Privacy Policy
Last Updated: July 13, 2026
At eilei, privacy is the cornerstone of our "Shared Command Center" architecture. This policy outlines how we handle data across your shared features and isolated individual environments to guarantee both synchronization and structural confidentiality.
- Data Architecture & Processing Environments
- We categorize and isolate data based on its clinical sensitivity and collaborative utility:
- Identity Data: Basic registration information (e.g., name, email address) and biometric metadata utilized exclusively for localized, secure application access.
- Command Center Data (Shared Assets): Synchronized real-time assets—including the Care Calendar, Birth Plans, and Journey Stage progress—that are bi-directionally linked to your designated partner.
- Hardened Private Data (Individual Assets): Personal wellness logs, post-birth physical recovery metrics, and mood tracking. This data is logically isolated at the database schema level and is strictly invisible to your linked partner.
- Clinical Mental Health Diagnostics (Isolated On-Device Processing): All standardized clinical screeners—explicitly including the Edinburgh Postnatal Depression Scale (EPDS) and related psychometric tools—are executed entirely within the Local On-Device Execution Environment. This sensitive clinical health data is processed locally via native device compute resources, is never transmitted across the network, and is never stored, replicated, or staged within our cloud infrastructure (including Firebase).
- Children’s Data (COPPA Compliance)
- Parental Consent: While eilei is strictly restricted to users aged 18 or older, the platform allows parents to log newborn data during the "Postpartum Flip" phase.
- Data Minimization: Any child data logged (e.g., feeding schedules, sleep tracking) is treated with the exact same architectural security as a Hardened Private Asset or a Shared Asset, as designated by the parents. We do not knowingly collect or solicit data from children under the age of 13.
- Data Synchronization & Authorized Subprocessors
- To prevent data conflict errors during critical transitions, collaborative updates utilize transactional logic:
- Atomic Packets: Modifications to Shared Assets are broken down into discrete, atomic units that either succeed completely or fail completely, ensuring both partners see a perfectly uniform state.
- Network Containment: While Atomic Data Packets utilize secure, encrypted transport layers to sync between linked devices via Firebase cloud databases, Local Clinical Diagnostics remain strictly excluded from this transport pipeline.
- Permitted Subprocessors: We engage third-party infrastructure providers solely to maintain platform operations (e.g., Firebase for data synchronization of shared assets, and Apple App Store / Google Play Store for tokenized subscription processing). These platforms act strictly as data processors under contractual confidentiality restrictions and are barred from using your data for any independent commercial purpose.
- The "Partner Link" and Consent Framework
- Establishing a link establishes a Joint Data Environment subject to the following rules:
- Bi-Directional Consent: Linking accounts grants an active, ongoing license for the linked partner to view designated Shared Assets.
- The Unlinking Protocol: If a partnership link is severed by either user, synchronization ceases instantly. The shared state transitions immediately to a "Read-Only Archive" for the non-originating party to preserve historical context without allowing ongoing tracking.
- Third-Party Transfer Prohibitions: The Company does not sell, lease, or commercially exploit user data. Health information is never shared with third-party medical providers, marketing agencies, or insurers unless explicitly initiated by the user via a manual data export action.
- User Rights & Data Portability
- Regardless of geography, eilei grants all users comprehensive control over their information:
- Right to Access/Portability: You have the unilateral right to request a complete export of your Private Vault and historical account records in a structured, machine-readable format.
- Right to Rectification: You can modify or update your core profile information directly through the application architecture at any time.
- Lifecycle, Retention, and Data Deletion
- Data persists continuously across the application's developmental phases (the "Postpartum Flip"):
- Retention Boundaries: Data is maintained only as long as necessary to fulfill active subscription states and core operational Journey Stages.
- Hard Purge Deletion: Upon a formal account deletion request, the Company initiates an immediate, irreversible "Hard Purge" of your cloud-hosted Private Vaults, and your local client app purges any remaining Local Diagnostic records.
- Residual Collaborative Records: To preserve the functional integrity of the platform for your partner, residual collaborative entries within the Shared Command Center (such as past calendar events manually created or updated by both users) may be maintained in a truncated, completely de-identified state only if the linked partner retains an active account.
- Security Architecture & Breach Notification Protocols
- Encryption Standards: We utilize industry-standard AES-256 encryption for data at rest and TLS 1.3 for data in transit. Our Private Vaults are logically separated at the database level to ensure that even a compromised Partner Link cannot bypass individual security parameters.
- Breach Protocol: In the highly unlikely event of a structural security compromise that impacts your personal data, eilei will notify affected users and applicable regulatory bodies within 72 hours of breach confirmation, outlining the specific vectors affected and immediate mitigation steps taken.
- Contact & Regulatory Enquiries
- For questions regarding your data privacy, the "Care Calendar" sync mechanisms, or to execute your right to delete your records, please contact our privacy compliance desk at:
- Email: support@eilei.app
© 2026 eilei. All Rights Reserved.
