Privacy Policy for the Masary App

Last updated: 24 August 2026 · Effective: 24 August 2026 · النسخة العربية

This Privacy Policy explains how Masary (the “App”, Google Play package masary.com), published by Al Wjhah Al Mothla, collects, uses, shares, stores, retains and deletes your information. Masary lets you pre-register for a hospital emergency department in Saudi Arabia and follow your place in the queue from your phone. Because doing that requires identity and health information, please read this policy before using the App. By using Masary you agree to the practices described here.

1. Who we are

  • • Data controller: Al Wjhah Al Mothla, Kingdom of Saudi Arabia.
  • • Contact for privacy questions, access requests and deletion requests: aalshehri@alwjhah-almothla.com
  • • Website: https://masary.alwjhah-almothla.com

2. Information we collect

We only collect information that is needed to register you at an emergency department and to keep you informed about your case. We do not collect data for advertising, and we do not sell your data.

2.1 Account and identity information

The App does not offer self-registration. Your account is provisioned for you as part of the service, and you sign in with your national ID number and the password issued to you. The account record holds:

  • • First name and last name.
  • • National ID / Iqama number, which is also your sign-in identifier.
  • • Your password, stored only as a salted cryptographic hash, never in readable form.
  • • Date of birth and gender.
  • • Phone number and address, when you provide them.
  • • Your chosen app language.

2.2 Information about dependants you register

If you open a case on behalf of a family member, we collect that person’s first and last name, national ID number, age, gender, whether they have medical insurance, and an optional photo you choose to attach. You are responsible for having the right to provide this information on their behalf.

2.3 Health information

This is sensitive personal data and we treat it accordingly. It includes the symptoms you describe, the case type you select, any photo of your condition that you choose to attach, any medical record entries and attachments associated with your account, and the status, priority, queue number and clinical notes recorded for your case by the receiving hospital’s staff.

2.4 Location information

  • • With your permission, the App reads your device’s approximate or precise location (ACCESS_COARSE_LOCATION, ACCESS_FINE_LOCATION) to show emergency rooms near you, estimate travel distance and time, and attach your location to an emergency case so staff know where you are coming from.
  • • Location is collected only while you are using the App. Background location and background location services are disabled in the App.
  • • We store your most recent coordinates, the time they were updated, and cached distances between you and nearby hospitals so the list does not have to be recalculated on every screen.
  • • You can refuse or later revoke the location permission in your device settings. The App will still work, but you will need to search for hospitals manually.

2.5 Photos

The App requests access to your photo library only at the moment you choose to attach an image to an emergency case or a dependant’s profile. We upload only the images you explicitly select. We do not scan or read your photo library.

2.6 Notifications and device information

  • • A push notification token issued to your device by Expo and Firebase Cloud Messaging, so we can tell you when your queue number changes, when you are called, or when the hospital sends you a message. Deleting the App or revoking notification permission stops this.
  • • Basic technical information needed to deliver the service and diagnose failures: device type, operating system version, app version, and error logs. These logs are not used to build a profile of you.

3. How we use your information

  • • To authenticate you when you sign in and to keep your session secure.
  • • To register your emergency case with the hospital you select and place you in its queue.
  • • To show you nearby emergency rooms and estimated distances.
  • • To send you notifications about the status of your case.
  • • To let hospital and emergency-room staff triage, prioritise and admit your case safely.
  • • To operate, secure, troubleshoot and improve the service, and to prevent fraud and misuse.
  • • To produce aggregated, non-identifying statistics such as average waiting times per facility.
  • • To comply with applicable laws and lawful requests from competent authorities.

We do not use your data for advertising or marketing profiling, and we do not sell or rent personal data to anyone.

4. Legal basis and consent

We process your data on the basis of the consent you give when you sign in and use the App, and when you grant the location, photo and notification permissions, and in order to perform the service you request. Sensitive health data is processed only for the purpose of delivering emergency healthcare registration. You may withdraw consent at any time by revoking the relevant permission in your device settings or by asking us to delete your account (section 7).

5. When and with whom we share your information

  • The hospital or emergency department you choose. Its authorised staff receive your identity details, your symptoms and case type, any attached image, and your location, so they can receive you. This is the core purpose of the App.
  • Service providers who process data on our behalf, under contract and only for the purposes described here. See section 6.
  • Competent authorities, where disclosure is required by the laws of the Kingdom of Saudi Arabia or by a valid legal order.
  • In connection with a corporate transaction such as a merger or acquisition, in which case the recipient remains bound by this policy.

We do not share your personal or health data with advertisers, data brokers, or any other third party for their own purposes.

6. Third-party services we rely on

  • Google Firebase Cloud Messaging and Expo Push Notifications deliver push notifications; they receive your device push token and the notification content. Firebase privacy · Expo privacy
  • Google Maps Platform renders maps and computes routes and distances; it receives the location coordinates needed to serve the map. Google privacy
  • Expo Application Services delivers app updates and crash diagnostics.
  • Our hosting provider operates the servers and database that store your account and case data, under our instructions.

7. Data retention and deletion

  • • Account and profile data is kept for as long as your account exists.
  • • Emergency case records, including health information, are retained for as long as required by the healthcare record-keeping regulations applicable in the Kingdom of Saudi Arabia, and are then deleted or irreversibly anonymised.
  • • Location coordinates and cached hospital distances are overwritten with each update and are not kept as a location history.
  • • Push tokens are deleted when you revoke notification permission, sign out, or remove the App.
  • You can ask us to delete your account and associated personal data at any time by emailing aalshehri@alwjhah-almothla.com and including the national ID number registered on the account so we can identify it. We confirm receipt and complete the deletion within 30 days, except for records we are legally required to retain, which are isolated and kept only for that legal period.

8. Your rights

Subject to the Saudi Personal Data Protection Law, you have the right to be informed about how your data is used, to access a copy of it, to have inaccurate data corrected, to request its deletion, and to withdraw your consent. To exercise any of these rights, contact us at aalshehri@alwjhah-almothla.com. We respond within 30 days.

9. How we protect your data

  • • All traffic between the App and our servers is encrypted in transit using HTTPS/TLS.
  • • Passwords are stored only as salted hashes; nobody at Masary can read your password.
  • • Session credentials are held on your device in the operating system’s secure storage (Keychain on iOS, Keystore on Android).
  • • Access to case data is restricted to the staff of the facility handling that case, through authenticated, role-based accounts.
  • • No method of transmission or storage is completely secure, so we cannot guarantee absolute security. We will notify affected users and the competent authority of a breach as required by law.

10. Children

Masary is not directed at children. Accounts cannot be created from within the App, so a child cannot sign themselves up. A parent or guardian may register a child as a dependant in order to open an emergency case on their behalf; that information is treated as described in this policy. If you believe a child’s data has been added without the right to do so, contact us and we will remove it.

11. Data location and transfers

Your data is stored on servers operated for us and processed in accordance with the laws of the Kingdom of Saudi Arabia. Some of the service providers listed in section 6 operate infrastructure outside the Kingdom; where data reaches them, it is limited to what the service requires and is covered by their contractual and legal safeguards.

12. Changes to this policy

We may update this policy. The “Last updated” date at the top always reflects the current version, and material changes will be announced in the App before they take effect. Continuing to use Masary after a change means you accept the updated policy.

13. Contact us

For any question about this policy or about your data, write to aalshehri@alwjhah-almothla.com.