Privacy Policy
Last updated: 20 August 2026
1. Who we are
Amuli ("we", "the Service") is a child health diary with an AI assistant. This policy explains what personal data we process, why, and what rights you have. Contact: [email protected].
2. What data we collect
- Account data: email, name, country, language and unit preferences.
- Child health data you enter: profiles (name, date of birth, weight, height), illness episodes, symptoms, temperatures, medications, allergies, vaccinations, doctor visits, family health history, uploaded medical documents, and your conversations with the AI assistant.
- Technical data: device information, crash reports and usage analytics needed to keep the Service working.
3. Health data and your explicit consent
Health information is a special category of personal data under Article 9 GDPR. We process it only with your explicit consent, given during onboarding, and only to provide the Service: storing the diary, building your child's health context, and generating AI responses informed by that context. You can withdraw consent at any time by deleting your account.
4. Children's data
The account holder is always the parent or legal guardian. You enter data about your child as their legal representative; children do not use Amuli directly. We collect no more data than is needed for the diary to work.
5. Who processes the data
- Amazon Web Services (EU region) — encrypted storage of the database and uploaded documents, and text extraction (OCR) from documents.
- Anthropic Claude via Amazon Bedrock (EU region) — generating AI assistant responses. Only the health context needed to answer is sent; your child's legal name is never included in the AI profile context. Inputs are not used to train models.
- Twilio SendGrid (US) — sending sign-in code emails. Receives your email address only, never health data. Standard Contractual Clauses apply.
- Google Firebase Crashlytics & Analytics (US) — crash reports and anonymous usage statistics (screen views, device model). No health content is sent. Standard Contractual Clauses apply; you can turn analytics off in Settings.
These providers act as data processors under data processing agreements. We do not sell or share your data with anyone for their own purposes. Ever.
6. Where the data lives
Your diary — the database and uploaded documents — is stored encrypted at rest and in transit in data centres in the European Union. AI answers are generated inside the EU as well (Amazon Bedrock EU inference). The only data leaving the EU are sign-in emails (SendGrid) and crash/usage telemetry (Firebase), both under Standard Contractual Clauses and neither containing health records.
7. How long we keep it
Your diary is kept for as long as your account exists. When you delete your account, all personal data — the database records, uploaded documents and chat history — is permanently erased, including the files in cloud storage; backups expire within 7 days. Technical activity logs are automatically anonymised and purged on a rolling schedule.
8. Your rights
- Access, export and correct your data — email [email protected]
- Delete your account and all data — a button in the app, not a support ticket
- Withdraw consent at any time (deleting your account withdraws it)
- Complain to your data protection authority
9. What Amuli is not
Amuli is an informational assistant and diary. It is not a medical device, does not diagnose, and does not replace professional medical advice. Assistant responses aregenerated by AI and are clearly marked as such in the app.
10. Changes
We will notify you in the app about material changes to this policy before they take effect.