Privacy Policy
Last updated 17 September 2026 · Applies to the Tari app and this website
Tari is a shared workspace for theatre teams — the theatre list, team coordination, clinical documentation and claims in one place. Because the app handles health information, privacy is a design constraint, not an afterthought. This policy explains what we collect, where it goes and the choices you have, in line with the Protection of Personal Information Act, 2013 (POPIA).
1. Information we collect
- Your account and profile — name, email address, cellphone number, professional role and speciality, the hospitals you work at, and (optionally) your HPCSA registration number if you choose to verify it. Some roles add one detail: theatre staff give their title and main hospital, and sales representatives give their company.
- What you capture in the app — anaesthetic records, operative notes, theatre lists, scanned documents (patient info sheets, vitals charts, remittances and statements), case photos, voice notes, private notes, billing codes and claims.
- Technical basics — push-notification tokens and minimal, content-free logs needed to run and secure the service.
2. Where your data lives
- Notes stay on your device. Anaesthetic records, operative notes and drafts are stored encrypted on your device and keep working offline.
- Your records folder. If you choose a records folder — on your device or your own cloud drive — finished notes, patient info sheets, scans and claims are filed there. The files are encrypted so they open only in Tari, and you decide when to export readable copies.
- Theatre lists are end-to-end encrypted. Your lists are encrypted on your device before they sync to your account. A shared list is encrypted with keys held only by its members, and the keys change when someone leaves. Patient-identifiable details are readable only by the list's clinicians, practice managers and verified theatre staff; clinicians' notes only by clinicians. The server stores ciphertext it cannot read.
- Team chat is end-to-end encrypted. Messages are encrypted on the sender's device. Someone who joins a chat cannot read earlier messages, and someone who leaves receives nothing new.
- Case photos and My notes. A case photo stays on the phone that took it. When you send one, each person you choose receives an encrypted copy, and the server's copy is deleted once they have it, or after 7 days. My notes on a case never leave your phone.
- Key backup. So you can recover on a new phone, your encryption keys are backed up in a locked form that only your passkey or your printed recovery code can open. Tari cannot open it.
- Cloud services. Sign-in, sync and notifications use Google Firebase. The database (Firestore), file storage and Tari’s own servers run in Johannesburg, South Africa. Google’s sign-in (Authentication) and push-notification services run on Google’s global infrastructure, which includes the United States. Everything held there is encrypted in transit and at rest, and theatre lists, chats and case photos are additionally end-to-end encrypted, so those servers hold data they cannot read. Account statements you upload are encrypted on your device first.
- Home-screen widgets (iPhone and iPad) are stored on your device and show only procedure names and list progress — never patient details.
3. AI processing
Photographs of patient documents stay in South Africa. Theatre lists, patient information sheets, vitals charts and pre-op documents you photograph are read by Tari's own AI server in Cape Town, South Africa. It is operated for Tari alone, and no other AI company receives those images. Before a vitals chart is read, the same server checks each page for identifying details.
- Text that goes abroad is de-identified first. Some drafting and tidying is done by OpenAI in the United States: turning your dictation into note fields, tidying voice notes, drafting operative notes from a template, standardising allergy and procedure wording, looking up billing codes, and the help and contacts assistants. Before any of that text leaves your phone, names, identity and file numbers, dates and other identifying details are replaced with code tokens. The table that turns the codes back never leaves your phone. OpenAI may hold what it receives for up to 30 days to detect abuse, then deletes it, and does not use it to train its models.
- Dictation. On iPhone and iPad your speech is turned into text on the device; the audio is never uploaded. On Android, the audio is sent to a speech-to-text provider outside South Africa (ElevenLabs, OpenAI or Google, depending on the language) and is not stored after transcription. The transcript is then de-identified as above before any further AI step.
- Account statements you upload for the Accounts feature have patient names removed on your device before any AI reads them, unless you turn de-identification off in the Accounts settings. When a statement is read in the background, the temporary copy is deleted as soon as the job finishes, and job records are deleted within 7 days.
- Which companies, and where. The AI and cloud providers we use, what each receives and the country it is in, are listed above and in section 2. We update this policy before any new provider goes live.
- All AI requests go through Tari's own authenticated backend. Logs are content-free — they never contain prompts, documents, audio, AI replies or anything derived from patient documents.
- AI output is a suggestion. Nothing is filed to a record until you have reviewed and confirmed it.
4. How we use information
- To provide the product: capturing, syncing and sharing your documentation on your instruction.
- To connect you with colleagues you choose to share with. Contact matching is consent-based and initiated by you, and phone numbers are scrambled on your device before they are checked. Your phone number and email are not shown to other users, and you choose whether colleagues can find you by search.
- To verify HPCSA registration when you ask us to, against the public HPCSA register.
- To show theatre staff which lists are on at their hospital. A hospital-board entry carries only the speciality, number of cases, start time and team initials — never patient details — and the list owner can take a list off the board.
- To send notifications you have enabled (for example, a theatre-list update from your team).
We do not sell personal information, and we do not use patient documents for advertising or model training.
5. Sharing
Sharing in Tari is always something you do: sharing a theatre list with named colleagues, setting up a sync link with another account (which shares your theatre lists — and, with a practice manager, your saved contact directories — until either of you ends it), sending a case photo to the people you pick, sharing a PDF through your phone's share sheet, or posting an update to a team. Role-based access applies — members without a clinical role, such as sales representatives, never receive the keys to patient-identifiable fields, and practice managers and theatre staff never receive clinicians' notes. Where information is processed outside South Africa (the providers named in sections 2 and 3), it is under written agreements that require protection substantially similar to POPIA.
6. Security
- Encryption in transit (TLS) and at rest for all cloud data.
- True end-to-end encryption for theatre lists, team chat and case photos (X25519 key exchange, AES-GCM payloads; private keys stay in your device's secure keystore), with new keys when someone leaves a list or chat.
- Records-folder files encrypted so they open only in Tari.
- An optional Face ID / fingerprint app lock and optional two-factor sign-in, controlled in Settings → Security.
- Authenticated, rate-limited access to all backend functions.
7. Your rights (POPIA)
- Access and correction — your profile and captured data are visible and editable in the app.
- Deletion — delete your account in the app (Settings → your name → Delete my account), or ask us to do it. Delete your account lists what is deleted and what is kept.
- Objection and complaints — you may object to processing or lodge a complaint with the Information Regulator (South Africa) at inforegulator.org.za.
As the clinician, you remain responsible for your own professional record-keeping obligations to your patients and your practice.
8. Retention
Account data is kept while your account is active. Records on your device and in your records folder remain under your control. Deleted lists and cases pass through a short recovery bin (about 7 days) before being purged. A sent case photo's server copy is deleted once every recipient has it, or after 7 days. Theatre staff devices remove list copies after 30 days unless the staff member chooses a longer period. When you delete your account, the data stored under your account is removed. Cases and photos you already shared into a list that others still use, messages you sent, and claims already sent to a billing company stay with those teams and companies.
9. Children
Tari is a professional tool for registered healthcare workers and is not directed at children.
10. Changes and contact
If this policy changes materially we will say so in the app. Tari is operated by Narkoc Inc (South Africa, company registration 2020/466657/21), which is the responsible party for personal information processed through the app. Questions and requests: hello@gettari.co.za.
- Address — Unit 12, Gateside Manor, Broadacres Extension 8, Johannesburg, Gauteng, 2191, South Africa.
- Information Officer — Tapiwa Nathan Jiri, at the address above or hello@gettari.co.za. Registered with the Information Regulator, registration number 2026-066816.