Privacy Policy

How Hiya collects, uses, and protects your personal data

Effective: March 1, 2026

Contents

  1. Who We Are
  2. Data We Collect
  3. How We Use Your Data
  4. Health & Cycle Data
  5. HealthKit Data
  6. Legal Basis for Processing
  7. Data Sharing & Third Parties
  8. Data Storage & Security
  9. Data Retention & Deletion
  10. Your Rights
  11. Partner Sharing Feature
  12. Children's Privacy
  13. Data Breach Notification
  14. Changes to This Policy
  15. Contact Us

1. Who We Are

Hiya (هِيَ) ("Hiya," "we," "us," or "our") is a women's wellness platform operated in the State of Kuwait. Hiya provides cycle tracking, wellness insights, and a marketplace connecting users with local wellness service providers.

Our registered business details will be updated here upon completion of Commercial Registration (CR) with the Kuwait Ministry of Commerce and Industry (MOCI). Until then, this policy governs all data handling within the Hiya mobile application and the website hiyakw.com.

Data Controller: Hiya (هِيَ)
Contact Email: privacy@hiyakw.com
Website: https://hiyakw.com

2. Data We Collect

We collect the following categories of personal data:

CategorySpecific DataWhen Collected
Account InformationName, email address, profile photo (optional)Registration via email, Google, or Apple Sign-In
Health & Cycle DataPeriod dates, flow levels, symptoms, moods, basal body temperature, cycle lengthWhen you log entries in the cycle tracker
Onboarding Health DataAge range, cycle regularity, health conditions (e.g., PCOS), wellness goalsDuring initial onboarding questionnaire
HealthKit DataSleep duration, step count (read-only from Apple Health)When you grant HealthKit permissions
Booking DataServices booked, provider details, dates, times, booking statusWhen you book wellness services
Payment DataTransaction IDs, amounts, payment status (card details are never stored by Hiya)When you make a payment
Device & Technical DataDevice model, OS version, app version, crash logs, anonymous usage analyticsAutomatically when using the app
Communication DataMessages between you and wellness providers, support emailsWhen you communicate through the app

3. How We Use Your Data

4. Health & Cycle Data

We recognize that menstrual cycle data, fertility parameters, and symptom logs are highly sensitive personal health information. We treat this data with the highest level of care:

Demo Mode: During our TestFlight beta testing phase, the app operates in demo mode. Demo bookings are clearly marked and no real payments are processed. All beta data handling follows the same privacy protections described in this policy.

5. HealthKit Data

If you choose to connect Apple HealthKit, we access sleep duration and step count in read-only mode. Hiya never writes data to HealthKit.

Critical: HealthKit data stays entirely on your device. It is never uploaded to our servers, never stored in our database, and never shared with any third party. HealthKit data is used exclusively on-device to enhance the accuracy of your cycle predictions and personalized insights.

6. Legal Basis for Processing

Legal BasisApplies To
Your Explicit ConsentHealth data collection, cycle tracking, HealthKit access, marketing communications, partner sharing
Contractual NecessityAccount creation, booking services, processing payments, provider communication
Legitimate InterestError monitoring, fraud prevention, service improvement (anonymized data only)
Legal ObligationCompliance with Kuwait regulations, responding to lawful government requests

You may withdraw your consent at any time. Withdrawing consent does not affect the lawfulness of processing that occurred before the withdrawal.

7. Data Sharing & Third Parties

Service ProviderPurposeData Shared
Google FirebaseAuthentication, database, storage, push notificationsAccount data, encrypted health data, bookings
SentryError tracking and crash reportingDevice info, error logs (no personal health data)
Tap PaymentsPayment processing (KNET, Visa, Apple Pay)Transaction amounts, payment tokens (Hiya never stores card numbers)
Wellness ProvidersFulfilling your bookingsName, booking details, messages. Never health or cycle data.
Apple / GoogleSign-in authenticationAuthentication tokens only

We do not sell, rent, or trade your personal data to any third party. We do not share your health or cycle data with wellness providers, advertisers, or any other party without your explicit, specific consent.

8. Data Storage & Security

Data Residency: Our infrastructure currently uses Google Firebase. As Google Cloud expands its Kuwait region, we intend to migrate sensitive health data to Kuwait-based servers to align with evolving data sovereignty requirements. We will update this policy when any data residency changes occur.

9. Data Retention & Deletion

Data TypeRetention Period
Account informationUntil you delete your account
Health & cycle dataUntil you delete the data or your account
Booking history12 months after service completion, then anonymized
Payment recordsAs required by Kuwait financial regulations (typically 5 years)
Error logs90 days
Communication records12 months after last message, then deleted

When you delete your account, all your personal data — including health and cycle data — is permanently destroyed from our systems within 30 days.

10. Your Rights

To exercise any right, email privacy@hiyakw.com or use the in-app data management tools. We will respond within 30 days.

11. Partner Sharing Feature

12. Children's Privacy

Hiya is intended for users aged 18 and older. We do not knowingly collect personal data from anyone under 18 years of age. If we learn that we have collected data from a minor, we will delete that data immediately. Contact us at privacy@hiyakw.com.

13. Data Breach Notification

14. Changes to This Policy

15. Contact Us

Email: privacy@hiyakw.com
General Support: support@hiyakw.com
Website: https://hiyakw.com

We aim to respond to all privacy inquiries within 30 days.