Telling patients a prescription is ready
Setting this up takes about a minute. The slow part is not the software — it is deciding what to call yourself, because the handle ends up on a poster and cannot be changed afterwards.
What this actually looks like
A prescription that is ready and a patient who does not know it is a second trip for them and a shelf you cannot clear. A sealed channel carries the collection reference and nothing else: “Ref 8842 — ready for collection.” There is no name in the alert and no contact detail in the system, so there is no list that can leak.
How you would set it up
- Create a private channel and give out its invite QR code at the counter, on the collection slip.
- Send the reference and the collection window. Never a medicine name — everyone who joined the channel can read it.
- Use the same channel for the notices everybody needs: opening hours, the duty rota, a stock shortage.
Private means sealed, not merely unlisted
A private channel is not one that is simply missing from a directory. It requires an invite code both to subscribe AND to read anything about it, and a request without one gets exactly the same “not found” as a handle that never existed — because a different answer would let anybody confirm that a school’s or an ops team’s channel exists by guessing its name. Invite codes can carry a use limit and can be revoked; revoking is a timestamp and by default removes nobody who already joined.
Nothing that could identify anybody
Subscribing needs no account, no email address and no phone number. What a subscription actually holds is a random identifier the app generated, a platform, an app version, a language and a time zone — coarse enough that hundreds of millions of people share one. There is no name, no contact detail, no advertising identifier and no location, and there is no export that would let an operator build one. You cannot leak a list you never collected.
Three numbers, and the one we will not print
You get: how many devices could be reached at the moment you sent, how many phones reported opening the alert, and how many acknowledged it. What you do not get is a delivery rate, because there is no per-device delivery record anywhere in this product — that absence is exactly what makes sending to four million people cost the same as sending to four. Reads and acknowledgements are self-reports from handsets that chose to send one, and they are labelled as such rather than dressed up as receipts.
Questions, answered plainly
Can somebody find my private channel by guessing the name?
No. A sealed channel answers a request without an invite code with exactly the same “not found” that a nonexistent handle gets. There is no response that distinguishes “this exists but you may not see it” from “this does not exist”, because that difference is itself a leak.
What do you collect about somebody who subscribes?
A random identifier the app generated, a push token, the platform, the app version, the language and the time zone. No name, no email address, no phone number, no location, and no advertising identifier. Subscribing needs no account at all.
Why is there no delivery rate?
Because there is no per-device delivery record anywhere in the product, and that is a deliberate design decision rather than a gap. A phone’s inbox is a query over sent alerts, which is what makes the cost independent of audience size. We would rather show three numbers we can stand behind than a fourth we invented.
Do subscribers need an account?
No. They install the app, subscribe to a handle, and that is the whole of it. Only the person running the channel signs up for anything.
Say it once. Every subscribed phone gets it.
Free up to 100 subscribers, no card to start, and the handle is yours permanently.
Start a channel