Measuring personal growth honestly
Wellbeing products are full of impressive numbers. Most of them measure how people feel about themselves. That is worth measuring, as long as everyone is clear that it is what is being measured.
People record things in a wellbeing app that they would keep from almost anyone. For UMOYA Zone we started from the assumption that the safest personal data is the data we never hold.
A personal development app collects some of the most sensitive information a person produces: what they are struggling with, what they want to change, how they rate themselves on a bad week. Some of that may count as health information under data protection law. All of it is the kind of thing people would be uncomfortable seeing in someone else's database.
When we designed UMOYA Zone with its founders, we took a position early. Personal progress data stays on the user's device. It is stored and encrypted locally, and it is not uploaded to our servers.
Most apps default the other way. Data goes to the cloud because the cloud makes features easy: sync across devices, dashboards, analytics, recommendations built from everyone's behaviour. The cost is that the company now holds the data, and holding it brings obligations that do not go away. It has to be secured, its use has to be justified, requests to see or delete it have to be answered, and a breach becomes a notifiable event.
For a product whose whole value depends on people being honest with themselves, trust is not a feature to add later. If users suspect their entries could be read by someone else, they stop writing the true ones.
Keeping data on the device is a design constraint, and it shapes almost everything.
Features have to work locally. Goal tracking, progress charts, reminders and self-assessment scores are computed on the phone. There is no server-side model looking across users to make suggestions.
Loss of the phone is a real risk. If the data only lives in one place, a lost or replaced device takes it with it. That is the honest cost of the design, and it is why any future backup has to be encrypted under a key the user controls.
Compliance gets simpler. Data we do not hold cannot leak from our systems and does not need a retention policy on our side. It does not remove every obligation, and the app still has to protect what is stored on the device, but it removes the largest ones.
UMOYA Zone is also offered to organisations for their people. An employer will reasonably ask whether the programme is working. The answer cannot be to hand the employer individual records. Any team-level view has to be anonymised, and each person decides whether to take part. South Africa's health information regulations, in force since March 2026, speak directly to employers, which is one more reason to keep individual entries out of their reach.
We think that is the right rule for any workplace wellbeing product. The question an employer should ask a vendor is where the underlying entries live and who else could read them.
The general lesson is one we apply in client work too: decide what data the system genuinely needs to hold before deciding how to protect it. Every field you do not collect is a field you never have to protect or answer for. Our wider position on data and AI is set out in our Responsible AI policy and on the trust and security page.
Part of From our delivery work. Get new articles by email or follow the RSS feed.
Wellbeing products are full of impressive numbers. Most of them measure how people feel about themselves. That is worth measuring, as long as everyone is clear that it is what is being measured.
An unsupported CRM is expensive to keep and dangerous to switch off, because a decade of customer history lives inside it. The answer we used keeps the history and retires the application.
Companies with one foot in Mauritius and one in South Africa get described as having two offices. The useful description is what each base does for an initiative in another African country, and what the partner on the ground gets back.