Security & privacy
Patient data is a responsibility, not a feature
Bedside handles names, contact details and appointment times so your reminders go out on time. This page explains how that data is protected — in plain language, and only claims we can stand behind.
The fundamentals
How your data is protected
Each clinic is walled off at the database
Every clinic's data is isolated with row-level security — rules enforced by the database itself, not just by our application code. Even if a bug slipped past us, the database refuses to hand one clinic's records to another.
Sign in the way you prefer
Use a one-time link sent to your email, your Google account, or a password. Passwordless and Google sign-in mean there is no Bedside password to be stolen or reused; if you do set one, it is stored only as a salted hash by our authentication provider, never in readable form.
Patients can opt out any time
If a patient texts STOP, Bedside stops texting them — automatically, on SMS and WhatsApp alike. Texting START opts them back in. No staff action needed on either side.
Integration keys can't be read back
Keys that connect your practice software to Bedside are stored only as a SHA-256 fingerprint. The full key is shown once, when you create it. After that nobody can recover it — not even us.
A delivery pipe, not a records archive
Bedside's job is to carry messages between your clinic and your patients. It is deliberately not the master copy of your records: your own practice system remains the retention copy, and anything shared through Bedside lives here only for as long as it is needed to be delivered. The less we keep, the less there is to worry about.
Shared report files
Built so a forwarded link is useless
When you share a lab result or a referral letter through Bedside, the patient gets a link. Here is what stands between that link and the file.
The link alone opens nothing
Opening a shared report takes two things: the unguessable link and the patient's date of birth. A forwarded or intercepted link is useless without the other half.
Guessing is rate-limited
Five wrong date-of-birth attempts lock the link for 15 minutes. Working through birthdays by trial and error is not practical.
Links expire, files are deleted
Every report link expires on a schedule your clinic chooses. Once it expires, the file itself is deleted from storage automatically — not just hidden.
Every attempt is on the record
Each access attempt is logged — opened, denied, locked or expired — and the log is visible to your clinic. We record the outcome and the time, nothing more: no IP addresses, no browser details.
Sub-processors
Who handles your data
Bedside runs on a small set of infrastructure providers. Each one touches only the data it needs to do its job.
Supabase
Database, sign-in and file storage (EU-hosted)
Patient records, appointments, message history and shared report files.
Cloudflare
Hosting and delivery of the Bedside app
Traffic between your browser, your patients and Bedside.
Resend
Email sending
Patient name, email address and the content of each email.
Meta (WhatsApp Cloud API)
WhatsApp messaging
Patient phone number and the content of each WhatsApp message.
Optional sign-in with a Google account
The staff member's name and email address, only if they choose Google sign-in.
Questions about any of this?
Good — you should ask. Reach us any time through contact@hamzabuilds.com and we'll answer plainly. See also our privacy policy and terms of service.
