Architecture and Cookie Interaction
DocVerb employs a Unique Identifier (UID) architecture that fundamentally separates patient identity from clinical data. This section explains how our cookie usage aligns with this architecture.
2.1 Core UID Principles
- No patient-identifying information stored: Only SOAP notes and prescriptions are stored on our servers. Patient names, contact details, and demographic data are never uploaded.
- Name/details shown once, never uploaded: During the first process, patient name and details appear on the clinician's screen for verification but are never transmitted to or stored on our servers.
- UID is anonymous by design: The UID is not linked to human identification on our servers. A patient cannot be identified from the UID alone.
- External linkage only: A patient can only be identified if the UID is explicitly shared from the outside world (e.g., by the clinician or patient themselves).
- Doctor ID + Patient ID matching required: Clinical data is inaccessible without a valid Doctor ID and Patient ID pair match. Without this match, data remains cryptographically inaccessible.
- Four-factor identification: The only way to identify a specific clinical record is through the combination of Doctor ID + Patient ID + UID + Timestamp—all four factors must align.
2.2 Cookie Implications
Because of the UID architecture, no cookies contain or can reveal patient-identifying information. Our cookie usage is strictly limited to:
- Doctor session authentication: Cookies like
dv_sessionanddv_refreshauthenticate the doctor's session only—not patient identity. - No patient-session cookies: There are no cookies that track, identify, or correlate patient data across sessions.
- No cross-patient tracking: Cookies cannot link clinical records between patients or associate a UID with a real-world identity.
- Analytics anonymity preserved: Optional analytics cookies (
_ga,_gid) operate on aggregated, anonymized usage patterns with zero clinical content and no UID exposure.
This architecture ensures that even if cookies were compromised, they would yield no patient-identifying information—only the authenticated doctor's session state.
3. What Are Cookies
Cookies are small text files placed on your device (computer, tablet, phone) when you visit a website. They store information about your visit—such as authentication state, preferences, or aggregated usage statistics. Similar technologies include localStorage, sessionStorage, IndexedDB, and tracking pixels. This policy covers all such technologies.
Cookies can be:
- Session cookies: Expire when you close your browser
- Persistent cookies: Remain until deleted or they reach their expiry date
- First-party cookies: Set by DocVerb (docverb.com and subdomains)
- Third-party cookies: Set by embedded services (payment, email, monitoring)
4. Categories of Cookies We Use
We group cookies into four categories. Only Essential cookies are placed without consent; Analytics, Preferences, and Security cookies require your opt-in via our consent banner.
4.1 Essential (Strictly Necessary)
These cookies enable core functionality: authentication, session management, security, and fraud prevention. They cannot be disabled without breaking the Service.
4.2 Analytics (Optional)
Aggregated, anonymized usage data to understand feature adoption and improve the product. No clinical content or patient identifiers are ever included. You can opt out at any time.
4.3 Preferences (Optional)
Remember your UI choices (theme, language, sidebar state, template defaults) so you don't re-configure on each visit.
4.4 Security (Optional)
Support fraud detection, rate limiting, and anomaly detection to protect your account and the platform.
5. Specific Cookies Table
| Name | Purpose | Duration | Type |
|---|---|---|---|
| dv_session | Active session token (JWT in HttpOnly cookie) | Session | Essential |
| dv_refresh | Refresh token for seamless re-authentication | 30 days | Essential |
| dv_csrf | CSRF protection token for form submissions | Session | Essential |
| dv_2fa_pending | Two-factor authentication challenge state | 10 minutes | Essential |
| dv_consent | Records your cookie category consent choices | 1 year | Essential |
| dv_theme | UI theme preference (light/dark/system) | 1 year | Preferences |
| dv_locale | Language/locale selection | 1 year | Preferences |
| dv_sidebar_state | Sidebar collapsed/expanded state | 1 year | Preferences |
| dv_template_default | Default specialty template selection | 1 year | Preferences |
| _ga | Google Analytics: distinguishes users (anonymized IP) | 2 years | Analytics |
| _ga_XXXXXXXX | Google Analytics 4: session persistence | 2 years | Analytics |
| _gid | Google Analytics: session grouping | 24 hours | Analytics |
| _gat | Google Analytics: request rate throttling | 1 minute | Analytics |
| dv_analytics_consent | Records analytics opt-in/opt-out | 1 year | Analytics |
| dv_fraud_score | Risk scoring for login anomaly detection | Session | Security |
| dv_rate_limit | Client-side rate limit bucket | 1 hour | Security |
6. Third-Party Cookies
We embed limited third-party services. Their cookies are subject to their own policies. We only load them after consent (where required) or when strictly necessary for the service.
6.1 Payment Processing
- Razorpay / Stripe: Set cookies for fraud prevention (Radar), 3D Secure authentication, and checkout session management. Cookies:
__stripe_mid,__stripe_sid,rzp_*. Duration: session to 1 year. See Stripe Cookie Policy and Razorpay Cookie Policy.
6.2 Transactional Email
- SendGrid / Postmark: Track email delivery, opens, and clicks for account notifications (welcome, billing, security alerts). No marketing emails. Cookies:
sg_*,pm_*. See respective provider policies.
5.3 Error & Performance Monitoring
- Sentry: Session replay (anonymized), error breadcrumbs, performance traces. No clinical content captured. Cookie:
sentry_*. See Sentry Cookie Policy.
7. Consent Management
6.1 Cookie Banner
On first visit, a banner appears with:
- Accept All (Essential + Analytics + Preferences + Security)
- Reject Non-Essential (Essential only)
- Granular Controls (per-category toggles)
- Link to this Cookie Policy
Essential cookies are always active. Non-essential categories default to OFF.
6.2 Granular Controls
Click "Cookie Settings" in the footer (or banner "Manage Preferences") to toggle Analytics, Preferences, and Security categories independently. Your choices are saved in dv_consent and dv_analytics_consent.
6.3 Withdrawal of Consent
You can withdraw consent at any time via the Cookie Settings link. Withdrawal:
- Deletes non-essential cookies on next page load
- Stops future non-essential cookie placement
- Does not affect Essential cookies or prior processing
8. How to Disable Cookies via Browser
Most browsers allow you to block or delete cookies:
- Chrome: Settings → Privacy and security → Cookies and other site data
- Firefox: Settings → Privacy & Security → Cookies and Site Data
- Safari: Preferences → Privacy → Manage Website Data
- Edge: Settings → Cookies and site permissions → Manage and delete cookies
- Mobile browsers: Settings within the browser app (Safari iOS, Chrome Android)
You can also install extensions like uBlock Origin, Privacy Badger, or Ghostery for finer control.
9. Impact of Disabling Cookies
| Category Disabled | Impact |
|---|---|
| Essential (not recommended) | Cannot log in; sessions expire immediately; CSRF protection fails; Service unusable |
| Analytics | No impact on functionality; we lose aggregated usage insights |
| Preferences | Theme, language, sidebar, template reset on each visit |
| Security | Reduced fraud detection; may trigger additional verification steps |
10. Changes to This Policy
We may update this Cookie Policy to reflect changes in our practices, technology, or law. Material changes will be notified 30 days in advance via email and in-app banner. The "Last Updated" date at the top reflects the latest revision. Continued use after changes constitutes acceptance.
11. Related Legal Pages
- Privacy Policy — overall data practices, your rights, DPDP/GDPR compliance
- Terms of Service — contractual terms for using the Service
- Security — technical safeguards, encryption, incident response
- DPDP Compliance — India-specific obligations under the Digital Personal Data Protection Act
- Data Retention Policy — how long we keep each data type
12. Contact
Questions about this Cookie Policy or your consent choices:
docverb.no.reply@gmail.com (Subject: Cookie Policy)