This page is not yet available in ml-IN. You are reading the en-IN version.
Security
How access works
Every request that touches a patient record resolves the caller's relationship to that specific patient — owner, guardian, caregiver, clinician, viewer, or a member of an organisation that holds a grant — and then checks whether that role is permitted the specific action. A record you have no relationship with returns "not found" rather than "forbidden", so the API cannot be used to discover who exists.
An organisation can restrict a staff member to particular wards, and that restriction applies to notifications as well as to screens: a nurse scoped to ward 2 is not paged about ward 3.
Sign-in
By one-time code to your phone. There is no password, because a password is a second door and the weaker door sets the security of the whole building. Sessions last 90 days and you can list and end every one of them, on every device, from inside the app. Ending a session also revokes that device's push token, so a lost phone stops receiving reminders that name your medicines.
Storage
Prescriptions and photographs live in private object storage and are served only through authenticated requests. Uploads are checked by content, not by filename — a file claiming to be a JPEG is rejected if it is not one.
What we do not do
We do not use third-party analytics or advertising SDKs. We do not log the contents of reminders. Support staff can look up an account to diagnose why a notification failed, and that lookup deliberately cannot return medication, dose or prescription data — knowing what somebody takes is not needed to work out why their phone is silent. Every such lookup is recorded.
Reporting a vulnerability
Write to hello@drbell.app with "Security" in the subject.
We will acknowledge within 72 hours. We will not take legal action against anyone who reports a genuine issue in good faith, who does not access more data than is needed to demonstrate it, and who gives us reasonable time to fix it before publishing. We will credit you if you want to be credited.
Please do not test against other people's accounts. If you need an account to test with, ask and we will make you one.
Who we are
DrBell is operated by Newtact Lab Private Limited (OPC) (https://newtact.in), registered in India.
Grievance Officer: Naveen Kumar Davuluri, Chief Executive Officer and Grievance Officer Email: hello@drbell.app
We answer every message to that address. If you are writing about your own data — to see it, correct it, or have it erased — say so in the subject line and we will treat it as a formal request under the Digital Personal Data Protection Act, 2023.