This page is for the clinician, clinic or institution that has to document a decision to use Shifaia Health with patients.
1. What never reaches us, by design
The patient’s name, chart or national ID number, and phone number are entered into dedicated fields, used on your device to print the prescription, and then deliberately dropped before anything is transmitted. The columns that would hold them in our database are written as empty on every save.
Two consequences worth noting, because they are the visible cost of this design:
- Prescription PDFs stored on our servers are anonymised copies — no patient name in the document or its filename. The named copy exists only on your device and in the message you send.
- We cannot offer cloud search by patient name, and never will. That continuity lives on your device only.
2. What does reach us
| Data | Why |
|---|---|
| Your professional account name, email, professional category, licence or syndicate details | To create your account, verify you are eligible to use a clinical tool, and enable or disable prescribing accordingly |
| De-identified clinical data age, sex, weight, symptoms, medications, allergies, comorbidities, lab values, the assessment produced | To generate decision support, run the safety checks, and let you reopen a past consultation |
| Anonymised prescription PDFs | So a patient can be sent a download link. Links expire after 7 days; stored copies are purged as you keep using the app, and always when you delete your account. |
| Operational records token counts, timings, error codes | To run and bill the service. These contain no clinical text. |
3. A second layer over free text
Clinical narratives are written as free text, and text pasted from a referral letter or a report can carry details the structured fields would have kept on the device. Before any free text leaves the device we therefore run an automated redaction pass over it, which removes phone numbers, national ID numbers, record numbers, email addresses and titled names.
This is a backstop, not the primary control — the primary control is that identifiers belong in their own fields, where they stay on your device. The pass is deliberately conservative: it acts on explicit cues rather than guessing, because a redaction that guessed would start deleting clinical words from a document you prescribe from.
4. Our role
- Your professional account data — we are the controller. We decide why and how it is processed and the obligations for it fall on us.
- De-identified clinical data — in our view neither controller nor processor applies, because data that does not identify a person is not personal data. We do not rest on that alone; the safeguards below apply to it regardless.
- Any patient personal data that does reach us — we are your processor. You remain the controller. The commitments in section 8 govern that case and are given to you directly.
5. Who else is involved
Every third party that receives data, what each receives and where they process it, is listed at Subprocessors. In summary: hosting in Frankfurt (EU), most AI processing in Sweden Central (EU), some AI processing on Google’s Gemini API which is not EU-pinned. None of them receives a patient identifier. None of them — and not us — uses your data to train AI models.
6. Security
- Encryption in transit and at rest; cleartext traffic disabled at the application level.
- Row-level security scoping every record to the account that created it. One clinician cannot read another’s data, and neither can an unauthenticated caller.
- Prescription files stored in a private bucket, each clinician confined to their own folder, shared only through short-lived signed links.
- An immutable prescription audit trail with no update or delete path.
- Where a patient name is needed to link audit entries, only a salted keyed digest is stored, and the key never leaves your device — so the name cannot be recovered from our servers.
- The app is excluded from Android system backups, so on-device history containing patient names is not copied to a third-party cloud.
7. Retention and deletion
- Consultation records are deleted 12 months after creation, automatically, by a scheduled job. The cloud copy exists so your history survives a lost or replaced phone; past a year a decision-support record has little clinical value left and holding it is a cost to your patients’ privacy rather than a benefit to their care.
- Prescription audit entries are deleted 12 months after creation, by the same job — the digest, the age and sex, the diagnosis and the drug list do not outlive the year.
- You can delete everything at any time from Settings, without contacting us. See Deleting your account and data.
- Shifaia is not the medical record. Your own patient chart remains the medical record, and any obligation you have to retain it is unaffected by anything here.
8. Our commitments to you
To the extent any patient personal data reaches us, we act solely as your processor, and we commit that we will:
- process it only to provide the service to you, and not for any purpose of our own;
- never sell it, never share it in any form that could be linked to you or to an individual patient, and not use it — or allow any provider to use it — to train or fine-tune AI models;
- keep it confidential and restrict access to those who need it to operate or support the service;
- apply the security measures in section 6, and not materially weaken them;
- keep our subprocessor page current, and update it promptly when a provider is added or removed;
- assist you in responding to a patient exercising their rights;
- notify you without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting your data;
- delete your data when you delete your account, and on the retention schedule in section 7.
On aggregated data
We may in future publish, share or license aggregated or fully anonymised datasets — prescribing patterns, drug-interaction statistics, epidemiological trends — that cannot be traced back to you, to any patient, or to any individual consultation. That is a different thing from the data covered above, and we would say so on this page before doing it. What we will not do is sell records about your patients or about you.
These are commitments we make to you here, not a negotiated contract. If your institution requires a signed data processing agreement, write to us and we will provide one.
9. What we ask of you
- Put patient identifiers in the fields provided rather than in the clinical narrative. That is what keeps them on your device, and it is the one habit that materially changes what leaves it.
- Obtain explicit written consent from each patient, in Arabic, before entering their health data. Egypt’s PDPL treats health data as sensitive and requires consent that is explicit, documented, and freely given. You are the controller, so the obligation is yours — but we do not leave you to draft it: the app generates a ready Arabic consent form at Settings → Patient consent form, covering what leaves your clinic, what does not, where it is processed, how long it is kept, and the patient’s rights under Law 151/2020. Print it, have the patient sign it, and keep it in your own file. We never receive it and hold no copy — storing patient signatures would make us a controller of patient data, which is precisely what this architecture avoids. Honour a refusal or a withdrawal, and never let either affect the care you give.
- Use the sharing features only with the patient’s agreement. When you send a prescription, your own device sends it; we never see your patient’s phone number.
- Keep your device and account secured. The identifiers we deliberately keep off our servers are on your phone.
10. Contact
Need a signed data processing agreement? Questions, deletion requests, breach reports, or a request for a signed agreement — write to us and we will provide one.
Email us →See also the Privacy Policy, Terms of Use and Subprocessors.
We will update this page as the service changes, and the version and date at the top will change with it. Nothing here is legal advice to you about your own obligations.