Last reviewed: this policy is versioned in our CMS; the "Last updated" date shown above reflects the most recent change.
NoSTDs ("we", "us", "our") operates a confidential platform for STD testing verification, a directory of clinics and labs, and consent-based sharing of a person's verified test status. This Privacy Policy explains what information we collect, how we secure it, when it is shared, and the choices and rights you have. We designed the platform around a simple principle: you control who sees your health status, and we collect as little as we need to make that work.
1. Information We Collect
1.1 Account & identity information
When you register we collect your name, email address, phone number, and a password. To protect these identifiers we store searchable fields (such as email and phone) as one-way blind-index hashes rather than as plain lookups, and each account is referenced internally by a random UUID rather than a sequential ID. If you enable two-factor authentication, we store the secret needed to verify your one-time codes.
1.2 Health & test information
The core of the service is your test data. This may include: STD test results (for example a positive/negative outcome and a result summary) uploaded by a partner clinic or lab, verification records and their status, self-declarations you choose to add, and private notes attached to your account. Health-related fields are encrypted at rest. Private notes are readable only by you.
1.3 Booking & directory activity
When you book a test with a clinic or lab in our directory, we record the booking, the selected test/service, and the clinic contact you used to confirm. Clinics see the booking details necessary to serve you.
1.4 Sharing & consent records
When you share your verified status, we generate a share token and log access to it (for example, when a shared link is viewed). These logs let you see who accessed what and let us rate-limit abuse of public share links.
1.5 Payment information
Paid subscriptions and applicable services are processed through our payment gateway (Razorpay). We do not store your full card or bank details on our servers — those are handled by the gateway. We retain records of your subscription, invoices, and transaction status (including amounts, which we store in the smallest currency unit).
1.6 Device, security & usage signals
To detect fraud and protect accounts we may record device fingerprints, IP-derived signals, and fraud indicators. We also keep basic operational logs and, where you consent, analytics about how the site is used.
1.7 Connected third-party platforms
If you choose to connect a dating platform, we store the connection and a token needed to share your status with that platform. You can disconnect at any time.
2. How We Use Your Information
- To create and secure your account and authenticate you (including two-factor authentication).
- To ingest, validate, and display your verified test results and verification status.
- To let you book tests with clinics/labs and to let those partners serve your booking.
- To generate share links and enforce the consent scope and expiry you select.
- To process subscriptions and payments and to send transactional receipts.
- To detect fraud, abuse, and unauthorized access, and to keep the platform safe.
- To send you service notifications through the channels you enable (email/SMS), subject to your notification preferences.
- To comply with legal obligations and enforce our Terms.
3. How Your Status Is Shared (Consent)
Your verified status is never public by default. Sharing happens only when you create a share, and each share carries a tier/scope (what the recipient can see) and an expiry. Depending on the tier, a recipient may see only a verified/non-disclosure confirmation, or a fuller report. You can review access logs and revoke a share. Public share links are rate-limited to reduce enumeration and abuse.
4. When We Disclose Information to Others
- Clinics & labs (partners): receive the booking and result information necessary to provide their service to you.
- API partners: approved integrators may perform a status lookup using an API key. Responses are limited to a status/result signal and do not expose your raw identifiers beyond what is necessary for the lookup you initiated or consented to.
- Recipients you choose: anyone you send a share link to, within the scope and expiry you set.
- Service providers: our payment gateway and infrastructure providers, bound by contract.
- Legal: where required by law, regulation, or valid legal process.
We do not sell your personal or health information.
5. Data Security
We apply layered safeguards: encryption of sensitive health fields at rest, blind-index hashing of searchable identifiers, token-based (Bearer) authentication, optional two-factor authentication, device/fraud signals, and access controls (policies) that restrict records to their owner. No system is perfectly secure, but we work to promptly detect, contain, and record any data-breach incident.
6. Data Retention & Deletion
We keep your information for as long as your account is active or as needed to provide the service and meet legal obligations. You can request deletion of your account; deleted records are purged through our scheduled clean-up process. Some records (for example, invoices) may be retained where the law requires.
7. Your Rights & Choices
- Access & export: you can export your data from your account settings.
- Correction: update your profile details at any time.
- Deletion: request account deletion.
- Communication preferences: control email/SMS notifications in Settings.
- Withdraw consent: revoke shares and disconnect connected platforms.
8. Children
The platform is intended for adults. We do not knowingly collect information from anyone under the age required to consent to medical testing in their jurisdiction.
9. Changes to This Policy
We may update this policy as the service evolves. Material changes will be reflected here with a new "Last updated" date.
10. Contact Us
Questions about your privacy? Reach us through the Contact page or at our support email.