Privacy Policy

Last Updated: October 6, 2026

1. Introduction

At ShifaNext (Pvt) Ltd (a subsidiary of Ideamath Solutions (Pvt) Ltd), we believe that medical privacy is a fundamental human right. Our platform is architected around the principle of data minimisation, meaning your personal health information is handled with the absolute minimum footprint required for professional healthcare delivery.

2. Consultation Recording

We record the audio of your consultation. Video is never recorded — only sound. The recording exists so that there is a record of what was discussed and advised, which protects both you and your doctor if a question arises afterwards.

  • Audio only. The video of your call is never recorded or stored.
  • Deleted after a limited period. Recordings are automatically and permanently deleted once that period has passed. We do not keep them indefinitely.
  • Not transcribed or analysed. The recording is not converted to text, not read by automated systems, and not used to train anything.
  • You can ask us to delete it. If you would rather a particular consultation was not kept, contact us and we will delete that recording. We will not ask you to justify the request.
  • Access is restricted and logged. You and your doctor can listen to your own consultation. Beyond that, only authorised staff reviewing a complaint or a safety concern can access a recording, and every access is recorded.

Because recording is part of how the service works, it is not something you switch on or off before a call — by using ShifaNext for a consultation you agree to it, as set out in our Terms. If you would prefer not to be recorded at all, please do not proceed with the consultation.

Other records are deliberately retained as part of your care, including in-app chat messages, issued prescriptions, and payment records — these are described in the sections below and in “Data Retention & Account Deletion.”

3. Information We Collect

To provide our services, we collect the following minimal information:

For Patients

Name, email address, phone number, and appointment history. If you choose to provide them: health details (conditions, medicines, allergies, blood group), symptom and vitals logs with any photos you attach, and notes you share with your doctor.

For Doctors

Professional credentials, licence numbers, specialization, and availability slots; identity and verification documents (including CNIC and photograph); English and Urdu voice samples; recordings of verification interviews (kept for 2 years); and bank and tax details used for payouts.

Consultation Messages

Text (and any images you choose to send) exchanged in the in-app chat tied to a specific appointment between you and the other participant.

Medical Records

Prescriptions issued by your doctor, stored as documents and associated with the relevant appointment.

Device & Notifications

A push-notification token for your device, used to send appointment reminders and call alerts. You can disable notifications in your device settings at any time.

Technical details of the device and app you use: device model, operating system, browser, app version, screen size, language, time zone and network type; whether the app is open and in use; whether microphone, camera and notification access is allowed; and whether your microphone and camera started during a consultation. We use this to keep ShifaNext working and to help you when something doesn’t. We do not collect your IP address, location, or your device’s name.

Financial Information

We do not store your card, bank account, or wallet details. All payments are securely processed by our payment partner (see “Payments” below). We retain transaction records (amounts, dates, and payout details) for billing and regulatory compliance.

4. Third-Party Services

We utilize trusted third-party infrastructure to power our platform:

  • 1Firebase (Google): Used for secure authentication, real-time database and document storage (including chat messages and prescription documents), and push notifications via Firebase Cloud Messaging.
  • 2LiveKit: Powers our high-performance, ephemeral video signaling infrastructure.
  • 3PayFast: Our payment partner, which securely processes bank account, card, and wallet payments on its own hosted payment page. See “Payments” below.
  • 4Google Sign-In: If you choose to sign in with Google, we receive your name, email address, and profile photo from Google to create and sign in to your account. ShifaNext’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

5. Payments

Consultation fees are collected at the time of booking through PayFast’s secure hosted payment page. The payment is charged upfront to confirm your appointment, and is automatically refunded if the appointment is cancelled in accordance with our cancellation terms.

  • Your card, bank account, and wallet details are entered directly with PayFast and are never stored on ShifaNext’s servers.
  • We retain a record of each transaction (amount, date, status, and the related appointment) and, for doctors, payout details — this is required for billing, refunds, and tax/regulatory compliance.

6. In-App Messaging

Each appointment includes a private chat between the patient and the doctor so you can communicate around your consultation.

  • Chat is available only between the two participants of an appointment — the patient and the doctor. No one else can read it, except where required for safety, legal, or abuse-prevention purposes.
  • Messaging opens once an appointment is scheduled and remains open through the consultation. After the appointment is completed, the conversation becomes read-only so both parties retain a record of what was discussed.
  • Messages are stored alongside the relevant appointment. When the appointment is removed — for example, when either participant deletes their account — the associated chat is permanently deleted with it.

7. Calendar Reminders

The ShifaNext mobile app can add your booked appointments to the calendar on your phone, so you get a reminder before each consultation. This is optional and works however you sign in.

  • Your phone asks for permission to access your calendar the first time you choose to add an appointment — from the booking confirmation or an appointment card. You can decline, and you can turn access off at any time in your phone’s settings.
  • We use this access only to add events for your appointments and to remove them if an appointment is cancelled. To do that, the app looks at the list of calendars on your phone (to choose where to add the event) and at the events it created itself. We never read, list, or change any of your other events.
  • Each event contains only the consultation time, the name of the doctor or patient, a reference to the appointment, and reminders — never your notes, symptoms, or messages.
  • This happens entirely on your device. Calendar content is never sent to our servers — we keep only the identifier of the event the app created, so it can be removed if the appointment is cancelled.
  • If your phone’s calendar is synced with an online account, such as Google or iCloud, that service stores and syncs these events like any other event you add.

8. AI-Assisted Features

ShifaNext has optional features that use artificial intelligence (AI) to help organise symptom information — for example, summarising the symptoms you choose to share so your doctor can prepare for your consultation. Where these features are switched on:

  • AI never gives you a diagnosis. Your doctor makes every clinical decision.
  • Only what the feature needs is sent — never your name, phone number, email address, or date of birth.
  • Strict Data Isolation: Your personal health information (PHI) is never used to train public or third-party foundational AI models.
  • If an AI feature is unavailable, everything else continues to work without it.

9. Security Measures

All data in transit is encrypted using TLS 1.3, and data at rest is protected by AES-256 encryption. We perform regular security audits to ensure your data remains inaccessible to unauthorized parties.

10. Data Retention & Account Deletion

You can request deletion of your account at any time from within the app. To protect you and others, deletion follows a structured process:

  • Grace period: When you request closure, your account is deactivated and you are signed out immediately, then permanently deleted after a 30-day grace period. You can cancel the closure and restore your account any time during this window by signing back in.
  • What is deleted: Your profile, authentication record, appointments and their chat history, availability slots, reviews, device information, and uploaded verification documents are permanently removed.
  • What is retained: Issued prescriptions (as medical records) and financial/transaction records are retained even after account deletion, where we are required to keep them for medical-record, audit, and tax/regulatory compliance.
  • Before closure can complete, any upcoming paid consultations and any outstanding doctor earnings must first be resolved.

11. Your Rights & Contact

You have the right to access, correct, or delete your personal data, subject to the retention obligations described above. To exercise these rights, or for any privacy-related inquiries, please contact our Privacy Officer at:

[email protected]

You can also reach us on WhatsApp at (+92) 317 2505536, or by post at the address on our Contact page.