# Privacy Policy for JagaJiran App


**Effective date:** 20 June 2026

**Last updated:** 20 June 2026


---


## 1. Introduction


JagaJiran ("**JagaJiran**", "the App", "we", "us", or "our") is a community health

management platform that helps community volunteers and coordinators support the

health and wellbeing of community members in Malaysia. The App connects two types

of users:


- **Community Health Navigators (CHN)** — volunteer field workers who identify

 community members in need, register them, and carry out supportive visits.

- **Case Management Team (CMT)** — coordinators and supervisors who review,

 approve, assign, and oversee cases.


This Privacy Policy explains what personal data we collect, why we collect it, how

we use and protect it, who we share it with, how long we keep it, and the choices

and rights you have. It applies to your use of the JagaJiran mobile application on

Android and iOS.


We are committed to handling personal data in accordance with the **Malaysian

Personal Data Protection Act 2010 (PDPA)** and applicable data-protection

principles. Where users are located outside Malaysia, we apply equivalent

safeguards.


**Data Controller:** **Doctors on Ground (DnG)**,

**PERTUBUHAN PERKHIDMATAN PERUBATAN UNTUK KOMUNITI (DOCTORS ON GROUND),

24 Jalan Ungu U9/28C ,

Sunway Kayangan, Shah Alam - 40150, Malaysia.**

For any privacy question or request, contact us at **leadership@jagajiran.com**.


By creating an account or using JagaJiran, you acknowledge that you have read and

understood this Privacy Policy.


---


## 2. Who this policy covers (two kinds of people)


JagaJiran processes personal data about **two distinct groups**, and it is

important to understand the difference:


1. **App users (volunteers and coordinators)** — the CHN and CMT individuals who

  register for and sign in to the App. You provide your own data directly.


2. **Community members ("Jiran" / beneficiaries / case subjects)** — individuals

  in the community whose information is **recorded by a volunteer** so that they

  can be supported. These people may not use the App themselves. Volunteers act

  as our authorised representatives when recording this data and **must obtain

  that person's consent** before entering their details (see Section 6).


If you are a community member and a volunteer has recorded your information, you

have the same rights described in Section 11, and you may contact us at

**leadership@jagajiran.com** to exercise them.


---


## 3. Information we collect


We collect only the information needed to operate the App and deliver community

health support. We do **not** sell personal data, and we do **not** use it for

advertising or cross-app tracking.


### 3.1 Information you provide as an app user (CHN / CMT)


When you register and use your account, we collect:


- **Identity data** — full name, role (CHN or CMT), and a unique account

 identifier (Firebase User ID).

- **Contact data** — mobile phone number (used to sign you in via one-time SMS

 passcode/OTP) and, where applicable, email address.

- **Demographic data** — date of birth / age (used to confirm you meet the

 minimum age and for account integrity).

- **Profile data** — occupation, organisation/affiliation, home or service

 address or area, and state/region.

- **Emergency contact data** — the name and contact number of a person you

 nominate as your emergency contact. You confirm at the point of entry that you

 have that person's consent to provide their details.


Depending on your role and what you choose to provide, your profile may also include your salutation, date of birth, gender, nationality and country/state of residence, occupation and organisation, skills, languages, certifications and registration number, a profile photo, emergency contact details (name, relationship and phone number), and health-related attributes such as blood group and Rhesus (Rh) factor. Providing these additional details is optional and at your discretion.


### 3.2 Information recorded about community members ("Jiran" registry)


When you act as a volunteer (CHN) or coordinator (CMT), you may record information about the community members ("Jiran") you assist. You provide this information on the community member's behalf, which may include their:



Because this data concerns another individual, you may only record it if you have that person's explicit consent or another valid, lawful basis to do so (see Section 6, "Consent for recording another person's data").


Sensitive personal data. Some of the information above is sensitive — in particular national identity card (IC) numbers, ethnicity, and health- or medical-related case information. We handle this data with additional care, use it solely to deliver and coordinate community support, and never use it for advertising, marketing, profiling, or sale to any third party.


### 3.3 Content you upload


- **Case attachments** — images and PDF documents that a volunteer attaches to a

 case (for example, a supporting document or photo relevant to the case).

 Limits: up to 2 files per case, 5 MB each, in JPEG, PNG, or PDF format only.

- **Field notes / messages** — text notes exchanged between volunteers and

 coordinators about a case.

- **Program/event images** — images uploaded by coordinators for community

 programs.


### 3.4 Information collected automatically


- **Diagnostic and crash data** — when the App crashes or encounters an error, we

 collect crash logs, error reports, and basic technical information (device

 model, operating-system version, and app version) through **Firebase

 Crashlytics** to keep the App stable. Crash reporting is **disabled in test

 builds**.

- **App-integrity signals** — to protect against fraud and abuse, the App uses

 **Google Play Integrity** (Android) and **Apple App Attest / App Check** (iOS)

 to confirm that requests come from a genuine, untampered copy of the App.


### 3.5 Location


JagaJiran is designed to operate **without continuous background location

tracking**. We do **not** track your device's location in the background. Any

address or state/region information is what you (or a volunteer) **type in**, not

GPS tracking. The App collects no device location; tapping a location opens an 

external maps app with a typed address.If a future feature uses device location, 

we will request your permission first and update this policy.


### 3.6 What we do NOT collect


- We do **not** collect your contacts, photos library (beyond files you

 explicitly choose to attach), calendar, microphone, or browsing history.

- We do **not** use third-party advertising or analytics-for-advertising SDKs.

- We do **not** track you across other apps or websites.


---


## 4. How we use your information


We use personal data for the following purposes:


| Purpose | Examples |

|---|---|

| **Provide the service** | Create and authenticate your account; verify your phone number via OTP; route you to the correct CHN or CMT experience. |

| **Coordinate community health support** | Register community members, create and assign cases, schedule and track visits, and record case progress. |

| **Communication within the App** | Field notes and case messages between volunteers and coordinators. |

| **Notifications** | Send in-app and push notifications about case assignments, reminders, and updates (only after you grant notification permission). |

| **Safety & integrity** | Verify app authenticity, prevent fraud and abuse, enforce minimum age, and protect accounts. |

| **Reliability & improvement** | Diagnose crashes and errors and improve performance and stability. |

| **Legal & compliance** | Comply with applicable law and respond to lawful requests. |


**Legal bases (PDPA / general principles):** we process personal data on the basis

of your **consent**, the **performance of the service** you request, our

**legitimate interest** in operating a safe and reliable platform, and **legal

compliance**. For sensitive (including health) data, we rely on **explicit

consent** obtained at the point of collection.


---


## 5. Push notifications


If you enable notifications, we send messages about case activity, reminders, and

program updates. We ask for notification permission **in context** (not silently

at first launch). You can turn notifications off at any time in your device

settings or within the App. As this is still in pipeline for future enhancement

feature, it might not be available in the initial version of the app, but will be

available soon.


---


## 6. Consent for recording another person's data


Because volunteers record information about community members and emergency/point-

of-contact persons, **consent is central** to how JagaJiran works:


- Volunteers are instructed, and must confirm in the App, that they have obtained

 the **informed consent** of any community member (and any nominated contact

 person) **before** entering that person's personal data.

- Community members may decline to provide data or ask that their data be removed

 at any time.

- We display a data-protection notice at the relevant input steps reminding

 volunteers of this obligation.


If you believe your data was recorded without your consent, contact us at

**leadership@jagajiran.com** and we will investigate and, where appropriate, delete

it.


---


## 7. Children's privacy


JagaJiran is **not intended for children under 13 years of age**, and the App

enforces a **minimum registration age of 13**. We do not knowingly create accounts

for, or knowingly collect personal data directly from, anyone under 13. If we learn

that we have collected an account holder's data from a child under 13 without

appropriate consent, we will delete it. (Note: a community member recorded in a

case may be of any age where lawful and consented to by a parent/guardian, because

that data is provided by an adult volunteer with consent — it is not the child

operating the App.)


---


## 8. How we share information


We share personal data **only** as described here. **We do not sell personal

data.**


- **Within the platform (role-based access):** information is shared between the

 volunteer who created a case and the coordinators responsible for reviewing and

 managing it, strictly to deliver community health support. Access is limited by

 role (CHN / CMT) and by the case relationship.

- **Service providers (sub-processors):** we use trusted infrastructure providers

 to run the App. The principal provider is **Google Firebase / Google Cloud

 Platform**, which provides:

 - *Firebase Authentication* — phone-number sign-in (OTP),

 - *Cloud Firestore* — secure database storage,

 - *Cloud Storage for Firebase* — file/attachment storage,

 - *Firebase Crashlytics* — crash and error reporting,

 - *Firebase App Check / Play Integrity* — app-integrity verification,

 - *Firebase Cloud Functions* — secure server-side processing.


 Google processes this data on our behalf under its terms and security

 commitments. See Google's Privacy Policy at

 https://policies.google.com/privacy and Firebase data handling at

 https://firebase.google.com/support/privacy.

- **Legal requirements:** we may disclose data if required by law, regulation,

 legal process, or a lawful governmental request, or to protect the rights,

 safety, and security of users and the public.

- **Business transfers:** if our organisation is involved in a merger, acquisition,

 or transfer, personal data may be transferred as part of that transaction, and

 we will notify you and ensure it remains protected under this policy.


---


## 9. Data storage, location, and security


- **Where data is stored.** Personal data is stored on Google Cloud / Firebase

 infrastructure. Our backend functions are deployed in the **Asia-Southeast

 (Singapore) region** (`asia-southeast1`), and data may be processed in Google

 data centres consistent with Firebase's regional configuration.

- **International transfer.** Where data is processed outside Malaysia, we ensure

 it is protected by appropriate safeguards and by Google's contractual and

 security commitments, consistent with the PDPA.

- **Security measures we apply:**

 - Encryption **in transit** (HTTPS/TLS enforced; cleartext traffic is blocked).

 - Encryption **at rest** for stored data on our cloud provider.

 - **On-device protection** of sensitive credentials using Android

   EncryptedSharedPreferences (Keystore-backed) and the iOS Keychain; the

   in-app screen is protected against screenshots/recents previews.

 - **Access controls** — database and storage security rules restrict reads and

   writes by authenticated role, and server-side validation guards uploads.

 - **App integrity** — Play Integrity / App Attest reduce abuse from tampered or

   automated clients.

 - **Single active session** — signing in on a new device signs you out of the

   previous one to protect your account.


No method of transmission or storage is 100% secure, but we work to protect your

data using industry-standard measures and to promptly address any vulnerability we

become aware of.


---


## 10. Data retention


- **Account data** is retained for as long as your account is active.

- **Case and registry data** is retained for as long as needed to provide

 community health support and to meet legal, audit, and record-keeping

 obligations, after which it is deleted or anonymised.

- **Crash/diagnostic data** is retained on a rolling basis by our crash-reporting

 provider, typically up to 90 days.

- **Uploaded attachments** are retained for the life of the associated case;

 draft attachments removed before submission are deleted. When you delete your

 account, your authored content is deleted or **anonymised** (personal

 identifiers are removed) so that community case records remain coherent without

 identifying you.


When data is no longer required, we delete or irreversibly anonymise it.


---


## 11. Your rights and choices


Subject to the PDPA and applicable law, you have the right to:


- **Access** the personal data we hold about you.

- **Correct** inaccurate or incomplete data.

- **Withdraw consent** to processing (this may limit your ability to use the App).

- **Request deletion** of your personal data.

- **Limit or object** to certain processing.

- **Lodge a complaint** with the relevant data-protection authority (in Malaysia,

 the Personal Data Protection Department, JPDP).


To exercise any of these rights, contact us at **leadership@jagajiran.com**. We will

respond within the timeframe required by applicable law. We may need to verify your

identity before acting on a request.


---


## 12. Account and data deletion


You can delete your account and associated personal data at any time:


- **In the App (Account Data):** open the navigation drawer → *Settings / Profile* **Delete

 Account**, and confirm. This removes your account and deletes or anonymises your

 associated data. 

- **In the App (Case Data):** open the cases tab*Submitted Cases* **DRAFTS***tap DELETE*

, and confirm. This removes your case data and deletes your

created data. CHN users have full control over their active case drafts. If you wish to delete a draft before submitting it to CMT, navigate to the Drafts folder / My Cases inside the app, select the specific draft you want to remove, and tap Delete. This instantly and permanently wipes the local and backend database records for that draft without affecting your user account.

- **By request:** if you cannot access the App, request deletion via

 **leadership@jagajiran.com** and we will process it.


When you delete your account, we delete your account profile and authored content

or anonymise records where deletion would break the integrity of shared community

case data (your name and identifiers are removed). Some information may be retained

where required by law. Crash logs already collected expire on the rolling schedule

in Section 10.


---


## 13. Permissions the App uses


JagaJiran requests only the permissions it needs:


- **Internet / network access** — to sync data with our secure backend.

- **Notifications** (Android 13+ / iOS) — to deliver case reminders and updates

 (optional; requested in context).

- **Files / documents** — to let you attach an image or PDF you explicitly select

 through the system file picker. We access only the files you choose.


We do not access your device's location (neither while using the app nor in the background), and we do not request access to your contacts, microphone, or full photo library. When you tap a case's location, the App opens your device's maps application using the address that was typed in, the App itself never reads your GPS position.


---


## 14. Third-party services


JagaJiran relies on Google Firebase / Google Cloud Platform as described in

Section 8. These services have their own privacy practices:


- Google Privacy Policy — https://policies.google.com/privacy

- Firebase Privacy and Security — https://firebase.google.com/support/privacy


We do not integrate advertising networks or social-media tracking SDKs.


---


## 15. Changes to this Privacy Policy


We may update this Privacy Policy from time to time to reflect changes in our

practices, technology, or legal requirements. When we make material changes, we

will update the "Last updated" date above and, where appropriate, notify you

in-app. Your continued use of the App after an update constitutes acceptance of the

revised policy.


---


## 16. Contact us


If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact:


Doctors on Ground (DnG)

Attn: Data Protection & Privacy Team Malaysia

Privacy & Support: leadership@jagajiran.com


---


## 17. Governing law


This Privacy Policy and our handling of personal data are governed by the laws of Malaysia, including the Personal Data Protection Act 2010 (PDPA). Where you record information about another individual through the App, you are responsible for meeting the applicable data-protection obligations when collecting that information and sharing it with us.


---


*JagaJiran — protecting communities, respecting privacy.*