Privacy Policy
Effective Date: July 31, 2026
Last Updated: July 31, 2026
IMPORTANT HEALTH DATA NOTICE: This document explains how Anjiy collects, uses, and protects personal information and sensitive health information. It is not a certification of compliance with any specific healthcare privacy framework unless separately stated in a signed agreement.
Table of Contents
- Introduction
- Information We Collect
- How We Use Your Health Information
- When We May Disclose Your Health Information
- Your Privacy Rights
- Data Security & Protection
- International Users & Data Transfers
- Children's Privacy
- Changes to This Policy
- Contact Us
1. Introduction
Welcome to Anjiy ("we," "our," or "us"). Anjiy helps users organize personal and family health information, appointments, reminders, documents, nearby care resources, wellness information, and a patient-controlled emergency health passport. Features that involve AI, payments, pharmacy fulfillment, telemedicine, biometric health scans, birth registration, or hospital administration are disabled in the first public release unless separately approved, configured, and disclosed.
- Applicable privacy and data protection laws in each jurisdiction where Anjiy is lawfully made available
- GDPR and applicable national law for European Economic Area users
- Other applicable consumer and health-data rules based on the user's country and the enabled service
Who We Are: Anjiy Inc. This notice does not mean that every Anjiy feature is legally available in every country. Availability depends on local approval, providers, infrastructure, and the release configuration.
2.1 Protected Health Information (PHI)
Sensitive health information may include information that can identify you and relates to your health. We collect:
Medical Information:
- Health profile: User-entered conditions, allergies, medications, blood type, emergency contacts, care-directive status, and related notes
- Appointments: Appointment requests, schedules, reminders, visit context, and user-uploaded documents
- Medications and immunizations: User-entered medication lists, refill reminders, vaccination records, and schedules
- Lab and health documents: Documents and values the user chooses to store
- Family health: Information a user is authorized to organize for a family member
- Emergency passport: A minimum emergency summary shared only when the user explicitly creates and enables a time-limited share
Personal Identifiers:
- Full name, date of birth, gender, nationality
- Email address, phone number, physical address
- Profile and insurance information the user chooses to provide
- Emergency contact information
Disabled first-release data flows:
The submitted first release does not intentionally process production payments, pharmacy orders, telemedicine audio/video, AI health prompts, biometric health scans, digital birth registration, or hospital-provider administration data.
2.2 Technical Information (Non-PHI)
- Device Information: Device type, operating system, app version, device ID
- Usage Data: Operational security events required to provide and protect the service; analytics and crash/performance telemetry are disabled in the submitted build
- Location Data: Device location, only after permission, for nearby hospitals and care resources; the nearby-care flow does not intentionally persist raw location history
- IP Address: For security, fraud detection, and regional service delivery
- Cookies & Similar Technologies: Authentication state, security, App Check, and saved preferences
3. How We Use Your Health Information
3.1 Care Coordination
We use health information to provide enabled Anjiy organization and care-coordination features:
- Organize appointments, reminders, documents, family health records, and emergency health passport information
- Share user-controlled context with healthcare providers where approved and configured
- Store lab result documents and user-entered health records
- Provide AI or regulated clinical workflows only where separately approved, enabled, disclosed, and configured
- Send medication reminders and health alerts
- Coordinate care context between approved participants at your direction
3.2 Payment
- Process payments only where production payment workflows are approved and enabled
- Prepare insurance or claims workflows only where approved partners are configured
- Manage transaction history for enabled payment features
- Provide invoices and receipts
3.3 Service Operations
- Quality improvement and safety monitoring
- Fraud detection and prevention
- Legal compliance and regulatory reporting
- We do not use health records to train public AI models in the submitted release
3.4 Other Uses (With Your Authorization)
We will NEVER use your health information for the following without your explicit written authorization:
- Marketing or promotional purposes
- Sale of your health information to third parties
- Psychotherapy notes disclosure
- Research studies (unless de-identified)
4. When We May Disclose Your Health Information
4.1 Disclosures You Authorize
- To Healthcare Providers: Share your medical history with doctors you consult
- To Family Members: With your permission, share health updates with designated contacts
- To Emergency Viewers: Show only the minimum emergency summary covered by an active share created by you
4.2 Disclosures Required by Law
We may disclose your PHI without authorization when:
- Court Orders/Subpoenas: When legally required by judicial order
- Public Health Authorities: Disease reporting, vaccine-preventable diseases, FDA adverse events
- Law Enforcement: Criminal investigations, missing persons, victims of abuse
- Health Oversight: Government audits, investigations, licensing
- Serious Threats: To prevent serious harm to you or others
- Worker's Compensation: Work-related injury or illness claims
- Coroners/Medical Examiners: For death investigations
4.3 Business Associates (Third-Party Vendors)
We share sensitive health information with trusted vendors who help us operate our services only where necessary and under appropriate contractual safeguards:
- Google Cloud (Firebase): Cloud infrastructure, data storage, authentication
- Firebase Authentication and App Check: Account authentication and application attestation
- Cloud Firestore: Structured account, health, appointment, emergency, and audit records
- Cloud Storage: Documents and images uploaded by users
- Google Maps: Map display and nearby-care requests after user action
Stripe, PayPal, Agora, Gemini, other AI providers, pharmacy-fulfillment providers, MOSIP, and government identity systems do not receive first-release user data while their production feature flags remain disabled.
5. Your Privacy Rights
Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a portable copy of personal information. You may also withdraw consent where consent is the legal basis for processing and complain to the competent data-protection authority.
- Profile and user-entered information can be reviewed or corrected through the app where the relevant control is available.
- Account deletion can be requested through the app or at www.anjiy.tech/account-deletion.html.
- Other privacy requests can be sent to privacy@anjiy.tech.
- We may need to verify your identity and may retain limited information where required for security, fraud prevention, legal claims, or another applicable legal obligation.
6. Data Security & Protection
6.1 Technical Safeguards
- Encryption: Google Cloud-managed encryption at rest and HTTPS encryption in transit
- Access controls: Firebase Authentication, user and role checks, and database and storage security rules
- Application attestation: Firebase App Check enforcement for production authentication, database, storage, and protected callable services
- Abuse controls: Server-side authorization, input validation, and rate limiting for sensitive endpoints
- Secrets: Server credentials are kept out of the distributed client and managed through restricted deployment controls
6.2 Administrative Safeguards
- Access Controls: Role-based permissions (patient, doctor, admin)
- Audit logging: Security and application audit events are recorded for protected workflows where implemented
- Operational controls: Production health monitoring, service-error alerts, budget alerts, incident procedures, and recovery controls
- Incident Response Plan: Documented breach response procedures
6.3 Physical Safeguards
- Data centers: Google Cloud infrastructure with physical and operational security controls
- Recovery: Firestore point-in-time recovery, deletion protection, and daily backups retained for 14 days
6.4 Data Retention
- Medical Records: Retained for the period required by applicable law and operational obligations
- Audit Logs: Retained for security, legal, and compliance purposes
- Account Deletion: You can request account deletion anytime at www.anjiy.tech/account-deletion.html; records required by law, security, payment, audit, or healthcare obligations may be retained for the required period and then securely destroyed.
7. International Users & Data Transfers
7.1 Where We Store Your Data
Anjiy currently uses more than one Google Cloud region. This means personal information may be transferred outside your country:
- Cloud Firestore: European multi-region
eur3
- Cloud Storage and server functions: United States regions, including
US-CENTRAL1 and us-central1
- Hosting and supporting services: May process traffic and security data through Google's global infrastructure
Where required, international transfers are governed by an applicable transfer mechanism and contractual safeguards. Do not use Anjiy where the required transfer basis or organizational approval has not been established.
7.2 European Union Users (GDPR)
If you are in the EU, you have additional rights:
- Right to Erasure ("Right to be Forgotten"): Request deletion of your data
- Right to Data Portability: Receive your data in machine-readable format
- Right to Object: Object to processing for direct marketing
- Right to Restrict Processing: Limit how we use your data
- Legal Basis: We process your data based on consent, contract performance, legal obligations, and legitimate interests
- Privacy contact: privacy@anjiy.tech
- Supervisory Authority: You may lodge a complaint with your local data protection authority
7.3 California Users (CCPA)
If you are a California resident, you have:
- Right to Know: What personal information we collect and how we use it
- Right to Delete: Request deletion of your personal information
- Right to Opt-Out: Opt-out of sale of personal information (we do NOT sell your data)
- Right to Non-Discrimination: We will not discriminate against you for exercising your rights
- How to Exercise: Email privacy@anjiy.tech
7.4 Other Regions
Rights and availability vary by country. Contact privacy@anjiy.tech for information about the service offered in your jurisdiction. Anjiy does not claim that every feature is approved or available in every country.
8. Children's Privacy
The first public release is intended for adults and is not directed to children. Do not create an independent account for a child. A parent or legal guardian may organize information for a dependent only where the feature and applicable law permit it. Contact us to request deletion if you believe a child created an account without required authorization.
9. Changes to This Privacy Policy
- We may update this policy when the service, providers, or applicable requirements change
- Material changes will be communicated through an appropriate channel before or when they take effect, as required by law
- You can always view the latest version at https://www.anjiy.tech/privacy-policy
- Current version: July 31, 2026
Important
This policy is a transparency notice, not a substitute for a specific consent where applicable law requires one. The legal basis for each processing activity depends on the feature, context, and jurisdiction.
Date of last review: July 31, 2026
© 2024-2026 Anjiy Inc. All rights reserved. |
www.anjiy.tech |
Terms of Service |
Privacy Policy