Skip to main content
Seges Verify

SEGES VERIFY

Privacy Policy

Last updated: August 14, 2026

This page describes only the data practices and unfinished boundaries that Verify can currently re-check. It does not describe or imply an enabled clinic directory, medical certification, or patient service.

1. Scope and current status

Verify's clinic feature is a deployed private evidence workflow, not a public clinic directory, medical-outcome rating, certification badge, or patient service. This page describes the public website preflight and clinic-owner claim flow. It does not certify a clinic, practitioner, treatment safety, or suitability for any person.

2. Public preflight and technical data

When you run the public website preflight, the service uses the connection IP in memory for short, per-instance rate limiting and reads the public HTTPS page you supply. The result is a one-time observation of visible HTML signals; it is not stored as a clinic profile and does not verify server-side data handling. Server error logs may contain a request identifier and technical failure detail for abuse and reliability investigation. This implementation is not a complete retention, deletion, or edge-protection program.

3. Data in the private clinic-owner workflow

The deployed private workflow is a default-closed, invite-only pilot. Invitation eligibility is represented only by an HMAC of the verified Google email; invitations can expire or be revoked, and Google sign-in never creates an account by itself. When an eligible owner uses the flow, it can create or collect: Firebase UID, verified email, display name, and last authentication time; the submitted legal or clinic name, display name, registration number, physical address, phone number, and public website; and domain-control challenge hashes, proof locations, claim records, and audit events. The challenge plaintext is shown only to the claimant at creation; the database retains a SHA-256 digest. These data support a private claim, observed domain control, human review, and dispute traceability, never a conclusion about clinical quality. Do not submit records, test results, images, identity documents, or any other patient data.

4. Sessions and consent records

General administrators use a separate administrator session. The clinic-owner flow uses a signed, httpOnly, SameSite=Lax, path=/, eight-hour session cookie named sv_clinic_token. It grants no reviewer, public-publishing, or medical-certification authority. Claim creation records only the necessary clinic_claim processing purpose; it does not create marketing consent. An eligible signed-in owner may request withdrawal of an unfinished private claim, while evidence and event records are retained rather than silently deleted for auditability.

5. What we do not claim

There are currently no published clinic profiles and no public medical certification, privacy-compliance certification, patient-data handling guarantee, independent audit, automated retention enforcement, or data-deletion portal. If older marketing language, legacy merchant-report text, or a third-party description conflicts with this scope and its limits, this page controls.

6. Corrections, deletion, and contact

Do not submit sensitive information through a form before the private test workflow is actually enabled. If you have submitted data or believe a public preflight describes a website incorrectly, contact us at the address below with the relevant URL and request. We will first verify identity and applicable obligations; this wording is not a completed statutory retention or deletion-time commitment. contact@seges.ai

← Back to the verified-business directory