We collect only what we need to operate the service. Because JaiCare handles health data, we are transparent about what we collect and why.
When linking family members or caregivers, we store their names, identifiers, and messages within the shared family conversation. JaiCare supports three roles: primary caregiver (full access), patient, and sibling (read-only via a secure link).
We use your information exclusively to:
We do not sell, rent, or share your data with third parties for marketing purposes. We do not use your health data to train AI models. We do not show you advertisements based on your health information.
Health data is classified as sensitive personal data under the PDPA. We process it based on your explicit consent — given when you begin using the service and at each major collection point (sharing a condition, uploading a report, telling us about a medication). The bot always asks for your confirmation before saving any health information. You may withdraw your consent at any time; doing so may restrict or end the service, as health data is essential for providing personalised advice.
All data is transmitted over HTTPS/TLS, and insecure connections are rejected.
All user data is stored in a database encrypted with SQLCipher (AES-256). The encryption key is stored separately and does not appear in application logs.
Each user's data is indexed by a unique identifier and processed independently. We do not mix data across accounts.
Server and database access is restricted to authorised operators via SSH key only. The admin dashboard is protected by a secret token.
Encrypted backups are maintained with a limited retention period to ensure service continuity.
To operate the service, we work with carefully selected third parties, each of which processes your data under its standard commercial terms:
| Provider | Role | Location |
|---|---|---|
| DigitalOcean | Hosting and storage | Singapore |
| Anthropic (Claude) | AI processing | United States |
| OpenAI (Whisper) | Voice-to-text conversion | United States |
| Meta (WhatsApp) | Messaging platform | United States / Ireland |
| LINE Corporation | Messaging platform | Japan |
| [Payment provider] | Subscription billing | [To be determined] |
Data sent to providers outside your country is subject to each provider's terms, which include data protection commitments and standard contractual clauses where applicable.
To exercise any of these rights, contact us at [data protection officer email]. We respond within 30 days.
| Data type | Retention period |
|---|---|
| Conversation history, health profile, medications, and reports | For the lifetime of the account — deleted upon request |
| Account data (phone, name) | Deleted within 30 days of deletion request |
| Billing records | As required by law, then deleted |
| Backups | Short rolling retention in encrypted storage |
In the event of a breach affecting your personal data, we will notify the relevant regulatory authority within the legally required timeframe, notify affected users without unreasonable delay if the breach could cause serious harm, and take immediate steps to contain it.
JaiCare is designed for adults and caregivers and is not intended for anyone under 18 years of age. We do not knowingly collect data from children. If you believe a minor has used the service, contact us and we will delete the data.
We may update this policy from time to time. We will notify users of material changes via the bot before they take effect, and continued use after notification constitutes acceptance.
Data Protection Officer: [Name] — Email: [privacy email] — Address: [registered address].