Clinic sharing is a pilot, and the patient’s half is not in the App Store build yet.

The portal on this page is deployed and running. The screens where your patient accepts your invite, ticks the categories and reads the access log are written and tested but not yet released, so a clinic that registers today can create an invite code that a patient’s current app cannot accept. Write to us and we will tell you exactly where that stands before you invite anyone. Everything below describes the portal, which is live — except where a sentence describes what your patient does on their phone, which is those same unreleased screens.

Tiro · For Clinics

See the weeks between
appointments.

Your patients are already logging every dose, every side effect and every weigh-in — in an app they chose, between the appointments you never see. Tiro for Clinics shows you that record, category by category, for the patients who tick the box.

A patient record in the Tiro clinician portal: the patient's name and shared categories, six summary tiles including current dose and weight change, and an estimated medication level chart labelled Model.

A real record from the portal. The patient is fictional.

Every look at a record, logged

Opening a record, taking a copy, reading your own notes on a patient — each one is written to the access log before the data comes back. Your patient sees the same list in their own app.

Seven categories, ticked one at a time

Doses, side effects, weight, nutrition, water, body scans, and the basics about them. Nothing is pre-ticked, and there is no screen anywhere that lets you ask for one they have not given.

No photograph, anywhere

Body-scan images are analysed on the phone and discarded there. The table that receives a scan has no column a photograph could land in — a structural fact rather than a promise.

The Tiro clinician portal patient list: four connected patients flagged for a severe symptom, a missed dose, low protein and silence, one unnamed row awaiting consent, and four tiles under the table — patients, those needing attention, those awaiting the patient, and open invites, which shows a dash rather than a number.

How it works
— three steps, and the patient holds the switch.

  1. 1

    You invite them

    Create an invite from your patient list — a code you read out in the room, or an email. Until they accept it on their own phone there is nothing to open: at most a row that says Awaiting consent — no name, no dose, no weight, and no record behind it.

  2. 2

    They choose what to share

    Seven categories, each with plain-language examples of exactly what it reveals. Nothing is pre-ticked — they tick what they want you to have and confirm it on their phone. That consent is the lawful basis for everything after it.

  3. 3

    The record is live, and so is the log

    From then on it updates as they log. They can see who opened it and when, and turn any category off from their own app without asking you — at which point what it covered is deleted, unless they are still sharing that category with another clinic.

In one patient’s record

  • Doses against the label

    The dose timeline over the schedule they were following, with every dose measured against the manufacturer’s own window rather than against a rule of ours.

  • An estimated level, labelled Model

    Computed from the doses they logged and published pharmacokinetics — never a blood test. It carries the same disclaimer the patient reads and links to the fourteen documents behind it.

  • Side effects as a pattern

    Thirteen symptom types, severity by day, laid beside the days they dosed — so “worse after the increase” is a shape rather than a memory.

  • Weight, with the rate

    The trend and the weekly rate, anchored on their last weigh-in and captioned with which weigh-ins it was measured over.

  • Nutrition as daily totals

    Calories, protein, fibre, carbs and fat per day, against their own targets. Never an individual meal, and never a food photo.

  • Body scans as numbers and a figure

    Every measurement a scan produced, the estimated body fat, and the same 3-D figure the patient sees — rebuilt from nine shape numbers, ten on a female record, not from an image.

  • Everything, in order

    One timeline of the whole period beside the tabs, and a print that reaches all of it including the panels a tab is hiding.

Across the day

  • Who needs attention, and why

    The list opens on the patients a rule fired for: a missed dose, a severe symptom, silence, a phone that has stopped syncing, an invite still unaccepted.

  • A rule you can read back

    Every flag is a sentence you can read back, and six of the seven name the number your clinic can set — a severity threshold, a weekly rate, a quiet period — as yours, or as the default it runs on until you choose. The seventh, a missed dose, rests on no setting of yours.

  • Search and sort over the whole list

    Search by name, and sort the whole clinic by needs-attention, next dose due, weeks at the current dose, last activity, name, or when they connected — paged across the entire clinic, not across the first screen of it.

  • Notes your clinic writes

    Kept against the link and visible to your team. They are read through the same audited path as everything else, so the patient can see that you read them.

  • A record you can print

    The whole thing as a PDF, laid out for paper, for the notes or for the patient to take away.

  • Your own access log

    Every record your clinic opened, every copy taken and every note read, in one filterable place — the clinic’s half of the same log the patient is looking at.

Two of those claims
are screenshots, not adjectives.

The Medication tab of a Tiro patient record: a dosing record timeline against the titration steps, and an estimated medication level chart carrying a Model chip and a Sources link.

The estimate says it is an estimate. The exposure curve carries the word Model, the same disclaimer the patient reads, and a Sources link to the fourteen prescribing documents and papers it is computed from. A clinical estimate whose citation dead-ends is worse than none.

The Access tab of a Tiro patient record, headed 'Who has looked at this record': each entry timed and, where a clinician made it, named — one showing the category read, one a copy taken, one recording that the patient changed what they share.

The log is a screen, not a claim. Every time your clinic opened this patient’s record, and every copy taken, named and timed. The patient sees this same list in their own app — which is what makes it worth anything.

Governance,
written into the database.

None of the five below is a policy we ask you to trust. Each is a check that runs inside the database on every request, which is why we can tell you what it does rather than what we intend.

  • Two factors, enforced in the database.

    Not a preference in the portal. Every clinic function checks for a second factor before it checks your role, so a stolen password reaches no patient record at all — not a dose, not a weight, not a symptom.

  • Explicit consent, Article 9(2)(a).

    Health data needs consent that is explicit, specific and freely given. That is why the sheet is seven separate boxes with examples under each, why none of them starts ticked, and why widening it is something only the patient can do.

  • Revoking deletes what was shared — and your notes on that link with it.

    When a patient ends the link, everything mirrored to us that no other consent of theirs still covers is deleted, and the notes your clinic wrote against that link are deleted unconditionally alongside it.

  • No photographs and no raw scan data.

    There is no image, no mask and no scan debug in what reaches you. What a body scan sends is its measurements and the nine shape numbers — ten on a female record — the figure is rebuilt from.

  • Every look at a record appears on their screen.

    The patient’s own app shows the same list your Access tab does — every record opened, every copy taken, every note read, named and timed. Two things are not on it: the caseload counts above your patient list, and joining the live channel, which reads no record and names nobody. An audit trail only the auditor can read is a filing cabinet; this one is the point.

The same Tiro patient record at 1024 pixels wide, with the timeline stacked above the tabbed panels.

The same record at 1024 wide — the screen a consulting room actually has.

The pilot
— free, and yours to end.

Register your clinic yourself and start inviting patients, or write to us and we’ll set it up with you. Either way you invite your own patients, they consent on their own phones, and nothing costs anything. If it is not useful, stop — and every patient can end their own link without asking either of us. As the notice at the top of this page says, the app screens your patients need for that are not in the current App Store release yet, so talk to us before you invite anyone.

Questions clinics ask,
answered honestly.

No. Tiro for Clinics displays what a patient chose to log and chose to share. It does not diagnose, calculate a dose, or recommend one. The single modelled number on the page — the estimated medication level — is labelled “Model”, carries the same disclaimer the patient reads in their own app, and links to the prescribing information and pharmacokinetic papers it is computed from. Every clinical decision stays with you.

Your patients already keep the record. Ask them to share it.

Write to us and we’ll have your clinic set up and inviting patients the same week — or register it yourself in a couple of minutes.

clinics@tiroglp1.app