MyChief
Privacy Policy
Effective 17 September 2026 · Version 2026-09-17
MyChief is a clinical documentation and decision-support tool for doctors practising in Nigeria. This policy explains what we do with information about you, what happens to the patient records you create, and what you can ask us to do. It is written to be read by a doctor, not only by a lawyer.
It applies to the MyChief application and to this website. Your use of MyChief is also governed by our Terms of Service.
1.The short version
If you read nothing else, read this. The rest of the document is the detail behind these five statements.
- We cannot read your patient records. Patient details, encounters, notes and uploaded results are encrypted on your device before they are sent to us. We store the encrypted result and we do not hold the key.
- We do hold your account details. Your name, your email address and your subscription status are stored in readable form, because the service cannot sign you in or bill you otherwise.
- Patient names are never sent to an AI model. When you use an AI feature, the clinical context we send carries a patient’s age, sex and occupation — never their name, address or phone number.
- We do not sell data, advertise, or track you. There is no advertising network, no analytics product and no session-recording tool in MyChief. There is no behavioural profile of you or of any of your patients.
- Encryption has a consequence you must understand. If you lose both your password and your recovery phrase, nobody — including us — can recover your patient records. See clause 6.
2.Who we are, and which hat we are wearing
MyChief (“MyChief”, “we”, “us”) operates the service described in this policy. We are contactable at privacy@mychief.app for anything in this document.
The Nigeria Data Protection Act 2023 (NDPA) distinguishes the party that decides why personal data is processed (the data controller) from the party that processes it on their instructions (the data processor). MyChief is in both positions, for different data, and confusing the two is the most common way a clinical product misstates its obligations.
| Data | Our role | What that means in practice |
|---|---|---|
| Your account: name, email, subscription, sign-in activity | Data controller | We decide what is collected and why. The rights in clause 10 are exercised against us. |
| Your patients’ records: biodata, encounters, notes, investigation files | Data processor | You are the controller. You decide what is recorded, for what care, and for how long. We process it on your instructions and, in practice, could not do otherwise — see clause 6. |
This allocation is not a disclaimer written for our own convenience. It is the standard position for clinical record-keeping: the treating doctor holds the doctor–patient relationship, the professional duty of confidence under the National Health Act 2014, and the record-keeping obligations that come with them.
3.What we collect about you
All of the following relates to you as a doctor using MyChief, and is stored in readable form on our infrastructure.
| What | Why we have it |
|---|---|
| Full name and email address | To create and identify your account, to sign you in, and to send service email such as address confirmation and password resets. Your name appears on the clinical notes you export. |
| Your password | Stored only as a one-way hash by our authentication provider. We never see or store the password itself. On your device it also derives your encryption key — see clause 6. |
| Specialty and institution, if you provide them | Optional profile details. Nothing in the product requires them. |
| Subscription status, payment references and renewal dates | To give you the correct tier and to reconcile payments. Card and bank details are handled entirely by our payment processor and never reach us — see clause 8. |
| Sign-in and account activity timestamps | Security: detecting unusual access to your account, and investigating it if you report a problem. |
| Technical logs from our servers | Errors, request paths and timings, so faults can be found and fixed. These carry no clinical content — see clause 11. |
What we deliberately do not collect
The following are excluded permanently, not merely unused today. Data that is never collected cannot be breached, mis-shared or demanded.
- National Identity Numbers or any government-issued identifier, for you or for a patient
- Biometric identifiers, and no face photographs
- Location data, GPS coordinates, device identifiers or browser fingerprints
- Patient financial or insurance information — MyChief does no patient billing at all
- Behavioural or usage tracking beyond what is needed to keep you signed in and to limit abuse of the service
4.Patient data, and why our answers are unusual
When you clerk a patient in MyChief you record clinical information: biodata, presenting complaints, history, examination findings, differentials, investigation results, treatment plans and notes. You may also upload photographs of laboratory results, and you may dictate notes by voice.
All of it is encrypted on your device before it reaches us. We store ciphertext. We do not hold, and cannot derive, the key that opens it.
The consequences run through the whole of this policy, and several of them cut against us rather than for us:
- We cannot read a patient record — not to support you, not to debug a fault, not to answer a request, and not if we were compelled to.
- We cannot search, index, aggregate, analyse or train anything on your clinical corpus, because to us it is a block of random-looking bytes.
- We cannot correct, export or delete the content of a particular patient record on your behalf. You do that in the app, where the key is. See clause 10.
- We can still see, and do hold, the non-clinical shape of your data: how many records exist, when they were created and updated, and which account they belong to.
What is not encrypted, and why
Two things sit outside the encrypted corpus, and you should know about both.
- Your account record (clause 3). An encrypted email address cannot be used to send you a password reset.
- The AI interaction log (clause 5). Every AI call is logged so that its clinical safety can be audited. The log is de-identified before it is written: it holds the patient’s age and sex, a one-way hash of the encounter identifier for correlation, and the clinical text of the exchange. It never holds a patient’s name, address or phone number, and it does not hold your name.
5.Artificial intelligence
Some MyChief features send clinical context to third-party AI models — to suggest differentials, propose investigations, draft a treatment plan, structure a dictated note, read a photographed laboratory result, or generate a SOAP note. Those providers are named in clause 7.
What leaves your device, and what does not
The clinical context sent to a model is de-identified before it is assembled, and this is enforced in code rather than by policy: the direct identifiers are not fields that context is able to carry.
| Sent to the model | Never sent |
|---|---|
| Age, sex and occupation; symptoms, history, examination findings, results you have recorded, and your own free text | Patient name, address, phone number, next of kin, alias or date of birth — and not your name either |
Photographs of investigation results deserve stating plainly, because an image carries whatever is printed on it. Before an image is sent to be read, identifiers found on it are painted out of the image itself on your device, and you are shown the masked image and asked to confirm it before anything is sent. What the provider receives is the bytes you approved. A PDF or HEIC file is converted to images on your device and takes the same path; the original file is never uploaded to be read.
Because what is sent is what you approved, the final check is yours and not ours — the detector can miss an identifier, and you are able to uncover anything it hid. Your responsibility for that check is set out in clause 5 of the Terms. Note also that masking affects only the copy sent to be read: the document stored in the patient’s record is your encrypted original, not a redacted version.
Voice
Dictated audio is sent to a transcription provider, transcribed, and discarded. We do not store the recording at any point. The text that comes back becomes part of your encounter and is encrypted with the rest of it.
Training
Your data is not used to train AI models, ours or anyone else’s. We do not build models, and our providers’ terms for the interfaces we use state that inputs submitted through them are not used to train their models.
What AI output is, and is not
MyChief is decision support. It does not diagnose, it does not prescribe, and its suggestions carry a confidence level rather than a conclusion. Clinical responsibility remains entirely yours. This is a privacy policy, so the full statement of that is in the Terms of Service.
6.Encryption, and the trade it makes
Your encryption key is derived on your device from your password. It is never sent to us in a form we can use. When you sign in, your device derives the key again and decrypts your records locally; when you save, it encrypts locally before sending.
Because your password alone would make a forgotten password fatal, you are given a recovery phrase when your account is set up. It is a second, independent way to unwrap your key. We hold neither your password nor your phrase.
If you lose both your password and your recovery phrase, your patient records cannot be recovered by anyone, including us. There is no reset, no support override and no back door. Keep the recovery phrase somewhere safe and offline.
This is a deliberate trade, and we would rather you understood it than discovered it. What you get in exchange: a breach of our database exposes ciphertext; a demand served on us produces ciphertext; and a member of our team cannot look at your patients even if they wanted to. We think that is the right side of the trade for clinical records, and it is why the answers in clause 10 are shaped the way they are.
You can take your data with you. Settings gives you an encrypted export of your account and its records, protected by a passphrase you choose.
7.Who else is involved
We use the service providers below. Each processes data on our instructions under its own data-processing terms, and we maintain an internal register recording what each one can actually read — which, for the clinical corpus, is nothing.
| Provider | What it does | What it can read | Where |
|---|---|---|---|
| Supabase | Database, authentication, file storage | Your account record. Patient records only as ciphertext. | Amazon Web Services |
| Vercel | Application hosting | Requests in transit. Nothing stored. | United States / global edge |
| OpenAI | Primary AI model, image reading, voice transcription | De-identified clinical context; dictated audio, transiently. | United States |
| Anthropic | Fallback AI model and fallback image reading | The same de-identified clinical context. | United States |
| Flutterwave | Payment processing for Pro subscriptions | Your payment details and email address. No clinical data of any kind. | Nigeria |
| Upstash | Rate limiting | Your account identifier only. No clinical or patient data. | Per region configuration |
| Sentry | Server-side error reporting | Stack traces and route names. No clinical payloads; the browser-side agent is switched off. | United States |
Transfers outside Nigeria
Several of these providers process data outside Nigeria, principally in the United States. Those transfers rely on the contractual safeguards in each provider’s data-processing terms. We will say this plainly rather than imply more than we have: the NDPC has not designated the United States as providing adequate protection under section 41 of the NDPA, and we rely on contractual safeguards rather than on an adequacy decision. The clinical corpus travels as ciphertext regardless of where it is stored.
Who we do not share with
We do not sell personal data. We do not share it with advertisers, data brokers, insurers, employers, pharmaceutical companies or researchers. We would disclose account data if compelled by a valid legal order, and we would tell you unless we were legally forbidden from doing so; for the clinical corpus, the only thing we could produce is ciphertext.
8.Cookies and what is stored on your device
MyChief sets no advertising or tracking cookies, and uses no analytics or session-recording product. What it does store on your device:
- Session cookies — to keep you signed in. Strictly necessary; the service cannot work without them.
- A theme preference cookie — whether you chose light, dark or system appearance.
- Encrypted drafts and a cached copy of your records, held in your browser’s local database so that a clerking survives a dropped connection and the app stays usable on a slow network. These are encrypted on the device in the same way as the copy we store.
- A small number of local keys holding identifiers and screen positions — which draft you had open, and where you were in it. No clinical content.
Signing out clears all of this, including the local database. On a shared or hospital computer, sign out rather than closing the tab. MyChief also locks itself after a period of inactivity and discards the decryption key when it does.
Payment card details are never stored on your device or on ours — they are entered on our payment processor’s own page.
9.How long things are kept
| What | How long | Why |
|---|---|---|
| Patient records, encounters and uploaded files (encrypted) | While your account is active, and seven years afterwards | Aligned with Nigerian medical-records retention expectations, which run longer than a data-protection default because a clinical record may be needed for clinical or legal reference. |
| AI interaction logs (de-identified) | Two years; the model’s response text is removed after 90 days | Clinical-safety auditing. The response text has no audit value once the encounter is closed, so it goes first. |
| Your account record | Until you delete your account | To operate the service. |
| Sign-in and security logs | One year | Investigating account compromise. |
| Dictated audio | Not stored at all | Transcribed and discarded within the same request. |
| Payment records | As required by applicable tax and financial record-keeping law | We cannot delete an invoice we are obliged to keep. |
Deleting your account removes your account record and the encrypted records attached to it. Because we cannot read those records, deletion is the only operation we can perform on their content — and it is irreversible.
10.Your rights
Under the NDPA 2023 you have the right to be told what we hold about you, to obtain a copy of it, to have it corrected, to have it deleted, to object to or restrict certain processing, and to receive it in a portable form. To exercise any of these, write to privacy@mychief.app. We will respond within 30 days. We may ask you to confirm your identity first, because handing account data to the wrong person is itself a breach.
The part that is genuinely different
Those rights are exercised against us for your data. For patient data, two things follow from the roles in clause 2 and the encryption in clause 6, and we would rather set them out than let you discover them at the worst moment:
- A patient exercising their rights goes to their treating doctor, not to us. You are the controller of that record; we have no relationship with your patient and no way to identify them.
- If you ask us to correct or export a particular patient record, we cannot. We can delete your account and everything attached to it, and we can tell you what metadata exists, but the content is not ours to touch. The tools that can reach it are in the app, in your hands.
If you are unhappy with how we have handled your data, please tell us first — we would rather put it right. You also have the right to complain to the Nigeria Data Protection Commission (NDPC).
11.How we protect what we do hold
- Everything travels over encrypted connections. Plain HTTP is refused.
- Every database table enforces record-level isolation between doctors, at the database itself rather than only in application code. One doctor’s account cannot read another’s rows even if the application were wrong.
- Clinical content is deliberately kept out of error reporting. Our browser-side error agent is switched off permanently, and browser console logging is prohibited in the clinical parts of the app, so a decrypted record cannot be left behind in the developer tools of a shared ward terminal.
- Uploaded files are stored as opaque encrypted objects, served only to the browser that uploaded them, and never executed.
- Text that you or a patient’s documents supply is sanitised before it is included in an AI prompt, so that instructions cannot be smuggled into a clinical request.
No system is perfectly secure, and we do not claim otherwise. What we can say is that the largest single category of harm — someone other than you reading your patients’ records from our servers — is addressed structurally rather than by promise.
12.If something goes wrong
If a breach occurs that is likely to result in a risk to people’s rights and freedoms, we will notify the NDPC within 72 hours of becoming aware of it, as the NDPA requires, and we will tell affected doctors directly where the risk is high. Because the clinical corpus is stored encrypted and we do not hold the key, a compromise of our storage would expose ciphertext rather than readable patient records — which is the central reason the architecture is built this way.
13.Children’s data
MyChief is for licensed doctors and is not offered to anyone under 18. Paediatric patient records, however, are an ordinary and expected part of clinical practice, and MyChief supports them. That data is the treating doctor’s to hold as controller, under the same terms as every other patient record in this policy, with the additional protections the NDPA gives to a child’s data.
14.Changes to this policy
If we change what we collect, who processes it, how long we keep it, or what you are agreeing to, we will publish a new version with a new effective date and, where the change is significant, tell you in the app or by email. The version you agreed to when you created your account is recorded against it.
15.Contact
For any question, request or complaint about this policy or about your data, write to privacy@mychief.app.
MyChief is currently operated by its founder and is not yet incorporated. When it is, the registered name and address of the operating entity will be published here and this policy will be reissued with a new version number. Until then, the address above reaches the person responsible.