The important part is section one: your activity and your identity live in two separate databases, and nothing in the product returns both at once.
MD-Universe holds two separate databases. One stores what you post and read, under an anonymous handle. The other stores who you are — your name, email, and NPI — encrypted, and is only opened for the things that need it, like logging you in or showing your name in the directory you chose to appear in.
No part of the product returns your handle and your real identity together. That is a deliberate architectural constraint, not a policy promise, and it is why anonymous participation stays anonymous even to us in ordinary use.
At signup: your legal name, email address, NPI number, credential, and specialty. Your NPI is checked against the public NPPES registry to confirm you are a licensed physician. Your email and NPI are stored encrypted.
As you use the product: the posts, comments, and listings you create; what you bookmark; and compensation figures you choose to contribute. Compensation is only ever shown to others as an aggregate across a specialty, never as your individual figure.
If you opt into the patient-facing directory: the practice details you enter yourself — address, phone, languages, insurance accepted, and where you see patients. Everything in that listing is there because you typed it and switched it on.
Technical data: basic request logs used to keep the service running and to investigate misuse.
No patient information. MD-Universe is not a clinical system, is not for discussing identifiable patients, and is not covered by a HIPAA business associate agreement. Do not post anything that identifies a patient.
No payment card details. We do not process card payments, and nothing in the product asks for one.
No advertising trackers, and no selling of member data to anyone, for any purpose.
Public, to anyone: article headlines and their opening lines, and the marketing pages.
Members only: full articles, comments, job and gig listings, vendor offers, deal listings, the member directory, and compensation aggregates.
Patients and the public, but only if you opt in: your MyCare listing. It is off by default, you choose every field in it, and you can switch it off at any time.
Nobody, ever: the link between your anonymous handle and your real identity.
Service providers who run the infrastructure: our hosting, database, and email delivery vendors. They process data on our instructions to operate the service and for nothing else.
The public NPPES registry, which we query with your NPI at signup to verify your licence. NPPES is a public federal directory and the query is a lookup, not a disclosure of anything you gave us privately.
Law enforcement, only where we are legally required to, and only to the extent required.
You can edit or delete anything you post, edit your directory and MyCare listings, or switch either listing off entirely.
You can ask us to close your account and delete your personal data. Write to us and we will action it. Aggregated, de-identified figures that no longer point to you — such as your contribution to a specialty median — may remain, because they cannot be traced back.
You can ask for a copy of the personal data we hold about you.
Identifying data is encrypted at rest and held in a separate database from your activity. Passwords are stored hashed, never in a readable form. Sessions use short-lived tokens.
No system is perfectly secure. If a breach affects your personal data, we will tell you.
The iOS and Android apps collect exactly what the website does and nothing more. They do not access your contacts, photos, location, microphone, or camera.
Your login is stored in the device keychain (iOS) or keystore (Android), not in ordinary app storage.
This policy may change as MD-Universe grows. Material changes will be posted here with a new date, and continuing to use the service means accepting them.
Last updated 6 August 2026. Questions, or a request to see or delete your data, go to contact@md-universe.com.