Privacy Policy
Effective date: September 2, 2026
Hali is a civic conditions visibility platform operated by Halicity Limited (“Hali,” “we,” or “us”). This policy explains what information Hali collects when you use the Hali app or website, why we collect it, and the choices you have.
Information we collect
Account and sign-in information
To create a Hali account, we collect your phone number. We send a one-time verification code to it by SMS, delivered through an SMS provider. Both that verification code and your session credentials are stored only as secure, irreversible hashes — never as your plain verification code and never as a plaintext login token. You may optionally add a display name.
Reports and civic-condition information
Reporting requires a signed-in account. We ask you to sign in so a report can be tied to a verified person, which is how Hali keeps its civic picture trustworthy and resists abuse. You can start writing before you sign in — your draft is kept on your own device until you do.
When you submit a report, we collect the text you write, the category and details Hali extracts from it, and the location associated with that report. Each report is linked internally to your account and to a reference for the device you submitted from — but that link is never shown to other people. What others see is a shared civic-condition summary for an area, not your individual report and not your identity.
Location information
See “How Hali uses location” below.
Device and technical information
We collect basic technical information about the app on your device — such as platform and app version — and a non-identifying device reference used to keep your account secure. We also collect operational diagnostics (such as error and performance data) to keep Hali reliable. Sensitive values are kept out of these records in two ways. Where a phone number, verification code, authentication token, or coordinates would appear in a diagnostic record’s web address or request headers, our systems strip them automatically before the record is sent. Separately, our engineering rules prohibit writing phone numbers, verification codes, authentication tokens, or the text of your reports into diagnostic records at all.
Notification information
If you enable notifications, we store a device push token, issued by a push-notification provider, so we can deliver alerts about conditions in areas you follow.
How we use your information
We use the information above to:
- verify your identity and keep your account secure;
- determine the civic area your report belongs to;
- interpret and classify what you’ve reported, using Hali’s fixed set of civic categories;
- combine your report with others into a shared civic-condition picture for your area;
- show you relevant local conditions and official updates;
- send notifications you’ve opted into; and
- maintain the reliability and security of the Hali service.
We do not sell your personal information, and we do not use your reports for advertising.
How Hali uses location
Hali asks for your location, or lets you search for a place, so it can attach your report to the right civic area and show you conditions relevant to where you are or the areas you follow.
When you search for a place by name, or choose to use your device location, Hali may send the minimum information needed for that task — the search text you typed, or the coordinates you chose to share — to mapping, place-search, and geocoding service providers, so the place can be identified and resolved to the right civic area. These providers receive only what their task requires: they are not sent your phone number, your account, your report text, or your Hali activity.
Precise coordinates associated with a report are used internally to resolve that report to a civic area and to help group it with similar reports. They are not shown to other users. What other people see is a general, human-readable description of the area — for example, a road or neighbourhood name — never your exact coordinates, and never anything that identifies who submitted a report. Reports created on the Hali website carry no coordinates at all; the area is taken from the place you chose.
AI-assisted interpretation of reports
Hali first tries to understand what you’ve reported using deterministic, rule-based logic that runs entirely on Hali’s own servers — no third party is involved at this stage.
When those rules cannot confidently interpret a report, Hali asks an external AI processing provider for help. This is AI-assisted interpretation constrained by Hali’s predefined taxonomy and validation rules: the model is asked to propose a bounded set of civic attributes — the category and subcategory, the kind and severity of the condition, whether it sounds temporary, ongoing or recurring, how widely it seems to reach, and any location wording contained in your own text — and every one of those values is then checked against Hali’s fixed lists before Hali will accept it. Anything the model returns that is not on those lists is discarded.
In this step, the provider receives your report text and the language it is written in, together with Hali’s own list of permitted categories. It does not receive your precise coordinates, your phone number, your account identifier, your device identifier, or any authentication credential.
Hali also keeps a rarely-used last-resort path for the uncommon case where both of its own interpretation stages fail. On that path only, the request additionally includes the location details submitted with that report — which can include precise coordinates, when your device supplied them — so the condition can still be placed. It never includes your phone number, account identifier, device identifier, or authentication credentials.
This AI-assisted step does not decide whether your report is accepted, how much it is trusted, whether it becomes visible to the public, how it is grouped with other reports, or whether a civic condition is marked resolved — those decisions are always made by Hali’s own rules on Hali’s own systems.
AI-generated civic summaries
Separately, Hali may use AI to write the short neutral sentence that describes an already-active civic condition on public surfaces. That request is built only from figures Hali has already calculated for the condition itself — its category and subcategory, the kind and severity of condition, how many people have reported it, and the area label — and it does not include the text of anyone’s individual report.
Service providers we work with
Hali relies on a small number of specialist service providers to operate the platform. Each is given only the information its specific task requires, may use it only to perform that task for Hali, and none of them decides anything about your civic participation:
- SMS and authentication providers — deliver the one-time verification code that signs you in. They receive your phone number and the message containing that code.
- Mapping, place-search, and geocoding providers — turn a place name or a set of coordinates into an identifiable place. They receive the search text you typed, or the coordinates being resolved, and the country being searched.
- AI processing providers — provide the constrained, taxonomy-bounded interpretation described above, and compose the neutral public summary sentence for an active condition. What they receive is set out in that section.
- Push-notification providers — deliver alerts to your device. They receive your device’s push token and the notification content.
- Cloud hosting, database, and monitoring providers — run and store the Hali service and help us detect and fix problems. What reaches them is the operational diagnostics described under “Device and technical information” above, handled as described there.
We do not sell personal information to data brokers or advertisers. We do not share the identity behind a report with other citizens, and we do not share it with institutions — institutions see the same anonymous civic-condition picture that citizens do.
International processing
Hali is operated for use in Kenya, but the service providers described above run internationally. This means information covered by this policy may be processed on systems located outside Kenya — for example when a verification code is delivered, a place name is resolved, a report is interpreted, a notification is sent, or the service is hosted and monitored.
Where that happens, the protection you rely on is the same one described throughout this policy: each provider is sent only the information its task requires, and the sections above state, for each kind of provider, exactly what that is. The specialist providers each see only their own narrow slice — the provider that delivers your verification code never receives your reports, and the provider that helps interpret a report is never told whose report it is.
Cloud hosting and database providers are the exception to that narrowness, and we state it plainly rather than imply otherwise: they necessarily hold the data that runs the Hali service, because that is what hosting is. They act only on our instructions, to operate the service for us, and not for their own purposes.
Data retention
We keep your information for as long as your account is active and as needed to operate Hali. Different kinds of information are kept for different lengths of time, and Hali does not currently apply a single fixed retention period across all of them. If you ask us to delete your information, see “Your rights and choices” below.
Your rights and choices
You can review and update your display name and notification preferences directly in the Hali app. To ask about, request a copy of, or request deletion of your personal information, contact us using the details below. Hali does not yet offer automated self-service deletion, so we handle these requests manually.
Changes to this policy
We may update this policy as Hali’s features change. We’ll update the effective date above when we do.
Contact us
For privacy questions or requests, contact us at info@halicity.io.
