Bedside

Security & privacy

Patient data is a responsibility, not a feature

Bedside handles names, contact details and appointment times so your reminders go out on time. This page explains how that data is protected — in plain language, and only claims we can stand behind.

The fundamentals

How your data is protected

Each clinic is walled off at the database

Every clinic's data is isolated with row-level security — rules enforced by the database itself, not just by our application code. Even if a bug slipped past us, the database refuses to hand one clinic's records to another.

Sign in the way you prefer

Use a one-time link sent to your email, your Google account, or a password. Passwordless and Google sign-in mean there is no Bedside password to be stolen or reused; if you do set one, it is stored only as a salted hash by our authentication provider, never in readable form.

Patients can opt out any time

If a patient texts STOP, Bedside stops texting them — automatically, on SMS and WhatsApp alike. Texting START opts them back in. No staff action needed on either side.

Integration keys can't be read back

Keys that connect your practice software to Bedside are stored only as a SHA-256 fingerprint. The full key is shown once, when you create it. After that nobody can recover it — not even us.

A delivery pipe, not a records archive

Bedside's job is to carry messages between your clinic and your patients. It is deliberately not the master copy of your records: your own practice system remains the retention copy, and anything shared through Bedside lives here only for as long as it is needed to be delivered. The less we keep, the less there is to worry about.

Shared report files

Built so a forwarded link is useless

When you share a lab result or a referral letter through Bedside, the patient gets a link. Here is what stands between that link and the file.

The link alone opens nothing

Opening a shared report takes two things: the unguessable link and the patient's date of birth. A forwarded or intercepted link is useless without the other half.

Guessing is rate-limited

Five wrong date-of-birth attempts lock the link for 15 minutes. Working through birthdays by trial and error is not practical.

Links expire, files are deleted

Every report link expires on a schedule your clinic chooses. Once it expires, the file itself is deleted from storage automatically — not just hidden.

Every attempt is on the record

Each access attempt is logged — opened, denied, locked or expired — and the log is visible to your clinic. We record the outcome and the time, nothing more: no IP addresses, no browser details.

Sub-processors

Who handles your data

Bedside runs on a small set of infrastructure providers. Each one touches only the data it needs to do its job.

Supabase

Database, sign-in and file storage (EU-hosted)

Patient records, appointments, message history and shared report files.

Cloudflare

Hosting and delivery of the Bedside app

Traffic between your browser, your patients and Bedside.

Resend

Email sending

Patient name, email address and the content of each email.

Meta (WhatsApp Cloud API)

WhatsApp messaging

Patient phone number and the content of each WhatsApp message.

Google

Optional sign-in with a Google account

The staff member's name and email address, only if they choose Google sign-in.

Questions about any of this?

Good — you should ask. Reach us any time through contact@hamzabuilds.com and we'll answer plainly. See also our privacy policy and terms of service.