Privacy
Privacy notice.
How Zeevio LLCcollects, uses, and protects your personal information — including your health data — when you use Mapigo Health on the web or as a mobile app.
Last updated 22 June 2026Summary
Mapigo Health is a personal blood-pressure tracker. To provide it, we store the readings and related logs you choose to record, the account details needed to sign you in, and a small amount of technical data needed to run the service. We treat your readings and other health entries as sensitive data and process them only to give you the app.
We do notsell your data, show you advertising, load third-party analytics or tracking scripts, or send your health data to any third-party AI model. You can export or delete everything at any time. The strongest statement the app ever makes about a reading is “above the target you set” — it does not diagnose. See the medical disclaimer.
Who we are
Mapigo Health is operated by Zeevio LLC, a company formed in Wyoming, USA (registration 2025-001807286). For the purposes of the EU and UK General Data Protection Regulation (GDPR), the South African Protection of Personal Information Act (POPIA), and the California Consumer Privacy Act as amended (CCPA/CPRA), Zeevio LLC is the controller of your personal information.
You can reach us about privacy at hello@mapigo.health. Full contact and registered-agent details are at the foot of this page.
What this notice covers
This notice applies to:
- the marketing website at
mapigo.health; - the web app (installable PWA) at
app.mapigo.health; - the mobile app for iOS and Android; and
- the doctor-share pages a clinician opens with a code you generate.
Where a practice differs between the website, the web app, and the mobile app, we say so. For a plain-English engineering companion to this notice, see How we handle data.
Data we collect
We collect only what the app needs to work:
- Account.Your email address, an optional display name, and a one-way hash of your password. We never store your plaintext password. If you choose “Continue with Google,” we receive your Google account identifier, email, name, and profile image instead of a password.
- Blood-pressure readings. Systolic, diastolic, and pulse values, whether a reading was single or doubled, the date and time, and any note you add.
- Monitor photos.If you choose to attach one, a photo of your blood-pressure monitor’s display. This is optional; the app works fully without it, and we only store photos after you give explicit, separate consent. When you attach a photo, it is uploaded to private cloud blob storage (a non-public file, not a guessable link) so it stays with the reading across your devices and can be included in a doctor-share you generate. Your monitor photos are visible only to you and to a clinician you choose to share with — they are never shared with anyone else and never sent to a third-party AI model. You can withdraw photo consent at any time in Settings; doing so permanently deletes every monitor photo we hold for you.
- Medications. Medication names, doses, schedules, start dates, notes, and the taken/skipped adherence entries you log.
- Triggers, activity, and mood. The everyday items you choose to log next to your readings (for example coffee, alcohol, exercise, mood), with quantities, intensities, timestamps, and optional notes.
- Settings. Your personal targets, concern thresholds, reminder schedule, and app preferences.
- Doctor shares. The active share codes you generate, the date range each covers, and an access log of when a code was redeemed or viewed. The access log records a masked IP address and a summarised device description. The plaintext code is shown to you once and is never written to our database.
- Technical and session data. Sign-in session records, the time and device type of each sign-in, and standard request metadata (IP address, browser/user-agent, requested URLs) that any web service receives.
- Push token (mobile only). If you enable reminders in the mobile app, a Firebase Cloud Messaging device token so we can deliver your notifications. The installed web app schedules reminders locally and does not use this.
- Sign-up attribution (website only). If you arrive from a campaign link, the referring URL, landing path, and any campaign (UTM) parameters, so we understand where sign-ups come from. This is not health data and is never linked to your readings for advertising.
Health data
Your readings, monitor photos, medications, adherence logs, mood, and activity entries are special-category / sensitive personal data concerning health. We process them only to provide the tracking features you ask for, only for as long as your account exists or until you delete them, and we never use them for advertising, profiling, or sale.
Where the law requires a specific condition to process health data (for example GDPR Article 9 or POPIA section 27), we rely on your explicit consent, given by creating an account and entering this data, and on the processing being necessary to deliver the service you requested. You can withdraw that consent at any time by deleting the data or your account (see Your rights).
How we use it
- To create and secure your account and sign you in.
- To store your readings and logs, compute simple arithmetic summaries (average, minimum, maximum, count), and chart your trend over time.
- To compare a reading to the personal targets youset, and to flag when a reading is above your own concern threshold — a numeric comparison, not a diagnosis.
- To generate doctor-share codes and render the read-only summary a clinician sees, scoped to the date range you choose.
- To send the reminders you configure, and transactional emails such as email verification and password reset.
- To keep the service secure, debug problems, prevent abuse (including rate-limiting share-code attempts), and meet legal obligations.
We do not use your data to build advertising profiles, and we do not make automated decisions that produce legal or similarly significant effects about you.
Legal bases (GDPR / POPIA)
- Performance of a contract. Most processing is necessary to provide the service you signed up for (storing and displaying your readings, running your account).
- Explicit consent. For the sensitive health data described above, and for optional reminders and optional Google sign-in. You can withdraw consent at any time.
- Legitimate interests. For keeping the service secure, preventing abuse, and understanding (in aggregate) where sign-ups come from, balanced against your rights.
- Legal obligation. Where we must retain or disclose limited records to comply with applicable law.
International transfers
Zeevio LLCis based in the United States, and some of our service providers operate in the United States and the European Union. Where your data is transferred across borders, we rely on appropriate safeguards — such as the European Commission’s Standard Contractual Clauses and equivalent mechanisms under UK and South African law — to protect it. The region of each processor category is listed on the service providers page.
How long we keep it
We keep your account and the data in it for as long as your account is active. When you delete an entry, it is removed. When you delete your account, we permanently erase every row we hold for you — readings, photos, medications, triggers, activity, mood, settings, shares, and the share access log — and we delete the stored photo files. We retain only a one-way hashed audit record of the deletion that cannot be used to re-identify you, and any limited records we are legally required to keep. Backups containing your data are rotated on a regular cycle and then overwritten.
Security
- All traffic is served over HTTPS/TLS.
- Passwords are stored only as bcrypt hashes; session and share-code secrets are stored only as hashes, never in plain text.
- Doctor-share codes are single-use, expire automatically, grant read-only access scoped to the date range you chose, and are rate-limited against guessing.
- Access to your records is scoped to your authenticated account; IP addresses in the share access log are masked before display.
- Our database and storage providers encrypt data at rest and in transit. The technical detail is described on the How we handle data page.
No method of transmission or storage is perfectly secure, but we work to protect your data using measures appropriate to its sensitivity.
Your rights
Depending on where you live, you have some or all of the following rights: to access your data, to correct it, to delete it, to export/port it, to restrict or object to certain processing, and to withdraw consent. We do not sell personal information, so there is nothing to opt out of in that respect.
You can exercise most of these directly in the app:
- Access / export.Export your readings as CSV from History, or export everything as a ZIP from Settings → Your data — the archive includes your monitor photos as image files.
- Correct / delete entries. Edit or delete any reading, medication, or log from its screen.
- Delete your account.Settings → Your data → Delete account erases everything we hold for you.
- Withdraw consent. Turn off reminders, or delete the relevant data or your account.
If you have lost access to your account, or want to make a request in writing, email hello@mapigo.health with the subject line Data subject request. We respond within the time your law requires (typically 30 days). You also have the right to complain to your local data-protection authority — for example the Information Regulator (South Africa), a supervisory authority in the EU/EEA, or the ICO (UK).
Children
Mapigo Health is not directed to children and is not designed for users under 16. We do not knowingly collect data from children under 16. A parent or guardian tracking a child’s readings should do so under their own account. If you believe a child has created an account, contact us and we will delete it.
Changes to this notice
When this notice changes materially, we update the “last updated” date above and, for significant changes, give notice in the app or by email before they take effect. Continuing to use Mapigo Health after a change takes effect means you accept the updated notice.
Contact
Questions or requests about this notice can be sent to hello@mapigo.health.
- Operator
- Zeevio LLC (Wyoming, USA)
- Registration
- 2025-001807286
- Registered agent
- Republic Registered Agent LLC
5830 E 2nd St, Ste 7000
Casper, WY 82609 - Contact
- hello@mapigo.health
- Phone
- +1 (307) 441-8720
- Parent
- zeevio.co.zw