RIJI Health ("RIJI Health," "we," "us," or "our") is committed to protecting your privacy and safeguarding your personal and health information. This Privacy Policy outlines how we collect, use, disclose, store, and protect your information when you use our mobile applications, web platform, application programming interfaces (APIs), and related services (collectively, the "Services").
We treat biometric data, medical history, symptom logs, wellness metrics, and voice data as Sensitive / Special Category Health Data that is collected and processed only with your explicit, informed consent.
Please read this Privacy Policy carefully. By creating an account, accessing, or using the Services, you acknowledge that you have read and understood this policy and consent to the collection and handling of your information as described herein.
Information We Collect
We collect information directly from you, automatically through your use of the Services, and from authorized third-party integrations.
A. Personal Information
- Account Identifiers: Full name, email address, phone number, date of birth, and authentication credentials.
- Profile Data: User preferences, timezone, avatar/profile image, and communication settings.
B. Sensitive Health & Wellness Data
To deliver core health functionality, we may collect and process sensitive health information with your explicit consent:
- Self-Reported Health Metrics: Symptoms, lifestyle factors, wellness logs, dietary entries, medication routines, and physical measurements.
- Audio & Voice Inputs: Voice recordings or transcriptions when utilizing voice-enabled features or conversational health agents.
- Connected Device & Health Ecosystem Data: Data imported via authorized integrations (such as Apple HealthKit, Google Health Connect, or wearable sensors) where explicitly enabled by you.
- Genetic & Ancestral Insights: Where you elect to use genetic analysis features, genomic data files you upload or authorize, processed solely for the insights you request.
C. Technical & Usage Data
- Device Telemetry: Device model, operating system version, unique device identifiers, IP address, mobile network provider, and crash logs.
- Interaction Logs: Features accessed, session durations, timestamps, and navigation flows within the app.
How We Use Your Information
We process personal and health information only for lawful, specified purposes:
- Delivering Core Services: Providing personalized health insights, trend analysis, symptom tracking, and wellness dashboards.
- AI & Natural Language Processing: Running queries against health knowledge systems, conversational agents, and data models to generate contextual insights.
- Safety & Service Integrity: Monitoring application performance, debugging technical errors, verifying account security, and preventing fraud.
- User Communications: Sending service notifications, security alerts, technical updates, and customer support responses.
- Legal Compliance: Fulfilling statutory obligations, responding to lawful regulatory requests, and enforcing our Terms of Service.
Zero Monetization & Total Privacy Guarantee
Zero-Knowledge Architecture & Cryptographic Processing
- Zero-Knowledge Architecture: RIJI Health is built on a zero-knowledge architecture. This means your personal health data is encrypted locally on your device before it ever reaches our servers. Even RIJI Health staff, engineers, and administrators cannot access, read, or share your raw health data without your specific client-side encrypted keys.
- On-Device vs. Cloud Execution: Where feasible, voice processing, biometric parsing, and ML inference occur locally on your device (edge computing). When cloud computing is required, data is processed in secure, ephemeral enclaves and remains cryptographically locked.
- Data Minimization: We collect only the minimum amount of health and personal information strictly necessary to fulfill the requested feature.
AI & Data Governance Transparency
We believe you have the right to understand exactly how artificial intelligence interacts with your health data:
- No Foundation Model Training: Your identifiable health data is never used to train, fine-tune, or improve foundation models — whether our own or those of third-party AI providers. Contractual and technical controls prohibit AI sub-processors from retaining or training on your inputs.
- Retrieval-Augmented Generation (RAG): When AI features answer questions about your health, relevant fragments of your data are retrieved at query time, processed transiently in memory, and discarded after the response is generated. Your data is not merged into any shared knowledge base.
- On-Device First: Wherever hardware permits, inference runs on-device. Cloud inference is used only when necessary, over encrypted channels, in ephemeral compute enclaves.
- AI Output Limitations: AI-generated insights are informational wellness guidance and do not constitute medical advice, diagnosis, or treatment. Always consult a qualified healthcare practitioner.
- Human Oversight & Explainability: Significant AI-driven insights are traceable to their underlying data sources, and you may request information about the logic involved in automated processing.
Legal Bases for Processing
Where the GDPR, UK GDPR, or equivalent laws apply, we rely on the following legal bases:
- Explicit Consent (Art. 9(2)(a) GDPR): For all collection and processing of special category health data, including biometric, genetic, and voice data. Consent is granular, informed, and withdrawable at any time.
- Contractual Necessity (Art. 6(1)(b)): Processing account and profile data required to deliver the Services you have requested.
- Legitimate Interests (Art. 6(1)(f)): Limited technical and usage data processing for security, fraud prevention, and service integrity — always balanced against your rights and freedoms.
- Legal Obligation (Art. 6(1)(c)): Processing required to comply with applicable laws and lawful regulatory requests.
Withdrawing consent does not affect the lawfulness of processing performed before withdrawal.
Data Security Measures
We employ industry-standard technical and organizational safeguards to protect your data:
- Military-Grade Encryption: Data is secured using military-grade encryption standards (AES-256-GCM) at rest and TLS 1.3 in transit. Your private keys are securely stored in your device's hardware Secure Enclave, ensuring that neither RIJI Health nor any unauthorized third party can decrypt your sensitive health information.
- Access Controls: Strict role-based access control (RBAC), multi-factor authentication (MFA), and audit logging for internal systems.
- Vulnerability Management: Regular code audits, automated dependency vulnerability scanning, and infrastructure monitoring.
- Breach Notification: In the event of a data breach likely to result in serious harm, we will notify affected users and relevant supervisory authorities (e.g., the OAIC, EU/UK regulators) within the timeframes mandated by applicable law.
Your Rights and Choices
Depending on your jurisdiction (including Australia, the EU/UK, and various US states), you possess specific statutory rights regarding your personal and health data:
Access & Portability
Request a structured, machine-readable export of your personal and health data.
Correction & Rectification
Update or correct inaccurate or incomplete profile and health entries directly within the app or by contacting us.
Deletion (“Right to Be Forgotten”)
Request the permanent erasure of your account and associated health records, subject to statutory record-retention requirements.
Withdrawal of Consent
Revoke permissions for health data access, microphone usage, or third-party device integrations via your device settings or account profile at any time.
Restriction & Objection
Restrict or object to specific processing activities, including any processing based on legitimate interests.
Complaint to a Regulator
Lodge a complaint with your supervisory authority — e.g., the OAIC (Australia), your EU Data Protection Authority, the UK ICO, or your State Attorney General (US).
To exercise any of these rights, contact us at support@rijihealth.com. We respond to verified requests within 30 days (or sooner where required by law), free of charge.
Data Retention
We retain your personal and health data only for as long as your account remains active or as needed to provide you with the Services. Upon account deletion:
- Your personal identifiers and identifiable health logs are permanently deleted or irreversibly anonymized within 30 days.
- Backup archives are overwritten according to our standard backup rotation cycle (not exceeding 90 days).
- Limited records may be retained longer only where required by statutory record-retention obligations (e.g., tax, audit, or health-records legislation), and are safeguarded for that sole purpose.
Children's Privacy
The Services are not directed to individuals under the age of 16 (or the legal age of consent in your jurisdiction). We do not knowingly collect personal health data from children without verified parental or guardian consent. If we become aware that a child has provided us with personal information, we will delete it promptly.
International Data Transfers
If data is transferred across international borders, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs), adequacy decisions, or equivalent legal mechanisms to protect your information under applicable data protection laws. For Australian users, cross-border disclosures comply with APP 8 (cross-border disclosure of personal information).
Regulatory Framework Alignment
Our privacy program is structured to align with leading global health-data standards:
Australia
Australian Privacy Principles under the Privacy Act 1988 (Cth), and the NSW Health Records and Information Privacy Act 2002 (HRIPA) where applicable.
EU & United Kingdom
GDPR and UK GDPR — including Articles 6 and 9 governing the lawful processing of special category health data.
United States
HIPAA privacy and security principles where applicable, and state-level privacy laws including the CCPA/CPRA (California) and comparable state health-data statutes.
App Marketplaces
Apple App Store Review Guideline 5.1 (Privacy) and the Google Play Developer Policy for health and medical apps, including health-data usage and consent requirements.
Alignment with a framework does not itself constitute certification; where formal certification or registration applies, it will be identified separately.
Changes to This Policy
We may update this Privacy Policy periodically. If we make material changes affecting how your health data is handled, we will notify you through the app interface, via email, or by a prominent notice on our website prior to the changes taking effect.
Contact Us & Data Protection Officer
For questions, feedback, or complaints regarding this Privacy Policy or our data practices:
- Entity: RIJI Health
- Email: support@rijihealth.com
- Website: https://rijihealth.com
If you are not satisfied with our response, you have the right to escalate your complaint to your local data protection authority.