POPIA and data protection

Protecting personal and health information is a core RubyHealth requirement.

RubyHealth handles sensitive family and health context with strict privacy controls. This page sets out the project's POPIA-aligned privacy principles for the public site and future application. We are in beta testing with a planned Q4 2026 launch.

Encrypted User Data

RubyHealth encrypts user data in the database. Health records, journal entries, wearable readings, account information, and related care context are protected using appropriate technical and organisational safeguards.

No Third-Party Sharing of Personal Details

RubyHealth does not sell or share personal user details with third parties. Personal information is only used for the service purpose agreed with the user, parent, guardian, clinician, or pilot participant.

De-identified Data Only

If data is used for reporting, research, pilot review, or product improvement, it must not be linked to personal details. Shared information is aggregated or de-identified so that a child, parent, family, or clinician cannot reasonably be identified.

Consent and Access Control

Access to personal and health information is permission-based. Parents, guardians, clinicians, and authorised users only see information they are allowed to access. Consent and account access rules are defined before live health data is collected.

Purpose Limitation

Data collected by RubyHealth supports monitoring, journaling, early-warning review, clinician summaries, and agreed care or pilot workflows. It is not reused for unrelated purposes without appropriate consent.