Privacy, Safety & Identity Protection
BloodOS operates as a non-profit emergency humanitarian network. We handle health and contact records with extreme clinical restraint, automated privacy controls, and zero commercial monetization.
Algorithmic Phone Masking
All Bangladesh phone numbers are publicly redacted to 01XXX***XXX to stop scrapers and unsolicited harassment.
56-Day Cooldown Ledger
Post-donation biological lockout is calculated strictly by automated system rules to protect donor cardiovascular and erythropoietic recovery.
Zero Brokerage Guarantee
We never buy, sell, broker, or monetize blood or donor records. Commercial exchange of blood is strictly illegal and blocked on our platform.
Permanent Data Erasure
Donors and recipients retain absolute sovereignty over their data with 1-click irreversible account erasure and clinical log de-identification.
1. Governance & Scope
BloodOS is an open humanitarian clinical coordination protocol purpose-built to accelerate emergency blood matching across Bangladesh. This Privacy Policy governs all interactions with the platform across web, mobile viewports, and automated emergency notification channels.
By accessing BloodOS or registering as a donor or requester, you acknowledge that your operational details (such as blood group, district, and emergency status) will be processed strictly in accordance with this document to facilitate life-saving blood transfers.
2. Information We Collect
Donor Profile Records
Collected upon voluntary registration to determine donation compatibility and geographic proximity:
- Full Legal Name & Verified Email
- Blood Group & Rh Factor (A+, B+, O+, AB+, etc.)
- Primary Phone Number (Bangladesh 11-digit)
- District & Upazila Jurisdiction
- Last Donation Date (for 56-day cooldown)
- Availability Flag (`isAvailable`)
Emergency Blood Request Records
Submitted when an urgent transfusion requirement is logged by a patient, attendant, or hospital coordinator:
- Patient Name or Identifier
- Hospital Name, District & Address
- Units Required & Target Transfusion Date
- Urgency Tier (STAT Emergency vs Standard)
- Hospital Attendant Contact Number
- Clinical Reason for Transfusion
3. How We Process Your Data
BloodOS enforces strict data minimalism. Data collected is used exclusively for the following operational workflows:
Automated cross-checking of ABO/Rh compatibility and geographic proximity within 64 districts.
Delivering real-time alerts and notifications to eligible matched donors when STAT alerts trigger.
Detecting duplicate requests, spam bots, and unauthorized commercial middlemen seeking blood products.
4. Automated Phone Masking Standard
To eliminate unsolicited commercial messages, identity theft, and harassment of female and vulnerable donors, BloodOS implements cryptographic server-side phone redaction:
01712***890
Only first 5 digits (operator/prefix) and last 3 digits remain visible for audit reference.
Direct full contact is unveiled strictly after an authenticated donor formally commits via “I Can Help” or hospital coordinator verification.
5. 56-Day Cooldown & Clinical Integrity
Under standard clinical guidelines (Directorate General of Health Services & WHO), a whole-blood donor must rest for at least 56 days (8 weeks) between donations to allow complete red blood cell regeneration and hemoglobin recovery.
BloodOS maintains an automated biological ledger. When a donation is marked confirmed, the donor's profile is instantly flagged as ineligible until the 56-day cooldown reaches zero. This metric is computed deterministically and cannot be manually overridden without administrative clinical review.
6. Zero Brokerage & Non-Commercialization
Blood is a humanitarian gift, not a commodity.
BloodOS operates with an absolute zero-tolerance policy against commercial blood brokerage, extortion, or paid matching. We do not sell user data to pharmaceutical entities, insurance brokers, advertisers, or third-party marketing brokers. Any account found demanding financial compensation for blood will be permanently suspended and reported to law enforcement.
7. Your Data Rights & Right to Erasure
You hold complete legal sovereignty over your personal records stored within BloodOS:
You can update your phone, district, availability, and donation history at any time from your Profile.
You can request full account deletion. All contact information is wiped and historical logs are permanently anonymized.
8. Technical & Clinical Security Safeguards
Our production infrastructure deploys multiple defensive perimeters to secure your medical information:
- End-to-End TLS 1.3 Encryption: All transit data between client browsers, Next.js servers, and MongoDB clusters is strictly encrypted.
- Role-Based Access Control (RBAC): Administrative audit terminals require dual-factor authorization and maintain immutable tamper-evident logs.
- No Plaintext Credential Storage: Passwords and session tokens utilize Argon2/Bcrypt cryptographic salting through Better Auth.
9. Data Protection Officer & Inquiries
For formal data access requests, clinical audit inquiries, or reporting unauthorized contact disclosures, reach our Data Protection & Ethics Committee: