Legal
Privacy Policy
Last updated: June 22, 2026 · Applies to Hakeem web and mobile apps
1. Introduction
Hakeem (“we”, “us”, or “our”) provides a clinical workbench for licensed healthcare professionals and their clinic teams to manage patients, write prescriptions, generate PDFs, and use AI-assisted tools. This Privacy Policy explains what information we collect, how we use it, and what device access the Hakeem mobile app requests on Android and iOS.
By creating an account or using Hakeem, you agree to this policy. If you do not agree, please do not use the service.
2. Who this policy covers
This policy applies to clinic staff who sign in to Hakeem (doctors, admins, and invited team members). It also describes how patient information entered by your clinic is processed when you use Hakeem to care for patients.
Hakeem is intended for professional use by adults. It is not directed at children under 13, and we do not knowingly collect personal information from children.
3. Information we collect
Account and clinic information
- Name, email address, and password (stored securely; passwords are hashed)
- Clinic name, address, doctor name, specialty, and branding settings
- Team membership, roles, and audit activity within your clinic
Patient and clinical information
When you use Hakeem, you and your team may enter or generate health-related data, including:
- Patient demographics (name, date of birth, gender, phone, email, weight)
- Allergies, medical conditions, diagnoses, and clinical notes
- Prescriptions, medications, lab orders, imaging orders, and follow-ups
- Prescription PDFs and shareable patient portal links
You are responsible for ensuring you have a lawful basis to collect and process patient data in your jurisdiction.
Files and images you upload
- Clinic logos and prescription letterhead templates (images or PDFs)
- Documents chosen during clinic onboarding for template extraction
Voice and audio
- Short voice recordings when you dictate a prescription or speak to the AI assistant
- Audio is transmitted to our servers for transcription and AI processing; temporary files may be created on your device during recording and are deleted when you cancel or finish a session
Technical and usage data
- Authentication tokens stored on your device to keep you signed in
- Server logs (IP address, request timestamps, error diagnostics) for security and reliability
- AI usage metadata (e.g. model calls, latency) for billing, debugging, and service improvement
4. Device permissions and access (mobile app)
The Hakeem mobile app requests access only when a feature needs it. You can deny permissions; related features will not work until permission is granted.
| Access | Why we need it | Used in |
|---|---|---|
Microphone Android: RECORD_AUDIO, MODIFY_AUDIO_SETTINGS iOS: NSMicrophoneUsageDescription | Record your voice to dictate prescriptions and to talk to the realtime AI assistant. Audio is streamed to our servers for transcription and AI responses. MODIFY_AUDIO_SETTINGS / voice-communication audio routing helps echo cancellation during assistant conversations. | Voice dictation (workbench), Realtime AI assistant |
Camera Android: Requested at runtime (camera intent) iOS: NSCameraUsageDescription | Capture a photo of your clinic letterhead or logo during signup or template setup when you choose “Take a photo”. | Clinic signup, Custom letterhead upload |
Photos / image library Android: System Photo Picker (no READ_MEDIA_IMAGES permission) iOS: NSPhotoLibraryUsageDescription | Let you pick an existing image from your gallery for your clinic logo, letterhead template, or onboarding document. On Android we use the system Photo Picker—you choose the file; we do not get ongoing access to your photo library. | Profile logo, Letterhead upload, Signup template import |
Files (PDF and documents) Android: Via system file picker (no broad storage access) iOS: Via system document picker | Let you choose a PDF or image file for letterhead templates and clinic onboarding. Only the file you pick is read. | Custom letterhead (PDF), Signup template import |
Internet and network Android: INTERNET iOS: Standard network access | Connect to your clinic’s Hakeem backend to sync patients, prescriptions, and settings. During development, iOS may also access devices on your local network when configured. | All signed-in features, AI services, PDF generation |
Local storage on device Android: App-specific temp and documents directories iOS: App-specific temp and documents directories | Store your sign-in token securely (Keychain / Android Keystore), save temporary voice recordings during dictation, and prepare PDFs or exports for the system share sheet. We do not scan unrelated files on your device. | Sign-in, Voice dictation, Share / save PDF |
Share sheet and clipboard Android: No special permission iOS: No special permission | Share prescription PDFs, portal links, or text summaries through your device’s share menu. Copy links or summaries to the clipboard when you tap Copy—we write to the clipboard only; we do not read clipboard contents. | Share PDF, Copy portal link, WhatsApp handoff |
Opening other apps (WhatsApp, browser) Android: Package visibility queries for https, tel, mailto iOS: Standard URL schemes | Open WhatsApp with a pre-filled message when you choose to send a portal link or summary, or open external links from Help and News. | WhatsApp share, Help links, News articles |
We do not request access to your contacts, SMS, location, Bluetooth, calendar, or background microphone when the app is not in use.
5. How we use your information
- Provide, maintain, and improve the Hakeem clinical workbench
- Authenticate users and enforce clinic-level access controls
- Generate prescription PDFs, share links, and patient portal pages
- Transcribe voice input and run AI-assisted extraction, safety checks, and the assistant
- Extract clinic branding and layout from uploaded letterhead templates
- Send transactional emails (e.g. password reset, team invitations) when configured
- Monitor security, prevent abuse, and troubleshoot errors
- Comply with legal obligations
We do not sell your personal information or patient data.
6. AI and third-party services
Hakeem uses third-party AI providers (including Google Gemini) to power voice transcription, prescription extraction, safety validation, template auto-mapping, and the realtime AI assistant. When you use these features, relevant text, audio, or images are sent to our servers and then to the AI provider for processing.
Before any data is sent to a third-party AI provider, the app shows an in-app disclosure explaining what is shared and with whom, and asks for your explicit consent. You can decline and continue using the rest of Hakeem, and you can turn AI data sharing on or off at any time under More → AI & data sharing.
AI outputs are assistive only and must be reviewed by a qualified clinician before clinical use. We configure AI services under our agreements with providers; data shared with the AI provider is not used to train their models, and you should not submit information you are not authorized to share.
Other infrastructure providers (hosting, email delivery, storage) may process data on our behalf under contractual safeguards.
7. How we store and protect data
- Your sign-in token on mobile is stored in the device secure enclave (iOS Keychain / Android Keystore) via platform secure storage APIs
- Data in transit is encrypted using HTTPS / WSS (TLS)
- Clinic data is isolated by tenant; access is limited to authenticated members of your clinic
- Passwords are hashed; we do not store plain-text passwords
No method of transmission or storage is 100% secure. If you believe your account has been compromised, contact us immediately.
8. Data retention
We retain account, clinic, and patient records for as long as your clinic maintains an active subscription or account, and as needed to provide the service, resolve disputes, and meet legal requirements. Temporary voice files on your device are removed when you finish or cancel a recording session.
When you request account or data deletion (see Section 9), we delete or anonymize data where we can. Some records may be retained where required by law or for legitimate business purposes—for example audit logs tied to clinical activity.
9. Account and data deletion
Hakeem accounts are created with an email address and password. You can delete your account at any time, directly inside the app—no email or support request is required.
Delete your account in the app (self-service)
On both mobile and web, go to More → Clinic profile → Settings, scroll to Delete account, and confirm. Deletion is immediate: your sign-in credentials are removed and you are signed out right away. You do not need to contact us.
What gets deleted immediately
- Your sign-in access (email, password, and authentication)
- Your display name and personal profile identifiers
- Any pending password-reset links tied to your account
What is retained (and why)
For legal and medical record-keeping obligations, the clinical records created in your clinic—prescriptions, patient records, and related clinical data—are retained in anonymized form and are no longer linked to your personal identity. We may also retain:
- Audit logs of clinical actions (who changed what, and when), in anonymized form
- Records we must keep for regulatory, tax, or legal compliance
- Backups until they rotate out on our normal schedule
- Aggregated or de-identified data that no longer identifies you
Closing an entire clinic
Deleting your account does not automatically close the whole clinic or remove other team members. If you want the entire clinic account and its records permanently closed (beyond the anonymized retention above), email support@hakeemcare.ai and we will process it after verifying your identity.
Before you leave
Export any records you need before deleting your account. After deletion you will lose access to patients, prescriptions, and PDFs in Hakeem, and you will not be able to sign in again with the same credentials.
10. Sharing and disclosure
We may share information:
- With service providers who help us operate Hakeem (under confidentiality obligations)
- With other members of your clinic according to their assigned role
- When you explicitly share content (e.g. PDF via share sheet, portal link to a patient)
- If required by law, regulation, legal process, or to protect rights and safety
- In connection with a merger, acquisition, or sale of assets, with notice where required
11. Your choices and rights
- Permissions: Manage microphone, camera, and photo access in your device Settings at any time
- Account data: Update clinic and profile information in Settings
- Sign out: Clears the stored authentication token on your device
- AI data sharing: Turn third-party AI processing on or off any time under More → AI & data sharing
- Account deletion: Delete your account yourself, in-app, under More → Clinic profile → Settings → Delete account (see Section 9)
- Access and correction: Contact us to access or correct personal information we hold about you
12. International transfers
Hakeem is operated from Egypt. If you access the service from other countries, your information may be transferred to and processed in jurisdictions where we or our providers operate, which may have different data-protection laws than your country.
13. Changes to this policy
We may update this Privacy Policy from time to time. We will post the revised version at this URL and update the “Last updated” date. Continued use after changes constitutes acceptance of the updated policy.
14. Contact us
Questions about this policy, your data, or account deletion:
- Email: support@hakeemcare.ai
- Website: https://hakeemcare.ai
- Support: hakeemcare.ai/support