Privacy Policy — Mobile
Effective May 26, 2026 · Last updated May 26, 2026
Introduction
GIGI is a caregiver-elder communication app that helps caregivers stay connected with the people they care for through video calls. This Privacy Policy explains what personal information we collect, how we collect it, why we use it, who we share it with, how long we keep it, and what rights you have over it.
This policy applies to users of the GIGI mobile application on Android and iOS. By creating an account or using GIGI, you acknowledge that you have read and understood this policy. If you do not agree, please do not use the app.
1.Who We Are
GIGI is developed and operated by Softaims, based in the United States. "We", "us", or "our" refers to Softaims. "You" or "user" refers to any person who uses the GIGI application.
2.Information We Collect
Account and Profile
- Email address
- Password — stored exclusively as a one-way bcrypt hash; your plain-text password is never stored or accessible
- Display name
- Profile picture (optional — stored in AWS S3; can be deleted from app settings at any time)
- Account role: Caregiver or Elder
- Email verification status
- Account creation date and last updated timestamp
Pairing and Relationship
- Pairing relationships between accounts
- Pairing PIN, stored as a one-way hash — never in plain text
- Pairing creation date and last updated timestamp
Call History and Metadata
We log metadata for every video call. We do not record, store, or access call audio or video content.
- Identities of participants
- Call status at each stage (ringing, active, missed, or ended)
- Call start time, end time, and total duration
- Whether the call was accepted, declined, or missed
Presence and Activity
- Real-time connection status (online or offline)
- Last active timestamp, updated each time a user disconnects
Device and Technical
- Device model and type
- Operating system name and version
- App version
- IP address (used for connection routing and security)
- Language and locale settings
- Country or region derived from IP address
We do not collect precise GPS location, advertising identifiers (IDFA, GAID), contacts, or browser history.
Push Notification Tokens
If you grant notification permission, we store the device token assigned by your OS. This token is used only to deliver incoming call alerts. We do not send marketing or promotional notifications.
Usage Information
- Features accessed and frequency of use
- Call initiation and acceptance patterns
- Session heartbeat signals (sent every 10 seconds during active calls to detect drops)
- Error events and performance metrics
- App settings and preferences
Support Communications
If you contact us for support, we may collect your email address, the content of your message, and any attachments. This is used only to respond to your inquiry.
3.How We Collect Information
- Directly from you — when you register, update your profile, or contact us
- Automatically — device info, IP address, usage data, and call metadata as you use the app
- From our infrastructure — call logs and session metadata generated by our backend
- From your device — push notification tokens when you grant permission
4.How We Use Your Information
- Create and manage your account and profile
- Authenticate your identity and maintain your session securely
- Connect caregivers and elders through the pairing system
- Initiate, route, and complete video calls
- Display your name and profile picture to your paired partner
- Show your online or offline presence to your paired caregiver
- Deliver real-time call alerts and push notifications
- Send transactional emails (OTP codes for verification and password reset)
- Store and display call history to both participants
- Detect, investigate, and prevent unauthorized access and security incidents
- Enforce our Terms of Service
- Diagnose technical problems and fix bugs
- Improve app performance and develop new features
- Respond to support requests
- Comply with applicable laws and legal obligations
We do not use your information for advertising, behavioral profiling, or targeted marketing. We do not sell your personal information to any third party.
5.Legal Bases for Processing (GDPR)
If you are in the EEA or United Kingdom, we process your data under these legal bases:
| Purpose | Legal Basis |
|---|---|
| Account creation and management | Contract — necessary to provide the service |
| Video calls and pairing | Contract — necessary to provide the service |
| Sending OTP and transactional emails | Contract — necessary to provide the service |
| Security logging and abuse prevention | Legitimate interests |
| Error logs and diagnostics | Legitimate interests |
| Responding to legal requests | Legal obligation |
| Optional profile picture | Consent |
| Push notifications | Consent |
You may withdraw consent-based processing at any time without affecting the lawfulness of prior processing.
6.Information We Share
We do not sell, rent, or trade your personal information. We share it only in these limited cases:
With Your Paired Partner
- Your display name
- Your profile picture
- Your online or offline status
- Your shared call history
With Service Providers
| Provider | Data Received | Purpose |
|---|---|---|
| Jitsi Meet (self-hosted) | Short-lived JWT token, call room ID | Video call infrastructure |
| Amazon Web Services (S3) | Profile picture files | Image storage |
| Resend | Email address, email content | Transactional email delivery |
| Amazon RDS (PostgreSQL) | All application data | Managed database hosting |
For Legal Compliance
We may disclose information if required by law to comply with a legal obligation, protect the rights or safety of users or the public, or prevent wrongdoing.
Business Transfers
If Softaims is involved in a merger or acquisition, your data may transfer as part of that transaction. We will notify you before your data becomes subject to a different policy.
We do not share your information with advertising networks, data brokers, or analytics companies.
7.Permissions We Request
| Permission | Platform | Why We Need It |
|---|---|---|
| Camera | Android, iOS | Capture and transmit video during calls |
| Microphone | Android, iOS | Capture and transmit audio during calls |
| Background audio | iOS | Keeps call audio active when the app is in the background |
| Notifications | Android, iOS | Deliver incoming call alerts and system notifications |
Each permission is requested at the point where it is needed with a clear explanation. You can revoke any permission at any time from your device settings. Revoking camera or microphone access will prevent video calls from functioning.
8.Video Calls
When a video call is active:
- Your camera video and microphone audio are transmitted in real time through our self-hosted Jitsi Meet server
- A short-lived JWT token authenticates both participants into the call room and expires when the call ends
- We do not record, monitor, or store the audio or video content of calls
- Call metadata (participants, duration, status) is logged as described in Section 2
- A heartbeat signal is sent every 10 seconds to detect connection drops
- Either participant can end the call at any time
9.Elder Safety and Control
GIGI is built around the principle that elders remain in control:
- A caregiver cannot reach an elder without an active pairing the elder participated in establishing
- Elders can unpair at any time, immediately revoking all caregiver access
- Elders can delete their account at any time from app settings
To report unauthorized access, misuse, or abusive behavior, contact us immediately at privacy@softaims.com. We may suspend or terminate accounts found to be misusing the service.
10.Third-Party Services
Jitsi Meet (Self-Hosted)
Our video infrastructure runs on a self-hosted server at call.gigisquad.com. Streams are not recorded. We do not share data with the Jitsi project or 8x8, Inc.
Amazon Web Services (S3)
Profile pictures are stored in an S3 bucket managed by us. Deleting your picture from app settings removes it from S3 immediately.
Resend
Transactional emails are sent via Resend. Resend receives your email address and email content only. It does not use this data for its own marketing.
Amazon RDS (PostgreSQL)
Our database is hosted on Amazon RDS, a managed PostgreSQL service. Data is encrypted in transit and at rest.
11.Data Storage and Security
- All data in transit is encrypted using HTTPS/TLS
- Passwords are hashed with bcrypt and never stored or transmitted in plain text
- JWT tokens are short-lived (15 minutes), stored in device secure storage (iOS Keychain / Android Keystore), and cleared on logout
- Database access uses authenticated, pooled connections with restricted permissions
- Employee access to user data is limited to what is necessary to operate the service
No security system is impenetrable. If you believe your account has been compromised, contact us immediately at privacy@softaims.com.
12.Data Retention
| Data | Retention Period |
|---|---|
| Account and profile data | Retained while active. Permanently deleted within 90 days of account deletion. |
| Call history and metadata | Retained for the lifetime of your account. Purged within 90 days of deletion. |
| OTP verification codes | Expire 10 minutes after generation and cannot be reused. |
| Presence and last active data | Cleared immediately on account deletion. |
| JWT tokens on device | Expire 15 minutes after issuance. Cleared immediately on logout. |
| Push notification tokens | Cleared on logout or account deletion. |
| Error and crash logs | Retained for up to 90 days. |
| Support communications | Retained for up to 2 years or as required to resolve your request. |
13.Your Rights and Choices
- Access — Request a copy of the personal information we hold about you
- Correction — Request correction of inaccurate information; update name and profile picture directly in the app
- Deletion — Delete your account from app settings; data purged within 90 days
- Portability — Request a machine-readable export by emailing privacy@softaims.com
- Withdraw Consent — Revoke permissions (camera, microphone, notifications) from device settings
- Object to Processing — Object to certain uses of your data by contacting us
- Lodge a Complaint — File a complaint with your local data protection authority
To exercise any right, contact privacy@softaims.com. We respond within 30 days and may ask you to verify your identity. We do not send marketing emails.
14.California Privacy Rights (CCPA / CPRA)
If you are a California resident, you have the following rights:
- Right to Know — What personal information is collected, used, shared, or sold
- Right to Delete — Request deletion of your personal information
- Right to Correct — Request correction of inaccurate personal information
- Right to Opt Out of Sale or Sharing — We do not sell or share personal information for cross-context behavioral advertising
- Right to Limit Use of Sensitive Personal Information — You may request that we limit use to what is necessary to provide the service
- Right to Non-Discrimination — We will not discriminate against you for exercising any of these rights
15.Children's Privacy
GIGI is not intended for children under 13. We do not knowingly collect data from children. If you believe a minor has registered, contact us at privacy@softaims.com and we will delete the account promptly.
16.International Data Transfers
Softaims is based in the United States. If you access GIGI from outside the US, your data may be processed in the US where data protection laws may differ. For transfers from the EEA or UK, we rely on Standard Contractual Clauses where required.
17.Changes to This Policy
When we make material changes, we will:
- Notify you via in-app alert or email at least 14 days before changes take effect
- Update the "Last updated" date at the top of this policy
- For significant changes, ask you to review and acknowledge the updated policy
Continued use of GIGI after changes take effect means you accept the updated policy.
18.Contact
For privacy questions, data requests, account deletion, or security concerns:
Email: privacy@softaims.com
Company: Softaims