Privacy
You are handing medical records to a company you had not heard of before today. Here is what happens to them.
Who can see your records
You, and anyone you deliberately share an export with. Records are scoped to the account that owns them and every request is checked against that account before anything is returned.
A small number of our engineers can technically reach production data, because someone has to be able to fix a broken restore or a failed upload. That access is limited to the people who need it and is not used to browse records.
What we do not do
We do not sell your data, and there is no arrangement under which we would. Not to insurers, not to pharmaceutical companies, not to advertisers, not to data brokers, and not in aggregate or “anonymised” form — re-identification of medical data from supposedly anonymous sets is well documented, and the safe policy is not to be in that business.
We do not use your medical records to train models. Reports are sent to an AI provider to be read, under terms that forbid retention and training on that content, and the extracted values come back to us.
How it is stored
Everything travels over TLS. Documents and the database sit on servers we control, with encrypted disks, and documents are held separately from the account records that point at them.
Passwords are stored as bcrypt hashes and cannot be read back by us or by anyone who obtains the database. Signing in on the web uses cookies that JavaScript on the page cannot read, so a scripting flaw cannot lift your session.
Taking it with you, and deleting it
Export the whole record whenever you like — as a PDF to read and as structured data to move elsewhere, including every original document exactly as you uploaded it. There is no export fee and no waiting period.
Delete your account and the records, the documents and the account go with it. We do not keep a shadow copy for analytics. Backups are rotated, so a deleted record can persist in an encrypted backup for up to thirty days before it ages out.
Where the law stands
Pakistan has no enacted general data protection statute at the time of writing, and the country has seen publicised breaches of personal data held by large institutions. That is precisely why the commitments above are stated plainly rather than left to a regulator to enforce, and why export and deletion are built in from the start: the strongest guarantee we can offer is that leaving is easy.
The formal document is the privacy policy. This page is the plain-language version of it, and where they differ, tell us — that is a mistake on our side.
Questions
Write to support@sehatreport.app. A person answers.