DocFai Privacy Policy
This policy covers the DocFai mobile app and the DocFai web platform at app.docfai.com. The mobile app presents the same DocFai platform on your phone, so the practices below apply to both. ScanFai and CTGfai have their own policies.
1. Who We Are
DocFai is operated by Tizfai Technologies AB. DocFai is a telemedicine and medical practice platform used by doctors, nurses, pharmacists, clinic assistants, administrators and patients.
Where a clinic, hospital or healthcare provider uses DocFai to treat patients, that organisation is normally the data controller for the patient records it creates, and Tizfai Technologies AB acts as a processor on its instructions — except where we must act as an independent controller for security, billing, legal or regulatory obligations.
2. Data We Collect
Account and identity. Name, email address, mobile number, role, profile photo, address, and national ID number where a role requires verification.
Patient profile. Age, date of birth, gender, blood group, height, weight, occupation, marital status, preferred language, address details, emergency contact, insurance details, and family or dependant links.
Clinical records. Prescriptions and prescribed drugs, appointments, diagnoses, investigations and laboratory results, medical journals, uploaded medical documents and images, symptom assessments, and vital signs.
Home monitoring. Where you use these features: blood pressure, heart rate and rhythm, oxygen saturation, temperature, respiratory rate, blood glucose, pain level, urine output, peak flow, sleep, and water intake.
Women's health. Where you use this module: menstrual cycles and flow, symptoms and mood, fertility information including test results and intercourse logs, pregnancy records including estimated delivery date, outcome and pregnancy loss, antenatal and postnatal visits, and postnatal depression screening responses including any self-harm indicator. This is among the most sensitive data on the platform, and the module offers an optional PIN so it can be kept private on a shared device.
Consultations. Live audio and video during a consultation, chat messages, and files shared in a call. Where transcription or AI note-taking is used, consultation audio is processed as described in section 4.
Technical. Authentication tokens, push notification device tokens, and security and audit logs used to protect the service.
3. Why We Process Data
- To provide clinical workflows: prescriptions, appointments, investigations, records and consultations.
- To enable video consultations, messaging and file sharing between authorised users.
- To provide AI-assisted clinical support, as described in section 4.
- To send notifications you have asked for, such as appointment reminders and call alerts.
- To authenticate users, enforce role-based access, and maintain audit trails.
- To detect abuse, investigate incidents, and meet legal and regulatory obligations.
4. AI Processing
DocFai uses artificial intelligence to assist clinicians — for example suggesting treatments and investigations, extracting values from uploaded lab and imaging reports, assisting with history taking, generating consultation notes, and answering questions in the AI Nurse feature. AI output is decision support for a qualified clinician. It is not a diagnosis and does not replace clinical judgement.
Who processes it. Our AI provider is OpenAI. Your device never contacts OpenAI directly: AI requests go to DocFai servers, which forward them to OpenAI. This means our API credentials are never exposed to a client, and we can log and limit AI usage.
Removing identifiers. Before clinical text from the prescription workflow is sent for AI processing, DocFai removes direct identifiers — name, phone number, email address, national ID and birth registration number, date of birth and address fragments. Age and gender are deliberately kept, because they are needed for safe dosing and clinical recommendations. Some features send only structured values rather than free text; the Health Score, for example, sends a factor breakdown and no free-text patient data.
What this does not cover. Where you type or speak freely — such as AI Nurse chat, or voice input and consultation audio sent for transcription — the content is processed as you entered it. If you state a name or other identifying detail in free text or speech, that detail is processed with the rest of the content. Please avoid entering identifying details that are not clinically necessary.
Audio. Where transcription or AI note-taking is used, consultation and voice-input audio is sent to OpenAI's speech-to-text service to produce a transcript.
What we keep. We record AI usage metadata — the feature used, model, token counts, cost, latency and outcome — for billing, quota enforcement and reliability. Prompt and response content is not stored in those usage logs. Content that is part of your record, such as a generated consultation note or an AI Nurse conversation, is stored with your record.
5. Who Else Receives Data
We do not sell personal data, and we do not share it with advertisers. DocFai contains no advertising SDKs, no third-party analytics SDKs and no crash-reporting SDKs. We use the following processors to run the service:
- OpenAI — AI processing as described in section 4, including audio transcription and reading uploaded medical documents.
- LiveKit — real-time audio and video for consultations.
- Wasabi — encrypted-in-transit object storage for uploaded documents, images, prescriptions and call files.
- Google Firebase Cloud Messaging and browser push services — delivery of push notifications to your device.
- SMS providers — one-time passcodes, appointment reminders and consultation links sent to your mobile number.
- Email providers — account and notification email.
- WhatsApp Business (Meta) — where enabled, notifications sent to your number.
- Payment provider — where paid features are used, transaction data is handled by the payment gateway.
We may also disclose data where we are legally required to, or to establish, exercise or defend legal claims.
6. Notification Content
Push notification text is deliberately generic — for example “You have a new message”. Notifications are rendered on lock screens, cached by the operating system and, on Android, pass through Google's servers, so they do not name a patient, drug or caller. The details are loaded inside the app after you open it.
7. Permissions on Your Device
- Camera — to capture medical documents, scan prescriptions and QR codes, and for video consultations.
- Microphone — for video consultations and Bangla voice input.
- Photo library — only when you choose an existing image to attach, or save a document you asked to download.
- Location — collected only when you use features that need it, to find nearby chambers and pharmacies and to select a delivery pharmacy. DocFai requests foreground location only and does not track your location in the background.
- Notifications — to deliver alerts you have enabled.
- Biometrics — to unlock the app.
Every permission can be revoked at any time in your device settings.
8. Biometric Unlock
Biometric unlock is handled entirely by your device's own Face ID, Touch ID or Android biometric system. DocFai receives only a success or failure result. We never collect, transmit or store your fingerprint or face data, and your biometric template never leaves your device.
9. Security
- All traffic between the app and our servers, and between our servers and the processors listed above, travels over encrypted connections (HTTPS/TLS).
- The most sensitive routes — AI history taking, AI Nurse, and Health Score — additionally encrypt the request and response payload with AES-256-GCM on top of TLS.
- On mobile, your authentication token is held in the operating system's secure storage (iOS Keychain / Android EncryptedSharedPreferences) and is only readable after the device is first unlocked.
- The mobile app blocks screenshots and screen recording to reduce the risk of medical data leaking into a device gallery.
- Where the web app stores data for offline use, the offline record is encrypted in the browser with a key derived from your credentials.
- Access follows role-based authorisation, and passwords and the women's health PIN are stored only as bcrypt hashes.
- Signing out revokes that device's access token.
No system is perfectly secure. If you believe your account has been compromised, contact us immediately using the details in section 13.
10. Deleting Your Account
You can delete your account from Settings in the DocFai mobile app at any time. You will be asked to confirm, and then to enter your password to prove it is you. The request takes effect immediately — it is not a support ticket. If you use DocFai in a web browser, email us and we will action it; see the account and data deletion page.
When you delete your account:
- Your name, email address, mobile number, profile photo, national ID, address and emergency and insurance details are erased or replaced with anonymous values.
- Your account is deactivated and can no longer be signed in to.
- Every access token on every device is revoked, and your push notification registrations are deleted, so notifications stop.
- Your mobile number is released, so you can register again later with the same number.
What is kept, and why. Prescriptions, investigation results and journals are medical records. The prescribing doctor carries a legal duty to retain them, and they are also referenced by other people's records — a doctor's own prescribing history, or a parent's dependants. So these clinical records are retained in de-identified form: the identifying details that tied them to you are removed, but the clinical record itself survives. This is deletion of your identity from the system rather than erasure of every row, and it is the approach both app stores accept for regulated health data.
11. Retention
Clinical records are retained for as long as the treating clinician or healthcare organisation is required to keep them under applicable medical record-keeping rules, and in de-identified form after account deletion as described above. Account and security logs are kept for as long as needed to operate and protect the service. Where your healthcare organisation sets its own retention policy, that policy governs the records it controls.
12. International Transfers
DocFai is used in Bangladesh and operated by a company established in Sweden, and some of the processors listed in section 5 operate outside your country — AI processing and parts of file storage occur on infrastructure located abroad. Where personal data is transferred outside the EEA or UK, we aim to rely on recognised transfer safeguards such as adequacy decisions or standard contractual clauses where required.
13. Your Rights and Contact
- You may have rights of access, rectification, erasure, restriction, objection and data portability, subject to applicable law and to the medical retention duties described in section 10.
- Where your clinic or hospital controls the records, please direct requests to that organisation first.
- We may need to verify your identity and authority before acting on a request.
For privacy requests or questions, contact kamal@tizfai.com.
If you are in Sweden or the EEA, you may also have the right to lodge a complaint with your local supervisory authority. In Sweden the supervisory authority is Integritetsskyddsmyndigheten (IMY).
14. Children
DocFai is intended for use by healthcare professionals and adult patients. A child's medical record may be created and managed within DocFai by a parent, guardian or treating clinician acting on the child's behalf; the app is not directed at children as independent users.
15. Changes to This Policy
We may update this policy as the platform changes. The date at the top of this page shows when it was last revised. Material changes will be communicated in the app or by email.