UZIMAPLAN Privacy Statement 2026

Privacy Statement

Last revised: 5 September 2026

UZIMAPLAN processes account and health-planning information to provide its service. This statement explains the information involved, the services used, your choices, and important limits.

1. Scope and Service

This statement applies to the UZIMAPLAN web application and related account, payment, support, and transactional-email services. UZIMAPLAN is for adults aged 18 or over. It provides personal planning information, not medical diagnosis, emergency care, or treatment.

2. Information We Process

Do not submit another person's health information or payment credentials. UZIMAPLAN never needs your M-Pesa PIN.

3. Why We Use Information

Acceptance at registration records agreement to the service documents, but consent is not automatically the appropriate legal basis for every processing purpose. UZIMAPLAN should maintain an internal record of its lawful bases, processors, retention periods, and safeguards.

4. Health and Food Information Notice

Calculations and menus are estimates based on the information entered and available food records. They can be incomplete, inaccurate, or unsuitable for an individual. Consult a qualified clinician or registered nutrition professional before important changes, particularly if you have a medical condition, take medication, are pregnant, have an eating disorder, or need a prescribed diet.

Food composition varies by cultivar, brand, serving, preparation, fortification, recipe, and source. My Food Global is intended to use generally recognized nutrition data and public-health principles, including relevant WHO/FAO guidance where applicable. UZIMAPLAN is not certified or endorsed by WHO or FAO, and no entry should be described as guaranteed to meet a WHO/FAO standard without a recorded source and validation.

The app is not an allergen detector. It cannot reliably identify ingredients, substitutions, cross-contact, brand variation, preparation methods, or religious certification. Check labels and preparation directly and obtain professional advice where necessary.

5. Cookies, Browser Storage, and Caching

UZIMAPLAN uses browser technologies needed to operate the app. Firebase may maintain authentication/session state. UZIMAPLAN uses local storage for saved app state, a temporary fallback copy of pending registration profile details, preferences and temporary messages; session storage for temporary navigation or status data; and a service worker/cache for static files and faster loading. These stores may contain personal or health-planning information.

Signing out does not necessarily erase all browser storage or cached data. On a shared device, sign out and use browser site-data controls after confirming important information has synchronized. Clearing site data can remove unsynced work and pending registration details.

Before sign-in, UZIMAPLAN displays an informational Cookies & Storage notice with a link to this section. Selecting Got it stores a local acknowledgement so the notice does not appear repeatedly. It acknowledges the explanation only and is not consent to optional analytics or advertising.

No optional analytics or advertising integration was identified in the source reviewed for this revision. This is not a complete real-time inventory of every technology a hosting or third-party service may use. If optional analytics or marketing technology is introduced, UZIMAPLAN should disclose it, keep it disabled initially, and provide equally clear accept and reject choices where required.

6. Storage, Security, and Transfers

Verified account and app information is stored using Google Firebase/Google Cloud services. Temporary or cached copies may remain on each device. UZIMAPLAN uses access rules, verified-account checks, server-side authorization for protected operations, secret management, and other reasonable safeguards. No internet service can guarantee absolute security.

Service providers may process information outside Kenya. UZIMAPLAN must use appropriate contractual, legal, and technical safeguards for applicable cross-border processing. Users should not interpret this statement as a certification that every transfer or configuration has been independently audited.

7. Payments and Email Providers

Safaricom M-Pesa processes STK Push and payment details under its own terms and privacy practices. UZIMAPLAN receives transaction status and the information needed to activate access and prepare a receipt.

Firebase and Google Cloud support authentication, hosting, database and server processing. Brevo is used for transactional email such as the combined registration acknowledgement/verification message and subscription receipts. The support mailbox may use Microsoft 365/GoDaddy services. Queued email content and provider logs can contain names, addresses, verification links, transaction references, delivery events and diagnostic details. A queued or provider-accepted message is not a guarantee that it reached the inbox.

UZIMAPLAN does not sell personal information. Limited information may be shared with service providers for the purposes above, with professional advisers, or where lawfully required.

8. Retention and Deletion

Information is retained only as long as reasonably needed for the service, security, disputes, and legal/payment/accounting obligations. Specific retention schedules should be documented and reviewed. Browser copies remain until they are overwritten or cleared.

Registration profile details are temporarily stored in a restricted pending-registration record so they can be attached to the verified account even when verification or first sign-in occurs in another browser. Client applications cannot read this collection directly. The pending record is deleted after successful verified profile completion or during account cleanup.

If a registered user does not subscribe within 168 hours (7 days) of Firebase Authentication account creation, an automated scheduled process may delete the Authentication account and associated UZIMAPLAN Firestore documents, including a remaining pending-registration record. The process excludes administrative accounts, accounts with successful subscription or payment evidence, and accounts with pending payment requests. Because the cleanup runs periodically, deletion may occur after, rather than exactly at, the 168-hour point.

The in-app deletion process deletes the active Firestore user profile and attempts to delete the Firebase Authentication user. It creates a minimal deletion record and removes email/phone from matching payment receipts while retaining limited payment/accounting information. If Auth deletion fails, contact support.

Deletion is not necessarily immediate or comprehensive across transaction/audit logs, email queues and provider logs, backups, legally retained records, or copies on other devices. Where information must be retained, access and use should be restricted to the stated purpose. Cancellation alone does not delete an account or health data.

9. Your Rights and Choices

Subject to applicable law, you may ask to be informed about use of your information, obtain access, object or restrict processing, correct inaccurate information, or request deletion. You may cancel a subscription separately from deleting the account. Some requests can be limited by legal retention duties or the rights of others.

Use the available account controls or contact support@uzimaplan.com. We may need to verify that the request concerns your account. If you are dissatisfied, you may also contact Kenya's Office of the Data Protection Commissioner.

10. Verification and Communications

An unverified Firebase Authentication record and a restricted pending-registration record may exist after registration, but unverified accounts are not permitted normal app access. Profile creation occurs after verified sign-in, when the pending details are promoted to the user profile and removed from the pending collection. A browser-local fallback remains for resilience.

Transaction and security messages are service communications. Email delivery cannot be whitelisted by UZIMAPLAN; domain authentication and sender reputation can improve delivery, but users may still need to check spam.

11. Changes and Contact

We may revise this statement. New registrations record the current 2026-09-05 revision. Material changes may require notice or renewed acceptance where appropriate; changing this page does not by itself prove that existing users accepted a later revision.

For privacy requests, enquiries, feedback, or support, email support@uzimaplan.com. We aim to acknowledge or initially respond within one business day, although completing a request may take longer where verification, investigation, provider assistance, or legal review is required.

Version: UZIMAPLAN Privacy Statement 2026, revision 2026-09-05.

Terms and Conditions | Back to UZIMAPLAN