Privacy Policy

Sehtak — صحتك · Effective 8 July 2026 · Version 1.0

In short: your medical passport — records, documents, family profiles — is stored only on your phone and is never uploaded to our servers. Our servers hold your account, favorites, booking requests, support messages and a security log. There are no ads, no analytics or tracking SDKs, and no cookies. Deleting your account in the app is immediate and permanent.

1. Who we are

1.1 The Sehtak mobile application and the pages published at this address (together, the “Service”) are operated by Sehtak L.L.C-FZ, a company registered in the United Arab Emirates (“Sehtak”, “we”, “us”). Sehtak is the data controller for the personal data described in this policy.

1.2 You can reach us about anything in this policy at support@sehtak.ae.

2. Scope and legal framework

2.1 This policy explains what personal data Sehtak processes, where it is stored, why, for how long, and what rights you have. It applies to the Sehtak app for iOS and Android and to the hosted policy pages; Sehtak operates no other website or web app.

2.2 We process personal data in accordance with the laws of the United Arab Emirates, including Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the “PDPL”). Under the PDPL, data relating to health is sensitive personal data that requires heightened protection.

2.3 Our core safeguard for health data is architectural: the app is built so that your health data never reaches our servers at all. Records, documents and family profiles are stored exclusively on your device (see section 3). We cannot lose, sell, leak or be compelled to hand over server copies of data that we never receive.

2.4 Where we do process personal data on our servers (section 4), we rely on the following bases: performance of the service you request (your account, favorites, bookings, support), our legitimate interest in keeping the Service secure (the security log), and your consent where the PDPL requires it. You may withdraw consent as described in section 9.

3. The on-device medical passport

3.1 The medical passport — health records, uploaded documents and photos, medication and nutrition entries, the emergency card, and the family profiles you manage — is stored only in the storage of your own device.

3.2 It is never uploaded to, synchronized with, or backed up on Sehtak’s servers. No server-side table for this data exists. We cannot read it, and neither can providers listed in the directory.

3.3 Because this data exists only on your device: it is removed when you delete the app; it does not survive the loss, reset or replacement of your device unless your own device backup restores it; and any sharing of it (for example showing your emergency card, or sending details over WhatsApp) happens from your device, at your sole discretion. Sehtak never places health information in message bodies or links on your behalf.

4. Data our servers process

4.1 The table below is the complete list of the personal data categories our servers process. If a category is not listed here, our servers do not process it.

CategoryExamplesWhere storedWhyRetention
Account data Phone number (required); name and email address (optional, added by you) Sehtak servers (database hosted by Supabase) Creating and operating your account; sign-in by one-time code Until you delete your account (deletion is immediate and permanent)
Favorites Providers you save Sehtak servers Keeping your saved list across sign-ins Until you remove them or delete your account
Booking requests The provider, requested time, and any note you include Sehtak servers Passing your appointment request to the provider and showing you its status Until you delete your account
Reviews and votes Review text, star rating, your votes and reports on reviews (review writing is currently disabled — see 4.3) Sehtak servers; published reviews are visible to all users Public feedback on providers Until you delete your account, or earlier if removed under our content rules
Support messages Messages you send to support, an optional contact email, a reference number Sehtak servers Answering your request and keeping a record of it Retained for a limited period; if you delete your account the ticket is unlinked from it (see 13.3)
Security log Sign-in and account events with a timestamp and the IP address they came from Sehtak servers (append-only log) Preventing fraud and abuse; investigating security incidents Retained as a security record, including after account deletion (see 13.4)
Interaction events In-app interaction events keyed to a random session identifier that resets every time the app starts Sehtak servers Understanding aggregate usage of discovery features Not linked to your account or identity; the session identifier is never persisted or joined to you
Notification registration A push-notification token and your device platform, if you enable notifications Sehtak servers Delivering the notifications you asked for Until you sign out on the device or delete your account

4.2 We never sell personal data, and we never share it with anyone except the service providers in section 7, acting on our instructions.

4.3 Review writing is currently disabled in the app; the reviews shown are read-only. The review rows above describe what will apply when writing is enabled.

5. Data that never reaches our servers

5.1 Health data. Everything in section 3 — records, documents, medications, nutrition, the emergency card, family profiles — stays on your device.

5.2 Location. If you grant location permission, your position is read and used on your device to sort and show nearby results. Your coordinates are never transmitted to Sehtak’s servers, and we keep no location history. If you deny the permission, the app works without it.

5.3 One honest technical note: on Android, map imagery is drawn by Google Maps, so loading map tiles necessarily reveals the displayed map area to Google as tiles are fetched, under Google’s own terms (see 7.4). The Sehtak app itself sends no coordinates to any Sehtak server.

6. No cookies, no tracking, no advertising

6.1 The app contains no advertising, no analytics SDKs, no tracking SDKs, and no crash-reporting services. We do not profile you and we do not track you across other apps or websites.

6.2 Sehtak sets no cookies anywhere: the app is a native mobile app, and these hosted policy pages are static HTML that set no cookies, load no third-party fonts or scripts, and embed no trackers.

7. Service providers (processors)

7.1 Three service providers process limited data on our behalf, each bound by its own data-processing terms and each receiving only the minimum needed for its role:

7.2 Twilio delivers the one-time sign-in codes. To send a code, Twilio receives your phone number and the delivery channel (SMS or WhatsApp). Codes are generated and checked through Twilio Verify; Sehtak never logs them.

7.3 Supabase hosts our database — the server-side data in section 4. Connections to it are encrypted and additionally pinned to the hosting provider’s certificate authority, so the app’s backend only ever talks to the genuine database server.

7.4 Google Maps renders map imagery on Android. Google receives the map-tile requests needed to draw the map, governed by Google’s own privacy policy. Sehtak passes Google no account information.

8. How we secure data

8.1 We describe here the measures we actually operate — nothing more:

8.2 No system is perfectly secure. Our strongest protection for your health data is that we do not hold it (section 3). You are responsible for securing your own device — anyone with access to your unlocked phone can see what is on it.

9. Your rights and how to exercise them

9.1 Under the PDPL you have, among others, the rights below. Exercising them is free of charge.

9.2 Access. You may ask what personal data our servers hold about you and request a copy. Email support@sehtak.ae from the email linked to your account, or include your account phone number so we can verify the request is yours.

9.3 Correction. Your name and email can be edited directly in the app (Menu → Settings). For anything else, email us as above.

9.4 Deletion. In the app: Menu → Settings → Delete account. Deletion is immediate and permanent — there is no recovery window. Without the app, email us as above. Details: account deletion page.

9.5 Objection and withdrawal of consent. You may object to processing or withdraw consent at any time by emailing us; note that some processing (for example your phone number) is necessary to operate an account at all, so withdrawing it means deleting the account. You can disable notifications and location in your device settings at any time.

9.6 We respond to rights requests within a reasonable period, and we verify every request against the account’s phone number or email before acting on it, so that no one else can exercise your rights.

9.7 If you believe we have not handled your data lawfully, you may lodge a complaint with the competent data protection authority in the UAE in addition to contacting us.

10. Children and family profiles

10.1 Sehtak accounts are for adults: you must be at least 18 years old to create an account. We do not knowingly create accounts for minors, and if we learn an account belongs to a minor we will delete it.

10.2 A parent or guardian may keep family profiles — including for children — inside their own on-device medical passport. By adding a family member, the account holder warrants that they have the authority (parental, guardianship or the member’s own consent) to hold that person’s information. Family profiles are stored on the account holder’s device only and never reach our servers.

11. Data breach notification

11.1 If a breach of security affects personal data our servers hold about you, we will notify you without undue delay, tell you plainly what happened, what data was affected and what we are doing about it, and notify the competent data protection authority where the PDPL requires it.

11.2 Because your medical passport is never on our servers, a breach of Sehtak’s servers cannot expose it.

12. International transfers

12.1 Our database is hosted on Supabase cloud infrastructure, and Twilio processes phone numbers to deliver sign-in codes. Where this means personal data is stored or processed outside the UAE, we rely on the transfer provisions of the PDPL and on the contractual safeguards in place with each provider.

12.2 We keep the list of providers and locations in section 7 current; if it changes materially we will update this policy (section 14).

13. Retention schedule

13.1 Account, favorites, bookings, reviews, votes, devices, sessions: kept while your account exists; deleted immediately and permanently when you delete your account.

13.2 Interaction events: keyed to a random per-launch session identifier that is never joined to your account; they carry no lasting link to you.

13.3 Support messages: retained for a limited period to handle open matters and meet legal obligations. If you delete your account, tickets are immediately unlinked from it and keep only what you put in them.

13.4 Security log: an append-only record of security events (with IP addresses) retained after account deletion, because deleting the audit trail would defeat its purpose of investigating fraud and abuse. It contains event data, not your passport or profile content.

13.5 On-device data: under your control, on your device, until you delete it or the app.

14. Changes to this policy

14.1 When we change this policy we will publish the new version at this address with a new effective date and version number. For material changes — anything that expands what we collect or how we use it — we will show a notice in the app before the change takes effect.

14.2 Earlier versions can be requested at support@sehtak.ae.

15. Contact

15.1 Sehtak L.L.C-FZ, United Arab Emirates · support@sehtak.ae.