Privacy Policy
Last Updated: June 28, 2026
1. Introduction
At ShifaNext (Pvt) Ltd (a subsidiary of Ideamath Solutions (Pvt) Ltd), we believe that medical privacy is a fundamental human right. Our platform is architected around the principle of data minimisation, meaning your personal health information is handled with the absolute minimum footprint required for professional healthcare delivery.
2. The Ephemeral Model
Unlike traditional telemedicine platforms, ShifaNext does not persistently store video or audio recordings of your consultations.
- Video and audio sessions exist only for the duration of the call.
- Temporary call data is purged immediately upon session termination.
- Metadata (such as appointment duration) is stored only for billing and quality assurance.
Please note that this ephemeral handling applies to live video and audio. Certain records are deliberately retained as part of your care, including in-app chat messages, issued prescriptions, and payment records — these are described in the sections below and in “Data Retention & Account Deletion.”
3. Information We Collect
To provide our services, we collect the following minimal information:
For Patients
Legal name, email address, phone number, and basic appointment history.
For Doctors
Professional credentials, license numbers, specialization, and availability slots.
Consultation Messages
Text (and any images you choose to send) exchanged in the in-app chat tied to a specific appointment between you and the other participant.
Medical Records
Prescriptions issued by your doctor, stored as documents and associated with the relevant appointment.
Device & Notifications
A push-notification token for your device, used to send appointment reminders and call alerts. You can disable notifications in your device settings at any time.
Financial Information
We do not store your credit or debit card details. All payments are securely processed by our compliant payment partner (see “Payments” below). We retain transaction records (amounts, dates, and payout details) for billing and regulatory compliance.
4. Third-Party Services
We utilize trusted third-party infrastructure to power our platform:
- 1Firebase (Google): Used for secure authentication, real-time database and document storage (including chat messages and prescription documents), and push notifications via Firebase Cloud Messaging.
- 2LiveKit: Powers our high-performance, ephemeral video signaling infrastructure.
- 3Safepay: Our payment partner, which securely processes card and wallet payments under strict PCI-DSS standards. See “Payments” below.
- 4Google Calendar: If you sign in with Google and choose to use the calendar feature, we add your appointments to your Google Calendar with reminders. See “Google Calendar Integration” below for details.
5. Payments
Consultation fees are collected at the time of booking through Safepay’s hosted checkout. The payment is charged upfront to confirm your appointment, and is automatically refunded if the appointment is cancelled in accordance with our cancellation terms.
- Your card and wallet details are entered directly with Safepay and are never stored on ShifaNext’s servers.
- We retain a record of each transaction (amount, date, status, and the related appointment) and, for doctors, payout details — this is required for billing, refunds, and tax/regulatory compliance.
6. In-App Messaging
Each appointment includes a private chat between the patient and the doctor so you can communicate around your consultation.
- Chat is available only between the two participants of an appointment — the patient and the doctor. No one else can read it, except where required for safety, legal, or abuse-prevention purposes.
- Messaging opens once an appointment is scheduled and remains open through the consultation. After the appointment is completed, the conversation becomes read-only so both parties retain a record of what was discussed.
- Messages are stored alongside the relevant appointment. When the appointment is removed — for example, when either participant deletes their account — the associated chat is permanently deleted with it.
7. Google Calendar Integration
For users who sign in with Google, ShifaNext offers an optional integration that adds your booked appointments to your Google Calendar so you receive timely reminders.
- We request the
.../auth/calendar.app.createdscope only, and only via incremental consent — you are asked when you book an appointment, not at sign-in. - We use this access solely to create, update, and delete the calendar events that ShifaNext itself creates for your appointments (including reminders). We never read, list, or modify any of your other calendar events.
- The integration runs entirely on your device using your Google account’s access token. We do not store or transmit your Google OAuth tokens or any Google Calendar content on our servers — we retain only the identifier of the event we created, so it can be updated or removed when you reschedule or cancel.
- You can revoke this access at any time from your Google Account permissions.
ShifaNext’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
8. AI-Assisted Processing
To enhance the efficiency of your medical care, we utilize advanced artificial intelligence (AI) for pre-consultation triage and medical history summarization.
- AI models process symptom descriptions to assist doctors in preparation.
- Strict Data Isolation: Your personal health information (PHI) is never used to train public or third-party foundational AI models.
- All AI processing occurs within secure, ephemeral cloud environments.
9. Security Measures
All data in transit is encrypted using TLS 1.3, and data at rest is protected by AES-256 encryption. We perform regular security audits to ensure your data remains inaccessible to unauthorized parties.
10. Data Retention & Account Deletion
You can request deletion of your account at any time from within the app. To protect you and others, deletion follows a structured process:
- Grace period: When you request closure, your account is deactivated and you are signed out immediately, then permanently deleted after a 30-day grace period. You can cancel the closure and restore your account any time during this window by signing back in.
- What is deleted: Your profile, authentication record, appointments and their chat history, availability slots, reviews, and uploaded verification documents are permanently removed.
- What is retained: Issued prescriptions (as medical records) and financial/transaction records are retained even after account deletion, where we are required to keep them for medical-record, audit, and tax/regulatory compliance.
- Before closure can complete, any upcoming paid consultations and any outstanding doctor earnings must first be resolved.
11. Your Rights & Contact
You have the right to access, correct, or delete your personal data, subject to the retention obligations described above. To exercise these rights, or for any privacy-related inquiries, please contact our Privacy Officer at:
[email protected]You can also reach us on WhatsApp at (+92) 317 2505536, or by post at the address on our Contact page.