Privacy Policy
Last updated: 24 June 2026
Summary: Chronic Wellness is a wellness-tracking app. We store the health information you choose to log in a secure, encrypted database. We never sell your data and never share it with advertisers. You can export or delete everything at any time. Your South African ID number is never stored on this app — it is used in transit only when you book a remote consultation or send a summary to a clinician.
1. Who we are (the Responsible Party)
Chronic Wellness ("the App") is owned and operated by Dolme SA (Pty) Ltd, a private company incorporated in the Republic of South Africa. For the purposes of the Protection of Personal Information Act, 2013 ("POPIA"), Dolme SA (Pty) Ltd is the Responsible Party for the personal information processed through the App.
CIPC registration number:
2017/073721/07
Registered address:
683 Block V, Soshanguve, Pretoria 0152, South Africa
Information Officer:
Tebogo Mazibuko (
tebogo.rallele@gmail.com) — required by POPIA Section 55.
Privacy enquiries:
privacy@dolme.co.za
2. Eligibility and children
You must be at least 18 years old to create your own account. Parents or legal guardians may create dependent profiles for minors in their care. We do not knowingly collect personal information directly from children under 18 without parental or guardian consent expressed through a primary account.
3. Health information is "Special Personal Information"
Under POPIA Section 26, health information is "Special Personal Information" requiring express consent before processing. By creating an account and using the App, you give us your express consent to process the health information you enter for the purposes described in this Policy. You may withdraw this consent at any time by deleting your account.
4. What data we collect
- Account information: email address, display name, date of birth (optional), preferred language.
- Medical profile: blood type, height, allergies, medical aid details, emergency contacts, primary care doctor, organ donor status, free-text medical notes — all entered voluntarily by you.
- Health tracking data: symptom logs (including severity, mood, notes, photos), medication records (names, dosages, schedules, adherence logs, side-effect notes), vital-sign readings, daily wellbeing check-ins (mood, sleep, energy, pain, appetite, concentration), doctor appointments.
- Conditions and disorders: the chronic illness categories and specific disorders you choose to track.
- Wellness photos: photos you attach to symptom logs.
- Dependent profiles: if you add sub-accounts for minors, elderly family members, or people in your care, we store their name, date of birth, relationship, and the health data you enter on their behalf.
- Emergency data: emergency contact names and phone numbers, SOS alert history, and GPS location at the time of an SOS trigger (only when you activate the emergency button — never in the background).
- Caregiver sharing: invite codes, sharing permissions, and the identity of linked caregivers.
- Virtual Clinic + Send-to-Clinic transmissions: when you choose to book a remote consult or send a summary, we transmit the relevant payload to a partner clinical workflow system (the "Clinical Partner Database"). See section 7 below.
- Device-local data: your emergency PIN hash is stored on your device only (not on our servers) using the platform's secure storage (iOS Keychain / Android Keystore).
- Anonymous crash reports: if the App crashes, an anonymised stack trace is sent to our error-tracking service. No health data is sent.
5. What we do NOT collect
- We do NOT store your South African ID number. When you enter it to book a Virtual Clinic consultation or send a summary, it is used in transit only to address the message to the correct patient file and then dropped from the App's memory.
- We do NOT track your location in the background. GPS is captured only at the moment you trigger the SOS button.
- We do NOT use advertising trackers, advertising SDKs, or third-party data brokers.
- We do NOT access your contacts, call logs, browsing history, or any data outside the App.
- We do NOT sell, rent, or share your data with any third party for marketing purposes.
- We do NOT interpret your data clinically. The App is a wellness tracker, not a medical device — it never produces diagnoses, recommendations, or clinical claims about your data.
6. How we use your data
- To provide the service: showing your health logs, generating wellness summaries and PDF reports, scheduling medication reminders, computing your own observational daily wellbeing score from your self-reported entries.
- To share with your caregivers: only the data categories you explicitly enable in your sharing settings, and only with caregivers you have invited via a unique invite code. You can revoke any caregiver at any time.
- To send emergency alerts: when you trigger the SOS button, your emergency contacts receive an SMS with your name and (if you granted location permission) a Google Maps link to your location. The SMS is sent via our SMS partner Clickatell or your device's native SMS composer.
- To transmit Virtual Clinic bookings + Send-to-Clinic summaries: when you initiate one of these actions, the specific payload you confirmed (booking details or a 10-day wellness summary) is sent to the Clinical Partner Database. See section 7.
- To improve the App: aggregated, anonymised usage patterns (e.g. which features are most used) may be analysed internally. No individual health data is used for this purpose.
- To comply with the law: we may process personal information where required by South African law, including responding to lawful requests from courts or the Information Regulator.
7. Cross-system data flows (Virtual Clinic + Send-to-Clinic)
Chronic Wellness sits in a small ecosystem of sister apps operated by Dolme. To support continuity of care, the App can send specific information to a partner clinical workflow system used by clinicians. This happens only when you initiate it.
- Virtual Clinic bookings (the Consult tab): when you confirm a booking, the App sends your name, the SA ID number you entered, your phone (if you provided one), the booking time and modality, the facility, and any home readings or symptoms you chose to attach. The SA ID number is used to address the booking and is not retained by the App.
- Send-to-Clinic wellness summaries: when you confirm a send, the App sends a 10-day summary of the data categories you toggled (symptoms, medications, vitals, appointments).
- The Clinical Partner Database is a separately-administered Supabase project, also subject to POPIA. Once data lands there, it falls under the partner clinical system's privacy notice and the receiving clinician's professional duties.
- You can stop using these features at any time. They are not automatic — every transmission is user-initiated.
8. Where your data is stored
Your primary data is stored in Supabase, a hosted PostgreSQL database platform. Supabase provides:
- Encryption at rest (AES-256) and in transit (TLS 1.2+).
- Row Level Security (RLS) ensuring each user can only access their own data.
- Data centres with SOC 2 Type II certification.
Photos attached to symptom logs are stored in Supabase Storage (private bucket, encrypted at rest). Only you and any caregivers you have authorised can access them.
9. Cross-border data transfer (POPIA Section 72)
Supabase's hosted infrastructure is provided from data centres located outside the Republic of South Africa. By using the App, you acknowledge and consent to the transfer of your personal information across South African borders for the purpose of providing the App's services. We rely on Supabase's contractual safeguards and the binding rules it imposes on its sub-processors to ensure your information is protected to a standard substantially similar to POPIA.
Supabase region used for this App: EU Central (Frankfurt) — eu-central-1.
10. Your rights under POPIA
As a data subject under POPIA, you have the right to:
- Be informed (this Policy).
- Access your stored data via the App's "Download my data" feature in Settings, which exports everything as a structured JSON file.
- Correction — edit your medical profile, conditions, medications, and other data directly in the App.
- Deletion — permanently delete your account and all associated data via the "Delete my account" button in Settings. This action is irreversible.
- Object to processing — withdraw consent by deleting your account. You may also revoke specific caregiver access or stop using the Virtual Clinic / Send-to-Clinic features at any time.
- Complain — you may lodge a complaint with the Information Regulator of South Africa if you believe your data has been processed unlawfully. Contact: inforegulator.org.za.
For most users, the in-app "Download my data" feature is the fastest route — no formal request needed. If you would prefer to submit a formal request under the Promotion of Access to Information Act, our PAIA Section 51 Manual sets out the procedure, fees, and timelines.
11. Data retention
We retain your data for as long as your account is active. When you delete your account, all associated data is permanently erased from our primary database within 30 days. Encrypted backup retention may extend this by up to a further 30 days, after which all copies are purged. Audit-log entries that record account-deletion events are retained as required by POPIA for accountability purposes.
12. Data breach notification (POPIA Section 22)
If there are reasonable grounds to believe that your personal information has been accessed or acquired by an unauthorised person, we will:
- Notify the Information Regulator and you as soon as reasonably possible after we become aware of the breach, unless a public authority instructs us otherwise.
- Provide sufficient information for you to take protective measures (the nature of the breach, what data was affected, recommended actions).
- Notify you in writing via the email on your account, supplemented by an in-app notification if practicable.
13. Children's data
The App allows a primary user (parent or guardian) to create dependent profiles for minors. The primary user is responsible for managing the minor's data and for ensuring that the minor's health information is entered accurately. Where a minor reaches the age of 18, they may request their data be transferred to their own account by contacting privacy@dolme.co.za.
14. Cookies and tracking
The mobile App does not use cookies. The web preview (used for development purposes only) does not set tracking cookies. No third-party analytics, advertising cookies, or marketing pixels are used.
15. Changes to this policy
We may update this Policy from time to time. Material changes will be communicated via an in-app notification. The "Last updated" date at the top of this page reflects the most recent revision. Continued use of the App after the effective date constitutes acceptance of the updated Policy.
16. Contact
For privacy-related enquiries or to exercise your POPIA rights, contact us at:
Email: privacy@dolme.co.za
Information Officer: Tebogo Mazibuko — tebogo.rallele@gmail.com
Company: Dolme SA (Pty) Ltd, Republic of South Africa.
Pre-launch reminder: this Policy must be reviewed by a POPIA-qualified South African attorney before public launch. It is intended to be substantively close to launch-ready but is not a substitute for professional legal review.