DocPro — Privacy Policy

Effective date: 14 July 2026

DocPro is clinic-management software published by UpTech ("we", "us"). It is used by independent medical clinics to run their day-to-day work: patient records, the waiting queue, appointments, lab tests, prescriptions and clinic finances.

This policy explains what information DocPro handles, where that information is sent, and who can see it. It covers the DocPro applications for Windows, Android and iPhone, and the DocPro patient portal.

1. Who is responsible for your data

This distinction matters, so please read it carefully.

If you are a patient and you want to see, correct or delete your records, please contact the clinic that treats you. They hold your file; we cannot make those decisions for them.

2. Each clinic's data is separate

Every clinic using DocPro runs in its own separate Google Firebase project, with its own database and its own accounts. One clinic's patients, visits and finances are not stored alongside another's, and no clinic can read another clinic's records. There is no shared, central pool of patient data at UpTech.

A clinic is identified by a private clinic code. Entering the code on a new device asks a DocPro directory service for that clinic's encrypted configuration so the app knows which database to connect to. That request contains the clinic code only — it carries no patient data.

3. What information DocPro handles

Staff accounts

Patient records, entered by the clinic

On your device

4. Where the information goes

DocPro sends data to the following services and to nowhere else.

Service What is sent Why
Google Firebase
(Authentication, Firestore)
Staff logins; all patient, visit, lab, queue and financial records This is the clinic's database. Each clinic has its own project.
Cloudinary Images only: handwriting drawings, lab result photos, scans of old paper records Image hosting. Images are stored under the clinic's own Cloudinary account.
Google Gemini
(AI assistant)
The text of a patient's record — only when a doctor presses an AI button. See section 5. To produce the summary, medication review or answer the doctor asked for.
WhatsApp / SMS / phone The patient's phone number and the message text, handed to the app you choose Only when a staff member presses call or send message. DocPro does not send messages by itself.

Handwriting recognition runs on your device. Converting a handwritten note to text uses Google ML Kit locally on the phone or tablet. The handwriting is not uploaded for that purpose.

5. The AI assistant — please read this

When a doctor uses an AI feature, the patient's record is sent to Google's Gemini service for processing. This includes the information needed to answer: name, age, allergies, chronic conditions, medications, vital signs, visit notes and diagnoses.

Nothing is sent to the AI unless a doctor deliberately presses one of the AI buttons (patient summary, clinical suggestions, medication review, or the patient chat). Simply opening a patient's file sends nothing.

The AI is decision support only. It does not diagnose and it does not prescribe. Every suggestion it produces carries an on-screen notice that the physician must verify it before acting, and the treating physician remains fully responsible for every clinical decision.

Clinics should tell their patients that an AI assistant is used, and should obtain consent where local law requires it. If a clinic does not want any patient data to leave for AI processing, the AI features can be disabled for that clinic — contact us and we will remove the AI key from your clinic's configuration.

6. The patient portal

Patients whose clinic has enabled it can sign in to the DocPro portal with their phone number and a password issued by the clinic. A patient can see only their own records — their visit history, including any old paper records the clinic has scanned into it, and their lab results — and can request an appointment. The portal cannot be used to view any other patient.

7. What we do not do

8. Device permissions

9. Security

No system can be guaranteed to be perfectly secure. If we become aware of a breach affecting a clinic's data, we will inform that clinic without undue delay.

10. Keeping and deleting data

Patient records are kept for as long as the clinic needs them, which medical record-keeping law in the clinic's country may require to be a number of years. The clinic decides this, not us.

A clinic may ask us to export or permanently delete its entire database at any time.

Deleting a patient inside the app removes that patient's record from the clinic's database. Please note that this does not automatically erase images already uploaded to Cloudinary (handwriting, lab result photos, scans). To have a patient's images permanently removed as well, contact us and we will delete them.

11. Children

Children are treated as patients of the clinic like anyone else, and their records are entered by clinic staff, not by the child. DocPro is not directed at children as users, and we do not knowingly create user accounts for them.

12. Changes to this policy

We may update this policy. The effective date at the top will change, and the current version will always be available at this address. Material changes affecting patient data will be communicated to clinics directly.

13. Contact

For questions about this policy, or to request export or deletion of a clinic's data:

Patients: please contact your clinic first — they hold and control your records.

14. Deleting your account

You can request deletion of your DocPro account and its associated data at any time. See Delete your account and data for what is deleted, what must be kept, and how to make the request.