Cryptex Medical app privacy policy
Last updated: 31 July 2026
This Privacy Policy describes how the Cryptex Medical iOS and Android applications and the services supporting them handle information. It is provided for doctors and employees authorised to use Cryptex Medical by a subscribing healthcare practice. Cryptex Medical is not a patient app or patient portal and does not offer public or in-app registration.
Access to Cryptex Medical is provided under a signed Usage Agreement between Cryptex and the subscribing practice. That agreement governs the commercial relationship, authorised users, support, processing instructions, service termination, data export and data disposition. This Privacy Policy describes the applications' data handling and does not replace or amend the Usage Agreement. The marketing website has a separate website privacy policy.
Who we are and our role
Cryptex Medical is provided by Cryptex Data Solutions CC. For patient and practice records, the subscribing practice generally determines why and how information is processed and is the responsible party under POPIA. Cryptex acts as the practice's operator and processes that information to provide Cryptex Medical under the Usage Agreement and the practice's instructions.
Cryptex is separately responsible for limited information used for customer administration, authentication, security, billing, diagnostics, legal compliance and operation of Cryptex Medical.
Information handled through the apps
- Practice and user information: practice details, user name, work email address, account identifier, role, permissions and practice membership.
- Patient and practice records: identity and contact details, appointments, medical-scheme and billing information, clinical notes and history, medicines, scripts, referrals, communications, reports and other records entered or selected by the practice.
- User-provided content: documents, photographs, files, audio selected for transcription and the resulting transcript.
- Security and diagnostics: IP address, app and operating-system version, device model, installation and service identifiers, access and audit events, crash reports and performance information.
Information comes from authorised practice users, the practice's existing records, people who provide information to the practice, service activity and integrations the practice chooses to use.
Permissions and information on the device
- Microphone: used only when a user chooses to record audio for transcription.
- Camera, photos and files: used only when a user chooses to capture or select an item for a practice record.
- Biometrics: Android may use the device's biometric service to unlock the app; Cryptex does not receive or store biometric templates.
The apps do not access HealthKit, Health Connect, the device contact book, device location or advertising identifiers. Authentication tokens are kept in protected device storage. Selected clinical media may be cached locally for viewing and can be cleared in Settings; it is also cleared on sign-out and practice switch. Uninstalling the app removes its local application data, subject to the device platform's backup and restore behaviour.
How information is used
- To authenticate users and apply the practice's role and permission controls.
- To provide patient records, scheduling, clinical documentation, billing, claims, transcription, communications and related practice workflows.
- To deliver information when an authorised practice user selects a recipient or service.
- To secure, support, diagnose and maintain Cryptex Medical and its audit trail.
- To administer the customer relationship and meet legal obligations.
Cryptex does not sell personal information, use patient information for advertising, or track people across unrelated companies' apps or websites. Cryptex Medical does not make autonomous clinical decisions. A healthcare professional must review transcriptions and other generated material before relying on them as part of a clinical record.
Service providers and practice-selected recipients
Cryptex uses selected service providers to operate Cryptex Medical. Amazon Web Services hosts the application, databases and practice files in Cape Town. Pusher supports realtime service events, and Sentry provides crash and performance diagnostics. These providers receive only the information needed for their respective functions.
When a user chooses transcription, the audio is processed by Deepgram through its European Union service. Cryptex Medical does not intentionally attach a patient identifier or supplementary patient metadata to that audio. The practice controls what its users dictate, and clinical content is treated as sensitive even when direct identifiers are omitted.
Practice communications are delivered through Twilio SendGrid for email, SMS Portal in South Africa for SMS and, when enabled, Meta for WhatsApp. These providers receive the destination address or telephone number and the practice-controlled message content required for delivery. Google Maps is used only to include practice-location maps in appointment-reminder emails; the native apps do not send device location to Google Maps.
Medical schemes, claims services, referral recipients and other recipients receive information only when an authorised practice user initiates the relevant transaction or communication.
Location and cross-border processing
Cryptex Medical hosting, databases, practice-file storage and authentication are operated in South Africa. Deepgram transcription uses its European Union service. Other communications, diagnostics and global delivery providers may process the limited information sent to them outside South Africa. Appropriate contractual and legal safeguards are applied where POPIA section 72 applies.
Security
Cryptex uses safeguards appropriate to healthcare information, including encryption in transit and at rest, authenticated access, role and permission controls, protected mobile token storage, tenant separation, logging and backups. Practices remain responsible for managing their users, devices, credentials and instructions. No service can guarantee absolute security.
Retention, access removal and deletion
Practice-controlled information is retained, exported, returned or deleted in accordance with the practice's instructions, the signed Usage Agreement, applicable law and professional record-retention duties. Removing one user's access does not delete the practice's patient records or required audit history. Cryptex retains its own customer, account, security, billing and diagnostic records only for as long as reasonably needed for the purposes described here and applicable legal obligations.
Each practice creates and manages access for its doctors and employees. Users must ask their practice administrator to change or remove their access. Cryptex accepts support, service, export and deletion instructions only from an authorised practice representative through the support channel agreed in the Usage Agreement. Optional device permissions can be withdrawn in device settings, although the related feature will then be unavailable.
Patient requests
A patient seeking access to, correction of or deletion of a practice record must contact the healthcare practice that controls that record. If Cryptex receives such a request, it refers the request to the relevant practice and assists the practice as its operator.
Changes and privacy questions
We update this policy when the apps, providers or applicable requirements change. Questions specifically about this Privacy Policy may be sent to support@cryptexmedical.com.