Scope and responsibilities
AfyaFamily is a multi-tenant platform used by health programmes and delivery partners. Aya is the AI assistant within AfyaFamily. This policy describes the platform’s general practices for participants, experts, partner staff and researchers.
The organisation responsible for deciding how your information is used may be your programme operator, AfyaFamily’s platform operator, or both in different roles. Its identity, local contact and jurisdiction-specific notice should be shown during onboarding. A programme supplement takes priority where it provides more specific, lawful protections.
Information we handle
What we collect depends on the features you use and the choices you make. It may include:
- Account details: a raw phone number accepted during setup, transformed into a tenant-scoped HMAC hash rather than stored as the raw number; a random internal username; PIN credentials in protected form; age from 10–99; country, region and language.
- Profile and preferences: accessibility and discreet-mode settings, journey status, methods previously used or considered, goals and support interests.
- Consent records: what you agreed to, refused or later withdrew, including version and timing.
- Aya activity: chat messages, citations, feedback and safety metadata when conversation history is enabled. Voice audio is processed to respond; operational metrics are designed to remain content-free.
- Care and expert activity: referrals, expert-chat ciphertext and encrypted attachments, delivery/read status, and notification preferences.
- Device information: push tokens and limited technical information needed for security and delivery.
- Location: coarse or precise coordinates only when you grant location permission and use a nearby-care feature.
- Service metrics: content-free provider and interaction events such as request timing, feature used, response success and token totals.
Why we use information
We use information to create and protect accounts; tailor language and accessibility; answer questions; retrieve vetted sources; support safety guardrails; locate care; deliver referrals, expert messages and notifications; respond to support requests; prevent abuse; maintain the service; and, where permitted, measure and improve programme delivery.
The applicable legal basis is programme- and jurisdiction-specific. It may include consent, provision of a requested service, public-interest health activity, a legal obligation or another lawful basis identified in your local notice. We do not invent a single legal basis for every deployment.
Granular consent choices
Essential processing keeps your account secure and provides features you request. Separate controls may cover de-identified research, product analytics, location, conversation history and reminders. The latest recorded choice governs future optional processing; withdrawing consent does not make earlier lawful processing unlawful.
History on
New conversations may be saved and shown in your history according to your programme’s retention period.
History off
New chats are hidden from history. Temporary server copies needed to process them are deleted within 24 hours; they are not “device only.”
Operating-system permission and an AfyaFamily consent choice may both be required for location or notifications. You can change optional choices in your privacy settings.
AI and specialist service providers
OpenAI processes Ask Aya text and voice inputs to generate responses. Ask Aya chat and voice are not end-to-end encrypted. When you explicitly choose to translate an expert message, OpenAI also processes the selected decrypted text after a warning.
Google Places receives your permitted location and search context to return nearby listings. Expo processes device push tokens and delivery requests. These providers may process information in other countries under contractual and legal safeguards described in your programme notice.
The public website uses necessary Django session and CSRF cookies for login and security. AfyaFamily does not describe these service operations as advertising or marketing cookies.
Private expert conversations
Direct messages and attachments between participants and experts are stored as ciphertext using device-held private keys. This protects message content from normal server-side access, but it cannot protect a conversation on an unlocked or compromised device.
Delivery status, timestamps and other routing metadata are not message ciphertext and may be processed to operate the chat.
Analytics and responsible research
Research is optional. Where consented, AfyaFamily uses allowlisted, content-free metrics and aggregate exports to understand access, quality, safety and care-navigation patterns. Operational analytics are designed not to include raw phone numbers, exact coordinates, audio transcripts or conversation text.
Exports apply safeguards such as small-cell suppression and, where configured, differential privacy. These methods reduce re-identification risk but do not justify a promise of absolute anonymity. Access should remain restricted and governed by programme protocols and ethics requirements.
Retention and deletion
Consented conversation history is retained for the period set by the applicable programme. When history is off, a temporary server copy is deleted within 24 hours. Account, consent, safety, referral and transaction records may have different lawful or operational retention periods.
Account export and deletion APIs support programme workflows. Deletion from active systems, backups, downstream processors and legally required records can take reasonable operational or lawful time; it is not necessarily instantaneous everywhere.
Security and discretion
Controls include tenant separation, protected credentials, access restrictions, encryption in transit, encrypted expert-chat content, auditability and limited analytics fields. No internet service can guarantee perfect security.
Discreet notifications reduce visible detail, but cannot erase operating-system notification history, cloud backups, screenshots or access by someone who controls your device. Use a device lock, keep your PIN private and sign out on shared devices.
Your access and choices
Depending on local law and your programme, you may ask to access, correct, export or delete information; object to or restrict some processing; withdraw optional consent; or complain. The mobile export control may not include every server-side record, so contact support or your programme for a formal request.
We may need to verify a request without asking for your PIN. Some requests can be limited where law requires retention or another person’s rights would be affected.
Children, adolescents and safeguarding
The service can accept ages 10–99, but technical acceptance does not by itself establish legal eligibility. Age requirements, guardian involvement, confidential adolescent access and safeguarding rules depend on the programme and local law and must be explained during onboarding.
Aya may identify urgent-safety language and encourage contact with emergency services, a qualified clinician or a trusted safeguarding resource. It is not an emergency monitoring service and cannot guarantee that someone will intervene.
Changes, questions and complaints
We may update this policy as the product, programmes or law change. Material changes should be shown in the service or through the programme before they take effect where required. The date at the top identifies the current version.
Questions or privacy requests can be sent to support@maternalapp.jkbytes.org. Your onboarding notice should also identify the local programme contact and, where applicable, the authority or regulator to which you may complain.