In short. KawanKeluarga stores menstrual cycle and reproductive health data — under Indonesia's Personal Data Protection Act this is classified as specific personal data. We do not sell it, do not share it for advertising, and do not give it to your spouse unless you turn that on yourself. Private notes and intimacy records have no sharing switch at all.
On this translation. This is an English rendering of a policy written in Bahasa Indonesia for users in Indonesia. Where the two versions differ in meaning, the Indonesian version prevails. References to Indonesian institutions and law are not substituted for foreign equivalents: this product operates under Indonesian law, and pointing you elsewhere would be misleading.
01 Who we are
KawanKeluarga is a menstrual cycle and fertility tracking app for married
couples, developed as part of the
digimana.in ecosystem. This policy applies
to the KawanKeluarga Android app and to the web pages at
digimana.in/kawankeluarga.
For all privacy matters, the person responsible can be reached at carikami@digimana.in.
02 Data we collect
| Type | What it contains | Why |
|---|---|---|
| Account identity | Email address, display name, role (wife/husband), time zone, birth year (optional) | Signing in via a one-time code sent to your email. We store no password, because this app does not use one. |
| Reproductive health data (specific personal data) |
Period dates, cycle length, basal body temperature, cervical mucus characteristics, mood, physical symptoms, intimacy records, private notes | Calculating cycle phases, estimating the fertile window, and flagging patterns that fall outside typical ranges. |
| Device | Random device identifier, notification token, app version | Sending reminders, and letting you revoke a session on a lost device. |
| Purchases | Google Play order number, plan type, payment status | Activating Pro status and resolving disputes. We never receive your card number or payment details — Google Play handles all of it. |
| Usage metrics | Number of questions asked of the AI assistant, timestamps, and the result of topic screening | Enforcing quotas and improving answer quality. It does not contain the content of your questions. |
03 Data we do not collect
Some comparable apps request permissions they do not need. We write this list down so you can hold us to it if that ever changes:
- GPS location — not requested, not used, not stored.
- Contacts and call logs — not accessed.
- List of installed apps — not read.
- Photos, camera, microphone — not accessed.
- Phone number — not requested; sign-in uses email.
04 Legal basis and purpose
Under Indonesian Law No. 27 of 2022 on Personal Data Protection, health data is classified as specific personal data and requires explicit, separate consent. Accordingly:
- Consent to process health data is requested on its own screen, not bundled into a Terms of Service checkbox.
- That consent is recorded together with the document version and timestamp.
- Users in the husband role are not asked for this consent, because the app does not process health data belonging to them.
- You may withdraw consent at any time. Withdrawing it stops the cycle features from running, and you may then request that the data be deleted.
Data is used only to operate the features you ask for. We do not sell data to anyone, and do not use it to build marketing profiles.
05 Sharing with your spouse
The app allows two accounts to be linked. The rules are:
- Once linked, your spouse sees only today's fertility level and the phase name. Every other category is off by default.
- Additional categories open only when the data owner turns them on personally, one at a time.
- Private notes and intimacy records cannot be shared under any circumstances. There is no setting to enable it.
- Data you have not permitted is never sent to your spouse's device — the filtering happens on the server, not hidden in the interface.
- Turning a category off also removes older summaries that contained it.
- Either party can unlink at any time, immediately, without the other's consent.
06 Advertising
The app shows rewarded video ads from Google AdMob, and only on the Account screen — never on the calendar, logging, or daily summary screens.
We request non-personalised ads and send no keywords, user segments, or page context of any kind to the ad network. Your health data is never an input to the ads you see.
We should state this plainly: Google's ad SDK can still receive basic technical data such as device type and a coarse regional estimate from your IP address, as described in Google's documentation. The details that apply are always listed on the Data Safety form on this app's Google Play page.
07 AI features
The app includes a generative AI assistant for questions about cycles and about fiqh relating to women (Islamic jurisprudence).
- The content of your questions is not stored on our servers. We keep only metrics: timestamp, the result of topic screening, and a digital fingerprint (hash) of the answer that cannot be turned back into text.
- The context sent to the model provider is limited to your current cycle phase and the mode you selected. Your name, email, private notes, and intimacy records are never included.
- Questions about diagnosis, medicines, dosage, terminating a pregnancy, and the religious ruling on contraception are not answered; they are redirected to health professionals or to official religious bodies.
- Every answer has a Report button. Reported answers are reviewed.
- AI answers are not medical advice and are not a fatwa.
08 Storage security
- All traffic between the app and the server uses TLS.
- Private notes and intimacy records are stored encrypted (AES-256-GCM) with a key held outside the database.
- Other cycle data is stored on encrypted storage with restricted access, because the calculation engine must be able to read it.
- Data on the device is stored in an encrypted local database.
- Server event logs never contain symptom content, private notes, or AI questions.
- In the event of a personal data breach, we notify affected users and the competent authority within 3×24 hours of becoming aware, as required by the Personal Data Protection Act.
09 Third parties
| Service | What for | What it receives |
|---|---|---|
| Google Play Billing | Payments | Transaction data. We do not receive card details. |
| Google AdMob | Rewarded ads | Basic device technical data. No health data. |
| Firebase Cloud Messaging | Notifications | Device token. Notification content is generic. |
| AI model provider | Answering questions | Question text & cycle phase. No identity. |
| Email service | Sign-in codes | Email address & message content. |
Outbound email is sent from notif@digimana.in. Replies to that
address are not read — to reach a human, use the address in section 15.
10 Your rights over your data
Under the Personal Data Protection Act, you have the right to:
- Access the data we hold about you.
- Correct data that is wrong.
- Export all of your data in a machine-readable format — available free of charge inside the app.
- Delete your data and your account.
- Withdraw consent to the processing of health data.
- Object to how we process your data.
Send requests to carikami@digimana.in. We respond within 3 working days.
11 Deleting your account
Account deletion is available inside the app, on the Account screen, without needing to contact anyone. If you have already uninstalled the app, use the account deletion form.
The details — what is removed, what remains, and for how long — are on that page.
12 How long data is kept
| Data | Retention |
|---|---|
| Cycle & health data | For as long as the account is active. Deleted no later than 7 days after account deletion. |
| Inactive accounts | Warned by email after 24 months without activity, then deleted 30 days later. |
| One-time sign-in codes | 10 minutes. |
| Transaction records | Kept as a bookkeeping and dispute-resolution obligation, but anonymised when the account is deleted, so they are no longer connected to you. |
| AI usage metrics | 12 months, in aggregate form without identity. |
13 Children
KawanKeluarga is intended for married adult users and is not intended for children under 17. We do not knowingly collect children's data. If you become aware that a child has created an account, tell us and we will delete it.
14 Changes to this policy
If this policy changes in a material way, we notify you through the app and by email before the change takes effect. For changes that expand the processing of health data, we ask for your consent again — we do not treat your silence as agreement. Every version carries its effective date at the top of this page.
15 Contacting us
Questions, complaints, and data rights requests:
carikami@digimana.in
If our answer does not satisfy you, you have the right to complain to the personal data protection supervisory authority in Indonesia.