Privacy & security notice.
Version 1.0 · May 2026 · MVP v1
What Sanko collects
When you use Sanko Vault via WhatsApp, Sanko stores information needed to create and maintain your records.
| Data | Why it is stored |
|---|---|
| WhatsApp number and display name | To identify your account and show your name on records. |
| Language preference | So the agent communicates in the right language. |
| Formulations, voice notes, photos and transcripts | To structure and preserve the records you create. |
| Conversation and activity timestamps | To keep short-term context and support the service. |
Patient records
Patient tracking is optional. If you choose it, Sanko stores the details you provide and links them to formulations and follow-ups. Practitioners are responsible for the lawful basis on which they record another person’s health information.
Who can see it
You have access to your own formulations and patient records. The Sanko MVP operator has access for debugging and technical support. No formulation data is shared with researchers or other third parties in v1.
Nagoya alignment
Every formulation identifies the practitioner as the source of knowledge. Sanko does not claim ownership of traditional knowledge. Research access is deferred to a later version and would require explicit practitioner consent and responsible access-and-benefit-sharing processes.
Storage and protection
- Connections use TLS in transit.
- Supabase provides encryption at rest.
- Voice notes and photos use private storage with expiring signed links.
- Row-level security separates practitioner records.
Retention and rights
Formulation and patient records form the practitioner’s professional archive. Conversation context is retained for 24 hours. Account deletion can be requested directly from the Sanko operator; self-service deletion is not yet available in MVP v1.
Contact
Felix Olajide Ayeni · felix@sanko.africa · Sanko Vault operator, v1