How we collect, use and protect your data, in plain terms.
Last updated: 15 August 2026
North Shore Digital LLC operates Tamna, a telemedicine platform that connects patients in Egypt with licensed doctors for online consultations. In this policy, "Tamna", "we" and "us" refer to North Shore Digital LLC as the operator responsible for the platform. Because we handle health information, we treat your data as confidential by default. This policy explains what we collect, why we collect it, who we share it with, and the control you have over it. It applies to our website, mobile applications and dashboards for patients, doctors and authorised staff.
1. Your Account
To create and maintain an account we collect:
Your full name and your mobile phone number, which is the primary identifier for your account.
An email address, where you choose to provide one or sign in with Google.
Your password, which is stored only as a salted cryptographic hash — we never store or see it in readable form.
Your preferred language (English or Arabic) and your dashboard theme preference.
Your role on the platform (patient, doctor, administrator or assistant) and your account status.
For doctors: professional credentials, licence and syndicate details, specialisation and verification documents submitted during onboarding.
You may sign in with a phone number and password, or with Google. If you enable two-factor authentication, we also store the encrypted secret used to generate your authentication codes.
2. Phone Number Verification and SMS
Your phone number is how we identify and reach you, so we verify that it belongs to you:
When you register, we send a 6-digit one-time passcode (OTP) by SMS to the Egyptian mobile number you provide.
We store only a cryptographic hash of that code, never the code itself, together with its expiry time and the number of attempts made.
Codes expire automatically after a short period, and both requests and verification attempts are rate limited to protect you against abuse.
Your account is not activated and you are not signed in until the code is verified.
Verification records are deleted once they are used or expire.
To deliver the SMS we pass your phone number and the message to our SMS provider. We do not permit them to use it for any other purpose.
Standard carrier message and data rates may apply to messages you receive. We only send transactional messages — verification codes and service notifications — and never marketing SMS without your separate consent.
3. Patient and Health Data
Health information is the most sensitive data we hold. Depending on how you use the service, this may include:
Demographic details such as date of birth, gender and blood type.
Your emergency contact name and phone number.
Your national ID, where you choose to submit it for identity verification.
Medical history, allergies, current medications and chronic conditions you record in your profile.
The symptoms, reason for visit and notes you provide when booking a consultation.
Clinical notes, diagnoses and prescriptions written by your doctor during or after a consultation.
Documents and images you upload, such as lab results, scans or referral letters.
Health data is only ever visible to you, to the doctor you are consulting (and any assistant that doctor has explicitly authorised), and to the small number of administrators who need it to resolve a support or safety issue. Access is enforced in the database itself through row-level security policies, not merely in the application.
4. Appointments and Video Consultations
When you book or attend a consultation we process:
The date, time, duration, status and type of the appointment, and the doctor involved.
Your position and waiting time if you join a queue.
Messages, voice notes, images and documents you choose to exchange with your doctor through in-app chat.
Ratings and reviews you choose to leave after a consultation.
Video consultations are carried out over Daily.co. The audio and video stream is encrypted in transit and is processed by Daily.co to connect you to your doctor. Tamna does not enable call recording and does not store the audio or video content of consultations. We retain limited call metadata — such as whether a call took place, when it started and how long it lasted — so that both parties have an accurate record of the visit.
5. Urgent Care and Emergency Services
The urgent-care queue is designed to connect you to an available doctor quickly. When you use it we process:
Your request time, urgency level and the symptoms you describe.
Your queue position, waiting time and the outcome of the request.
Your emergency contact details, where a doctor judges it clinically necessary to use them.
Where there is an immediate risk to life or safety, we may disclose the information strictly necessary to emergency services or to your listed emergency contact. Tamna is not a substitute for emergency medical care — in a life-threatening emergency you should call the Egyptian emergency services on 123 directly.
6. Payments
Consultations are paid in full at the time of booking. To process a payment we handle:
The consultation fee, any applicable service fee, discount codes applied, and the total amount charged.
The transaction reference, status, currency and timestamp.
Invoices, receipts and refund records.
Where you pay by manual transfer, the payment proof you upload and the reference you supply.
Card payments are processed by Paymob, our licensed Egyptian payment gateway. Your full card number, expiry date and CVV are entered on Paymob's systems and are never transmitted to or stored on ours — we only receive a masked reference and the result of the transaction. Financial records are retained for as long as Egyptian tax and accounting law requires.
7. Notifications and Communications
We use your contact details to send you messages that are part of the service:
SMS — verification codes and time-critical account or appointment alerts.
WhatsApp — appointment confirmations, reminders and queue updates, sent through the WhatsApp Business Platform.
Email — receipts, verification links, password resets and account notices.
Mobile push notifications — appointment, payment, queue and message alerts delivered through Expo and the notification service operated by your device platform. For this purpose, we store a push token, device platform and an optional device label.
In-app notifications — everything above, plus messages from your doctor.
Transactional messages are part of providing the service and cannot be fully disabled while your account is active, though you can adjust channel preferences in your notification settings. Marketing messages are only ever sent with your explicit opt-in, and every one of them includes a way to opt out.
8. Technical and Usage Data
We automatically collect a limited amount of technical data when you use the platform:
Device type, browser, operating system and screen size.
App version and limited device information needed to operate, secure and troubleshoot the mobile application.
IP address, used for security, fraud prevention and rate limiting.
Pages viewed and features used, in aggregate.
Error reports and diagnostic traces when something goes wrong.
The mobile app stores your sign-in session, language, theme, local medication reminders and a limited reference to an unfinished payment on your device so that those features continue to work. Camera and microphone access is requested only for video calls, voice notes or a photo you choose to take. Photo-library and document access is requested only when you choose a file to upload. We use strictly necessary cookies on the website to keep you signed in and remember your preferences. If you scan a doctor's printed QR code, we also set an opaque first-party referral cookie for up to seven days so we can measure, in aggregate, whether printed cards lead to a profile visit or paid booking. The cookie is cleared after it is linked to a booking, and it is not used for advertising or cross-site tracking. We use Vercel Analytics and Speed Insights for website traffic and performance, and Sentry for error monitoring. Where you have consented on the website, we use the Meta Pixel to measure advertising effectiveness; you can withdraw that consent at any time.
9. How We Share Data
We do not sell your personal data, and we never share health information for advertising. We share data only in these situations:
With the doctor you are consulting, and any assistant that doctor has authorised, so they can treat you.
With service providers who process data to operate Tamna: Supabase (database, authentication and file storage), Daily.co (video), Paymob (payments), Meta (WhatsApp Business Platform), Resend (email), our SMS provider, Expo and Apple or Google (mobile push delivery), Vercel (hosting), Upstash (rate limiting) and Sentry (error monitoring).
With your explicit consent, for example when you ask us to share records with another provider.
Where required by Egyptian law, a court order or a lawful request from a competent authority.
Where necessary to prevent an imminent threat to someone's life or safety.
Some of these providers operate servers outside Egypt. Where data is transferred abroad, we rely on contractual safeguards that require the provider to protect it to the standard set out in this policy.
10. How Long We Keep Data
We keep data only as long as we have a reason to:
Medical records are retained for the period required by Egyptian healthcare regulations, which is longer than the life of your account.
Financial and transaction records are retained for the period required by tax and accounting law.
OTP verification records are deleted as soon as they are used or expire.
QR referral records expire after seven days; paid-booking attribution is retained only as aggregate counts.
Technical logs are retained for a short period and then deleted or anonymised.
Other account data is deleted or anonymised after you close your account.
11. Security
We protect your data with layered technical and organisational measures:
All traffic is encrypted in transit with TLS, and data is encrypted at rest.
Row-level security policies in the database restrict every record to the users entitled to see it.
Passwords are stored only as salted hashes; optional two-factor authentication is available.
Rate limiting protects sign-in, registration and verification against brute-force attempts.
Access by our staff is limited to what their role requires. Sensitive administrative actions are recorded where supported, and we maintain security monitoring intended to detect and investigate misuse.
No system can be guaranteed completely secure. If a breach ever affects your personal data, we will notify you and the relevant authorities without undue delay.
12. Your Rights
Under Egypt's Personal Data Protection Law (Law No. 151 of 2020) you have the right to:
Know what personal data we hold about you and why.
Access a copy of your data — you can export it yourself from your account settings.
Correct data that is inaccurate or incomplete.
Request deletion of your data, subject to the retention periods above.
Withdraw consent you have previously given, including for analytics and marketing.
Object to a particular use of your data, or ask us to restrict it.
Complain to the Egyptian Personal Data Protection Centre.
You can export your data or request account deletion directly from your account settings, or contact us using the details below. We respond to requests within 30 days.
13. Children
An account must be held by someone aged 18 or over. A parent or legal guardian may create a dependant profile and book consultations for a child, and remains responsible for that child's data. We do not knowingly allow anyone under 18 to hold an account in their own name; if we discover one, we will remove it.
14. Changes to This Policy
We may update this policy as the service develops or the law changes. The date at the top of this page always reflects the current version. If a change materially affects your rights, we will notify you in the app or by message before it takes effect.
15. Contact Us
For any question about this policy, or to exercise any of the rights above:
Operator and data controller: North Shore Digital LLC, operating Tamna.