Legal

Privacy Policy

Last updated: August 2026

Compliance note: iSehat processes data in accordance with the Indonesian Personal Data Protection Law (UU No. 27/2022) and treats health data as sensitive personal data requiring explicit consent.

1. Introduction and Scope

iSehat respects your privacy. This Privacy Policy explains how iSehat ("we", "our", "us") collects, uses, stores, and protects personal data when you visit the public website isehat.biz.id or use the iSehat application at app.isehat.biz.id (together, the "Services").

This policy applies to all users of our Services, including users in Indonesia. iSehat is committed to complying with the Law of the Republic of Indonesia No. 27 of 2022 on Personal Data Protection ("UU PDP"), which has been fully effective since 17 October 2024, and with other applicable regulations.

2. Data Controller and Contact

The data controller for personal data processed through the Services is iSehat. Questions, requests, or complaints about your personal data — including requests to exercise your rights — can be submitted through the contact page or via email to the address published there.

We respond to verified data subject requests within the timeframes required by applicable law.

3. Legal Basis for Processing

We process personal data only on a valid legal basis under the UU PDP, including:

  • Explicit consent given by you for one or more specific purposes (for sensitive health data, consent is always explicit, free, and specific);
  • Compliance with legal obligations applicable to us;
  • Legitimate interests that do not override your fundamental rights; and
  • Contractual necessity to provide the Services you requested.

4. Personal Data We Collect

The public website isehat.biz.id does NOT collect personal health data. This website is an informational and educational site.

Data collected on the public website (only if you voluntarily submit it):

  • Contact form: name, email address, and message content;
  • Newsletter form: email address;
  • Theme preference stored locally in your browser (localStorage), not transmitted to us.

Data collected in the iSehat application (app.isehat.biz.id):

5. Sensitive Health Data and Explicit Consent

Under the UU PDP, health data is classified as specific (sensitive) personal data and receives the highest level of protection. Your health data is only processed after you give explicit, free, and specific consent.

You may withdraw consent at any time without affecting the lawfulness of processing that was based on consent before the withdrawal. Withdrawing consent may limit some features (for example, AI features), but you can continue using core recording features.

Sensitive data — including symptom details, red flag details, cycle, pregnancy, lactation, menopause status, AI memory, and doctor report details — is only accessible by you and, with your explicit permission, your family members or caregivers. Access without consent is not permitted.

6. Purposes of Data Processing

We process personal data for the following purposes:

  • Providing and operating the Services (recording, storing, and displaying your health measurements);
  • Generating rule-based interpretations and 30-day PDF reports for you to bring to your doctor;
  • Operating AI features (AI Clinical Copilot, photo reading, WhatsApp AI) within the safety limits described in the Medical Disclaimer;
  • Emergency escalation: when deterministic rules detect red flags or emergency conditions, we may show emergency guidance or notify your designated emergency contacts;
  • Account management, customer support, and responding to your requests;
  • Improving the Services through aggregated, de-identified analytics;
  • Meeting legal and audit obligations.

7. AI Features and Data Use

AI features are provided under the iSehat AI Clinical Copilot Safety Runtime. Every AI output passes through 13 safety detectors and always includes an automatic medical disclaimer. AI does not make final medical decisions for you: interpretations shown are primarily rule-based, and AI assists in explaining and reading data.

When you use AI chat or the photo-reading feature, the data you submit (for example, a photo of a device display or your chat message) is sent to a cloud AI model to generate a response. This data is processed under a valid legal basis (your consent), is not used to train third-party models, and is retained only for the duration needed and as described in the retention section.

You can disable AI features at any time in the application settings.

8. Children's Privacy

The Services are intended for users aged 18 and above. Children under 18 years old may only use the Services with consent from a parent or legal guardian. Health data of minors is processed only with guardian consent and only to the extent necessary.

9. Cookies and Tracking

The public website uses localStorage to store theme preferences (light/dark/warm). No tracking cookies are currently used.

If we add analytics or advertising pixels in the future, we will update this policy, limit data to aggregated and de-identified form, and request your consent before placing any non-essential trackers.

10. Data Retention

We retain personal data only for as long as necessary for the purposes described in this policy, and we delete or de-identify data when the retention period ends.

Specific retention rules:

  • Account and health data: retained while your account is active and for a reasonable period after account closure to comply with legal obligations;
  • AI chat and photo processing data: retained for the minimum duration needed to provide the response, maintain audit logs, and investigate safety incidents;
  • Audit logs (including AI safety flags): retained for security and compliance purposes;
  • You can request deletion of your data at any time (see section 13).

11. Data Security

We implement technical and organizational security measures to protect personal data, especially sensitive health data, from unauthorized access, disclosure, alteration, or loss:

  • Encryption in transit: all connections use TLS 1.2 or higher (HTTPS);
  • Encryption at rest: stored data is encrypted using strong encryption standards;
  • Access control: role-based access control and least-privilege principles; sensitive data requires explicit permission plus audit logging;
  • Audit trails: all access to sensitive data and every AI model run is recorded;
  • Safety runtime: the AI Clinical Copilot Safety Runtime enforces 13 safety detectors on every AI output;
  • Cross-user isolation: data belonging to one user can never be accessed by another user (verified by automated isolation tests);
  • Backups: data is backed up to ensure availability and recovery, with access restricted to authorized personnel;
  • Secret management: API keys and credentials are never stored in source code or databases — they live in secure secret storage.
  • We continuously monitor, test, and improve our security controls. However, no system is 100% risk-free; we cannot guarantee absolute security.

12. Cross-Border Data Transfer

Some services (for example, cloud AI inference and cloud infrastructure) may process data through providers located outside Indonesia. In line with UU PDP requirements, we only transfer personal data to providers that offer adequate protection, we use appropriate safeguards (such as contractual protections), and we limit transfers to what is necessary for the Services.

13. Your Rights as a Data Subject

Under the UU PDP (Articles 5–13), you have the right to:

  • Obtain clear information about how your data is processed (identity of the controller, purposes, legal basis);
  • Request access to, and a copy of, your personal data;
  • Request correction or completion of inaccurate or incomplete data (we act within 3×24 hours as required by law);
  • Request deletion or destruction of your data;
  • Withdraw your consent at any time;
  • Object to decisions based solely on automated processing, including profiling, that produce legal effects or significantly affect you (our health interpretations are rule-based and never fully automated final decisions);
  • Request restriction or postponement of processing;
  • Request portability of your data in a structured, machine-readable format;
  • Claim compensation for violations of the processing of your data, in accordance with applicable law.

To exercise these rights, submit a written request through the contact page. We verify your identity before processing the request and respond within the timeframes set by law. Some rights may be limited by applicable legal obligations.

14. Data Breach Notification

In the event of a personal data protection failure (data breach), we will, in accordance with Article 46 of the UU PDP, provide written notification no later than 3×24 hours to:

  • the affected data subjects; and
  • the competent authority (lembaga).

The notification will include: (a) the personal data that was exposed; (b) when and how it was exposed; and (c) the remediation and recovery measures we are taking. Where required by law, we will also notify the public.

15. Third-Party Processors

We use the following categories of service providers, which act as processors under our instruction:

  • Cloud infrastructure and hosting (e.g., Cloudflare Pages and Cloudflare Workers);
  • Cloud AI inference providers for AI features;
  • WhatsApp Business API provider (Meta) for WhatsApp AI features — only messages you choose to send are processed;
  • Payment providers, if and when paid plans are offered;
  • Analytics providers, limited to aggregated and de-identified data.

Each processor is bound by contractual data protection obligations and may only process data for our stated purposes.

16. Policy Changes

We may update this Privacy Policy from time to time to reflect changes in our services, technology, or legal obligations. Significant changes will be announced on this website and, where required, we will request fresh consent. The effective date at the top of this page indicates the latest revision.

17. Contact

If you have questions about this policy or wish to exercise your rights, contact us through the contact page. We respond to privacy requests within the timeframes required by applicable law.