Sijil

Privacy Policy

What Sijil collects, why, and who can see it.

In effect from 2026-09-13

Who we are

Sijil is clinic management software at sijilhealth.com. Clinics use it to run their appointments, patient records, consultations and accounts. Patients use it to book appointments and read what their clinics publish to them.

For any question about this policy or about your data, write to [email protected].

Two kinds of user, two different responsibilities

A patient's medical record belongs to the clinic that created it. The clinic decides what goes in it, who inside that clinic may read it, and when it is deleted. Our job is to store and protect it on the clinic's behalf.

The clinic's own account — the owner's name, email and phone, its subscription invoices, its support messages — is data we are directly responsible for.

A patient's Sijil account is a different thing again from their medical record at a clinic. The account belongs to the person, and it holds no clinical data at all.

What we collect

From a clinic and its staff:

  • Name, email address, phone number, and role within the clinic.
  • The clinic name, specialty, sites, addresses and opening hours.
  • Last sign-in time, and a record of actions taken inside the software.
  • Whatever the clinic itself records about its patients: medical records, appointments, invoices, stock.
  • Files the clinic uploads, such as X-rays, lab results and photographs.

And what we collect from a patient

If you create a Sijil account to book an appointment:

  • Your name, your email address or phone number, and how you signed in.
  • Your bookings, and the documents your clinic chooses to publish to you.
  • Your notification preferences, and the devices registered to receive them.

Passwords never reach us

There is no password column in our database, neither in plain text nor hashed. All sign-in goes through Firebase, from Google, which stores and checks the password.

That means your password never reaches us at all — not in a message, not in a log, not in a backup.

Each clinic sees only its own data

Separation between clinics is enforced twice: once in the software, and again inside the database through row-level security policies.

The second layer means that a query written wrongly returns nothing, rather than returning another clinic’s records. One clinic cannot search another clinic’s patients, and cannot tell that they exist.

No clinic can tell that you also attend another clinic. Your account appears to each clinic under a different reference, so the two cannot be matched.

Who at Sijil can see your data

Plainly: Sijil’s technical staff hold database access capable, technically, of reading any row in it. That is true of every company that hosts your data, and anyone who tells you otherwise is describing something else.

What we do about it is this. The platform console — the tool we actually run Sijil with — displays no clinical content at all. No medical records, no diagnoses, no prescriptions, no attachments, and none of a clinic’s invoices to its patients. What it shows is account and subscription data, and aggregate counts.

Sensitive actions — suspending a clinic, disabling an account, resetting a password — are restricted to a higher level of administrative access, require a written reason, and are recorded against the name of whoever took them.

Reading is recorded too

We log more than changes. Opening a patient record, viewing a consultation, downloading an attachment — each is written to a log carrying who did it, when, and from which site.

That log cannot be edited or deleted: the permission to do so is withheld from the software at the database level, so it cannot rewrite its own history even if it tried.

Files and X-rays

These are held in private storage. No file has a public link.

When a file is opened, a temporary link is created that is valid for sixty seconds, and only after checking that whoever asked for it is entitled to see it. The link does not outlive the page it was rendered on.

The original filename is never part of the path — because a name like "ahmed-hiv-results.pdf" discloses the very thing it should not.

Encryption and backups

Connections to the website and the apps are fully encrypted (HTTPS).

The database sits on an encrypted disk. Nightly backups are themselves encrypted before they are written, and no unencrypted copy exists at any point.

We handle no card details

Sijil has no payment gateway. We do not ask for a card number, do not store one, and do not pass one to anybody — not from a clinic and not from a patient.

What a clinic records in the software is that an amount was received: an accounting entry, not a collection.

A clinic’s own Sijil subscription is paid outside the software, and recorded here by hand once it arrives.

Artificial intelligence

No AI feature operates on patient data today. The only AI in use searches the public clinic directory, which touches no medical record.

If we add a clinical feature in future, it will run only with the clinic’s explicit agreement, and it will not make a medical decision — that stays with the doctor.

Cookies and tracking

We use cookies for signing in only: a session cookie no script in the browser can read, and a cookie remembering whether you chose the light or dark theme.

There is no advertising tracker and no third-party analytics anywhere on this site. Even the fonts are hosted by us rather than fetched from an outside server — because a clinic directory that reports every visitor to a third party is not something we are willing to publish.

The services that help us

We rely on a small number of providers, each for a single purpose:

  • Google (Firebase Authentication) — signing in, and storing passwords.
  • Google (Firebase Cloud Messaging) — delivering notifications to patients’ phones.
  • Cloudflare (R2) — storing files and attachments.
  • Cloudflare — carrying and protecting site traffic.
  • A hosting provider, for the server the database runs on.

Processing outside Egypt

The companies listed above are international, and processing by them may take place outside Egypt.

How long we keep it

We keep a clinic’s data for as long as its account exists. Medical records belong to the clinic, and it decides when they are deleted, within whatever the law requires of it.

Encrypted backups rotate over a limited period, so data deleted from the system may persist in a backup for a short time afterwards.

Your rights

If you are a patient: you can see your account, your bookings and the documents published to you at any time from inside your account, change your details, and unlink your account from a clinic. Your medical record inside the clinic is held by the clinic, so a request for a copy, a correction or a deletion goes to them.

If you are a clinic: you can export your data as CSV files from inside the software.

For any other request about your data, write to [email protected].

Complaints

If you believe we have handled your data wrongly, write to [email protected] and we will answer you.

Changes to this policy

Any change is published on this page with a new effective date. We suggest reading it again from time to time.