This policy explains what information PracProof handles, where it lives, and the choices you have. PracProof is built so that patient-identifiable information stays on your device — it is never stored on our servers in a form we can read. There are two exceptions, both optional and under your control: the optional AI features (section 4), where information is sent to an AI provider to do the work and is not kept afterwards; and practice sharing (section 5), where the records you choose to share with your own practice team are synchronised between your practice’s phones as end-to-end encrypted data that we cannot decrypt. PRACPROOF (PTY) LTD (registration 2026/509315/07) is the responsible party under the Protection of Personal Information Act (POPIA) for your account, and an operator acting on your instruction for the optional AI features.
1. On your device (not sent to us)
Your NHLS Labtrak/TrakCare password, recently viewed lab results, and any prescriptions or sick notes you prepare are stored on your device. They are held in the operating system’s secure store (iOS Keychain / Android Keystore), encrypted, and automatically deleted after a window you control (24 hours by default). This information is not transmitted to, or stored on, our servers — unless you choose to share specific records with your own practice team, in which case they are end-to-end encrypted first (section 5). Your HPCSA number is stored on your device the same way, and is additionally linked to your account on our servers solely so we can confirm your registration against the public HPCSA register (section 2).
2. What is on our servers
Our servers hold what is needed to run your account and subscription: your account identifier (the email you sign up with), your subscription status, and — for doctors — the HPCSA number you enter at setup, used only to confirm your registration against the public HPCSA register. If you use practice teams, they also relay and store the end-to-end encrypted practice records described in section 5, which we cannot decrypt. No patient names, ID numbers, MRN/episode numbers, lab results, prescriptions or sick notes are ever stored on our servers in readable form.
3. How lab results reach you
When you look up results, your device connects to the NHLS Labtrak/TrakCare portal directly, using your own credentials, and reads the result on the device. The result data does not pass through our servers. We do not alter the underlying laboratory data.
4. Optional AI features
PracProof includes optional AI features: drafting a document from your typed notes, recording a consultation to draft a note, and photographing a sticker or a medical report to read its details. These are the only features that send information off the device, and each one is optional with a manual alternative, requires the patient’s consent before you use it, and produces a draft that you review, correct and sign. What is sent differs by feature: when drafting from typed notes, the patient’s direct identifiers (name, ID number, contact details, dates) are removed on this device first, so the AI sees only the clinical text; recording a consultation, and photographing a sticker or report, send the audio or photo as-is, because they cannot be de-identified. The information is processed by a third-party AI provider via our secure gateway — currently Google, with Anthropic as an automatic backup for text drafting if Google is unavailable — to produce the draft; it may be processed outside South Africa, on paid tiers that are not used to train AI models, and it is not stored after the draft is produced. Our gateway keeps no copy of the audio, image, text or result — only an anonymous count of requests for usage limits. Standard calculators and the document verifier remain fully on-device and send nothing.
5. Practice teams (optional sharing with your practice)
If you create or join a practice and choose to share records with it — a patient, consult handovers, the day’s outpatient flow, appointments and, where the practice owner switches it on, the day’s prescriptions and documents for dispensary printing — those records are synchronised between your practice’s phones through our servers. They are end-to-end encrypted on your phone before they are sent: the encryption keys exist only on your practice’s devices, so our servers relay and store data we cannot decrypt. Nobody outside the practice, including PracProof, can read what is shared. Removing a member re-secures the practice with a fresh key for everything shared afterwards; copies a colleague’s phone has already synchronised remain on that phone under their professional control, as with any clinical record. A doctor’s drawn signature never syncs — a colleague’s phone prints documents without it.
6. Payments
PracProof is currently free and collects no payment information. If a paid add-on launches in future (such as AES e-scripts), payment would be handled on the web by a payment provider (such as Paystack): your card details would be entered with the provider and processed under their own security and privacy terms; we would not see or store your full card number, and would receive only confirmation of your plan status.
7. Anonymous usage statistics
We keep simple, anonymous counters of how often app features are used — for example, the total number of times the app was opened, or a medicine reference page was viewed, on a given day. These counts contain no name, email, account or device identifier, no location, and no patient data: a request only increments a number. We use them to understand which content matters and, in future, to report aggregate interest levels (never individual behaviour) to content partners. The document verifier is deliberately excluded — verification runs entirely on your device and sends nothing.
8. Where your account data is processed
Account and subscription data is processed by our authentication and database provider (Supabase) in a European (London) data centre, chosen because it offers the lowest latency to South Africa in a jurisdiction with data-protection laws recognised as providing adequate protection. Any such cross-border processing is done in line with POPIA.
9. Your controls and rights
You can wipe your credentials and cached results immediately with “Clear on-device data now”, and toggle history caching and AI on or off at any time. Under POPIA you may ask us to confirm, access, correct or delete the personal information we hold about you (your account and subscription details), and you may object to processing or lodge a complaint with the Information Regulator of South Africa. To exercise any of these, contact us using the details below.
10. Security
On-device data is encrypted in the OS secure store. Connections to our services and to Labtrak use encrypted (HTTPS) transport. Practice sharing adds end-to-end encryption on top: the keys live only on your practice’s devices. Because patient-identifiable data stays on your device (or reaches our servers only as ciphertext we cannot decrypt) and is auto-purged, the risk from a server-side breach is minimised by design. You are responsible for the security of the device itself (screen lock, OS updates).
11. What we never do
We do not sell or rent your data. We do not share your personal information with third parties for their own marketing. We do not store patient-identifiable information on our servers in readable form — what your practice shares is end-to-end encrypted with keys we never hold. And if sponsored material ever appears in the app, it will be clearly labelled as such.
12. Children
PracProof is intended for use by registered clinicians and is not directed at children. We do not knowingly collect personal information from children through the app. Patient information you view remains on your device and under your professional control as the treating clinician.
13. Retention
On-device patient data is retained only until it auto-purges (24 hours by default) or you clear it. End-to-end encrypted practice records are retained while your practice uses the sharing features, so its phones can stay in sync. Account and subscription data is retained while your account is active and for a reasonable period afterward to meet legal, tax and audit obligations, then deleted or anonymised.
14. Changes to this policy
We may update this policy as the app evolves or the law changes. We will revise the version date below and, for material changes, tell you in the app. Continued use after an update means you accept the revised policy.
15. Contact us
For any privacy question or to exercise your rights, contact the PracProof Information Officer at admin@pracproof.co.za. Responsible party: PRACPROOF (PTY) LTD (registration 2026/509315/07).
Version 2026-07-28 · You can re-read this any time from Account.