A timeline, newest first
Documents filed by type, date, facility and tags, merged with visits and appointments, undated documents last instead of guessed at. A misread date has a correction path.
Works todayAvailable now
In build
The whole team
Nineteen specialists, each with a defined job and an honest status label.
See all nineteenA chronological timeline of what you upload, a search that is refused and recorded the moment it sounds clinical, and deletion that reaches everything it touches — per record, per profile, or immediately on request. There is no column anywhere in this product for a value, a unit or a reference range — the shape a lab result would need to be interpreted rather than filed.
How it works
Three steps, and the second one stops short of the thing Doctor cannot honestly answer.
Log a document with what it plainly says about itself — type, date, issuing facility, the clinician's name as printed — or add it from a photo. Every field is stated by the document or typed by the person; nothing is derived from reading it for meaning, which is what keeps the timeline a filing system rather than a clinical record. A misread date is corrected, not silently overwritten.
Search is literal, over filing metadata and the person's own notes — never over what a document says. A clinical-sounding query, the kind a habit types without thinking, is classified before it runs and never executed: the search route returns 400 and writes a recorded escalation to the person's own clinician instead, because an empty result would itself have been a clinical answer.
Withdraw a consent in one call, export everything held, or file an erasure request that runs immediately rather than joining a queue. Deleting a single record or a whole profile both work today; a profile deletion cascades in application code rather than a database cascade, specifically so the count of what was removed can be returned and audited.
The boundary
The specification once imagined Doctor extracting a lab report's parameter rows itself — name, value, unit, reference range. What shipped is narrower than that on purpose: comparing a value to a range is where transcription ends and interpretation begins, so that triple has nowhere in Doctor's schema to land. Doctor receives document type, date, facility and clinician from a digitised lab report — never the value, the unit or the reference range. That triple is withheld by a positive allowlist matched on field name, not by a convention someone could forget, and a nested copy of the same field is refused for the same reason. There is no value column, no unit column and no reference-range column anywhere in Doctor's own tables to put it in.
Refusing is the feature
Every reference product in this category treats search as harmless, because a search only ever finds what is already there. Doctor treats a diagnostic-shaped query as the exception: it is checked before it is classified, and the refusal path itself writes to the database, so the record that somebody asked survives independently of whatever the client does next.
Deletion that reaches everything
A person filing health records for a parent or a child is trusting this product with the one category of data where 'we deleted most of it' is not an acceptable answer. Doctor's DPDP consent dashboard is built around the three actions the Act actually names — access, correction, erasure — plus the fourth, nomination, and erasure does not wait in a queue.
What it does
Each card carries its own limit, and the label is derived from the backend's capability module rather than written here — nothing on this page can award itself a stronger status than the code supports.
Documents filed by type, date, facility and tags, merged with visits and appointments, undated documents last instead of guessed at. A misread date has a correction path.
Works todayA photo is staged as its own row and only becomes a filed record through a mandatory confirm step you drive — never automatic, so a misdetected type can't silently land in the wrong family member's profile. Edge detection, perspective correction and type/date classification need a document-AI credential this deployment hasn't set; without it, you supply the type and date yourself at confirm time.
Needs a credentialPer-person profiles with everything filed under one of them. A dependent profile is refused unless it names the guardian who consented, re-checked when a date of birth is corrected downward.
Works todayDate, facility, clinician and the person's own note about why they went, linkable to records in the same workspace. Nothing reads the note.
Works todayA fixed catalogue of neutral, open-ended questions works with no credential. Personalising them to your own notes calls the platform LLM, and every candidate line is independently filtered before it can be stored — must read as a question, no dosage numbers, no diagnostic-assertion patterns — and falls back to the same fixed catalogue if the LLM is unconfigured or every line it wrote is rejected, so you're never left with nothing.
Needs a credentialName, dose and frequency stored exactly as entered, optionally linked to the prescription record. No interaction check, no dose validation, no adherence score.
Works todaySchedules are stored and validated as local wall-clock times with a zone, so a dose does not shift when the person travels. Dispatch needs a push or SMS provider.
Needs a credentialFilename, MIME type, size, checksum and scan state are registered and scoped through their record. Storing and serving the bytes needs object storage with managed keys and malware scanning; there is no download route until both exist.
Needs a credentialA complete machine-readable export of everything held works now — and so does a share bundle: a scoped, single-use hashed token with a required expiry and an optional view cap, revoked instantly and checked live on every access. What it hands over is filing metadata plus visit notes, medications and appointments — never the underlying scanned file itself, which needs the same managed object storage and malware scanning document-vault-storage is still waiting on.
Needs a credentialSearch over filing metadata and the person's own notes, filterable by profile, type and date range. A clinical-sounding query is never executed as a search.
Works todayAppointments tracked per profile and filtered to genuinely upcoming ones; status is only ever set by the person. Reminder delivery needs a push or SMS provider; calendar export is not built.
Needs a credentialPurpose-scoped consents that must name the notice version shown, one-call withdrawal, all four DPDP request types with erasure executed immediately and receipted with counts, full export, and per-record retention with an explicit purge.
Works todayA lab report is digitised in full on the shared platform, parameter rows included, and Doctor receives only document type, date, facility and clinician. Scanned reports need an OCR credential.
Built, with limitsA shared caregiver role — invite, view-only or view-and-add, revoke instantly — with the bearer token shown once and stored only as a hash. The view link re-derives invited/active/revoked/expired live from the grant's own timestamps on every access, so a revoke takes effect immediately rather than only blocking a future login. A bearer-token holder is never extended write access beyond viewer today, whatever role they're invited as.
Works todayEvery field is copied verbatim from your own filed records, medications, visits and appointments and frozen at creation, so a later edit can't silently rewrite a brief already handed to a clinician. The PDF and public share views render as a self-contained HTML page rather than a byte-level PDF file — a browser's own Print to PDF covers that — and a share link expires and can be revoked outright.
Works todayA fixed, generic default catalogue — vaccination record, current prescription, recent lab report, insurance document, discharge summary — plus your own custom items, computed live against what's actually filed rather than cached. Copy is neutral by design (present or not; never 'overdue' or 'at risk'), and there is no age- or condition-specific item anywhere on this surface — a 'diabetic, should have an HbA1c every three months' rule would be a care schedule, which this stays out of.
Works todayA per-user language preference and a genuinely translated string table for Doctor's own labels — document types, relationship names, navigation — with no placeholder text padded in; an incomplete language reports its fallback keys explicitly instead of quietly mixing languages. There is deliberately nowhere on this surface to route an uploaded document's own content, or a filed record's free text, to translation — only Doctor's own interface text is ever translated.
Works todayAn ABHA address is validated and declared per profile, and a consent request is scoped to one facility, one purpose and one required expiry so nothing here can express a blanket 'always allow' grant. Nothing reaches the real government system yet: this deployment has no ABDM Consent Manager gateway credentials, so every request sits in a requested/blocked_no_gateway state and fetching records always refuses, naming exactly what's missing rather than returning an empty list you could misread as 'no records exist'. Even with the gateway credentials set, going live also needs HIU registration and certification — a government relationship, not a feature flag.
Needs a credentialNot built yet
The trend chart isn't a backlog item to knock out next — it's left out because a chart with an implied line reads as a clinical verdict even with no text saying so, the same interpretation boundary the missing value column already protects.
Not built, and it does not follow automatically once digitisation does: a chart with an implied trend line reads as a clinical verdict even with no text saying so, which is the same interpretation boundary the missing value column already protects.
Everything above is traced to a route, a model or a status entry in the code, and a test fails the build if the two drift apart. That is engineering honesty, not clinical review. Before this page goes live for real patients and caregivers, a qualified clinician or a health-data-privacy reviewer should read the boundary claims specifically — not to check that they are true of the code, which the tests already do, but to confirm they read correctly to someone who is not a developer. Saying that here is a trust signal, not an admission: a page about a health product that skipped this step would be the more surprising outcome.
Before you switch
Tell us what you are currently keeping in a folder, a drawer or a phone gallery, and we will tell you exactly what Doctor can organise today — and what still needs your own clinician.
Questions
No, and it cannot by construction. Doctor receives document type, date, facility and clinician from a digitised lab report — never the value, the unit or the reference range. That triple is withheld by a positive allowlist matched on field name, not by a convention someone could forget, and a nested copy of the same field is refused for the same reason. There is no value column, no unit column and no reference-range column anywhere in Doctor's own tables to put it in. Comparing a value to a range is where transcription ends and interpretation begins, and that is a clinician's judgement, not this product's.
The search never runs. The query is classified before it is executed, and a clinical-sounding one is refused with a 400 and turned into a recorded question toward your own clinician instead — the escalation is written to the database before the refusal is even raised, so the record that you asked survives even if your connection drops right after.
You can delete a single record, or a whole profile. Deleting a profile cascades through every document, medication, reminder, appointment and visit filed under it in application code rather than a database cascade, specifically so the counts of what was removed can be returned to you. A DPDP erasure request runs immediately, not on a queue, and its own record is the receipt.
No. Building a timeline, managing family profiles, logging visits, tracking medications, searching your own filing, inviting a caregiver, the completeness checklist, regional-language labels and the full DPDP consent dashboard all work today with nothing configured. Several things need a credential you add later — storing the actual file bytes needs object storage, reminder delivery needs a push or SMS provider, and linking through ABHA needs an ABDM gateway credential — and each one says so on its own card below rather than pretending to work until it silently doesn't.
Yes, as separate profiles under one account, each with its own timeline. A profile for a minor or a dependent is refused unless it names the guardian who consented, and that check re-runs if a date of birth is later corrected downward, so an edit cannot quietly remove a consent requirement that used to apply.
It transcribes what a document states about itself — type, date, facility, the clinician's name as printed — and files it. It does not summarise, rank or comment on what any value in the document means. The two free-text fields that do exist hold the person's own words about their own visit or appointment, and nothing in this codebase ever parses, summarises or classifies them.