Version 1.0 · Last updated 2 October 2026
This policy is linked from the home page of maalin.app, from the app’s sign-up step (“What’s included”) and from You → About and legal.
The short version
- Maalin keeps your health data on your phone, and a locked copy with your account so a new phone can get it back.
- The locked copy is encrypted on your phone first. Nobody, Maalin included, can open it without your passkey or your recovery kit.
- We never sell your health data, and we don’t share it with anyone. If a future feature needs to share it, Maalin will ask you separately first and name the company.
- We don’t use your health data for ads, and we don’t set up virtual boundaries (geofences) around places where people get health care.
- You can see, export and delete all of it in the app, at any time.
1. Who this policy is for, and who we are
This policy is for people in the United States, and in particular for residents of Washington, Nevada and Connecticut, whose laws give special protection to “consumer health data”. We apply it to everyone in the US.
Maalin is made by Maalin Technologies Ltd (“Maalin”, “we”, “us”), a company being registered in England and Wales (its company number and registered office will be added here once registration completes), with its head office in Nairobi, Kenya. Contact: company@maalin.app, with the subject “Health data request”.
Our Privacy Policy covers all the data Maalin handles, for everyone. This policy adds what US consumer health data laws ask for. If the two ever seem to differ for your health data, this policy applies.
2. What’s included
This is the list of health data Maalin keeps. The consent you give at sign-up covers all of it, stored in locked form with your account.
| Kind of data | Examples | Where it lives |
|---|---|---|
| Sleep | When you slept and woke, how long, sleep stages from Apple Health, and your sleep check-ins (bedtime, wake time, how you slept) | Your phone; locked with your account |
| Movement and activity | Steps or wheelchair pushes, distance, active energy, workouts, activities and how hard they felt, activity plans | Your phone; locked with your account |
| Routes | The path of an activity you recorded, only if you chose to save it | Your phone; locked with your account |
| Heart data | Resting heart rate, heart rate variability, VO₂ max, as daily summaries | Your phone; locked with your account |
| Body measurements | Weight, waist, blood pressure and others you enter in Maalin | Your phone; locked with your account |
| Food and water | Meals and what was in them, calories and nutrients, water | Your phone; locked with your account |
| Mood and energy | Your mood and energy check-ins, and their notes | Your phone; locked with your account |
| Fasting | Fasting windows and fasting days, including religious fasts | Your phone; locked with your account |
| Habits | Health habits you track, for example stretching or screens after a set time | Your phone; locked with your account |
| Your body and safety profile | Birth year, sex (optional), height, goals, activity level, age band, and if you’re pregnant or breastfeeding or use a wheelchair (optional) | Your phone; locked with your account |
| Targets | Your calorie, protein, water, step, active minutes and sleep targets | Your phone; locked with your account |
| What Maalin works out about you | Readiness, daily summaries, patterns (for example spending after short sleep), usual times and meals, and insights | Your phone; locked with your account |
| Checkups you set (from version 1.0) | The name and interval of recurring appointments you add, and the date of the last one | Your phone; locked with your account |
| Notes | Anything you type in a quick note, which may mention your health | Your phone; locked with your account |
The same sign-up consent also covers your faith data (prayer log, prayer settings, religious habits), which isn’t health data but is just as sensitive, and the rest of what you log, such as spending and places. The Privacy Policy describes those.
What isn’t in the list, because Maalin never keeps it: your Apple Health history (Maalin reads it when needed and keeps only the daily summaries above), your calendar, voice recordings, meal photos (read on your phone, then deleted), and Face ID or Touch ID data (Apple checks them; Maalin never receives them).
3. Where it comes from
- You: what you log, type, say or photograph in Maalin, and your answers during set-up.
- Apple Health on your iPhone: only the types you allowed, which may come from devices and apps you connected to Apple Health (for example a watch, a ring, a scale or a food app).
- Your iPhone: motion data, and your route when you record an activity with “Record route” on.
- Maalin’s own calculations, on your phone, from the data above.
We never buy health data or get it from data brokers or other companies.
4. Why Maalin uses it
Only to give you the app you asked for:
- to fill in your day and suggest the next thing to do, with its reason;
- to track your targets, pace and progress;
- to learn your usual times, meals and patterns, and show you insights;
- to keep suggestions safe (for example, no hard activity while fasting, and no calorie cuts if you’re pregnant or breastfeeding);
- to keep a locked copy with your account, so you can get it back on a new phone.
All of this is worked out on your phone. Our server never calculates anything from your health data, and it can’t read it.
We don’t use your health data for advertising, marketing, research, or to train AI.
5. What Maalin can and can’t read
- Your locked data: Maalin can’t read it. It’s encrypted on your phone with a key only your passkey or recovery kit can open. Our server sees a random ID for each record, the hour it was uploaded, which key version locked it and a rounded size. Nothing about what the record is or what it says.
- Your account data: Maalin can read your sign-in identifier and email, your list of devices and short server logs, to run your account (Privacy Policy, section 3.3). None of it is health data.
- Anonymous counts: Maalin counts which screens are used, with no identifier. Screens of a health area are counted only as “a module screen”, never by which one, so the counts reveal nothing about your health (Privacy Policy, section 8).
6. Who we share it with
Nobody. Maalin doesn’t share your consumer health data with any third party or affiliate.
Categories of consumer health data we share: none. Third parties and affiliates we share it with: none.
Our processors. Scaleway stores your locked data for us. An encrypted backup copy is kept with a second provider, Hetzner, in Germany (EU). Both work only on our instructions, under a data processing agreement, and neither can open your data:
| Processor | What it does | Where |
|---|---|---|
| Scaleway SAS (France) | Hosts our server, database and backups, which hold your locked data | Paris, France (EU) |
| Hetzner Online GmbH (Storage Box, Germany) | Keeps an encrypted copy of our database, made each night, as a second backup | Germany (EU) |
No other company receives your health data. Our email provider (Scaleway Transactional Email) sends only sign-in codes and security notices, which contain no health data.
WhatsApp messages. If you add a phone number, Maalin can send you sign-in codes, security alerts, reminders and news on WhatsApp. These messages are optional, and they never contain consumer health data. Meta Platforms delivers them for us, as our processor.
Our website. The website maalin.app collects no consumer health data. It has no account and no forms. Its analytics and advertising tools run only with the visitor’s consent (see the Cookie notice). They see only that someone visited maalin.app and what they clicked. They get no Maalin account ID and nothing you put into the app. We never build advertising audiences around health conditions, ever.
At your direction, on your phone. If you allow it, Maalin writes meals, water, body measurements, sleep check-ins, mood and activities to Apple Health on your iPhone, so your other health apps can see them. This stays on your phone under your control in the Health app.
If a future feature needs to share. Maalin has no such feature at launch. If one is added (for example sending a meal photo to an AI company to read it), it will be off until you turn it on, and Maalin will ask for your separate consent to share, naming the company, before anything is sent.
Legal requests. If an authority asks for data, we can hand over only what we can read, which contains no health data. We can’t open your locked data. We tell you about a request unless the law forbids it.
7. We never sell it, and we don’t geofence
- We never sell consumer health data. Selling it would require your signed authorisation under Washington law, and we’ll never ask for one.
- We don’t set up geofences around places that provide health care, to identify, track, collect data from or send messages to people there.
- Maalin never uses your location in the background. It notes the approximate location of a place only when you log there and have turned on place suggestions.
8. Your consent
To collect. When you create an account, Maalin asks for your consent in one unticked line, separate from the Terms:
I agree that Maalin keeps my health and faith data encrypted on its EU servers, so I can get it back on a new phone. I can withdraw by deleting my account.
The “What’s included” link next to it opens section 2 of this policy.
To share. Maalin shares nothing today. Any future sharing needs a separate consent, asked for at the time, naming the company.
Withdrawing. Maalin keeps your data with your account so it’s never lost with a phone, and it can’t work without that. You withdraw your consent by deleting your account (section 10). Any future sharing consent will be a switch you can turn off at any time.
9. Your rights
You have the right to:
- Know whether we collect, share or sell your consumer health data, and see it. Section 2 says what we keep; section 6 says we share with no one and sell to no one. The app shows your data, and You → Privacy and data → What Maalin learned shows what Maalin worked out.
- Get a copy. You → Privacy and data → Export gives everything as JSON and CSV.
- Delete it. You → Privacy and data → Delete data deletes one area, one day, what Maalin learned, or everything. Deleting your account deletes everything with it (section 10). When you delete, we also delete it from our processors’ systems and backups within 30 days.
- Withdraw your consent, by deleting your account (section 8).
- Appeal if we turn down a request (below).
We won’t treat you differently for using any of these rights.
How to use them
- In the app, at any time, with no need to contact us. Because your data is locked with your key, the app is the only place it can be opened, exported or corrected.
- By email to company@maalin.app, with the subject “Health data request”. We’ll ask you to confirm the request from the app or from your account’s email, so we don’t act on someone else’s request.
- We answer within 30 days, or sooner where a law requires it.
- An authorised agent may make a request for you, with your signed permission.
Appeals
If we turn down your request, you can appeal by writing to company@maalin.app with the subject “Appeal”, within 45 days of our answer. We’ll answer within 30 days and explain our decision. If we still turn it down, you can complain to your state’s Attorney General:
- Washington: Attorney General’s Office, atg.wa.gov
- Nevada: Attorney General’s Office, ag.nv.gov
- Connecticut: Attorney General’s Office, portal.ct.gov/ag
10. How long we keep it
| Data | Kept for |
|---|---|
| Your health data on your phone and locked with your account | Until you delete it or your account |
| Voice recordings | Not kept |
| Meal photos | Not kept. Deleted once read |
| Suggestions and what you did with them | 180 days, then only as a summary in your patterns |
| Something you deleted | Gone from the app at once; removed from every device within 30 days |
| After you delete your account | Removed from our live server at once, and from all backups, including the second backup provider’s copy, within 30 days |
Deleting your account. In You → Account and sync → Delete account, confirmed with your passkey. The locked copies of your key are deleted at once, so nothing on our server can be opened any more, and your records are deleted from the live server at once and from backups within 30 days. Without a passkey, the deletion happens after a 7-day wait, announced on every device and by email, and you can stop it until then with your iPhone’s Face ID, Touch ID or passcode. The Privacy Policy, sections 14 and 15, has the full steps, including what happens if you can’t sign in.
11. How we protect it
- Your health data is encrypted on your iPhone with a 256-bit key made there, before it’s synced. Our server holds only locked copies.
- Nobody, Maalin included, can open your data without your passkey or your recovery kit.
- Connections are encrypted, and Maalin talks only to our server, Apple’s services and, if you choose it, Google’s sign-in page.
- Notifications and widgets show no health facts on your lock screen unless you turn on “Show numbers on the lock screen”.
- Only authorised staff can reach our server, with two-factor sign-in, and every action is logged. Staff can’t read your locked data.
- If a breach ever affects your data, we’ll tell you and the authorities as the law requires, including the US Federal Trade Commission under its Health Breach Notification Rule.
The Privacy Policy, section 16, has more.
12. Changes to this policy
When we change this policy, the new version gets a new number and date at the top. If a change affects how we collect or share your health data, we’ll tell you in the app and by email first, and we’ll ask for your consent again where the law requires it. We’ll never start sharing or selling your health data without new, separate consent. Earlier versions stay public at maalin.app/legal/history.
13. Contact
Maalin Technologies Ltd, Nairobi, Kenya · company@maalin.app Email: company@maalin.app (subject “Health data request”, or “Appeal” for an appeal)
Maalin gives general wellbeing guidance, not medical advice. It isn’t a healthcare provider, and HIPAA doesn’t apply to it. Our Terms of use say more.