Overview
Most people in Kenya pay for care the moment they receive it: at a hospital counter, often for someone else, often with less on M-Pesa than the invoice says. The gap is covered by phone calls to family and by borrowing on terms nobody has time to read.
Jireh turns that informal support into structure. A Circle of relatives and friends backs a small interest-free credit line, cashback builds up from every payment, and one payment flow lets patients mix these sources at the counter. My job was to make that feel as simple as sending money on M-Pesa, the bar every Kenyan user compares us to.
Four constraints shaped every screen:
- 3G and low-end Android. Screens had to load fast and survive a dropped connection mid-payment.
- Money, ID and health in one app. Every request for a National ID, selfie or PIN had to explain itself.
- Paying for someone else. The payer and the patient are separate throughout.
- Data costs money. Heavy screens and surprise downloads cost users before we'd earned their trust.
Principles
- Every shilling is visible. Amounts always show the currency and use tabular figures. During a payment, allocated vs. owed is always on screen.
- One decision per screen. Long flows are split into steps, each with one question and one primary action within thumb reach.
- Money moves only on a PIN. The PIN sheet opens over the payment summary, so who is being paid and how much stay in view.
- Never lose progress. Multi-step forms save as people type, so a refresh or a dropped connection resumes where they were.
A shared design system holds these rules in place across more than a hundred screens: semantic colour tokens, one heading ramp, and three page shells (journey, sign-in and status), so no screen builds its own chrome.
Paying at the counter
Fast Track happens in the most stressful place: a queue at a hospital cashier. Each partner facility shows a payment number at its counter, or the patient can search for the hospital instead. Entering it brings up the hospital, the desk and the cashback rate before any money is involved; then the patient adds the invoice, the amount and who they're paying for.
The wallet step is where Jireh differs from a checkout page: one bill can be split across several sources, and a bar fills as the patient allocates. The loan drawer shows what's left to cover, asks for a repayment period and states the cashback earned on repaying, so the loan becomes something to plan around. After submitting, the app always lands on the status screen, so a nervous second tap can't pay twice.







Home
Patients hold two kinds of money with Jireh: cashback they've earned and credit they can borrow. Home shows both as cards side by side, with a toggle to switch between them, and each card has its own colour (purple for cashback, teal for loans), so people know which one they're in without reading. The next step sits directly under each balance, and "Pay Medical Bill" is always pinned above the tab bar.


Circle
A Jireh loan is backed by a Circle, not a credit score. The hard part was explaining shared responsibility without sounding like a debt collector. The Circle screen draws people around you rather than listing them, and the explainer leads with what you get before the shared risk.
A Circle holds two kinds of people. Circle members are adults you trust to repay: two of them unlock borrowing, and they are the only people who receive an invite, as a custom SMS or a recorded voice note for anyone without a data bundle. Dependants, such as children and elderly parents, are people whose medical bills you manage. You add them by name and can pay for them straight away, and they never receive an invite or take on any of the risk.




Designing the Circle meant designing around trust between people, as much as trust in the product.
Onboarding
Sign-up has no password: a phone number, an SMS code, your name as it appears on your ID, then a PIN. The PIN screen says what it's for, because people take a PIN more seriously when they know what it protects.
Identity checks come only when they're needed. The National ID step can be skipped, and the app routes by what's missing rather than a fixed order, so leaving halfway always brings you back to the right step. Unlocking loans turns the remaining requirements into a checklist that ticks off over time, and a failed selfie match goes to a person for review instead of a dead end. Permissions follow the same rule: alerts, installing the app and sharing location each say what they're for, and nothing is switched on until the patient chooses it.






Paying from an invoice
Not every bill is paid in person, or at a facility in the Jireh network. The invoice route names its three steps up front: the facility's payment details, a photo of the bill, then how to pay. Patients can upload several pages at once, and consent for Jireh to use their medical data is asked right beside the upload it covers. While the invoice is checked, the screen says how long it takes and what comes next, instead of showing a spinner. On the review screen every detail has its own edit button, so a wrong amount or Paybill is fixed in place. Repaying is just as calm: Paybill and account numbers have copy buttons, and an overdue loan is one clear state with one action.







Ask Jireh
The newest feature is an assistant in the centre of the tab bar. It answers questions about payments, loan limits, Circles and cashback, and points people to nearby facilities. Before the first chat, a sheet asks the patient to accept the AI chat terms, with Decline as a full-size choice beside Accept. After that, the chat opens by name with suggested topics, so nobody faces an empty box, and past chats are one tap away. Wellness answers carry a fixed disclaimer, and when someone types too fast it says so plainly: "Give me a moment, you have been chatting fast." Many patients first hear from Jireh by SMS, so links in those messages open the chat with the SMS already shown.


Testing with patients
To test in person, I split the patient app off into a standalone prototype. It runs in the browser on fake data and uses the same components as production, so what people test is what ships. A facilitator panel can drop a participant at any point in the journey (before their name, before ID, fully onboarded) and reset between sessions.