DoctoPalDoctoPal
DashboardHealth AssistantInteraction CheckerCalendar
Medical Disclaimer: DoctoPal is an educational wellness tool and does not provide medical diagnosis or treatment. All recommendations are based on published scientific research. Always consult your healthcare provider before starting any supplement or making changes to your medication.
DoctoPal
© 2026 DoctoPal. All rights reserved

Evidence Meets Nature. AI Meets You.

Privacy Policy|Terms of Service|About|hello@doctopal.com

Evidence-based integrative medicine · Backed by peer-reviewed research

Security

The security of your health data is our top priority. Here are the security layers that keep you safe.

Data Encryption

All health data is encrypted in transit with TLS 1.3 and at rest with AES-256 encryption.

KVKK & GDPR Compliance

Full compliance with Turkish KVKK and EU GDPR regulations. You have the right to download and delete your data.

Authentication

Secure session management with Supabase Auth. Google and Facebook OAuth, email verification supported.

Infrastructure Security

Hosted on Vercel, Supabase PostgreSQL database. DDoS protection, automatic backups.

Access Control

Every API endpoint requires authentication. Rate limiting (10 requests/minute) enforced.

Data Minimization

Only necessary data is collected. Health data stored in encrypted columns. Maximum 2-year retention.

Input Validation

All user inputs are sanitized. Protection against XSS, SQL injection, and other OWASP threats.

Error Monitoring

Real-time error monitoring and performance tracking with Sentry. Security events reported instantly.

Found a security vulnerability? Please report it to us.

security@doctopal.com