Privacy Policy
Shifa' | شفاء ("Shifa", "we", "our", or "us") is a dental student clinical coordination platform designed to help eligible students discover, reserve, and manage dental patient cases.
This Privacy Policy explains what information may be collected, how it is used, and how we protect information when you use Shifa.
1. Information We Collect
Student account information
When a student creates or uses an account, we may process information such as:
- University email address
- Student name and student identifier
- Account verification and activation status
- Profile photo, if the student chooses to upload one
Patient and clinical case information
Shifa may process information relating to patient cases that is submitted through the patient intake system or made available for clinical coordination.
This information may include:
- Patient name
- Age
- General location or area
- Dental complaint or requested treatment
- Dental case category or classification
- Tooth-related information
- Relevant medical or chronic disease information voluntarily provided as part of the patient intake process
- Patient case photographs, where provided
- Phone or contact information
Patient contact information is restricted and is made available only to an authorized student after a successful patient reservation, where applicable.
Reservation and case activity
We may store information needed to operate the patient reservation and case-management system, including:
- Reserved patient cases
- Active and previous cases
- Reservation-cycle usage
- Case status and outcomes
- Relevant timestamps and activity records
Device and security information
To protect student accounts and patient information, Shifa may process security-related information such as:
- Trusted-device identifiers or derived device hashes
- Trusted session identifiers
- Device binding and security status
- App integrity and abuse-prevention signals
- Authentication and security event information
We use services such as Firebase App Check and platform integrity technologies to help identify unauthorized or modified clients and protect backend services.
Notification information
If notifications are enabled, we may process push notification tokens and related platform information so that Shifa can deliver important account, reservation, and service notifications.
2. How We Use Information
Information processed through Shifa may be used to:
- Create, verify, and manage student accounts
- Provide access to available dental patient cases
- Process patient reservations
- Manage active and completed clinical cases
- Restrict patient contact information to authorized users
- Deliver notifications and service updates
- Provide profile and account features
- Detect fraud, unauthorized access, and security violations
- Maintain and improve application reliability
- Comply with applicable legal, safety, and regulatory obligations
3. How We Share Information
We do not sell personal information.
Information may be shared only when needed to operate Shifa, provide its features, maintain security, or comply with legal obligations.
Shifa uses third-party infrastructure and service providers that may process limited information on our behalf, including:
- Google Firebase services
- Firebase Authentication
- Cloud Firestore
- Firebase Cloud Storage
- Cloud Functions
- Firebase App Check
- Notification delivery services, including Google, Apple, and Expo services where applicable
These providers process information according to their own terms, security practices, and privacy policies.
4. Patient Information Access
Shifa is designed to limit access to sensitive patient information.
Patient contact information is not generally displayed to all students. Where applicable, contact details become available only after a student successfully reserves the relevant patient case.
Students are expected to use patient information only for legitimate clinical coordination and educational purposes.
5. Security
We use technical and organizational safeguards intended to protect information against unauthorized access, alteration, disclosure, or destruction.
Security measures may include:
- Authenticated access
- University email verification
- Administrative account activation
- Trusted-device security controls
- Firebase security rules
- App integrity verification
- Restricted access to sensitive patient information
No system can guarantee absolute security, but we continuously work to reduce unauthorized access and misuse.
6. Data Retention
We retain information for as long as reasonably necessary to provide Shifa, maintain case and reservation records, protect the service, satisfy legitimate operational requirements, or comply with applicable obligations.
Retention periods may vary depending on the type of information and the reason it is processed.
7. Account and Data Requests
Users may contact us to request information about their account or to request correction or deletion of eligible personal information.
Certain information may need to be retained where required for security, legitimate record keeping, dispute resolution, or legal obligations.
8. Children's Privacy
The Shifa student application is intended for eligible dental students and is not directed to children as student users.
9. Medical Disclaimer
Shifa is a platform for organizing and coordinating dental student clinical cases.
Shifa does not provide medical diagnosis, treatment advice, or emergency medical services and does not replace professional clinical judgment.
10. Changes to This Privacy Policy
We may update this Privacy Policy when Shifa features, practices, or applicable requirements change.
The effective date shown at the top of this page will be updated when material changes are published.
11. Contact Us
If you have questions, privacy concerns, or requests relating to your information, contact:
Shifa' | شفاء
Email:
support@shifa-patient.org