Privacy Policy
This Privacy Policy describes how Solo-Doctor (“we,” “us,” or “our”) collects, uses, stores, and shares information when you use the Solo-Doctor mobile and desktop application (the “App”) and related services hosted at https://www.solo-doctor.com (the “Service”).
1. Who is responsible for your data
The data controller for account and server-side data processed through the Service is the operator of Solo-Doctor. For privacy questions or requests, contact us at:
- Email: info@solo-doctor.com
- Website: https://www.solo-doctor.com
Important note about patient records: When you, as a healthcare professional, enter patient information into the App, you are generally responsible for that information under applicable healthcare and privacy laws in your jurisdiction. Patient clinical data described below is stored primarily on your device unless you choose to send it to us (for example, through the Contact us feature).
2. Information we collect
2.1 Doctor account information (stored on our servers)
When you register or sign in, we collect and store:
- Full name
- Phone number (used as your account identifier)
- Password (stored only as a secure hash; we do not store your plain-text password)
- Registration date and time
- Authentication session data (access tokens)
- Device binding information, including a device identifier and technical device details such as manufacturer, model, platform, screen size, and a platform-specific device ID used to enforce one-device registration per account
2.2 Patient and clinical information (stored on your device)
The App allows you to create and manage clinical records. This information is stored locally on your device in an on-device database and local file storage, including but not limited to:
- Patient demographics (name, sex, date of birth, address, phone, occupation, marital status, blood type, insurance details, emergency contacts, notes)
- Appointments and visit records
- Vital signs and biometric measurements
- Medical conditions, allergies, medications, and clinical history
- Billing and payment status for visits
- Clinical attachments and files you add to records
- Print settings associated with your practice
We do not currently synchronize or back up patient clinical records to our servers as part of the standard App functionality.
2.3 Information you send to us voluntarily
If you use Contact us, we process:
- Subject and message body
- File attachments you choose to upload (up to 5 MB total per message)
- Your account name and phone number (included with support messages)
These messages are transmitted to our servers and delivered by email to info@solo-doctor.com.
2.4 Information stored on your device for app operation
- Login session token (stored using platform secure storage)
- Remembered phone number (if you enable remember-me)
- Notification preferences for appointment reminders
- Locally scheduled appointment reminder notifications
2.5 Information sent to third-party clinical search services
When you use in-app search for diagnoses (ICD-10), medications, conditions, or lab tests (LOINC), the App sends your search terms over the internet to the U.S. National Library of Medicine clinical tables API (clinicaltables.nlm.nih.gov) to retrieve reference results. We do not intentionally send patient names or identifiers with these search requests.
2.6 Information we do not collect
- We do not sell your personal information.
- We do not use the App for interest-based advertising.
- We do not integrate with Apple HealthKit, Google Health Connect, or similar consumer health platforms.
- We do not collect precise location/GPS data.
- We do not knowingly collect information directly from children.
3. How we use information
We use information to:
- Create and manage doctor accounts and authenticate users
- Enforce device binding and protect accounts from unauthorized use
- Provide App functionality (scheduling, records, printing, reminders, billing views)
- Deliver local appointment notifications you configure
- Respond to support and Contact us messages
- Maintain, secure, and improve the Service
- Comply with legal obligations
4. Legal bases for processing (EEA/UK users)
Where applicable under GDPR/UK GDPR, we process personal data based on:
- Contract: to provide the App and account services you request
- Legitimate interests: to secure accounts, prevent fraud, and improve the Service
- Consent: where required for notifications or optional features
- Legal obligation: where we must retain or disclose data under law
5. How we share information
We may share information only in these circumstances:
- Service providers: hosting, database, email (SMTP), and infrastructure providers that help us operate
www.solo-doctor.com - Clinical reference APIs: search queries sent to NIH clinical tables as described above
- Legal requirements: if required by law, regulation, legal process, or governmental request
- Protection of rights: to protect the safety, rights, or property of users, patients, or the public, as permitted by law
We do not share patient clinical records from your local database with third parties except when you choose to export, print, email, or attach that information (for example, via Contact us).
6. Data storage and international transfers
- On-device data: patient clinical records remain on your device unless you export or transmit them.
- Server data: doctor account data and support messages may be processed on servers operated by our hosting providers. Depending on your location, data may be stored or processed outside your country.
- Where required, we use appropriate safeguards for international transfers (such as standard contractual clauses or equivalent mechanisms).
7. Data retention
- Doctor account data: retained while your account is active and as needed to provide the Service, resolve disputes, and comply with law.
- Contact us messages: retained as long as needed to handle your request and for reasonable business record-keeping.
- On-device clinical data: retained on your device until you delete it within the App or uninstall the App.
- Session tokens: retained until logout, expiry, or account deletion.
8. Security
We use administrative, technical, and organizational measures designed to protect information, including HTTPS for communications with our servers, hashed passwords, and platform secure storage for session tokens. No method of transmission or storage is 100% secure. You are responsible for securing your device, operating system, and account credentials.
Your responsibilities as a healthcare professional: You should use the App in accordance with applicable professional, ethical, and privacy obligations regarding patient information in your jurisdiction.
9. Your rights and choices
Depending on your location, you may have rights to:
- Access personal information we hold about you
- Correct inaccurate account information
- Delete your account and associated server-side data
- Object to or restrict certain processing
- Withdraw consent where processing is consent-based
- Data portability (where applicable)
- Lodge a complaint with a supervisory authority (EEA/UK)
California residents may have additional rights under the CCPA/CPRA. We do not sell or share personal information for cross-context behavioral advertising.
To exercise your rights, email info@solo-doctor.com. We may need to verify your identity before fulfilling a request.
9.1 Account deletion
You can delete your Solo-Doctor account inside the App from the user menu (Delete account). You will be asked to confirm with your password. Account deletion:
- Removes your doctor account from our servers
- Deletes all patient and clinical records stored locally on your device
- Removes local appointment reminders and signs you out of the App
You may also request account deletion by emailing info@solo-doctor.com.
9.2 Notifications
You can control appointment reminders in App settings and through your device notification settings. On Android 13+, the App may request notification permission.
10. Children’s privacy
The App is for use by healthcare professionals and is not directed to children. We do not knowingly collect personal information from children under 13 (or under 16 where applicable). If you believe we have collected such information, contact us and we will take appropriate steps to delete it.
Healthcare professionals may record information about pediatric patients as part of clinical care; that processing is the responsibility of the professional using the App.
11. Permissions used by the App
| Permission / feature | Purpose | Platform |
|---|---|---|
| Internet / network access | Account login, registration, contact email, clinical code search | All |
| Notifications | Local appointment reminders | Android, iOS, Windows |
| File picker / documents | Attachments in Contact us and clinical records | All |
| Secure storage | Store session token securely | All |
12. Third-party services
- National Library of Medicine (NIH) — clinical terminology search (clinicaltables.nlm.nih.gov)
- Hosting and email providers — operation of
www.solo-doctor.comandinfo@solo-doctor.com
Third-party services have their own privacy policies. We encourage you to review them.
13. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. We will post the updated version at this URL and update the “Last updated” date. If changes are material, we may provide additional notice within the App or by email where appropriate. Continued use of the App after the effective date constitutes acceptance of the updated policy.
14. Contact us
If you have questions about this Privacy Policy or our data practices:
- Email: info@solo-doctor.com
- Web: https://www.solo-doctor.com
Appendix A — Store disclosure summary
| Data category | Collected? | Linked to user? | Used for | Shared? |
|---|---|---|---|---|
| Name (doctor) | Yes | Yes | Account, support | Hosting/email providers only |
| Phone number (doctor) | Yes | Yes | Account, authentication, support | Hosting providers only |
| User IDs / device ID | Yes | Yes | Security, one-device binding | Hosting providers only |
| Health info (patient records) | Yes (on device) | Yes (doctor’s records) | App functionality | Not shared by default; user may export/email |
| Emails / messages | Yes (Contact us) | Yes | Customer support | Email provider only |
| Files and docs | Yes (optional) | Yes | Support attachments, clinical attachments (local) | Only if user sends via Contact us |
| App activity (search terms) | Yes | No* | Clinical code lookup | NIH clinical tables API |
Google Play: App category Medical / Business. Complete Health apps declaration: handles health data — Yes; medical device — No; data encrypted in transit — Yes (HTTPS); account deletion available — Yes (in-app and by email request).
Apple App Store: Privacy nutrition labels — Data Linked to You: Name, Phone Number, User ID, Health (patient data entered by professional), Contact Info; Data Not Linked to You: search queries to NIH. No tracking declared.
Microsoft Store: Publish this policy URL in Partner Center. Age rating: recommend 17+ / Adults only due to medical content.