Product preview notice

Privacy, in plain language.

Last updated: 6 September 2026

This notice describes the Phase 1 public website supplied in this package. It should be reviewed and adapted to the final company, hosting, analytics and app data practices before production launch.

1. Who this website is for

This website introduces Me by Shifi and lets visitors send an enquiry or request early-access information. It does not provide the full Me by Shifi application inside the browser.

2. Information submitted through the contact form

If the site owner enables the contact form, it asks for a name, email address, enquiry category and message. This information is used to receive and respond to the enquiry. Do not include health records, passwords, payment details or other sensitive information in the form.

3. Technical information

The hosting provider may process standard server information such as IP address, browser type, timestamps and requested pages for security, delivery and diagnostics. The supplied Phase 1 code does not include third-party analytics, advertising pixels or social-media trackers.

4. Cookies and local storage

The supplied website uses a PHP session for contact-form security, including a CSRF token. It does not include advertising cookies. If analytics, consent tools or other services are added later, this notice and any consent experience must be updated.

5. Retention and access

Retention depends on the mailbox and hosting systems configured by the site owner. Before production, the operator should define deletion periods and a clear method for people to request access, correction or deletion where applicable.

6. The Android app

The future production privacy policy must separately document app data such as account details, agent preferences, conversations, reminders, meal information, fitness information, images and device tokens. It must also identify each processor and explain sharing between agents.

7. Security

The website should be served over HTTPS and kept on supported PHP and server versions. API keys and other secrets must remain on the server and must never be embedded in public website or Android client code.

8. Contact

Use the contact page for privacy questions after the site owner has configured its delivery address.