This policy explains what the CodeBlue mobile application collects about you, why it collects it, who else ever sees it, how long it is kept, and how you delete it. It covers the CodeBlue apps for Android and iOS and the CodeBlue service behind them.
Effective 1 September 2026 · Last updated 1 September 2026
CodeBlue is operated by Hotinformation, in the Arab Republic of Egypt. Hotinformation is the controller of the personal information described here. You can reach us about anything in this policy at dr_t_shaalan@yahoo.com.
CodeBlue dispatches medical care. A patient requests a visit; the service finds doctors and nurses who are on duty nearby and offers the request to them; one accepts and travels to the patient. Almost everything in this policy follows from that single mechanic — matching two people by where they are, and letting them reach each other once they have both agreed.
To create an account you give us your mobile phone number (which identifies the account), a password, your name, and your email address. We store your chosen language and your role — patient or medical provider. Your password is stored only as a cryptographic hash; we never hold the password itself. We send a numeric verification code to confirm your email address, and a similar code if you ask to reset your password.
Patients provide a home address and nearby landmarks so a provider can find the door, and may add an occupation and a relative's contact number.
Doctors and nurses provide their workplace and upload documents that let us verify they are who they claim to be and licensed to practise: an identity card, a medical licence, and professional certificates. These documents are visible to CodeBlue's administrators for verification and are never shown to patients or to other providers.
You may upload a profile photo, taken with your camera or chosen from your photo library. Providers upload photographs or scans of the documents above. We access your camera and photo library only at the moment you choose to add an image, and we do not read the rest of your library.
Location is the core of the service and is described in full in its own section below.
We store a push notification token for each device you sign in on, together with a device identifier, so that an incoming emergency request, a provider accepting your visit, or a payment reminder can reach the right phone. These tokens are useless to anyone but the push service and are removed when you sign out or delete your account.
For each visit we record the address, the location, the price, the status of the visit, and who the two parties were. Where a visit or a subscription is charged, we record the invoice and the payment.
Card details never reach CodeBlue. Payments are taken by Paymob, our payment processor. You enter your card inside Paymob's own secure page, displayed within the app. Your card number, expiry date and security code go directly to Paymob and are never seen or stored by CodeBlue. We keep only the card brand and the last four digits, so that a receipt is recognisable.
It is worth being explicit, because people reasonably assume a medical app collects more than it does:
CodeBlue collects precise location from your device. How it does so depends on which side of a visit you are on.
Your location is collected while you are using the app: to show you which providers are available near you, to place your request at the right address, and, once a provider has accepted, to show them where to drive. Location is not collected when the app is closed or in the background.
CodeBlue collects location data to match you with nearby emergency requests and to show a patient your approach, even when the app is closed or not in use.
This happens only while you have deliberately gone on duty. An emergency request is offered to the closest available providers, so a provider who is on duty but whose phone has been put away must still be findable — otherwise the request goes to someone further away, and the delay is measured in minutes that matter. Android shows a permanent notification while this is running.
Going off duty stops background location collection entirely. You can also withdraw the permission at any time in your device settings; if you do, you will stop receiving emergency requests, because there is no way to route one to you.
| Purpose | What it uses |
|---|---|
| Creating and securing your account | Phone, password hash, email, verification codes |
| Verifying that a provider is licensed | Identity card, medical licence, certificates, workplace |
| Matching a request to the nearest available provider | Precise location, on-duty status |
| Getting the provider to your door | Address, landmarks, location |
| Letting the two of you reach each other | Name, phone number — released only as described below |
| Telling you something has happened | Push token, device identifier |
| Charging for a visit or a subscription, and issuing receipts | Invoice and payment records, card brand and last four digits |
| Support, safety, and preventing abuse of the service | Account and visit records |
| Meeting our legal and accounting obligations | Invoices and payment records |
We rely on your consent for device permissions such as location, camera, photo library and notifications, and you can withdraw any of them in your device settings at any time. We rely on the necessity of performing our service to you for the rest, and on our legal obligations for keeping accounting records.
This is the only sharing that happens between users, and it is deliberately narrow. Before a visit is confirmed, neither side sees the other's phone number. Contact details are released only once both parties have confirmed the visit, and this is enforced by our servers, not merely hidden in the app. Once confirmed, the two of you can see each other's name and phone number so that you can coordinate the visit, and the provider can see the address and location they are travelling to.
We use a small number of service providers. They act on our instructions, may use the data only to provide their service to us, and may not use it for their own purposes:
We disclose personal information outside the list above only where we are required to by law, by a court, or by a competent authority, or where it is necessary to protect someone's life or safety. We do not sell your personal information, and we do not share it for advertising.
CodeBlue's servers and several of the providers listed above operate outside Egypt. Using CodeBlue therefore involves your information being transferred to and processed in other countries, under contracts that require it to be protected to the standard described here.
You can delete your CodeBlue account yourself, from inside the app, without asking us and without a waiting period: menu → Delete account. If you can no longer sign in, email dr_t_shaalan@yahoo.com from the address or phone number on the account and we will delete it within 30 days.
Deletion destroys your name, phone number, email address, address and landmarks, occupation, relative's contact number, profile photo, and — for providers — workplace and every uploaded document, removed from file storage rather than merely hidden. Your password is replaced with a value nobody holds.
Records of visits that actually took place, and invoices that were issued, survive: a visit is the shared history of two people, and invoices are accounting records we are obliged to keep. In both, your name is replaced with “Deleted user” and your phone number with an internal reference, so nothing in them leads back to you.
You can ask us to give you a copy of the personal information we hold about you, correct it if it is wrong, or delete it. Much of this you can do yourself in the app — your profile is editable and deletion is one menu away. For anything else, email dr_t_shaalan@yahoo.com and we will respond within 30 days. You may also withdraw any device permission — location, camera, photo library, notifications — in your device settings; where a permission is essential to a feature, that feature will stop working, and we explain which above.
Traffic between the app and our servers is encrypted in transit. Passwords are stored only as hashes. Provider documents are not publicly addressable and are served only through our servers behind expiring tokens. Access to production data is restricted to the people who operate the service. No system is perfectly secure, but we would rather describe what we actually do than make a claim we cannot keep.
CodeBlue is not directed to children. You must be 18 or older to create an account. A parent or guardian may request a visit for a child from their own account, in which case the account and its information belong to the adult. If we learn that we hold an account created by a child, we delete it.
If we change how CodeBlue handles personal information, we will update this page and change the “Last updated” date above. Where a change materially affects you, we will tell you in the app before it takes effect.