Sanpha
Boring on purpose

Boring choices, honestly described.

The interesting parts of healthcare are the medication and the people. Everything underneath should be predictable, fast, and well-defended.

6-digit OTP sign-inEncrypted in transitRole-based access
A · The mechanics

How signing in actually works.

No mystique. Here is what happens when you sign in and when your data travels — in plain words.

One-time codes

You sign in with your phone number and a six-digit code sent to you. No code, no entry — even if someone knows your number.

What you see

Codes expire within minutes and lock after three wrong attempts.

Passwords are hashed

Where passwords exist, we store a bcrypt hash — a one-way scramble. Nobody at Sanpha can read your password, including us.

What we store

bcrypt is one-way: we can check a password is right, never read it back.

Encrypted in transit

Every connection between the app and our servers is encrypted with TLS. Consultations, chats and orders never travel in the clear.

Every connection

The app refuses plain connections — video, chat and orders all travel encrypted.

B · The choices

Six things we did on purpose.

C · Your data

What we hold, and who sees it.

The honest inventory. We hold what the service needs to work — no more — and access follows the job, not curiosity.

DataWhy we hold itWho can see it
Identity & contactYour name, phone and email run your account, OTP sign-in and notifications.You, and support staff when you ask for help.
Health records & prescriptionsConsultation notes and e-prescriptions so your care carries over between visits.You, and only the doctors and pharmacists you consult.
Orders & addressesDelivery addresses and order details make pharmacy delivery and ambulance dispatch possible.You, the pharmacy handling your order, and the courier or driver on the active job.
Payments & receiptsAmounts in MAD, invoices and receipts — for your records and ours.You, and finance staff who process refunds and payouts.

You can request an export or deletion of your data at any time from the app or by writing to us. AI prescription parsing and analytics run only with your separate, explicit consent.

D · Plain language

What we do, don't do, can't yet claim.

  • WE CAN

    Verify identity, log every action, encrypt traffic, and let you delete your account.

  • WE CANNOT

    Replace your doctor, guarantee no platform ever has a bug, or detect malice without you reporting it.

  • WE WON'T

    Sell your health data, run ads against it, or share it with third parties without your explicit consent.

E · Disclosure

Found a security bug?

Write to security@sanpha.ma. We acknowledge within one working day and credit you publicly once a fix is shipped, if you'd like.

Reply within one working dayRead by a human
  • Initial acknowledgement within one working day.
  • Triage and severity within five working days.
  • Please do not test on accounts you do not own. No phishing, social-engineering or DoS.
  • Bounties — yes, on a case-by-case basis for valid findings.

Please give us reasonable time to ship a fix before any public disclosure — we move quickly and we will keep you posted.