Notifying patients at a practice
Setting this up takes about a minute. The slow part is not the software — it is deciding what to call yourself, because the handle ends up on a poster and cannot be changed afterwards.
What this actually looks like
Most of what a practice needs to tell patients is not personal at all: the surgery is shut on Friday, the flu clinic opens on Monday, the phone lines are down. A sealed channel carries those to everybody who joined it, and carries a reference number when it needs to point at one person without naming them.
How you would set it up
- Create a private channel for the practice and print its invite QR code on the appointment card.
- Send practice-wide notices as they happen, and schedule the seasonal ones — flu clinics, holiday cover — weeks ahead.
- Never put a diagnosis, a result or a medicine in an alert. A reference and “please call us” does the same work and identifies nobody.
Private means sealed, not merely unlisted
A private channel is not one that is simply missing from a directory. It requires an invite code both to subscribe AND to read anything about it, and a request without one gets exactly the same “not found” as a handle that never existed — because a different answer would let anybody confirm that a school’s or an ops team’s channel exists by guessing its name. Invite codes can carry a use limit and can be revoked; revoking is a timestamp and by default removes nobody who already joined.
Nothing that could identify anybody
Subscribing needs no account, no email address and no phone number. What a subscription actually holds is a random identifier the app generated, a platform, an app version, a language and a time zone — coarse enough that hundreds of millions of people share one. There is no name, no contact detail, no advertising identifier and no location, and there is no export that would let an operator build one. You cannot leak a list you never collected.
Draft, schedule, send — and what cancelling cannot undo
Composing and sending are deliberately different permissions, so the person or script that writes an alert can be forbidden from publishing it. A scheduled alert becomes visible at its time without anything having to run at that minute, which means a server that was briefly down delivers late rather than never. Cancelling is honest about its limits: it stops an alert reaching phones that have not fetched it yet and does nothing at all to the phones that already have it. An alert cannot be unsent.
Questions, answered plainly
Can somebody find my private channel by guessing the name?
No. A sealed channel answers a request without an invite code with exactly the same “not found” that a nonexistent handle gets. There is no response that distinguishes “this exists but you may not see it” from “this does not exist”, because that difference is itself a leak.
What do you collect about somebody who subscribes?
A random identifier the app generated, a push token, the platform, the app version, the language and the time zone. No name, no email address, no phone number, no location, and no advertising identifier. Subscribing needs no account at all.
Can I unsend an alert?
No. Cancelling stops it reaching phones that have not fetched it yet, and does nothing to the ones that already have it. Compose as a draft and read it back before you send; that habit is worth more than any undo button we could offer.
Do subscribers need an account?
No. They install the app, subscribe to a handle, and that is the whole of it. Only the person running the channel signs up for anything.
Say it once. Every subscribed phone gets it.
Free up to 100 subscribers, no card to start, and the handle is yours permanently.
Start a channel