DNAi Systems: Asha AI Privacy Notice
If you migrate data to Asha from another application or service at your direction, we process that imported data under the same protections described in this policy. Imported data is stored in your isolated user environment and is subject to the same retention, deletion, and access controls as data created natively on Asha. We do not retain copies of data from third-party platforms beyond what is necessary to complete the migration.
In the Asha mobile apps you can choose to connect Apple Health (iOS) or Health Connect (Android). If you do, Asha reads only these types, and only after you grant permission in the system dialog: steps, heart rate, resting heart rate, heart rate variability, sleep, active energy, and weight. Asha never writes to Apple Health or Health Connect.
We use this data for one purpose: to show your own readings back to you and to give Asha context when you ask about your health, so her answers reflect your recent sleep, activity, and vitals. The readings are stored in your isolated user environment under the same encryption, retention, and deletion rules as everything else in this policy. We do not sell Health Connect or Apple Health data, we do not use it for advertising or credit, insurance, or employment decisions, and we do not share it with third parties except the infrastructure providers that process data on our behalf under contract. You can disconnect at any time from My Account (Connected devices), or by revoking Asha's permission in Health Connect or the Health app; deleting your account deletes the readings with it.
Health information is considered sensitive personal data under GDPR and similar laws. We process this data only with your explicit consent and for the purpose of providing personalized health guidance.
Important: Your data is processed by AI software only. No humans read your conversations, review your health data, or monitor your sessions in real-time.
Your information is used by AI to:
Asha uses a combination of on-premise inference infrastructure and third-party AI services, all operating under zero data retention (ZDR) agreements or equivalent data isolation guarantees. This includes:
We process your data under the following legal bases:
You may withdraw consent at any time by contacting us or using in-app controls. Withdrawal does not affect the lawfulness of processing before withdrawal.
We will NEVER:
You may choose to contribute de-identified health conversations to improve Asha for future users. This program is:
Asha works identically whether you contribute or not. Your choice has no impact on service quality or features.
Your conversation history and health profile are retained to provide continuity of care. You may request deletion of your data at any time by contacting us.
All retained data is stored on secured primary infrastructure with off-site backups. Backup copies follow the same retention schedule and are purged within 30 days of the primary data's deletion.
You can delete your account and all associated data yourself, without contacting us: sign in, open your profile (Health Summary), and choose Delete Account. Deletion removes your account record, conversation history, health profile, uploaded documents, and private memory. This works the same on askasha.org and in the Asha mobile apps. The link for app store listings is https://askasha.org/privacy#delete-account.
Under GDPR (EU/EEA), DPDP Act (India), and CCPA/CPRA (California), you also have the right to request complete deletion of your personal data by email. Contact [email protected] to exercise this right. We will respond within:
In the event of a data breach that affects your personal data, we will:
Asha is not intended for use by children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, contact us immediately at [email protected] and we will delete it promptly.
Users between 13 and 17 may use the service with verifiable guardian consent. For minor users, the following safeguards apply:
Asha may offer voice-based interaction including speech-to-text and text-to-speech. When you use voice features:
Required for authentication and session management. Cannot be disabled.
Optional cookies to help us understand usage patterns and improve the service. You can accept or decline these via the cookie banner.
Asha uses third-party service providers in the following categories. Specific providers may change over time; we maintain data processing agreements with all processors and will update this section as material changes occur:
A current list of specific sub-processors is available upon request by contacting [email protected].
Your health data is stored on DNAi Systems' sovereign infrastructure in the United States. We do not use shared cloud databases for your personal health information.
If you access Asha from outside the United States, your data may be transferred to and processed in the United States. We protect such transfers through:
By using Asha, you consent to the transfer of your data to the United States, where data protection laws may differ from your jurisdiction.
You have the right to:
EU/EEA users have rights under the General Data Protection Regulation (GDPR). California users have rights under the California Consumer Privacy Act (CCPA/CPRA). India users have rights under the Digital Personal Data Protection Act (DPDP Act).
For all privacy inquiries and data requests:
Email: [email protected]
Website: dnai.systems
Grievance Officer (India, DPDP Act 2023 and Consumer Protection (E-Commerce) Rules, 2020): Dr. Paridhi Anand, Chief Product Officer. Email: [email protected]. Acknowledged within 48 hours, resolved within one month.
DNAi Systems · Incorporated in Delaware