This policy explains how Mzansi Mind (“the app”, “we”, “us”) handles personal information under South Africa's Protection of Personal Information Act, 2013 (“POPIA”) and, where applicable, other data-protection laws.
You can use Mzansi Mind without an account. Offline questions stay on your device. For an online answer, your question and any selected photo go through our secure server to Google Gemini after you give permission. Online content is processed for the reply and is not kept in our normal chat-log database. Separately, you may choose to share only future text questions and answers for up to 180 days to improve Mzansi Mind. This choice is off by default, never includes old chats or photos, and does not change Free or Pro access. You can turn it off and delete stored source copies in Settings. We do not sell personal information or use it for advertising. Mzansi Mind is for ages 12 and older; users under 18 need prior permission from a parent or legal guardian for features that process personal information online.
VaKoop (Pty) Ltd is the responsible party for Mzansi Mind. Our Information Officer can be contacted at [email protected]. Physical address: 40 Elray Street, Gauteng, 2192, South Africa. Customer support: [email protected]; +27 72 551 3728.
Your local chat history, offline content, language and most settings are stored on your device. They may remain until you clear chats, clear app storage or uninstall the app. Mzansi Mind disables Android app-data backup. On Apple devices, operating-system or user-controlled backups may contain local app data according to the device's backup settings.
After the app asks for your permission, online text and photo requests are sent over HTTPS to our server. For photos, our server removes embedded metadata and resizes the image before forwarding it to Google Gemini. Google processes the request to generate a response. Do not submit secrets, identity documents, banking details, health records or another person's private information unless it is necessary and you have the right to do so.
We do not authorise the paid Gemini API to use your content to train general AI models. Under Google's current Gemini API terms, Google may retain prompts and responses for up to 55 days only for abuse monitoring, safety, security and required legal disclosures, unless a zero-data-retention configuration applies. You can withdraw online-AI permission in Settings and continue using available offline features.
This is a separate, voluntary choice. It is off by default. After you press Allow future text chats, only later text questions and answers may be sent when your device reports Wi-Fi or Ethernet. The app does not backfill old chats, does not include photos and does not keep a second raw upload queue on your device. Free and Pro features remain available if you decline.
Automatic checks remove obvious email addresses, South African phone and ID numbers, long number sequences and labelled passwords or PINs before upload, and the server checks again. Automated redaction can miss information, so do not include secrets. A limited number of authorised VaKoop staff may read retained text for language-quality review. It is not public, sold or used for advertising, but it is not end-to-end encrypted from VaKoop because authorised review is the stated purpose.
| Data | Where/retention | Purpose and recipients |
|---|---|---|
| Local chat history and preferences | On your device until cleared/uninstalled | Conversation continuity and personalisation |
| Online question/recent context | Not retained as chat content by VaKoop; Google may retain limited abuse-monitoring logs for up to 55 days under its API terms unless zero-data retention applies | Our server and Google Gemini generate the answer |
| Optional future text questions and answers | Separate access-controlled store, up to 180 days or deletion/withdrawal sooner | Authorised VaKoop staff may review language quality and improve Mzansi Mind; not linked to the normal app identity by the improvement token |
| Hashed improvement-consent record | Up to 24 months after last activity or withdrawal | Prove and enforce the consent choice without retaining the raw token |
| Selected photo | Discarded by VaKoop after the request; Google may retain limited abuse-monitoring logs for up to 55 days under its API terms unless zero-data retention applies | Our server strips metadata, then Google Gemini analyses it |
| Redacted request metadata | Our server, up to 30 days | Reliability, abuse prevention and language-quality diagnosis |
| Linked daily usage records | Our server, up to 31 days | Plan limits and abuse prevention |
| Aggregated AI usage and cost | Our server, up to 24 months | Capacity, cost control and accounting; no chat content |
| Feedback/report contents | Our server, up to 24 months | Safety review and quality improvement |
| Account identity | While account is active; provider backups may persist after deletion | Firebase Authentication, Apple or Google sign-in |
| Purchase and entitlement | As required for the account, transaction and legal records | Apple/Google billing and RevenueCat |
| Patch request and cached patch | Technical request processed by Shorebird; patch cached on the Android device until replaced or app data is cleared | Checks for and installs tested Dart bug-fix patches; Shorebird states that its updater does not send personally identifiable information |
These providers may process information outside South Africa, including in the United States or other countries. We use provider contracts and safeguards intended to provide protection comparable to POPIA section 72 requirements. We do not permit these providers to use Mzansi Mind data for advertising on our behalf.
The periods above are maximum operational periods unless law requires longer retention. Expired verification codes are removed automatically. Optional improvement-chat source copies are automatically removed after 180 days. Turning sharing off stops future collection immediately and sends a deletion request for source copies associated with the separate token; if offline, the app remembers the deletion request and retries. Deleting source copies cannot undo learning or model changes already completed before deletion.
Account records are deleted from our active database when an authenticated deletion succeeds. We also request deletion of the matching RevenueCat customer record and its purchase history. This does not cancel an Apple or Google subscription, and Apple, Google, tax or consumer-law transaction records may still be retained where required. Firebase or infrastructure backups can take up to 180 days to expire under provider retention processes.
In the app, use Settings → Account → Delete account. This removes the Mzansi Mind account and linked server records. For an account created with Sign in with Apple, the app asks you to authenticate again and revokes the Apple authorization as part of deletion. Account deletion does not automatically cancel a store subscription, which you must manage in your Apple or Google subscription settings. If you cannot open the app, use our account-deletion page or email [email protected].
Subject to applicable law, you may ask to access, correct, delete, restrict or object to our processing of your personal information; withdraw consent; receive an available portable copy; and complain to the South African Information Regulator. Contact [email protected]. We may need to verify your identity and will respond within the period required by law.
A parent, legal guardian or other competent person who gave consent for a child may contact us to review that processing, withdraw permission or request deletion, subject to identity and authority verification.
Information Regulator: inforegulator.org.za.
Mzansi Mind is intended for people aged 12 or older. A person under 12 must not use the app. South African law generally treats a person under 18 as a child for personal-information processing. A user under 18 must therefore have prior permission from a parent, legal guardian or other competent person before using features that send personal information online, including online AI, photo questions, sign-in, feedback and optional chat improvement. Available offline features can be used without sending prompts or photos to us. We do not ask for or store a date of birth. Contact [email protected] if you believe a child used an online feature without the required permission so we can investigate and delete information where appropriate.
We use HTTPS, server-held API keys, access controls, rate limits, data minimisation, content redaction and photo-metadata removal. No system is perfectly secure. If a security compromise creates a notification duty, we will notify the Information Regulator and affected people as required by POPIA.
AI answers are suggestions, not decisions that produce legal or similarly significant effects about you. Mzansi Mind may identify VaKoop as an affiliated marketplace when relevant. The affiliation is disclosed in the app and terms.
We may update this policy when the app or law changes. We will update the effective date and provide notice in the app before a material change takes effect where required. Questions and privacy requests: [email protected].