Last updated 21 July 2026
Privacy Policy
JagaHealth holds medical records, which is about as sensitive as personal data gets. This policy says plainly what we collect, who touches it, and how you get it back or get rid of it.
The short version
- Your medical records are stored so you can use them. We do not sell them, we do not advertise against them, and we do not use them to track you.
- Document images and record content are sent to an AI provider so the app can read and answer questions about them. You can turn this off.
- You can export everything or delete your account and all its data from inside the app, at any time.
- We have no advertising SDKs and no third-party analytics SDKs. Product analytics is off unless you switch it on.
This policy applies to the JagaHealth mobile app and to jagahealth.app. The data controller is Ibudata Solutions, Malaysia.
What we collect
Information you give us
- Account details. Your email address, and your name if you provide one. If you use Sign in with Apple and choose to hide your email, we receive Apple's relay address instead.
- Health records. Everything you add: document photos and PDFs, clinic visits, prescriptions and medicines, dose logs, lab results, vitals and biometrics, ongoing conditions, appointments, and medical expenses and claim status.
- Family profiles. The profiles you create for the people you look after, the records filed under each, and the access level you give anyone you share a profile with.
- Your questions. The chat threads you create when you ask about your records.
- Settings. Your privacy toggles, accessibility preferences, and reminder preferences.
Information collected automatically
- A user identifier that links your records to your account.
- Usage counts needed to enforce plan limits. For example, how many AI actions you have used this month.
- Crash and error reports, which tell us the app broke and roughly where. These are configured to exclude personally identifying information.
- Product analytics: which screens and features get used. This is off by default and only collected if you turn the analytics toggle on.
- Subscription status, if you buy JagaHealth+.
We do not collect your location, contacts, calendar, advertising identifier, or browsing activity on other apps and sites.
How we use it
| What | Why |
|---|---|
| Health records and documents | To store, organise, display and search your records. This is the core function of the app |
| Document images and record content | To extract structured details, and to answer the questions you ask about your own records |
| Email address and user ID | To create and secure your account and sign you in |
| Usage counts | To apply free-plan limits and subscription entitlements |
| Crash reports | To find and fix defects |
| Product analytics (opt-in) | To understand which features are used and improve the app |
We do not use your health data for advertising, we do not sell personal data, and we do not share it with data brokers. We do not use your records to train AI models, and we instruct our AI provider not to either.
AI processing, and how to switch it off
Reading your documents is the thing the app is for, and it needs an AI model to do it. Here is exactly what that means.
When you scan a document, the image is sent to OpenRouter, an AI routing provider, which passes it to a large language model, by default a Google Gemini model. The model returns the structured details it found. When you ask a question in the Ask tab, the relevant parts of your records are sent the same way so an answer can be produced.
The app's privacy settings give you four independent toggles:
- Organising: letting the app sort and file what you add.
- AI extraction: sending document content to an AI provider. Turn this off and no document content leaves for AI processing at all. You can still add records by hand, and the app keeps working.
- Reminders: appointment and medication prompts.
- Analytics: optional, anonymous product analytics. Off unless you enable it.
You are asked to set these when you first set up your account, and you can change any of them at any time in the app: open the Profile tab and tap Privacy & data. Changes take effect immediately. Turning off AI extraction stops document content being sent for processing from that moment on.
AI output is a summary of your own records. It is not a diagnosis and not medical advice. JagaHealth is not a medical device.
Who else touches your data
We use a small number of service providers to run the app. Each one receives only what it needs.
| Provider | What it receives | Purpose |
|---|---|---|
| Convex | All your records and uploaded files | Database and file storage |
| Clerk | Email address, authentication identifiers | Sign-in and account security |
| OpenRouter | Document images and record content, when AI is enabled | Routing requests to an AI model |
| Google (via OpenRouter) | The same content, as the model provider | Reading documents and answering questions |
| Sentry | Crash and error diagnostics, without identifying details | Stability monitoring |
| RevenueCat | Subscription status and a user identifier | Managing JagaHealth+ purchases |
| Apple / Google | Payment details, which we never see | Processing subscription payments |
We may also disclose data if required by law, or to protect the rights and safety of our users or the public. If our business is ever transferred, your data may transfer with it, and we will tell you before that happens.
Sharing you initiate
Two features share data because you asked them to, and both stay under your control:
- Doctor packs. You can generate a link, optionally as a QR code, that shows a summary of selected records. These links expire, and you can revoke one at any time. Anyone holding an unexpired link can view what it contains, so share it only with people you intend to.
- Family access. When you give someone access to a profile, they can see the records in it at the access level you chose. You can change or remove that access.
How long we keep it
- While your account is active, we keep your records so you can use them.
- Deleting a single record moves it to a bin for 30 days so you can undo a mistake. After that it is permanently erased, including any stored file.
- Deleting your account or a whole profile is immediate. It does not go through the 30-day bin. The records and files are erased straight away.
- Backups and crash logs age out on their own schedule, typically within 90 days.
Your rights and controls
In the app, without asking us for anything, you can:
- Export all of your data.
- Correct any record. Every field the AI extracts is editable, before and after saving.
- Delete individual records, whole profiles, or your entire account. See how to delete your account.
- Restrict processing using the privacy toggles.
Malaysia's Personal Data Protection Act 2010 gives you rights of access, correction, and withdrawal of consent, and the right to limit processing for direct marketing, which we do not do. If you are in the EEA or the UK, the GDPR additionally gives you rights to erasure, portability, restriction, and objection, and a right to complain to your local supervisory authority. Our legal bases are your consent for AI processing and analytics, performance of a contract for running the service, and our legitimate interest in keeping the app secure and working.
To exercise any right we have not already built into the app, email [email protected]. We respond within 30 days.
Security
- All data is encrypted in transit using TLS.
- Stored data and uploaded files are encrypted at rest by our hosting provider.
- Your sign-in token is held in the device's secure keystore: the iOS Keychain or the Android Keystore.
- Access to production systems is limited to the people who need it.
No system is perfectly secure. If a breach affects your personal data, we will notify you and the relevant authority as required by law.
Device permissions
- Camera: to photograph medical documents. Only used when you open the scanner.
- Photo library: to let you pick an existing photo of a document.
- Notifications: for appointment and medication reminders, if you enable them.
You can revoke any of these in your device settings. JagaHealth does not record audio and does not access your microphone, location, or contacts.
Children and family profiles
JagaHealth is for adults. You must be 18 or older to hold an account. You may create profiles for children in your care, and you are responsible for that data as their parent or guardian. We do not knowingly let children create their own accounts; if we learn that one has, we will remove it.
Where your data is stored
Our database and file storage run on Convex's cloud infrastructure. Crash diagnostics are processed in the European Union. AI processing takes place on infrastructure operated by OpenRouter and the model provider, which may be located outside Malaysia. Where data leaves Malaysia, we rely on our contracts with these providers to keep it protected to the standard described here.
Changes to this policy
If we change this policy we will update the date at the top of the page. For changes that materially affect how your data is handled, we will tell you in the app before they take effect.
Contact us
Questions, requests, or complaints about privacy: [email protected].
Ibudata Solutions, Malaysia.