1. About this policy
KAAH Resident supports authorized residents and staff in the General Surgery Training Program. This policy covers the iPhone and iPad app, its connected resident portal, and the public support and privacy website.
For questions about this policy or your information, contact the app developer, Abdulrahman Alabdali, at dr.alabdali15@gmail.com.
2. Information used by the service
Information may be provided by you, entered by program staff or evaluators, or recorded when you use a feature. Records associated with your account are linked to your identity.
- Account information: your name, email address, account or resident identifier, and information needed to authenticate your sign-in.
- Training and administrative records: training level, rotations, academic activities, attendance, on-call duties, leave requests, evaluation records, and related decisions.
- Content you submit: request details, explanations, notes, and feedback entered through the portal.
- Attendance location: precise location, location accuracy, check-in time, and verification results when you use a location-based attendance check. Location records can include latitude, longitude, and distance from the attendance location, linked to your account.
- Feature activity: sign-in events, request submissions, actions on program records, and notification-read status needed to operate the service and maintain an audit trail.
- Support correspondence: your email address, the message you send, and any details you choose to include when contacting support.
The current service is for training administration, not medical diagnosis or treatment. It does not offer medical-report submission or maintain sick-leave health records. Please do not enter patient information or medical details in free-text fields or support messages.
3. How information is used
Information is used to authenticate accounts, show the appropriate resident records, coordinate training activities, process requests and evaluations, verify attendance, provide operational notices, answer support requests, and protect the integrity of program records. Your name may also be used to personalize the greeting shown in your account.
The app does not use these records for advertising or for tracking you across other companies’ apps and websites for advertising purposes.
4. Location, camera, and session information
Location: location is requested for attendance check-in, not for continuous background monitoring. Check-in attempts may retain precise coordinates and verification results, including unsuccessful attempts. You can change location permission in your device settings; disabling it may prevent location-based check-in.
Camera: the camera is used to scan attendance QR codes. Camera frames are processed on your device to decode the QR value; the decoded value, rather than a camera recording, is sent to the attendance service. You can revoke camera permission in your device settings.
Sessions: the portal uses session information to keep you signed in and associate requests with your account. Hosting and delivery providers may also process technical request information when serving the portal or website.
5. Access and service providers
Program staff and evaluators use information relevant to their assigned administrative or evaluation duties. Information is also processed by the services used to operate the app and respond to support requests.
- Google services support the hosted portal, backend processing, program data storage, and support email.
- Cloudflare services host the public support and privacy website and deliver the QR-scanning library. The public support website is separate from the resident-record system.
Hosting and delivery providers may process IP addresses, request times, browser information, and technical logs to deliver and protect their services. Their processing is described in the Google Privacy Policy and the Cloudflare Privacy Policy. The public support website does not contain a resident-record database or a form for uploading training records.
6. Retention and record handover
During training, resident records are kept to support the program’s training and administrative activities. After completion of training, the resident receives their records, and program staff manually delete the resident’s training records from the working Google Sheets. This is a manual process, not automatic deletion.
Deleting records from the working sheets does not necessarily erase earlier spreadsheet versions, separate account or attendance-audit records, exports, backups, support correspondence, or provider technical logs. These may remain after handover. There is no single specified deletion period for all of these additional records; retention depends on the type of record, system settings, and relevant service-provider practices.
To ask which records remain or request their deletion, contact dr.alabdali15@gmail.com. Your request will be reviewed against the records and systems involved; we do not promise immediate or automatic erasure of every copy.
7. Your requests and choices
To request access to your records, correct inaccurate information, request account or data deletion, or ask about withdrawing consent, email dr.alabdali15@gmail.com. Describe the request and identify the account using your registered email. Identity verification may be needed before records are disclosed or changed.
You can revoke camera and location access through your device’s permission settings. Revoking a permission stops future access through that permission; it does not itself delete information already submitted. Contact support about existing records or an attendance alternative if you cannot use the check-in feature.
Never send a password, PIN, verification code, patient information, or another resident’s records in a privacy or support request.
8. Changes to this policy
Changes to the service’s information practices will be reflected in an updated policy with a revised date. You can return to this page to read the current policy or contact us with questions.