Privacy Policy

Last updated: 7 June 2026 · Effective date: 7 June 2026


1. Introduction

VaultAir Systems (Pty) Ltd ("VaultAir", "we", "us", or "our") operates Jan on Health ("JoH"), a digital health and wellbeing companion available at https://janonhealth.com and through WhatsApp.

This Privacy Policy explains how we collect, use, store, share, and protect personal information when you:

  • visit our Website;
  • use JoH on WhatsApp or related channels;
  • subscribe to our articles or newsletters;
  • contact us; or
  • interact with us in any other way.

We are committed to protecting your privacy and handling your information responsibly. This Policy is designed to comply with:

  • the Protection of Personal Information Act, 2013 (POPIA) in South Africa;
  • the General Data Protection Regulation (GDPR) in the European Union and European Economic Area;
  • the UK GDPR and Data Protection Act 2018;
  • United States privacy laws, including principles aligned with the Health Insurance Portability and Accountability Act (HIPAA) where applicable; and
  • other applicable data protection laws in countries where we operate.

Please read this Policy together with our Terms of Service.


2. Who Is Responsible for Your Data?

Data controller / responsible party:
VaultAir Systems (Pty) Ltd
Company registration number: 2025/540482/07
Registered address: Stellenbosch, 7600, Western Cape, Republic of South Africa
Email: privacy@vaultair.systems
Website: https://janonhealth.com

Information Officer (POPIA):
Jan Pool
Email: privacy@vaultair.systems
Subject line: Information Officer

You may contact the Information Officer at the address above for any matter relating to the processing of your personal information. (POPIA requires responsible parties to register their Information Officer with the Information Regulator of South Africa.)

EU/UK representative (GDPR Article 27 / UK GDPR):
VaultAir does not currently maintain an establishment in the European Economic Area or United Kingdom. If you are in the EEA or UK, contact our Information Officer at privacy@vaultair.systems with the subject line EU/UK Privacy. Where applicable law requires us to appoint an EU or UK representative under Article 27, we will appoint one and publish their contact details on this page.


3. Important Notice About Health Information

JoH is a wellbeing companion, not a healthcare provider. We are not a HIPAA covered entity and not a business associate under HIPAA unless we enter into a separate written agreement stating otherwise.

However, because you may share health-related information with JoH, we treat that data as special category personal data under GDPR and special personal information under POPIA. We apply enhanced safeguards and require your explicit consent before processing this data for the Service.

Do not use JoH for medical emergencies. Call your local emergency number.


4. What Information We Collect

We collect information you provide directly, information generated through your use of the Service, and limited technical information.

4.1 Information you provide

CategoryExamplesPurpose
Contact detailsWhatsApp phone number, name, email (if provided)Account setup, communication, support
Conversation contentText messages, captions, voice notes, images, videos, documents, locationsProvide and personalise the Service
Health and wellbeing informationSymptoms you mention, conditions, medications, fitness goals, dietary preferences, habits, mental wellbeing topicsPersonalise guidance and maintain context
Language preferencePreferred language for responsesDeliver the Service in your language
Consent recordsAcceptance or rejection of Terms and Privacy Policy, timestampLegal compliance and audit
Support requestsMessages asking to speak to a person, bug reports, product feedbackCustomer support and product improvement
Payment-related informationSubscription tier, billing status, transaction referencesManage subscriptions (payment card details are handled by Paystack, not stored by us)
Website formsContact form submissions, newsletter sign-upsRespond to enquiries, send updates

4.2 Information collected automatically

CategoryExamplesPurpose
Usage and technical dataMessage timestamps, delivery status, device/browser type (Website), IP address (Website), API logsOperate, secure, and improve the Platform
Derived profile dataFacts, goals, and short-term context extracted from conversationsPersonalise responses
Observability dataError logs, performance traces (via Pydantic Logfire)Monitor reliability and fix issues

4.3 WhatsApp and Meta

When you use JoH on WhatsApp, Meta Platforms, Inc. processes your messages and metadata under WhatsApp's own privacy policy. We receive message content and related data through the WhatsApp Business Platform to provide the Service.

4.4 Website cookies

Our Website may use cookies and similar technologies. See Section 12 (Cookies) below.


5. How We Use Your Information

We use personal information only for lawful purposes, including to:

  • provide, operate, and maintain JoH;
  • personalise your experience using conversation history, facts, goals, and short-term context;
  • generate AI-powered responses and safety checks;
  • detect language and translate messages where supported;
  • manage subscriptions, trials, and billing;
  • record and verify your consent;
  • respond to support requests and escalation to human staff;
  • send service messages (for example, trial expiry or payment reminders);
  • monitor, debug, and improve the Platform;
  • detect abuse, fraud, and security incidents;
  • comply with legal obligations; and
  • enforce our Terms of Service.

We do not sell your personal information.
We do not use your health information for third-party advertising.

5.1 Direct marketing

We send newsletters and other marketing communications only where you have opted in, or where otherwise permitted by applicable law (including section 69 of POPIA). Every marketing message includes a simple way to opt out, and you can unsubscribe at any time using the unsubscribe link or by emailing support@vaultair.systems.

Service messages (for example, consent confirmations, trial-expiry notices, payment reminders, and security notices) are not marketing. They are necessary to provide the Service and to comply with our legal obligations, and you cannot opt out of them while you use the Service.


Depending on your location and the type of data, we rely on one or more of the following legal bases:

Legal basisWhen it applies
ConsentHealth-related information, marketing communications (where required), and WhatsApp onboarding
ContractProviding the Service you request, including subscriptions
Legitimate interestsSecurity, fraud prevention, service improvement, and internal analytics (balanced against your rights)
Legal obligationTax, accounting, regulatory, and law enforcement requests

For special category / sensitive data (including health information), we rely primarily on your explicit consent under GDPR Article 9 and equivalent provisions under POPIA.

You may withdraw consent at any time (see Section 10). Withdrawal does not affect processing already performed and may mean we can no longer provide the Service.


7. Artificial Intelligence and Automated Processing

JoH uses automated processing, including AI models (currently from OpenAI), to:

  • classify and understand your messages;
  • extract facts, goals, and short-term context;
  • generate responses;
  • validate content for safety;
  • detect language and translate text; and
  • suggest follow-up questions.

No solely automated decision is made that produces legal or similarly significant effects on you (such as credit, employment, or insurance decisions). AI outputs are informational only and are not professional medical advice.

Training of AI models. Our AI subprocessors process your messages only to generate responses and safety checks for you. We use these providers under their business/API terms, and we do not permit your conversations or health information to be used to train third-party AI models, except where we tell you clearly in advance and obtain any consent required by law.

Prompts and responses may be logged for quality, safety, debugging, and compliance. We apply access controls and retention limits to these logs.


8. How We Protect Your Information

We implement appropriate technical and organisational measures, including:

  • De-identification: WhatsApp phone numbers are mapped to internal user identifiers (UUIDs) so phone numbers are not stored directly in core user and conversation tables;
  • Encryption in transit: HTTPS/TLS for data in motion;
  • Encryption at rest: Database and infrastructure encryption where supported by our cloud provider;
  • Access controls: Role-based access, API keys, and authentication for internal systems;
  • Webhook security: Signature verification for WhatsApp webhooks;
  • Caching limits: Recent conversation data in Redis cache with time-limited retention (for example, approximately 4 hours for active sessions);
  • Automatic expiry: Short-term health context (episodes) expires automatically, typically within 1–90 days depending on context;
  • Audit trails: Consent records and operational logs for accountability;
  • Safety validation: Automated checks on AI-generated responses; and
  • Vendor assessment: Due diligence on subprocessors that handle personal data.

No system is completely secure. Please use strong device security and avoid sharing information you are not comfortable storing digitally.


9. Data Retention

We retain personal information only as long as necessary for the purposes described in this Policy, unless a longer period is required by law.

Data typeTypical retention
Account and profile dataWhile your account is active, plus a reasonable period after deletion for backup and legal purposes
Conversation historyWhile your account is active; deletable on request
User facts and goalsWhile relevant and your account is active
Short-term episodesUntil automatic expiry (typically 1–90 days) or deletion
Consent recordsFor the duration of the relationship and as required for legal and audit purposes
Billing recordsAs required by tax and accounting law (typically 5–7 years)
Cache data (Redis)Short-term (for example, hours) for active sessions
Logs and observability dataLimited retention for troubleshooting and security

When data is no longer needed, we delete or anonymise it in accordance with our retention schedule.


10. Your Rights

Depending on where you live, you may have the following rights regarding your personal information:

RightDescription
AccessRequest a copy of personal information we hold about you
RectificationCorrect inaccurate or incomplete information
ErasureRequest deletion ("right to be forgotten")
RestrictionAsk us to limit processing in certain circumstances
PortabilityReceive your data in a structured, machine-readable format (where applicable)
ObjectionObject to processing based on legitimate interests
Withdraw consentWithdraw consent at any time where processing is consent-based
ComplaintLodge a complaint with a supervisory authority

10.1 How to exercise your rights

Email us at privacy@vaultair.systems with the subject line "Privacy Request". We may need to verify your identity (for example, by confirming your WhatsApp number).

We aim to respond within 30 days (or sooner where required by law, such as one month under GDPR).

10.2 South Africa (POPIA)

You may request access to, correction of, or deletion of personal information, and object to processing where POPIA allows. You may also complain to the Information Regulator (South Africa) at https://inforegulator.org.za.

10.3 European Union / UK (GDPR)

You have the rights listed above and may contact your local data protection authority. For EU users, authorities are listed at https://edpb.europa.eu. For UK users, contact the ICO at https://ico.org.uk.

10.4 United States

Residents of certain US states (including California, Virginia, Colorado, and others) may have additional rights such as knowing what personal information is collected, requesting deletion, and opting out of certain processing. We do not sell personal information.

While we are not a HIPAA covered entity, we apply administrative, technical, and physical safeguards appropriate to the sensitivity of health-related information you choose to share.


11. Sharing and Subprocessors

We share personal information only as described below. All subprocessors are bound by contractual obligations to protect your data.

RecipientRoleLocation
Meta / WhatsAppMessaging platform and deliveryGlobal
OpenAIAI model processing (response generation, safety, language)United States and other regions
Amazon Web Services (AWS)Cloud hosting, database (PostgreSQL), cache (Redis), and transactional email (Amazon SES)Primarily eu-west-1 (Ireland) and related AWS regions
PaystackPayment processingAfrica / applicable payment regions
Pydantic LogfireObservability, logging, and error monitoringEuropean Union (Logfire EU region)
Google (Google Ireland Limited / Google LLC)Website analytics (Google Analytics 4), loaded only with your consentEU and United States
SubstackNewsletter / article subscription delivery (if you subscribe)United States
Professional advisersLegal, accounting, or compliance (when needed)Various
Law enforcement / regulatorsWhen required by valid legal processAs applicable

We may also share information in connection with a merger, acquisition, or sale of assets, with notice where required by law.

A current list of subprocessors is available on request at privacy@vaultair.systems.


12. International Data Transfers

VaultAir is based in South Africa. Your information may be processed in South Africa, the European Union, the United States, and other countries where our subprocessors operate.

Where personal data is transferred from the EEA, UK, or other jurisdictions requiring safeguards, we rely on appropriate mechanisms such as:

  • Standard Contractual Clauses (SCCs) approved by the European Commission;
  • UK International Data Transfer Agreement or Addendum where applicable;
  • Adequacy decisions where available; and
  • Your explicit consent where required.

You may request a copy of applicable transfer safeguards by contacting us.


13. Cookies and Website Analytics

When you visit our Website, we and our service providers may use cookies, local storage, and similar technologies as follows:

Tool / typeCategoryPurposeProvider
Session and security cookiesEssentialRequired for the Website to function (for example, security and basic operation)First-party (Jan on Health)
Cookie consent preferences (localStorage)EssentialRemembers your cookie choices so we do not ask again on every visitFirst-party (Jan on Health)
Google Analytics 4 (GA4)Analytics (consent required)Page views, approximate location, device/browser type, and how visitors use the WebsiteGoogle Ireland Limited / Google LLC (Google Privacy Policy)

GA4 is loaded only after you accept Analytics cookies in our cookie consent banner. You can change your preferences at any time by clearing site data in your browser or revisiting the banner after clearing cookie-consent-preferences from local storage.

You can also manage cookies through your browser settings. Disabling essential cookies or storage may affect Website functionality.

This section applies to the Website only. The WhatsApp Service does not use browser cookies.


14. Children's Privacy

JoH is intended for users aged 18 and over. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it promptly.


15. Data Breach Notification

If a personal data breach (a "security compromise" under POPIA) is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority and affected users as required by POPIA, GDPR, UK GDPR, and other applicable laws. Where GDPR/UK GDPR applies, we aim to notify the competent authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach. Under POPIA, we notify the Information Regulator and affected data subjects as soon as reasonably possible after discovery.


Our Website may link to third-party sites (for example, Substack, Instagram, Facebook, or payment pages). We are not responsible for the privacy practices of those sites. Review their privacy policies before providing personal information.


17. Changes to This Policy

We may update this Privacy Policy from time to time. We will update the "Last updated" date and, where changes are material, notify you through the Website, WhatsApp, or email.

If changes require renewed consent under applicable law (for example, for health data processing), we will ask for your consent before applying the changes to the Service.


18. Contact Us

For privacy questions, rights requests, or complaints:

VaultAir Systems (Pty) Ltd
Company registration number: 2025/540482/07
Registered address: Stellenbosch, 7600, Western Cape, Republic of South Africa
Information Officer: Jan Pool
Email: privacy@vaultair.systems
Subject line: Privacy Request or Information Officer
Website: Contact us


This Privacy Policy should be read together with our Terms of Service.