Your medical information deserves a clear explanation of how it is handled.
This policy explains what WhatDx processes, why it is used, the role of third-party providers, and what happens to a case after its active research window.
1. Who operates WhatDx
WhatDx is operated by What dx, India. For privacy or data-related questions, contact contact@whatdx.com. You may also use the alternative founder contact at undefined.santaaaaa@gmail.com.
2. Information we process
WhatDx does not require a conventional user account for a research case. You are not required to provide an email address, phone number, social-media login or real name merely to create or reopen a token-based case.
However, the service is designed to process health information that you choose to provide. This may include age, sex or other medically relevant characteristics, symptoms, diagnoses, treatments, medication history, responses to treatment, family or personal medical history, free-text answers, and uploaded records such as laboratory reports, prescriptions, imaging reports, scans, photographs or other medical documents.
We also process technical and operational information needed to run the service, such as a hashed research-token identifier, timestamps, case state, workflow status, model-usage records, purchase and payment references, security information, and diagnostic or error logs where enabled.
3. How we use information
We process information to provide and operate WhatDx, including to reconstruct a case history, maintain a longitudinal research state, ask follow-up questions, analyze uploaded material, conduct AI-assisted research, generate case outputs, reopen an active case when new evidence arrives, verify purchases, issue research tokens, provide support, prevent abuse, maintain security, and troubleshoot the service.
We may also process information where reasonably necessary to comply with applicable law, respond to lawful requests, protect users or the service, and maintain accounting or transaction records. Where applicable, we rely on your consent and other lawful grounds permitted by applicable law.
4. AI, research, payment and infrastructure providers
Relevant portions of the information you submit may be sent to third-party service providers that help operate WhatDx. Depending on the configuration in use at the time, these may include AI providers such as OpenAI, Anthropic and Google/Gemini, web-research services, payment services such as Razorpay, and hosting, security, logging or infrastructure providers.
The exact hosting provider or server location may change as WhatDx develops. We therefore do not promise that information will always be stored with a particular hosting company or in a particular city or country. Information may be processed in locations where our service providers operate, subject to applicable law and the arrangements we maintain with those providers.
WhatDx is not designed to store full payment-card numbers or card security codes. Payment information entered into Razorpay checkout is handled by Razorpay under its own terms and privacy practices; WhatDx retains the payment and order references needed to verify the transaction and provide access.
5. Research window, locking and retention
A WhatDx research token currently provides an active research window of 90 days. During that period, the associated case can ordinarily be reopened and updated in accordance with the service rules.
After the active research window ends, the case may be locked. A locked case cannot be modified through the normal research workflow. Where the service continues to make an existing dossier or case output available, this is provided for convenience and should not be treated as permanent storage.
Locked or expired case data may be deleted without prior notice. You should download and safely retain any case output or information you want to keep before or at the end of the active research period. WhatDx does not guarantee indefinite storage, archival retrieval or recovery of an expired case.
Payment, security, fraud-prevention, accounting, legal or operational records may be retained separately for longer where reasonably necessary or required by law. Temporary purchase-recovery information may also be kept for a limited period to allow an interrupted checkout to be recovered.
6. Your research token
Your research token is the credential used to access the associated case. The plain token is intended to remain under your control; stored case folders are associated with a cryptographic representation of that token.
You are responsible for keeping the token secure. Anyone who obtains it may be able to access the associated case. Do not publish it or send it through ordinary email unless WhatDx specifically asks you to use an appropriate support process. Losing a token may mean losing practical access to the case.
7. Adults and information about minors
WhatDx is intended to be used by people aged 18 or older. A person under 18 should not independently purchase or operate a WhatDx case.
A parent or legal guardian who is 18 or older may use WhatDx on behalf of their minor child where they have authority to provide and process the child's information. The parent or guardian is responsible for the information submitted and for deciding, together with qualified healthcare professionals, how any output should be used.
8. Security
WhatDx uses technical and organizational measures intended to reduce unauthorized access or loss, including token-based access, hashed identifiers, protected server directories, file validation, session protections and transport security when correctly deployed. No internet service can guarantee absolute security.
You should also protect your own copy of the token and any downloaded dossier or medical records. Avoid using shared devices or insecure storage for sensitive information.
9. Your choices and privacy requests
You may choose what information to provide, subject to the information reasonably required to run the research process. Do not upload information that you are not authorized to share.
To ask a privacy question or request access, correction or deletion where available under applicable law, email contact@whatdx.com. Because WhatDx is token-based and may not know your real-world identity, we may need reasonable evidence that you control or are authorized to act for the relevant case before acting on a request.
Do not include the full research token or unnecessary medical records in an ordinary email unless specifically requested through an appropriate support process.
10. Browser storage and similar technologies
WhatDx may use essential browser storage, session cookies and similar technologies to keep the application functioning, maintain security, remember an in-progress checkout or recover an interrupted purchase. These technologies are used for service operation rather than for building a conventional advertising profile.
11. Changes to this policy
We may update this Privacy Policy as the product, providers, legal requirements or operating practices change. The current version will be posted on this page with an updated effective date. Material changes may also be highlighted in the service where appropriate.