Simpo EHR privacy policy
Last updated: 30 September 2026
Simpo EHR is an app that clinics use to keep patient records: registration, visits, vital signs, consultations, lab results, prescriptions, stock and billing. Clinic staff use it on tablets and phones. Patients do not use the app themselves.
This policy explains what the app records, where that information goes, and who can see it. The app is made by DoveStreet (Latif Amars, Sweden). Questions about this policy go to latifamars@gmail.com.
Who is responsible for the records
The clinic that uses Simpo EHR decides what goes into its records and who may read them. Under data protection law the clinic is the controller of its patients’ data. Each clinic’s records are stored on a server the clinic chooses: usually a small computer in the clinic itself, or a server rented for it. The app sends records only to that server.
If DoveStreet runs a server for a clinic, we handle the records only to keep that server running and backed up, and only on the clinic’s instructions. We do not read, sell or share them.
If you are a patient and want to see, correct or remove your record, ask the clinic that treated you. The clinic can do it in Simpo EHR, and we will help the clinic if it asks us to.
What the app records
About patients, as clinic staff enter it: - name, sex, date of birth, phone number, ward and village, and a next of kin with their phone number; - national ID and health insurance numbers, when the clinic records them; - the patient number printed on the patient’s card; - visits, vital signs (such as temperature, blood pressure and weight), clinical notes, diagnoses, allergies and long-term conditions; - lab tests ordered and their results; - medicines prescribed and dispensed; - charges and payments, including the payment method (for example cash or a mobile money service).
About staff: username, full name, role and which clinic they work at. Passwords and PINs are stored only as one-way hashes, so nobody can read them back. The app also logs when staff sign in and which patient records they open, so the clinic can check who looked at a record.
About the device: a code and a name for each tablet the clinic enrols, so the clinic’s server can tell its tablets apart and can shut out a lost one.
The app does not collect location, contacts, photos or any information from other apps.
Permissions the app asks for
- Camera, to scan patient cards and medicine barcodes. The picture is read on the device to find the code, then thrown away. It is not stored or sent anywhere.
- Bluetooth, to print patient cards, labels and receipts on the clinic’s printer.
- Nearby devices (local network), to reach the clinic’s server on the clinic’s own network.
- Notifications, to tell staff when a result is ready or a reading is dangerous. Notifications shown outside the app never name a patient.
Where the information goes
Records are saved on the tablet so staff can keep working when the internet or the clinic’s network is down. When the tablet can reach the clinic’s server, it sends new records there and receives records made on the clinic’s other tablets.
That server is the only place the app sends records. The app contains no advertising, no analytics and no crash-reporting service. The barcode scanner comes from Google (ML Kit) and runs on the device; we have switched off its usage reporting, so it sends nothing to Google.
Google Play may collect its own information about the app, such as crash reports and install counts, under Google’s privacy policy. That information does not include patient records.
How the information is protected
- Records on the tablet are kept in an encrypted database. Its key is held by the Android Keystore and never leaves the device.
- Records travel between the tablet and the server over an encrypted connection (HTTPS).
- Staff must sign in, and what each person can do depends on their role: for example, only clinicians write consultation notes and prescriptions, and only the lab enters results.
- A clinic can shut out a lost or stolen tablet from its server. The next time that tablet connects, it deletes the clinic’s records.
- Backups are encrypted with a key that only the clinic holds. Without that key, nobody can read a backup, including us.
How long records are kept
Medical records are kept for as long as the clinic must keep them by law and for patient care. The clinic decides this. Removing the app from a tablet deletes everything stored on that tablet; the clinic’s server keeps its copy.
Deleting your data
Simpo EHR has no public sign-up. Staff accounts are made by the clinic, and patient records are kept by the clinic, so the clinic is who deletes them.
- Patients: ask the clinic that treated you to delete or correct your record. The clinic’s administrator does it on the clinic’s server. The clinic may have to keep parts of a medical record for as long as the law requires, and it will tell you which parts and for how long.
- Staff: ask your clinic’s administrator to close your account. Your name stays on the records you wrote, such as notes and receipts, because a medical record must show who wrote each part.
- If the clinic does not answer, write to latifamars@gmail.com with the clinic’s name. We will pass the request to the clinic and help it carry it out.
- Removing the app from a tablet deletes everything stored on that tablet at once. The clinic’s server keeps its copy until the clinic deletes it.
Children
Clinics record children as patients, with the information above entered by staff. The app is for clinic staff and is not meant to be used by children.
Laws
Simpo EHR is built for clinics in Tanzania and follows Tanzania’s Personal Data Protection Act, 2022. DoveStreet is based in Sweden, so the EU General Data Protection Regulation also applies to anything we do with personal data.
Changes to this policy
If we change this policy, we will post the new version at this address and change the date at the top.