Shifaia Healthby Union Pharmaceutical
Privacy

Privacy Policy

What we collect, what never leaves your device, and what we will never do with any of it.

Effective 21 August 2026 Previous version 20 August 2026 Union Pharmaceutical, Cairo العربية
The Arabic text is the one that governs. This policy is published in Arabic and in English. The Arabic version is authoritative; this English text is provided for convenience only. If the two differ in meaning, the Arabic prevails.

Shifaia Health (“we”, “us”), a product of Union Pharmaceutical (Cairo, Egypt), provides an AI clinical decision-support application for licensed healthcare professionals and students, and operates this website. This policy explains what we collect and how we handle it. Questions: zeyad@shifaia.com.

The most important point: Direct patient identifiers — name, national/chart ID, phone — remain on the clinician’s own device. They are never written to our cloud servers and never sent to any AI model. This is enforced two ways: those fields are structurally excluded from everything the app transmits, and an automated redaction pass removes identifiers from free-text boxes before the text leaves the device. Clinical data stored in the cloud is de-identified.

1. Patient data stays with you

The treating clinician is the data controller for their patients. The app is designed so that patient-identifying information stays on your device; only de-identified clinical data (such as age, sex, symptoms, diagnoses and medications) is stored in the cloud, and no patient identifiers are ever transmitted to the AI models that help generate assessments. Use sharing features (e.g. sending a prescription over WhatsApp) only with the patient’s agreement, and obtain any consent required by law.

1a. Our own role, stated plainly

Which role we occupy depends on which data you mean, and the honest answer is that it is three different answers:

  • Your professional account data — we are the controller. Your name, email, professional category and licence details are ours to hold. We decide why and how they are processed, and the obligations for them fall on us.
  • Any patient data that reaches us — we are a processor, acting on your instructions. You remain the controller. We do not decide what to do with your patients’ data; we do what the app is asked to do with it and nothing else.
  • De-identified clinical data — in our view neither role applies, because data that does not identify a person is not personal data. We do not rely on that argument by itself: the safeguards in sections 4, 5 and 9 apply to that data regardless of how it is classified.

2. Information we collect

  • Professional account data: your name, email, professional category, syndicate/licence details (or university, faculty and study year for students), and your 18-or-over declaration, to create your account and record your declared eligibility.
  • De-identified clinical data: clinical fields without direct patient identifiers, used to produce and improve decision support.
  • AI-output reports: when you choose to report an unsafe or incorrect output, we collect the reason and any note you enter, linked to your account and a local consultation reference. The assessment and patient details are not attached automatically; do not enter patient-identifying information in the note.
  • Voice input: the app uses offline speech recognition when the bundled model is available. If it falls back to the Android speech service selected on your device, that provider may process audio under your device and provider settings.
  • Website data: website visits. The early-access waitlist form has been retired; emails previously submitted through it are kept only until removal is requested.
  • Technical data: basic device and usage information needed to operate and secure the service.

3. How we use information

To provide and secure the service; run safety checks; verify professional eligibility; improve clinical quality and performance; and communicate with you about access and updates.

We also keep per-account operational records — consultation counts, feature use, timings, and error reports — to run, secure and improve the service. These are operational, not clinical, and a small clinical team may see them alongside the de-identified records described in section 3a. No patient identifiers are attached to them by design.

We do not sell your personal data, and we do not sell or share clinical data in any form that could be linked to you or to an individual patient. We may in future publish, share or license aggregated or fully anonymised datasets — prescribing patterns, drug-interaction statistics, epidemiological trends — that cannot be traced back to any person. If we do, we will say so here first.

3a. Do we train AI on your data? No.

We do not use your clinical data, or your patients’ data, to train, fine-tune or otherwise develop any AI model — ours or anyone else’s. We do not operate our own trained models; the app works by sending a carefully constructed instruction to a general-purpose model, and improving the app means improving that instruction, not learning from your cases.

Our AI providers make the same commitment for their side: Microsoft states that data submitted to Azure OpenAI is not used to train its models, and Google states the same for paid Gemini API use.

There is one thing we do do, and we would rather state it than let you discover it. We read de-identified consultation records ourselves — a founder or clinical reviewer opening a stored record to check whether the app gave good advice, and to fix the instruction when it did not. That is human quality review of de-identified data. It is not model training, it is not automated, and it is how a decision-support tool is made safe rather than merely plausible. If you would prefer your records excluded from that review, email us and we will exclude them.

4. AI processing

Decision-support outputs are generated in part by AI models. Only de-identified clinical inputs are sent for processing. Patient identity is excluded in two independent ways: the name, chart number and phone fields are never part of the payload the app transmits, and since August 2026 an automated redaction pass also strips names, phone numbers, national ID numbers and record numbers out of free-text boxes — the symptom description, pasted referral letters, dictated notes — before anything is sent.

Automated redaction is not infallible. Please do not deliberately type patient identifiers into free-text fields; the structured name field exists for that, and what you put there stays on your device.

5. Where data is stored and processed

Account and de-identified clinical data are hosted with our infrastructure provider (Supabase) in the European Union (Frankfurt, Germany).

Most AI processing runs on Microsoft Azure OpenAI / AI Foundry in Sweden Central (European Union). Under Azure’s standard abuse-monitoring, the de-identified text sent for processing may be retained by Microsoft for up to 30 days so that automated systems and, where an abuse signal is raised, authorised Microsoft reviewers can check for misuse; it is then deleted. Microsoft states that data submitted to Azure OpenAI is not used to train its models.

Some processing runs on the Google Gemini API, which is not region-pinned to the European Union and may process data in other countries, including the United States.

These locations are outside Egypt. For de-identified clinical data we consider that no cross-border transfer of personal data occurs, because data that does not identify a person is not personal data. For your professional account data, which is identified, the transfer is made on the basis of your consent, given when you register. In both cases our providers are bound by their own contractual data-protection terms.

The full list of who receives what is at Subprocessors, with the controller-facing summary at For data controllers.

6. Sharing

We share data only with service providers that help us run the app (such as hosting and AI processing) under appropriate confidentiality and data-protection terms, and where required by law.

7. Retention

  • Consultation records: 12 months. De-identified consultation records are automatically deleted 12 months after they are created, by a scheduled job that runs nightly.
    Why 12 months and not less: your consultation history lives on your device, and the cloud copy exists so that it survives a lost, stolen or replaced phone. For that to be worth anything it has to outlast the gap between you losing a device and replacing it, and cover a full year of care — including a complaint that recurs seasonally and a follow-up booked months out. Past a year, a decision-support record has little clinical value left, and holding it is a cost to your patients’ privacy rather than a benefit to their care. Twelve months is where those two lines cross.
  • Prescription audit records: 12 months. The audit trail that links each generated prescription to a salted, irreversible digest of the patient’s name is deleted 12 months after each entry is created, by the same scheduled job.
  • Account data: kept while your account is active, and deleted when you delete your account.
  • Waitlist emails (the early-access form is retired): kept only until you ask us to remove them.

Shifaia is not the medical record. It is a decision-support tool, and the record it keeps is a record of the decision support it gave you. Your own patient chart remains the medical record, and any obligation you have to retain it — which may be considerably longer than 12 months — is unaffected by anything here and remains yours to meet.

8. Your rights, including deletion

Consistent with Egypt’s Personal Data Protection Law (Law No. 151 of 2020), you may request access to, correction of, or deletion of your personal data, and you may withdraw consent.

Delete your account and everything in it Settings → Delete account and all data, in the app. Immediate, permanent, and it removes your consultations, prescriptions and PDFs, your profile, your login and this device’s local history.

How deletion works →

9. Security

We use encryption in transit and at rest, row-level access controls that scope every record to the account that created it, an immutable prescription audit trail, and audit logging. Where a patient name is needed to link prescription audit entries, it is stored only as a salted HMAC-SHA256 digest whose key never leaves your device, so the name cannot be recovered from our servers. The app is also excluded from Android system backups, so local history containing patient identifiers is not copied off your device.

No system is perfectly secure; please keep your device and credentials protected.

10. Not for patients or children

The app is for licensed professionals and enrolled students — not for patients or the general public — and is not intended for anyone under 18.

11. Changes

We may update this policy; the effective date above reflects the latest version. Material changes will be notified in-app or by email.

12. Language of this policy

This policy is published in Arabic and in English. The Arabic text is the authoritative version and is the one that governs; the English text is provided for convenience only. If the two differ in meaning, the Arabic text prevails.