Sifa — Privacy Policy
Last updated: 24 July 2026 Effective date: 24 July 2026
1. Who we are and how to reach us
Sifa ("the app") is provided by SURREEL YAZILIM VE PAZARLAMA ANONİM ŞİRKETİ ("we", "us").
| Data controller | SURREEL YAZILIM VE PAZARLAMA ANONİM ŞİRKETİ |
| Address | Evliya Çelebi Mah. Meşrutiyet Cd. No:90 Beyoğlu/İstanbul, Türkiye |
| [email protected] | |
| EU representative (GDPR Art. 27) | [EU REPRESENTATIVE — name/address/email: to be completed before EU distribution] |
For any privacy question or request: [email protected]
2. In short
- Your health records are stored, tied to your account, in the European Union (Frankfurt).
- We do not use your health data for advertising, marketing or profiling, and we do not sell it.
- We use analytics tools only to measure app usage and advertising performance, using non-health technical data only; your health data is never sent to them (see §3.3, §5.6–5.7).
- Data read from Apple Health is never written to iCloud.
- Your health summary is sent to Aria (the AI assistant) only if you give explicit consent; you can withdraw consent any time, and Aria still works without it.
- You can permanently delete your account and all your data from within the app.
- You can export your data as JSON at any time.
The sections below detail all of the above.
3. What data we collect
3.1 Data you enter
- Profile: name, birth year/age, sex, height, weight, blood type, city.
- Health records: lab/imaging/visit records and the lab values inside them (name, result, unit, reference range, status).
- Medications: name, dose, frequency, start/stop date, intake logs, stock.
- Appointments: physician name, specialty, date/time, location, notes.
- Medical history: diagnoses, procedures, family history.
- Daily logs: check-ins, symptoms, activities, meals, program enrollments.
- Documents: report images and PDFs you upload or scan with the camera.
- Aria conversations: the messages you write and Aria's replies.
3.2 Data read from Apple Health (only if you allow it)
When you allow it, we read only the following types from Apple Health. Apple requires each health data type taken from the device to be disclosed individually; this is the list:
| Measurements | Profile characteristics |
|---|---|
| Step count | Biological sex |
| Resting heart rate | Blood type |
| Heart rate variability (HRV) | Date of birth |
| Sleep analysis | |
| Weight · Height | |
| Blood pressure (systolic/diastolic) | |
| Blood oxygen (SpO₂) | |
| Blood glucose | |
| Body temperature |
We never write any data to Apple Health — access is read-only. You can revoke this permission any time in iOS Settings → Health.
3.3 Data collected automatically
- Account information: your user ID; if you signed in with Apple or Google, the email address those providers pass to us. No email is collected for guest (anonymous) sign-in.
- Technical logs: error and security logs, app version.
- Usage and measurement data: to improve the app and measure advertising performance, analytics tools (Google Firebase Analytics and the Meta/Facebook SDK) collect non-health technical data: screen views, session information, device model, operating system, app version, app install/session events. On iOS the advertising identifier (IDFA) is used only if you grant permission (App Tracking Transparency); if you decline, only Apple's privacy-preserving, identifier-free SKAdNetwork is used. See §5.6–5.7.
3.4 What we never do with your health data
- We never send your health data (records, labs, medications, diagnoses, documents, Aria conversations) to advertising, marketing or analytics tools; these tools cannot access it.
- We do not sell your data, do not give it to data brokers, and do not use it for credit, insurance or employment decisions.
- We do not continuously track your location; location is used only in the moment you search for an appointment address.
4. Why we use this data
| Purpose | Legal basis (GDPR Art. 6/9 · KVKK Art. 5/6) |
|---|---|
| Store, display and let you search your records | Performance of a contract · explicit consent (health data) |
| Compare lab values against reference ranges and flag them | Explicit consent |
| Send medication and appointment reminders | Performance of a contract |
| Aria answering your questions | Explicit consent (separate and revocable) |
| Voice features (speech-to-text, text-to-speech) | Explicit consent (can be turned off in settings) |
| Measure app usage and advertising performance (non-health technical data only) | Legitimate interest · explicit consent (ATT) for the advertising identifier |
| Security, abuse prevention, debugging | Legitimate interest |
| Legal obligations | Legal obligation |
What we don't do: we do not use your health data for advertising or marketing, do not sell it, do not give it to data brokers, do not use it for credit/insurance/employment decisions, and do not process it for any other purpose without your consent. Analytics and advertising measurement use non-health technical/usage data only, and the advertising identifier depends solely on your ATT permission. For data from Apple Health, these prohibitions are additionally required by Apple's rules.
5. Who we share with
We do not sell your data. The service providers below act as data processors on our behalf, on our instructions. For each we state what is sent, how long it is kept, and where it is processed.
5.1 Supabase — hosting and database
- What is sent: all data in your account (records, medications, documents, conversations).
- Where: AWS eu-central-1 (Frankfurt), our primary region.
- Protection: Supabase states that customer data is encrypted with AES-256 at rest and TLS in transit, and that it is SOC 2 Type 2 compliant.
- Access: each record is readable only from your own session via row level security (RLS).
- Subprocessor list: https://trust.supabase.com
5.2 Anthropic (Claude) — Aria's replies
- What is sent: the messages you write to Aria and — only if you have consented — your health summary: age, sex, height, tracked conditions, diagnoses, lab values suggested for review, current readings, active medications, the last 30 days of records, and the specialty and date of an upcoming appointment.
- What is NOT sent: your name, your physicians' names, your uploaded documents and images, your email.
- Training: Anthropic's commercial terms prohibit training models on the content we send ("Anthropic may not train models on Customer Content from Services").
- Retention: Anthropic deletes API inputs and outputs within 30 days. If content is flagged by Anthropic's automated safety systems as a usage-policy violation, this may extend to 2 years (up to 7 years for classification scores).
- Where: Anthropic states data is stored in the United States.
- Subprocessor list: https://trust.anthropic.com/subprocessors
5.3 Groq — speech-to-text (only when "Cloud STT" is on)
- What is sent: the voice recording you speak to Aria.
- Training: Groq's services agreement prohibits training or fine-tuning models on inputs/outputs.
- Retention: Groq does not retain data by default on inference requests; if a temporary log is kept for reliability or abuse review, it is kept for at most 30 days.
- Where: retained data is held on servers in the United States.
- This feature is off by default; while off, your speech never leaves the device and iOS's own speech recognition is used.
5.4 Google (Gemini) — reading replies aloud in a natural voice (only when "Natural voice (cloud)" is on)
- What is sent: Aria's reply text (to be converted to speech).
- Retention: on the paid Gemini API, Google logs prompts and responses only for prohibited-use monitoring for a limited time; the logging window is at most 55 days.
- Training: on the paid tier, Google does not use this content to improve its products.
- This feature is off by default; while off, speech is generated on the device and the text never leaves it.
5.5 Apple
Sign in with Apple, notification delivery and app distribution are subject to Apple's own terms. Your Apple Health data stays on your device; we only read the types in §3.2.
5.6 Google — Firebase Analytics (app usage measurement)
- What is sent: non-health usage/technical data only — screen views, session information, device model, operating system, app version and a randomly generated app-instance identifier. No health data is sent.
- Purpose: to understand how the app is used and improve it.
- Linking: this data is not linked to your health data and is not used for ad personalization.
- Where: Google infrastructure (may include the United States).
5.7 Meta Platforms (Facebook) — advertising measurement and attribution
- What is sent: non-health app events only (app install, session start and — where applicable — purchase) and, if you grant ATT permission, the advertising identifier (IDFA). No health data is sent.
- Purpose: to measure and attribute the effectiveness of our advertising campaigns.
- Permission: on iOS the advertising identifier is used only with App Tracking Transparency permission; if you decline, only Apple's identifier-free, aggregate SKAdNetwork is used. You can change this any time in iOS Settings → Privacy & Security → Tracking.
- Where: Meta infrastructure (includes the United States).
5.8 Other sharing
- Shares you start: the summary you generate with "Share with your doctor" goes only to the person/app you choose, and each such share is logged in your account.
- Legal obligation: where legally required, to the minimum extent necessary.
- Transfer: in a merger/acquisition, subject to maintaining the same protection as this policy.
None of these third parties may use the data for their own purposes; our agreements require them to provide the same or equivalent protection as stated in this policy.
6. Aria and artificial intelligence
- Aria's replies are generated by AI and may contain errors. Aria is not a physician, does not diagnose, and does not set medication doses. Consult your doctor for medical decisions.
- The first time you open Aria, we ask for your explicit consent to send your health summary to Anthropic. If you decline, Aria still works — it sees only your typed message, and your health summary is not sent.
- You can withdraw consent any time in Settings → Aria → Privacy. After you withdraw, your health summary is not sent with your subsequent messages.
- Record suggestions Aria extracts (e.g. "I started this medication") are not saved without your confirmation.
7. Retention and deletion
- We keep your data for as long as your account is open.
- Deleting your account: Settings → "Delete my account". This permanently deletes your account, all health records, medications, appointments, Aria conversations and uploaded documents. It cannot be undone and does not require contacting support.
- After a deletion request, any residual copies at third-party processors disappear when their own retention periods (Anthropic 30 days, Groq at most 30 days, Google at most 55 days) in §5 expire.
- Export: Settings → "Export my data" gives you everything as JSON. The file is created on your device and goes only where you choose.
- Limited records subject to a legal retention obligation (e.g. security logs) may be kept until that period expires.
8. Your rights
Under KVKK and GDPR you have the right to access, rectify, erase, restrict processing, port, and object to processing of your data, and to withdraw consent you have given. You can exercise the erasure and export rights instantly from within the app (§7). For other requests, write to [email protected]; we respond within 30 days at the latest.
Complaint authority: in Türkiye, the Personal Data Protection Authority (KVKK); in the EU, the data protection authority of the country where you are located.
9. Security
TLS in transit, AES-256 encryption at rest; row level security (RLS) so each record is readable only by its owner; documents kept in a private, non-public bucket; API keys stored only server-side. We do not store health data in iCloud. No system is 100% secure; in the event of a breach we will notify you and the competent authority within the period required by law.
10. Children
Sifa is not designed for children under 13, and we do not knowingly collect data from anyone under that age. Where the applicable minimum age in your country is higher (for example 16 in some EU countries), that age applies. If you learn that a child has provided us data, write to [email protected] and we will delete it.
11. Changes
If we update this policy we will notify you in the app and change the "last updated" date above. For significant changes, we will ask for your consent again where required.