العربية
Privacy Policy — Doctors' Daftar
Effective date: May 22, 2026 · Last updated: June 6, 2026
This Privacy Policy explains how Doctors' Daftar ("we," "us," or "the app") collects, uses, stores, and shares information when you use our mobile application. We built this app for medical consultants in Egypt and the wider Arab region to track their professional fees across multiple hospitals.
1. Who we are
Doctors' Daftar is operated by Diaa El Ghannam as an independent application. For privacy-related questions you can reach us at privacy@doctorsdaftar.app.
2. Information we collect
2.1 Information you provide directly
- Account details: your name, medical syndicate ID, specialty, title, phone number, optional email, and password.
- Practice data: hospital names, patient identifiers (MRN), patient names, ages, gender, phone numbers (optional), service descriptions, fee amounts, dates, and payment status.
- Bank-account details (if you choose to add them in Settings): bank name, account number, IBAN, SWIFT code, account holder name.
- Feedback you submit through the in-app feedback form.
2.2 Information collected automatically
- Device information: device model, operating-system version, app version, and language preference.
- Usage data: features you access, error reports, and crash logs (used only to improve the app).
- Analytics events: we log key actions (sign-up, fee added, OCR used, import completed, settlement marked, etc.) along with a tag for which hospital the action relates to, the fee category, status, case type, and the EGP amount. These metrics tell us which features work and what your typical workflow looks like — they never include patient identifiers (names, MRNs, phone numbers, notes) or any image / file contents. Your syndicate ID is included so we can debug per-account issues. Analytics and crash reporting are active only in the published app (they are disabled in development builds).
- Biometric authentication: if you enable Face ID / Touch ID, the biometric template is stored on your device by Apple/Google — we never see it. We only store a flag indicating biometric sign-in is enabled.
2.3 Information you upload to the app
- Images of fee sheets: when you photograph or upload an image for case extraction (OCR), the image is sent to our AI processing service (see Section 4) and returned as structured case data.
- Imported files (Excel/CSV): parsed locally on your device; only the parsed fee records are stored.
- AI Assistant queries: the in-app AI Assistant runs entirely on your device. Your questions and its answers are generated locally from the data already stored on your device and are not transmitted to us or any third party. We log only that the Assistant was used — never the content of your questions or its answers.
3. How we use your information
- To provide the core service: tracking, sorting, filtering, and summarising your fees.
- To authenticate you and protect your account.
- To extract case data from images via OCR (see Section 4).
- To answer your questions in the in-app AI Assistant — computed locally on your device from your own data, with nothing sent off the device.
- To generate PDF statements and bank-account sheets at your request.
- To enable the referral program (sharing your unique code).
- To improve the app through anonymised usage metrics and crash diagnostics.
We do not use your data for advertising, sell your data to third parties, or share patient information with anyone other than the providers listed in Section 4.
4. Third-party processors
To deliver certain features we use the following service providers, each bound by their own privacy commitments:
- Anthropic PBC (USA) — used to extract case data from the fee-sheet images you choose to upload (OCR). The image is sent to Anthropic's API solely for this purpose; Anthropic does not retain images sent via the API and does not train its models on API data. Their policy: anthropic.com/privacy. (The in-app AI Assistant does not use Anthropic — it runs entirely on your device.)
- Google Firebase / Google Cloud (Google LLC) — used for account sign-in (email + password), encrypted cloud storage and cross-device sync of your records (see Section 5), the syndicate-ID uniqueness record (your syndicate ID and name), usage analytics, crash reporting, and the OCR + account-deletion cloud functions. Cloud region: europe-west1 (Belgium). Their policy: firebase.google.com/support/privacy.
- Apple Inc. / Google LLC — when distributed via the App Store / Google Play, these companies collect download and crash data per their store policies.
5. Where your data is stored
Your practice data — fee records, patients, hospitals, settlements, tax profiles, and your profile — is stored in the cloud in Google Firebase Firestore, scoped to your account so that only you can access it, and cached on your device for offline use. This is what lets your data follow you when you sign in on a new device.
Patient privacy by design: the directly-identifying patient fields — patient name, medical record number (MRN), phone, and free-text notes — are encrypted on your device before they are uploaded, using a key derived from your password that never leaves your device. They are therefore stored in the cloud only as ciphertext that we cannot read. The remaining fee/ledger data (amounts, dates, hospital, payment status) is stored to provide the service.
Our cloud (Firestore and cloud functions) is hosted in the EU — europe-west1, Belgium — chosen for its proximity to Egypt and its alignment with both Egyptian Personal Data Protection Law (151/2020) and GDPR standards. We also hold a syndicate-ID uniqueness record (your syndicate ID and name), so the same ID cannot be registered by two doctors, plus pseudonymous usage analytics and crash diagnostics.
6. How long we keep your data
- Active account data: kept as long as your account is active.
- When you delete your account (in-app: Settings → Delete Account): your account and all your data — every cloud record and the syndicate-ID record — are permanently deleted, and your syndicate ID becomes available again. This cannot be undone.
- Uninstalling the app removes only the on-device cache; your cloud data remains until you delete your account as above.
- Crash logs and anonymised analytics: 90 days.
- Uploaded images: not retained after OCR processing.
7. Your rights
Under Egyptian PDPL 151/2020 and applicable international laws you have the right to:
- Access your personal data and receive a copy.
- Correct inaccurate or incomplete data.
- Request deletion of your data.
- Object to or restrict certain processing.
- Export your data in a portable format (Excel/PDF — available in-app via Settings).
- Withdraw consent at any time.
To exercise any of these rights, email privacy@doctorsdaftar.app. We respond within 30 days.
8. Data security
We use industry-standard measures to protect your data:
- Client-side encryption of patient identity: patient name, MRN, phone, and notes are encrypted on your device (AES-GCM) before upload, with a key derived from your password that never leaves your device — so we store those fields only as ciphertext we cannot read.
- TLS encryption for all network traffic.
- Encryption at rest in the cloud (Google-managed) and on the device (iOS/Android default).
- Cloud data is access-controlled so each account can reach only its own records.
- Your password is verified by Google Firebase Authentication and is never stored in plaintext; biometric sign-in is available as an additional layer.
- Restricted access to production systems.
No system is 100% secure. If we ever become aware of a data breach affecting your information, we will notify you within 72 hours.
9. Children's privacy
Doctors' Daftar is intended for licensed medical professionals only. We do not knowingly collect data from anyone under 18. If you believe a minor has provided us with personal information, please contact us and we will delete it.
10. Patient data and your responsibilities
You are responsible for the patient information you enter into Doctors' Daftar. You confirm that you have a lawful basis (treatment relationship, patient consent, or other) to record this information. We store the data you enter to provide the service — with the patient-identifying fields encrypted on your device before upload (Section 5) so they are not readable by us — and we do not use patient data for any other purpose.
11. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be communicated via in-app notification or email. The "Last updated" date at the top reflects the latest revision.
12. Contact
For any privacy-related question, complaint, or request:
Email: privacy@doctorsdaftar.app
Subject line: "Privacy Inquiry — [your topic]"