The short version
A plain-language summary. The full policy below is what governs — please read it before booking a consultation or syncing your health data.
Current app status
CardioRehab PK is being rolled out in stages. This table tells you exactly what's actually collecting or processing data today, versus what's described in this policy for features that are built but not yet switched on. Sections below are labelled the same way.
| Feature | Status |
|---|---|
| Local, on-device tracking (readings, meds, symptoms, streaks) | Live now |
| Local backup / restore (export & import a data file) | Live now |
| Device reminders (local notifications via your browser) | Live now |
| Booking a consultation via WhatsApp | Live now |
| Clinic-held patient records at PIC / affiliated hospitals | Live now |
| Google account sign-in & cloud sync | Live now |
| In-app online payment (Safepay / JazzCash checkout) | Planned – not yet live |
| Doctor-side booking dashboard | Planned – not yet live |
| Server-delivered push notifications | Live now |
| In-app linking of your account to a clinic MRN record | Planned – not yet live |
In short: right now, everything you track stays on your own device, and booking happens by messaging the clinic on WhatsApp. Nothing is uploaded, no account is required, and no payment is collected inside the app.
1Overview & scope
This Privacy Policy describes how CardioRehab PK ("the app", "we", "us") collects, uses, stores, shares, and protects information when you use the app, its website (app.ahmedzainsubhani.com), and its Android app, and when you book, pay for, or attend a consultation with Dr. Ahmed Zain Subhani through it.
It covers the app's full set of features, including consultation booking and payment, optional cloud sync and sign-in, the doctor-side booking dashboard, prescriptions and the patient registry (MRN), and reminder notifications. If you are using a version of the app where a particular feature (for example, online payment or cloud sync) is not yet turned on, the sections describing that feature simply don't apply to you yet — they describe how that feature works once it is live.
By using CardioRehab PK, you agree to the practices described in this policy. If you don't agree, please don't use the app, or use it only in signed-out, local-only mode, which keeps your data on your device.
2Who we are
CardioRehab PK is developed and operated by Dr. Ahmed Zain Subhani, Specialist Cardiac Surgeon and Assistant Professor, Punjab Institute of Cardiology (PIC), Lahore, Pakistan. Dr. Zain is the data controller for the personal and health information described in this policy — he decides what data is collected and why, and he (through his clinic staff, where applicable) is the person responsible for it.
Contact details are at the bottom of this page and in Section 19.
3Information we collect
3.1 Information you provide directly
- Profile information: name, age/date of birth, sex, contact number (optional), patient category (general cardiology, planned surgery, post-surgery, or caregiver), surgery type and date, and comorbid conditions you select (e.g., diabetes, hypertension, on warfarin).
- Health readings you log: INR values and warfarin doses, blood pressure readings, blood sugar readings (fasting/random/A1c), symptom entries (e.g., chest pain, breathlessness) with severity, GTN dose counts, medication list and daily adherence ticks, and smoke-free tracking (quit date, relapse history).
- Appointment and booking details: consultation type (physical or online), requested date and time, and any notes you add.
- Payment-related booking information: Planned – not yet live once in-app payment exists, this would be the fee amount, consultation type, and which slot it relates to. Your card number, CVV, or mobile-wallet PIN would never be collected or stored by us — see Section 6.
- Account information (optional): Live now if you choose to sign in with Google to enable cloud sync, we receive your Google account email address and a unique account identifier. Sign-in is entirely optional — without it the app works fully on your device and no account exists.
- Messages sent via WhatsApp: if you use a "Book on WhatsApp" button, the pre-filled message you send is handled by WhatsApp — see Section 7.
3.2 Information collected automatically
- Local storage: most of the data above is stored directly in your device's local app storage. It is not automatically sent anywhere unless you turn on cloud sync.
- Device and technical data: general device/browser type and app version, used only to keep the app working correctly (e.g., service-worker caching) and, if applicable, anonymous crash information.
- Local reminders: Live now if you turn on reminders, your browser stores a local notification permission and schedule on your device so it can show you appointment, medicine, and reading-alert reminders. This does not involve sending any token or data to us.
- Notification token (server-delivered): Live now a device notification token lets us deliver reminders from our servers even when the app is closed. The reminder messages themselves carry no health information — your device fills in the medicine or appointment details locally.
- IP address: the app loads typefaces from Google Fonts, which may see your IP address as part of that request. We do not otherwise log or use your IP address.
3.3 Information from your care team
- Live now if you're seen at PIC or one of Dr. Zain's affiliated clinics, clinic staff may create a basic patient record (name, age, MRN, contact) for scheduling and record-keeping, and if Dr. Zain issues you a prescription, its clinical content (diagnosis notes, findings, medicines, advice) is recorded against that patient record. This clinic record-keeping is independent of the app.
- Planned – not yet live linking your app account to your clinic MRN record, so a prescription automatically appears in your app and merges into your tracker, is a planned feature and not yet available.
4How we use your information
- To provide the app's core features: trackers, educational content, reminders, and your recovery timeline. Live now
- To let you message the clinic to book a consultation via WhatsApp. Live now
- To send reminders and out-of-range alerts for readings you log — these are always framed as "consider booking a consultation," never as a diagnosis. Live now
- To keep the app secure, prevent abuse, and fix problems. Live now
- To manage consultation scheduling and payment processing, and to allow Dr. Zain to review booking and payment details, once those features are live. Planned
- To generate and deliver prescriptions inside the app, and to merge accepted medicines into your tracker with correct dosing and reminder times, once account linking is live. Planned
- To maintain a patient registry (MRN) for continuity of care across visits — this already happens at the clinic today, independent of the app (Section 3.3); linking it to your app account is planned. Live at clinic / app-linked: Planned
5Health data & consent-based sharing
Health information is sensitive, so CardioRehab PK is built "local-first, sealed by default":
- Today, the app is signed-out only: Live now everything you track stays on your device only, in local browser storage. Nothing is uploaded to us, and there is no account to sign into.
- Signed in (optional): Planned – not yet live once available, signing in would sync your data to your own private cloud record so it's available across your devices. Every record would be tied to your account only — there would be no way for another account, including another patient's, to read or list your data, and Dr. Zain's account would not automatically get read access either.
- Doctor visibility opt-in, per consultation: Planned – not yet live once a doctor-side dashboard exists, it would only ever show scheduling facts (your name and the slot) — never your health readings, unless you separately agree. You would be asked at booking time: "Share your recent readings and medicine record with Dr. Zain for this consultation?" Declining would be a full, first-class option. Today, the only way Dr. Zain sees your readings is if you choose to share them yourself — for example, by describing them in your WhatsApp message or showing him your device at your appointment.
- Walk-in / clinic-entered records: Live now if you're seen in person, they contain only what Dr. Zain or his staff record clinically at the clinic (see Section 3.3), and are not connected to the app in any way today.
6Payments Planned – not yet live
When online payment goes live, booking a paid consultation will take you to a secure, hosted checkout page run by a licensed Pakistani payment provider (such as Safepay or JazzCash). That page — not the app — will collect your card or mobile-wallet details directly.
- We will never receive, see, or store your full card number, CVV, or wallet PIN.
- We will store only what's needed for your booking and our accounting: the transaction reference, amount, currency, payment status (pending/paid/failed/refunded), and which consultation it relates to.
- Overseas patients will be able to alternatively pay by bank transfer or Wise; in that case we would store the reference code you're given and its confirmation status, and Dr. Zain would confirm receipt manually.
- Payments will be for a real-world medical consultation service, so they will be processed by our payment gateway rather than through Google Play Billing.
- Refunds, where applicable, will be processed by the payment gateway per our stated refund policy, shown to you before checkout.
7WhatsApp
Tapping a "Book on WhatsApp" button opens WhatsApp with a pre-filled message to Dr. Zain's clinic number. Once you send it, that conversation is a normal WhatsApp chat, governed by WhatsApp's own privacy policy, not this one. We don't control, and this policy doesn't cover, how WhatsApp/Meta handles that message — we only see what you choose to send us, the same as any WhatsApp conversation with the clinic.
8Notifications
If you enable reminders, the app uses your browser's local notification permission and its service worker to remind you about:
- Upcoming appointments
- Medicine times
- Out-of-range readings, with a suggestion to consider booking a consultation
- Daily tracking prompts
These reminders are generated and shown entirely by your own device, based on the schedule you set.
Live now: Server-delivered push reminders (reminder tokens). When you switch reminders on, the app registers a push notification token (a device identifier issued by Firebase Cloud Messaging, a Google service) together with your reminder times — clock times and opaque slot codes only. This is what lets a reminder reach your phone even when the app is closed. No health information travels through the push system: the push message contains no medicine names, no doses, no readings, and no appointment details — your own device composes the notification text locally from data stored only on the phone. The token identifies a device, not you by name; it is encrypted in transit, is deleted automatically when it becomes invalid, and is removed when you turn reminders off, clear site data, or uninstall the app.
یاد دہانیاں آن کرنے پر ایپ ایک «پش ٹوکن» (فائربیس کلاؤڈ میسجنگ — گوگل کی سروس — کا جاری کردہ ڈیوائس شناختی کوڈ) اور صرف یاد دہانی کے اوقات محفوظ کرتی ہے۔ پش پیغام میں کوئی طبی معلومات نہیں ہوتی — نہ دوا کا نام، نہ خوراک، نہ ریڈنگ — نوٹیفکیشن کا متن آپ کا اپنا فون مقامی ڈیٹا سے بناتا ہے۔ یاد دہانیاں بند کرنے یا ایپ ہٹانے پر ٹوکن حذف ہو جاتا ہے۔
You can turn reminders off anytime in the app or your device's notification settings. Critical-band wording (e.g., very low blood pressure, hypoglycemia, very high INR) is stronger and points you to emergency guidance rather than routine booking — but the app is not a monitoring or emergency-alert service, and does not contact anyone on your behalf in an emergency.
10Data retention
- Local, on-device data: Live now your readings, medicines, symptoms, and any local backup files stay on your device until you delete them, clear your browser's site data for the app, or uninstall/remove the app. We hold no copy of this data ourselves — if you lose your device without a backup file, that data cannot be recovered by us.
- Backup files you export: Live now a backup file you download is saved to your device's Downloads (or wherever you choose) and is retained for as long as you keep that file. It is never sent to us.
- Clinical records (prescriptions, MRN entries) held by the clinic: Live now if you're seen at PIC or an affiliated clinic, those records are retained by Dr. Zain's practice for continuity of care and standard medical record-keeping, in line with normal healthcare record-keeping practice, unless you request deletion and no clinical or legal reason requires retaining them.
- WhatsApp booking messages: Live now retained within WhatsApp per its own retention settings (see Section 7) — we don't separately store a copy on our side beyond what's needed to schedule your appointment.
- Cloud-synced data: Planned – not yet live once available, this would be kept while your account is active, and deleted when you delete your account.
- Payment and booking records: Planned – not yet live once in-app payment is live, these would be retained for accounting, tax, and dispute-resolution purposes for as long as reasonably necessary.
11Data security
- Live now because your tracked data stays on your own device today, its security depends mainly on your device's own lock screen, browser, and operating system protections — we'd encourage you to keep your device locked and its software up to date.
- Live now the app is served over an encrypted (HTTPS) connection, and any communication you send us via WhatsApp is protected by WhatsApp's own end-to-end encryption.
- Live now synced records are restricted so that every account can only read and write its own data — there is no query path that lets one account list or read another's records, and server-verified timestamps mean stored dates can't be backdated.
- Planned – not yet live once online payment exists, it will use hosted, PCI-compliant checkout pages; sensitive card/wallet data will never pass through our servers.
- Planned – not yet live once a doctor-side dashboard exists, access to it will be restricted to Dr. Zain's own verified account and cannot be self-granted by any other account.
No system is completely secure, and we can't guarantee absolute security — but we've deliberately designed the data model and access rules, live and planned, to minimize what could be exposed if something goes wrong.
12Data breach notification
If we become aware of a security incident that compromises personal or health information we hold (for example, once cloud sync or payment processing is live and something goes wrong with it), we will:
- Investigate and, where possible, contain the incident as quickly as reasonably practical.
- Notify affected users without undue delay — we aim for within 72 hours of confirming a breach that poses a real risk to you — describing what happened, what information was involved, and what we're doing about it.
- Notify you using the contact details we hold for you (e.g., email, if you've signed in) or, where that isn't possible, through a clear notice inside the app and on this website.
- Notify the relevant Pakistani authorities where required by law, and cooperate with any resulting investigation.
- Recommend practical steps you can take to protect yourself, where relevant (for example, if a password or payment reference may be affected).
Because everything you track is stored locally on your device today, a breach of our infrastructure could not by itself expose your health readings — those live only on your own device, protected by your device's own security, until cloud sync goes live.
13Your rights & choices
- Access & export your data: Live now use the backup / export feature in the app anytime to download your data as a file you keep, for one patient profile or all of them.
- Correct or delete individual entries: Live now every reading, medicine, and symptom entry can be edited or deleted directly in the app, with charts and alerts recalculating immediately.
- Delete everything on your device: Live now because there's no account or cloud copy today, you're always in full control — clear the app's site data in your browser settings, or uninstall/remove the app, to permanently erase your local data. There is no separate "cloud" copy for us to delete on our end. See our data deletion page for step-by-step instructions, including how to request deletion of a clinic-held record.
- Delete your account and cloud data: Live now if you signed in to sync, the app's Account & Sync screen has a "Delete my account & data" option that permanently removes your cloud records, with a separate choice about whether to also clear local device data.
- Revoke consent: you can sign out anytime to stop cloud sync (Live now). Revoking a share-at-booking grant with your doctor is Planned – not yet live and will be available from your profile once doctor-sharing exists.
- Notifications: Live now turn reminders off anytime in the app or your device's notification settings.
- Questions or requests: Live now contact us using the details in Section 19 for anything not covered by an in-app control, including requests about clinic-held records.
14Children's privacy
CardioRehab PK is intended for adult cardiac patients and their adult caregivers, and is not directed at children. Where a caregiver profile is used to help manage the care of a minor patient, an adult caregiver is responsible for that information and for deciding what is entered. We do not knowingly collect information directly from children.
15International users
CardioRehab PK is built primarily for patients in Pakistan, but overseas patients can also book consultations, including by bank transfer or Wise. If you use the app or book a consultation from outside Pakistan, information you choose to sync or submit may be processed on servers located outside your country (including on Google Cloud infrastructure, which may be located outside Pakistan). By using the app, you understand and accept that your information may be processed in this way.
16Pakistani legal framework
Pakistan does not yet have a comprehensive, enacted data protection law; a Personal Data Protection Bill has been in draft for several years and has not been passed by Parliament as of this policy's effective date. In the meantime, matters involving unauthorized access to or misuse of data in Pakistan primarily fall under the Prevention of Electronic Crimes Act (PECA) 2016, as amended in 2025, along with applicable healthcare record-keeping and financial-sector rules.
Even without a dedicated data protection statute currently in force, we've designed CardioRehab PK around widely recognized data protection principles — collecting only what's needed, being clear about how it's used, and giving you real control over it — as described throughout this policy.
17Medical disclaimer
18Changes to this policy
We may update this policy as the app's features change — most notably, as the "Planned – not yet live" items throughout this policy actually go live. When we do, we'll update the "Version" and "Effective" fields at the top of this page, and we'll highlight material changes inside the app. We encourage you to review this page from time to time.
| Version | Date | What changed |
|---|---|---|
| 1.1 | 12 Jul 2026 | Rewrote the policy to clearly separate what's actually live today (local-only tracking, WhatsApp booking) from planned features (cloud sync, in-app payment, doctor dashboard). Added the "Current app status" table, this version log, and the data breach notification section (Section 12). |
| 1.0 | — | Initial policy. |
19Contact us
Questions about this policy, or requests about your data, can be sent to:
| Data controller | Dr. Ahmed Zain Subhani, Specialist Cardiac Surgeon |
|---|---|
| Clinic | Punjab Institute of Cardiology (PIC), Lahore, Pakistan |
| submedic@gmail.com — monitored directly by Dr. Zain's practice | |
| Phone / WhatsApp | +92 335 1115330 |