Privacy Statement
UZIMAPLAN processes account and health-planning information to provide its service. This statement explains the information involved, the services used, your choices, and important limits.
1. Scope and Service
This statement applies to the UZIMAPLAN web application and related account, payment, support, and transactional-email services. UZIMAPLAN is for adults aged 18 or over. It provides personal planning information, not medical diagnosis, emergency care, or treatment.
2. Information We Process
- Account and eligibility: name, email, date of birth, sex, country, Firebase email-verification status, age confirmation, and records of accepting the Privacy Statement and Terms.
- Health-planning inputs: height, weight, waist circumference, activity level, steps, walking information, exercise, water, sleep, and diet-alignment entries.
- Calculated information: BMI, BMR, TDEE, waist-to-height ratio and category, calorie and macronutrient targets, Heart Points, history, and charts.
- Food and menu activity: searches and filters where retained, generated-menu state, and foods a user has hidden or allowed. The allergy and dietary-preference editor has been withdrawn and should not be treated as an active safety control.
- Account operations: subscription plan/status/expiry, cancellation and deletion requests, support correspondence, authentication/security events, and technical diagnostic information.
- Payments and messages: M-Pesa phone number and transaction references, amount, receipt, dates and callback status; email address, recipient name, message content, delivery state and provider events for verification and receipts.
Do not submit another person's health information or payment credentials. UZIMAPLAN never needs your M-Pesa PIN.
3. Why We Use Information
- To create, verify, secure, and support an account.
- To calculate and display health-planning measures and save them across sessions and devices.
- To generate regional weekly-menu suggestions and maintain hidden-food choices.
- To process subscription payments, provide access, issue receipt messages, and maintain payment/accounting records.
- To send verification, password-reset, receipt, security, and essential service communications.
- To prevent abuse, diagnose failures, protect the service, meet legal obligations, and respond to rights or support requests.
Acceptance at registration records agreement to the service documents, but consent is not automatically the appropriate legal basis for every processing purpose. UZIMAPLAN should maintain an internal record of its lawful bases, processors, retention periods, and safeguards.
4. Health and Food Information Notice
Calculations and menus are estimates based on the information entered and available food records. They can be incomplete, inaccurate, or unsuitable for an individual. Consult a qualified clinician or registered nutrition professional before important changes, particularly if you have a medical condition, take medication, are pregnant, have an eating disorder, or need a prescribed diet.
Food composition varies by cultivar, brand, serving, preparation, fortification, recipe, and source. My Food Global is intended to use generally recognized nutrition data and public-health principles, including relevant WHO/FAO guidance where applicable. UZIMAPLAN is not certified or endorsed by WHO or FAO, and no entry should be described as guaranteed to meet a WHO/FAO standard without a recorded source and validation.
The app is not an allergen detector. It cannot reliably identify ingredients, substitutions, cross-contact, brand variation, preparation methods, or religious certification. Check labels and preparation directly and obtain professional advice where necessary.
5. Cookies, Browser Storage, and Caching
UZIMAPLAN uses browser technologies needed to operate the app. Firebase may maintain authentication/session state. UZIMAPLAN uses local storage for saved app state, a temporary fallback copy of pending registration profile details, preferences and temporary messages; session storage for temporary navigation or status data; and a service worker/cache for static files and faster loading. These stores may contain personal or health-planning information.
Signing out does not necessarily erase all browser storage or cached data. On a shared device, sign out and use browser site-data controls after confirming important information has synchronized. Clearing site data can remove unsynced work and pending registration details.
Before sign-in, UZIMAPLAN displays an informational Cookies & Storage notice with a link to this section. Selecting Got it stores a local acknowledgement so the notice does not appear repeatedly. It acknowledges the explanation only and is not consent to optional analytics or advertising.
No optional analytics or advertising integration was identified in the source reviewed for this revision. This is not a complete real-time inventory of every technology a hosting or third-party service may use. If optional analytics or marketing technology is introduced, UZIMAPLAN should disclose it, keep it disabled initially, and provide equally clear accept and reject choices where required.
6. Storage, Security, and Transfers
Verified account and app information is stored using Google Firebase/Google Cloud services. Temporary or cached copies may remain on each device. UZIMAPLAN uses access rules, verified-account checks, server-side authorization for protected operations, secret management, and other reasonable safeguards. No internet service can guarantee absolute security.
Service providers may process information outside Kenya. UZIMAPLAN must use appropriate contractual, legal, and technical safeguards for applicable cross-border processing. Users should not interpret this statement as a certification that every transfer or configuration has been independently audited.
7. Payments and Email Providers
Safaricom M-Pesa processes STK Push and payment details under its own terms and privacy practices. UZIMAPLAN receives transaction status and the information needed to activate access and prepare a receipt.
Firebase and Google Cloud support authentication, hosting, database and server processing. Brevo is used for transactional email such as the combined registration acknowledgement/verification message and subscription receipts. The support mailbox may use Microsoft 365/GoDaddy services. Queued email content and provider logs can contain names, addresses, verification links, transaction references, delivery events and diagnostic details. A queued or provider-accepted message is not a guarantee that it reached the inbox.
UZIMAPLAN does not sell personal information. Limited information may be shared with service providers for the purposes above, with professional advisers, or where lawfully required.
8. Retention and Deletion
Information is retained only as long as reasonably needed for the service, security, disputes, and legal/payment/accounting obligations. Specific retention schedules should be documented and reviewed. Browser copies remain until they are overwritten or cleared.
Registration profile details are temporarily stored in a restricted pending-registration record so they can be attached to the verified account even when verification or first sign-in occurs in another browser. Client applications cannot read this collection directly. The pending record is deleted after successful verified profile completion or during account cleanup.
If a registered user does not subscribe within 168 hours (7 days) of Firebase Authentication account creation, an automated scheduled process may delete the Authentication account and associated UZIMAPLAN Firestore documents, including a remaining pending-registration record. The process excludes administrative accounts, accounts with successful subscription or payment evidence, and accounts with pending payment requests. Because the cleanup runs periodically, deletion may occur after, rather than exactly at, the 168-hour point.
The in-app deletion process deletes the active Firestore user profile and attempts to delete the Firebase Authentication user. It creates a minimal deletion record and removes email/phone from matching payment receipts while retaining limited payment/accounting information. If Auth deletion fails, contact support.
Deletion is not necessarily immediate or comprehensive across transaction/audit logs, email queues and provider logs, backups, legally retained records, or copies on other devices. Where information must be retained, access and use should be restricted to the stated purpose. Cancellation alone does not delete an account or health data.
9. Your Rights and Choices
Subject to applicable law, you may ask to be informed about use of your information, obtain access, object or restrict processing, correct inaccurate information, or request deletion. You may cancel a subscription separately from deleting the account. Some requests can be limited by legal retention duties or the rights of others.
Use the available account controls or contact support@uzimaplan.com. We may need to verify that the request concerns your account. If you are dissatisfied, you may also contact Kenya's Office of the Data Protection Commissioner.
10. Verification and Communications
An unverified Firebase Authentication record and a restricted pending-registration record may exist after registration, but unverified accounts are not permitted normal app access. Profile creation occurs after verified sign-in, when the pending details are promoted to the user profile and removed from the pending collection. A browser-local fallback remains for resilience.
Transaction and security messages are service communications. Email delivery cannot be whitelisted by UZIMAPLAN; domain authentication and sender reputation can improve delivery, but users may still need to check spam.
11. Changes and Contact
We may revise this statement. New registrations record the current 2026-09-05 revision. Material changes may require notice or renewed acceptance where appropriate; changing this page does not by itself prove that existing users accepted a later revision.
For privacy requests, enquiries, feedback, or support, email support@uzimaplan.com. We aim to acknowledge or initially respond within one business day, although completing a request may take longer where verification, investigation, provider assistance, or legal review is required.