SihatAI logo
Home About Us FAQ Contact Us
Get the app

Contents

  1. Who we are
  2. Sensitive data
  3. Data we collect
  4. Purposes
  5. Notice & choice
  6. AI processing
  7. Payments
  8. Disclosure
  9. Security
  10. Retention
  11. Your rights
  12. Transfers
  13. Children
  14. Third parties
  15. Changes
  16. Contact
Legal

Privacy Policy

Last updated: September 2026

How SihatAI collects, uses, and protects personal data under Malaysian law.

1 Who we are and the law that applies

SihatAI App (“we”, “our”, “us”) is a SenangApps product. This Privacy Policy explains how we collect, use, disclose, store, and protect personal data when you use the SihatAI website, mobile application, and related services (the “Services”). For PDPA purposes we are the data user of personal data you submit through SihatAI.

We process personal data as a data user under the Personal Data Protection Act 2010 (Act 709) (“PDPA”), as amended by the Personal Data Protection (Amendment) Act 2024. The PDPA’s seven core principles apply: General; Notice and Choice; Disclosure; Security; Retention; Data Integrity; and Access.

By registering, using the Services, or submitting data, you acknowledge this notice. Where the PDPA requires consent (including for sensitive personal data), we rely on the consent you give in the app, on this site, or by continuing a clearly described processing activity after notice.

This Policy should be read with the Terms & Conditions and Safety Standards.

Personal Data Protection Act 2010 (Act 709), including the interpretation of “personal data” and “sensitive personal data” in section 4; Personal Data Protection (Amendment) Act 2024 (further obligations such as data portability and, where prescribed, a Data Protection Officer).

2 Health information is sensitive personal data

Under section 4 of the PDPA, sensitive personal data includes personal data relating to the physical or mental health or condition of a data subject (as well as certain other categories such as political opinions, religious beliefs, and the commission of an offence).

Much of what you enter in SihatAI — blood pressure, glucose, oxygen, weight, heart rate, sleep, steps, water, meals, food-label scans, journals, medical-report files, Health Wizard answers, and AI analyses derived from them — is or includes sensitive personal data.

We process sensitive personal data only:

  • with your explicit consent; or
  • where another PDPA exception applies (for example, where processing is necessary to protect your vital interests and you cannot give consent, or where Malaysian law requires it).

You may withdraw consent through the app settings or by contacting us. Withdrawal does not make past lawful processing unlawful. If you withdraw consent for core processing, we may not be able to provide the Services and may close the account.

3 Data we collect

Depending on how you use SihatAI, we may collect:

3.1 Account and profile

  • Name, email address, password (stored in hashed form), phone number if you provide one, and profile photograph.
  • Demographics you choose to enter (for example gender, date of birth, race, blood type, height, weight, lifestyle fields such as diet, smoking, alcohol, exercise, sleep pattern).
  • Family history, travel history, existing conditions, medications or supplements, and allergies, if you enter them.
  • Authentication tokens and device records (including a push-notification token if you enable notifications).

3.2 Health and wellness logs

  • Manual or synced vitals and activity (blood pressure, glucose, oxygen, weight, heart rate, sleep, steps, calories, water).
  • From on-device health platforms (for example Android Health Connect), we store only the types we have designed the server to accept — currently steps, sleep, calories, and heart rate — not every permission a phone OS might list.
  • Meals and meal images; food-label / product images and barcode; OCR and AI-extracted nutrition and ingredient text; your saved product analyses.
  • Journal entries, mood, and feelings you log.
  • Medical report files you upload and AI extracts of those files.
  • Health Wizard questionnaires, generated plans, and related metrics.

3.3 Credits and payments

  • Wallet balances (free and paid Credits), ledger entries, and conversion from Points.
  • For purchases: package, amount, receipt number, CHIP payment status, and limited billing identifiers (name and email used at checkout). We do not store full card PAN, CVV, or bank passwords.

3.4 Technical data

  • IP address, device type, app version, approximate timestamps, crash or application logs, and security logs.
  • Website cookies or similar technology strictly as needed for the marketing site (for example session/CSRF). We do not sell advertising profiles of your health data.

3.5 Support

  • Messages you send via Contact Us or email, including any health details you choose to include.

We do not require you to provide every optional profile field. Fields you leave empty are not collected.

4 Purpose of collection (General Principle)

Under the PDPA General Principle, we process personal data for purposes that are necessary for the Services you request, including:

  • creating and securing your account;
  • storing and displaying your logs, images, and documents back to you;
  • running AI features you invoke (Health Wizard, meal/label recognition, document summary, personalised product analysis);
  • charging or granting Credits and recording the ledger;
  • sending transactional notices (for example analysis ready, payment result) and, if you enable them, push notifications;
  • preventing fraud, Credit abuse, and unauthorised access;
  • complying with Malaysian law, court orders, or regulators;
  • improving reliability and fixing defects (using aggregated or minimised logs where practicable).

We do not sell your personal data. We do not use your health records to decide employment, insurance underwriting, or creditworthiness.

5 Notice and Choice Principle

This Policy is our written notice of the purposes, classes of data, and classes of persons to whom data may be disclosed. In the app, specific features (camera, notifications, Health Connect) also prompt for OS-level permission.

You may choose not to use a feature (for example, do not upload a medical report). Some features cannot run without the related data (for example, food-label AI needs an image or text).

6 Use of artificial intelligence

When you use an AI feature, the minimum content needed for that feature (for example an image, OCR text, or a structured summary of your profile and product data) is sent to our application servers and may be sent to an AI processing provider acting for us.

  • Processing is for the feature you requested, not to train a public marketing profile of you.
  • Results may be stored on your account so you can reopen them (for example a completed product analysis) without paying Credits again, until you edit nutrition/ingredients in a way that invalidates that analysis.
  • AI output can be wrong. It is not a medical opinion. See the Terms and Safety Standards.

Where a third-party AI provider processes data for us, they are a data processor (or equivalent) and may process only on our instructions for that purpose, subject to contract and the PDPA Security Principle.

7 Payment processing

Credit package payments are processed by CHIP Collect, a licensed third-party payment gateway. You are redirected to CHIP’s checkout. CHIP handles card, bank, or e-wallet credentials under CHIP’s own policies and payment-industry rules.

We share with CHIP limited data needed to create and reconcile a purchase: your name, email, amount, and our internal references (for example receipt number). CHIP may send webhooks and status responses to our servers so we can credit your wallet only when status is paid.

This section does not apply to any money you pay a clinic, pharmacy, or another person outside SihatAI. We do not process those payments.

8 Disclosure Principle

We disclose personal data only as the PDPA allows, including:

  • to you, on your account;
  • to processors who host, send email, send push notifications, process payments, or run AI, each only as needed for their function;
  • to Apple or Google as required for store operations, not including a dump of your health diary;
  • to a person you expressly ask us to share with (for example a family feature you enable);
  • when required or authorised by law, a court, or a lawful regulator (for example the Personal Data Protection Commissioner, police under a lawful power, or Bank Negara-related payment fraud investigations involving CHIP);
  • to professional advisers under confidentiality (for example lawyers or auditors) for a legitimate purpose.

We will not sell, rent, or trade your health diary to data brokers.

9 Security Principle

We take practical steps to protect personal data from loss, misuse, unauthorised access, disclosure, alteration, or destruction, as required by the PDPA Security Principle, including:

  • TLS/SSL encryption in transit between the app or browser and our servers;
  • access controls on application and storage systems;
  • hashed passwords;
  • separation of payment card collection onto CHIP Collect;
  • server-side permission limits on Health Connect types we persist.

No internet transmission is 100% secure. You also have a duty to keep your device, PIN, and password confidential. Notify us if you believe your account was accessed without authority.

10 Retention Principle

We keep personal data only as long as necessary for the purposes in this Policy, or as required to meet legal, accounting, dispute, or security obligations.

  • Account and health logs: for the life of the account, and for a reasonable period after deletion to complete backup rotation and to handle chargebacks or abuse investigations.
  • Payment and ledger records: for the period needed under commercial and tax record-keeping practice in Malaysia.
  • Support emails: for as long as needed to resolve the request and for a limited audit trail.

When data is no longer required, we will delete or irreversibly anonymise it where practicable. Residual copies in encrypted backups may remain until those backups expire.

11 Integrity, Access, correction, and portability

Under the Data Integrity Principle, we take reasonable steps to ensure personal data we process is accurate, complete, not misleading, and kept up to date — but you control most health entries. Please correct errors in the app.

Under the Access Principle, you may request access to your personal data and request correction of inaccurate data, subject to PDPA exceptions (for example, where access would be a breach of confidentiality we owe to another person, or is subject to legal privilege).

The Personal Data Protection (Amendment) Act 2024 introduces a data portability right in the form provided by that Act and any regulations or guidelines issued under it. Where that right applies to you and to the data concerned, we will provide a copy in a commonly used machine-readable form within the time the law allows, subject to technical feasibility and the rights of others.

To exercise access, correction, withdrawal of consent, deletion (where applicable), or portability, use in-app settings where available, the Delete Account page, or email support@senangapps.com from your registered email and identify the request. We may need to verify your identity before acting.

If you are not satisfied with our response, you may complain to the Personal Data Protection Commissioner in Malaysia in the manner published by the Commissioner.

12 Storage location and transfers outside Malaysia

Application servers and databases for SihatAI are operated for us in connection with our Malaysia hosting. Object storage (for example images) may use a cloud provider whose regions can be inside or outside Malaysia.

If personal data is transferred outside Malaysia, we will do so only as the PDPA allows (including the transfer conditions under the PDPA as amended in 2024 and any whitelist or contractual safeguards then in force). AI or email processors may process data on servers outside Malaysia. We will not transfer your health diary to a third country for sale.

13 Children

The Services are directed at persons aged 18 years and above (Age of Majority Act 1971). We do not knowingly collect sensitive personal data from a child to create a standalone account. If you believe we have collected a child’s data without proper guardian authority, contact us and we will delete or restrict it as required.

14 Third-party providers, links, and what we do not cover

Processors may include hosting and object storage, CHIP Collect, email delivery, push notification providers, AI infrastructure, and app-store operators. They may process data only to perform their function for us.

If you share health information with another person outside the app (WhatsApp, email, clinic counter), that sharing is outside this Policy. We are not responsible for another user’s or a clinic’s handling of data you send them yourself.

Our website may link to third-party sites (Apple, Google, social media). Their policies apply on those sites.

15 Changes to this Policy

We may update this Policy by posting a new version on this page and changing the “Last updated” date. Material changes will be notified in the app or by email where reasonably practicable. Continued use after the effective date constitutes acknowledgement of the updated notice, except where the PDPA requires fresh consent for a new purpose.

16 Contact us

For privacy requests or complaints:

  • Email: support@senangapps.com
  • Web: Contact Us
  • Website: me-tech.com.my

Where the PDPA Amendment 2024 requires a Data Protection Officer for our class of data user, that officer’s contact details will be published here or in the app when appointed. Until then, use the contacts above.

This Policy is intended to satisfy the Notice and Choice Principle. It is not a substitute for reading the PDPA itself or taking your own legal advice.

SihatAI logo

Your everyday health companion — track vitals, scan meals, and get AI-powered insights, all in one app.

Facebook TikTok

Explore

  • Home
  • About Us
  • FAQ
  • Contact Us

Legal

  • Privacy Policy
  • Terms & Conditions
  • Safety Standards
  • Delete Account
© 2026 SenangApps. All rights reserved. Powered by SenangApps