MZANSI MIND · LEGAL
Privacy Policy
How Mzansi Mind handles your information, the choices you control, and the providers used to deliver the service.
Effective date: 31 August 2026
This policy explains how Mzansi Mind (“the app”, “we”, “us”) handles personal information under South Africa's Protection of Personal Information Act, 2013 (“POPIA”) and, where applicable, other data-protection laws.
1. Responsible party and contact details
VaKoop (Pty) Ltd is the responsible party for Mzansi Mind. Our Information Officer can be contacted at privacy@vakoop.co.za. Physical address: 40 Elray Street, Gauteng, 2192, South Africa. Customer support: cs@vakoop.co.za; +27 72 551 3728.
2. Information we handle
2.1 Information you choose to provide
- Questions, recent conversation context and photos: sent only when you choose an online AI feature. A short recent conversation may accompany a question so the reply makes sense.
- Feedback and reports: if you report an answer or send feedback, we retain what you submit, the reported answer, language, rating and a pseudonymous user or device reference for review.
- Optional improvement chats: only if you separately press Allow, future text questions and Mzansi Mind answers, including answers created offline, may be retained so authorised VaKoop staff can review language quality and improve the service. Old chat history and photos are not included.
- Account information: if you use Apple or Google sign-in, Firebase Authentication provides us with a user ID and may provide your name and email address. Apple may provide a relay email. We never receive your social-account password.
- Optional invite codes: if you use the invite feature while signed in, we store your account's random invite code and whether another signed-in account applied it. Invite attribution does not include chat content and does not currently grant money, subscription time or other rewards.
- Preferences: your chosen language, assistant personality and optional display name. Most preferences remain on your device.
2.2 Information handled automatically
- Pseudonymous identifiers: a random code for each app installation, a separate Mzansi Mind-only device code, and, if signed in, your Firebase user ID. The install code measures installations and enforces service limits. The app-device code helps us avoid counting a normal reinstall as a new device. On Android, the app sends a one-way, app-namespaced hash derived from the operating system's app-signing-key-scoped identifier. On Apple devices, it uses a random value stored in this app's Keychain. The app-device code can change after a factory reset, device restore, Keychain reset, user-profile change or platform/security change, so it is not treated as proof of a person's identity. We do not use an advertising ID, IMEI, hardware serial or contact list.
- Separate improvement token: improvement chats use a different random token. Our server stores only a one-way hash of it; the improvement endpoint does not receive your Mzansi Mind account ID, name, email or normal app device code. Hosting security logs may still process an IP address.
- Optional welcome and first-use analytics: if you check the separate optional box during welcome, the app creates a different random installation ID for PostHog. It may send the welcome version and step reached, time on a step, chosen app language, phone platform, whether setup completed, whether the first question received an answer, the actual online/offline answer route, coarse network state and error category, and whether the later improvement-sharing prompt received a choice. It may also send simple signed-in and Pro-status booleans. It never sends question or answer words, photos, names, email addresses, Firebase IDs, the normal app device code, advertising IDs or social-account details. PostHog person profiles, automatic screen capture, heatmaps and session recording are disabled.
- Usage and diagnostic metadata: request time, selected language, model/strategy, quality flags, daily message/photo counts, token and service-cost totals. Production diagnostic chat logs contain no prompt or answer text.
- Subscription information: product, entitlement and purchase status from Apple, Google and RevenueCat. We do not receive your complete card number.
- Network and technical information: IP address, app/device information and security logs may be processed by our hosting, security, authentication and subscription providers to deliver and protect the service.
2.3 On-device information
Your local chat history, offline content, language and most settings are stored on your device. They may remain until you clear chats, clear app storage or uninstall the app. Mzansi Mind disables Android app-data backup. On Apple devices, operating-system or user-controlled backups may contain local app data according to the device's backup settings.
3. How online AI processing works
After the app asks for your permission, online text and photo requests are sent over HTTPS to our server. For photos, our server removes embedded metadata and resizes the image before forwarding it to Google Gemini. Google processes the request to generate a response. Do not submit secrets, identity documents, banking details, health records or another person's private information unless it is necessary and you have the right to do so.
We do not authorise the paid Gemini API to use your content to train general AI models. Under Google's current Gemini API terms, Google may retain prompts and responses for up to 55 days only for abuse monitoring, safety, security and required legal disclosures, unless a zero-data-retention configuration applies. You can withdraw online-AI permission in Settings and continue using available offline features.
3.1 Optional chat improvement
This is a separate, voluntary choice. It is off by default. After you press Allow future text chats, only later text questions and answers, including answers created by the offline assistant, may be sent when your device reports Wi-Fi or Ethernet. The app does not backfill old chats, does not include photos and does not keep a second raw upload queue on your device. Free and Pro features remain available if you decline.
Automatic checks remove obvious email addresses, South African phone and ID numbers, long number sequences and labelled passwords or PINs before upload, and the server checks again. Automated redaction can miss information, so do not include secrets. A limited number of authorised VaKoop staff may read retained text for language-quality review. It is not public, sold or used for advertising, but it is not end-to-end encrypted from VaKoop because authorised review is the stated purpose.
4. Data map
| Data | Where and retention | Purpose and recipients |
|---|---|---|
| Local chat history and preferences | On your device until cleared or uninstalled | Conversation continuity and personalisation |
| Online question and recent context | Not retained as chat content by VaKoop; Google may retain limited abuse-monitoring logs for up to 55 days under its API terms unless zero-data retention applies | Our server and Google Gemini generate the answer |
| Optional future text questions and answers | Separate access-controlled store, up to 180 days or deletion or withdrawal sooner | Authorised VaKoop staff may review language quality and improve Mzansi Mind; the improvement token is not linked to the normal app identity |
| Hashed improvement-consent record | Up to 24 months after last activity or withdrawal | Prove and enforce the consent choice without retaining the raw token |
| Optional welcome and first-use events plus separate random analytics ID | PostHog US Cloud, up to 12 months | Measure consented welcome-screen drop-off and whether the first question receives an answer; no question or answer words, photos, name or email |
| Selected photo | Discarded by VaKoop after the request; Google may retain limited abuse-monitoring logs for up to 55 days under its API terms unless zero-data retention applies | Our server strips metadata, then Google Gemini analyses it |
| Redacted request metadata | Our server, up to 30 days | Reliability, abuse prevention and language-quality diagnosis |
| Linked daily usage records | Our server, up to 31 days | Plan limits and abuse prevention |
| Pseudonymous install and app-device codes | Our server, up to 24 months after last activity | Enforce fair limits, protect the service, and report signed-in accounts, app devices and reinstall events separately; not used for advertising or cross-app tracking |
| Aggregated AI usage and cost | Our server, up to 24 months | Capacity, cost control and accounting; no chat content |
| Feedback and report contents | Our server, up to 24 months | Safety review and quality improvement |
| Account identity | While the account is active; provider backups may persist after deletion | Firebase Authentication, Apple or Google sign-in |
| Invite code and account-to-account attribution | While either linked account remains active, or until account deletion | Provide optional friend invitations, prevent self-use and count successful applications; no chat content |
| Purchase and entitlement | As required for the account, transaction and legal records | Apple or Google billing and RevenueCat |
| Patch request and cached patch | Technical request processed by Shorebird; patch cached on Android until replaced or app data is cleared | Checks for and installs tested Dart bug-fix patches; Shorebird states that its updater does not send personally identifiable information |
5. Service providers and international transfers
- Google Gemini API: online AI text and photo processing. Gemini API terms.
- Google Firebase Authentication: sign-in identity, authentication security and account records. Firebase privacy information.
- Apple and Google: social sign-in, app distribution, payments and store-managed transaction records.
- RevenueCat: purchase status, app user ID, product and technical information used to provide Pro access. RevenueCat privacy policy.
- PostHog US Cloud: only the optional welcome and first-use events described above, joined with a separate random analytics installation ID. We disable person profiles, automatic capture, session recording, heatmaps, event geolocation and console-log capture, and configure IP anonymisation. Ordinary HTTPS and provider-security logs may still temporarily process an IP address. PostHog privacy information.
- Shorebird (Android release only): the updater contacts Shorebird's service on launch to check for a signed Dart patch and may process ordinary network and release information such as IP address, app ID, app version and platform. Shorebird states that the updater sends no personally identifiable information. Patches are cached in the app's local cache and take effect on a later launch. Shorebird updater information.
- Cloudflare and our hosting provider: secure delivery, network logs, rate limits and abuse protection.
These providers may process information outside South Africa, including in the United States or other countries. We use provider contracts and safeguards intended to provide protection comparable to POPIA section 72 requirements. We do not permit these providers to use Mzansi Mind data for advertising on our behalf.
6. Why we process information
- Contract and requested service: to answer questions, maintain your account and provide purchased Pro access.
- Consent: to share online requests with the AI provider, process optional photos, sign you in, keep submitted feedback, retain future text chats for improvement only after a separate choice, and send privacy-minimal welcome and first-use events to PostHog only after another separate optional choice. You can withdraw these choices in Settings. For a user under 18, prior consent must come from a parent, legal guardian or other person legally competent to consent for the child where applicable law requires it.
- Legitimate interests: security, fraud and abuse prevention, service reliability, enforcing fair limits and measuring aggregate cost, balanced against your rights.
- Legal obligations: transaction, tax, consumer-protection and lawful-request records where required.
7. Retention and deletion
The periods above are maximum operational periods unless law requires longer retention. Expired verification codes are removed automatically. Optional improvement-chat source copies are automatically removed after 180 days. Turning sharing off stops future collection immediately and sends a deletion request for source copies associated with the separate token; if offline, the app remembers the deletion request and retries. Deleting source copies cannot undo learning or model changes already completed before deletion.
Turning optional welcome analytics off stops future PostHog collection and clears events that have not yet left the phone. Because uploaded events use an anonymous installation ID that is not linked to an account, name or email, earlier events normally remain until the project's 12-month deletion period. Contact privacy@vakoop.co.za if you have an analytics privacy request; we will explain what can be located and deleted without weakening another person's privacy.
Account records, including the account's invite code and invite links to or from that account, are deleted from our active database when an authenticated deletion succeeds. We also request deletion of the matching RevenueCat customer record and its purchase history. This does not cancel an Apple or Google subscription, and Apple, Google, tax or consumer-law transaction records may still be retained where required. Firebase or infrastructure backups can take up to 180 days to expire under provider retention processes.
In the app, use Settings → Account → Delete account. This removes the Mzansi Mind account and linked server records. For an account created with Sign in with Apple, the app asks you to authenticate again and revokes the Apple authorization as part of deletion. Account deletion does not automatically cancel a store subscription, which you must manage in your Apple or Google subscription settings. If you cannot open the app, use our account-deletion page or email privacy@vakoop.co.za.
8. Your rights
Subject to applicable law, you may ask to access, correct, delete, restrict or object to our processing of your personal information; withdraw consent; receive an available portable copy; and complain to the South African Information Regulator. Contact privacy@vakoop.co.za. We may need to verify your identity and will respond within the period required by law.
A parent, legal guardian or other competent person who gave consent for a child may contact us to review that processing, withdraw permission or request deletion, subject to identity and authority verification.
Information Regulator: inforegulator.org.za.
9. Age eligibility
Mzansi Mind is intended for people aged 12 or older. A person under 12 must not use the app. South African law generally treats a person under 18 as a child for personal-information processing. A user under 18 must therefore have prior permission from a parent, legal guardian or other competent person before using features that send personal information online, including online AI, photo questions, sign-in, feedback and optional chat improvement. Available offline features can be used without sending prompts or photos to us while optional improvement sharing remains off. We do not ask for or store a date of birth. Contact privacy@vakoop.co.za if you believe a child used an online feature without the required permission so we can investigate and delete information where appropriate.
10. Security and incidents
We use HTTPS, server-held API keys, access controls, rate limits, data minimisation, content redaction and photo-metadata removal. No system is perfectly secure. If a security compromise creates a notification duty, we will notify the Information Regulator and affected people as required by POPIA.
11. Automated output and VaKoop affiliation
AI answers are suggestions, not decisions that produce legal or similarly significant effects about you. Mzansi Mind may identify VaKoop as an affiliated marketplace when relevant. The affiliation is disclosed in the app and terms.
12. Changes and contact
We may update this policy when the app or law changes. We will update the effective date and provide notice in the app before a material change takes effect where required. Questions and privacy requests: privacy@vakoop.co.za.