Privacy Policy
Kite Labs, Inc. · Effective August 4, 2026
As of July 28, 2026, Kite is operated by Kite Labs, Inc. (previously Grounding LLC). Our privacy practices are unchanged.
Health data is also covered by our Consumer Health Data Privacy Policy, the separate, dedicated policy required by Washington’s My Health My Data Act and similar laws. It describes the health data we collect, why, who we share it with, and your rights over it.
Who we are and what this covers
Text-messaging (SMS) program
Information we collect
- Account information: your mobile phone number (your account identifier), an optional display name, your time zone, and your messaging channel preference.
- The content you send: the messages, photos, and voice notes you choose to send, and the documents (such as bills, lab results, or insurance papers) you share.
- Health information you share in conversation so your agent can remember it for you — for example, symptoms, conditions, medications, allergies, vaccines, and the providers you see. This is also covered by our Consumer Health Data Privacy Policy.
- A coarse demographic baseline you ask us to remember: your general home area (city and state), your year of birth, and — only when relevant to a screening — your sex. We deliberately keep these coarse and do NOT store your precise street address, ZIP code, or full date of birth, and we do not track your device location.
- Care logistics you ask us to handle: reminders, referrals, appointments, and (if you connect it) limited Google Calendar data — see below.
- If you install the optional Kite iPhone app and connect them: Apple Health data, the events on the calendars set up on your phone, and your reminders, plus the daily summaries and pattern observations we derive from them. The exact data types are listed in “The Kite iPhone app” below.
- If you connect a wearable service (Oura, WHOOP, Strava, or a Dexcom glucose monitor): the health and activity history that service holds for you, retrieved with your authorization through its official interface. The exact data types are listed in “Connected wearables” below.
- Billing information if you subscribe: handled by our payment processor, Stripe; we store a customer identifier, not your full card number.
- Limited technical and usage data: counts and events about how the Service is used (never the content of your messages), and consent records (including the time, version, and where you gave it — on our website, or by your reply in the text thread; website consents also record the IP address and device/browser used).
How and why we use your information
- To run the conversation and remember what you tell us, so you don’t have to repeat yourself.
- To answer your questions with educational context, using AI models that process your messages to generate replies.
- To use your saved home area to help find care near you, and your year of birth and sex to surface age- and sex-appropriate preventive-screening information — never for advertising.
- To take actions you ask for — finding providers, attempting bookings, calendar events, reminders, and emailing you documents we generate.
- If you use the Kite iPhone app or connect a wearable service: to compute daily summaries and pattern observations from the data you connect, text you what we noticed, and answer your questions about your own numbers.
- To operate, secure, troubleshoot, and improve the Service, prevent abuse, and comply with law. A small number of authorized team members may review conversations when needed to support, troubleshoot, or secure the Service, under access controls, confidentiality obligations, and access logging.
- Reviewing conversations to improve the product happens only if you separately opt in. We ask you directly, saying no changes nothing about the Service, and you can change your mind at any time by telling your agent.
Consent
What we never do
Who we share information with (service providers)
- Cloud hosting, storage, and database: Amazon Web Services (AI processing and file storage), Supabase (our database), Railway (application hosting), and Vercel (our website, including the pages and charts we generate for you).
- AI model processing: Amazon Web Services (Amazon Bedrock) and Anthropic, which run the models that generate replies and that, only if you separately opt in, help our team review conversations to improve the Service. Both process your messages under commercial terms that prohibit using them to train their models.
- Messaging delivery: our SMS carrier (Twilio) and our iMessage relay (Sendblue), which deliver texts between you and your agent.
- Payments: Stripe, which processes subscription billing.
- Calendar and email (only if you connect them): Google, as described below.
- Web search for current information: a third-party search provider (Exa), which receives only a generalized query with your name and identifying details removed — not your full messages — and an optional re-ranking provider (Voyage) that re-orders the public search results for relevance and receives the generalized query and those results, not your identity.
- Finding and comparing care: when you ask Kite to find or compare nearby doctors, we send a provider’s name and address (never your personal information) to Google’s Places service to retrieve that office’s public ratings and reviews.
- Reference images: when you ask to see what a condition looks like, we send only the condition name (never your personal information) to Wikimedia Commons to fetch a public medical illustration.
- Voice-note transcription and outbound email of your own documents: Amazon Web Services (Transcribe and SES).
- Product analytics and error monitoring: providers that receive event counts and diagnostics only, never the content of your messages or your health data.
- Appointment booking automation (only when you ask us to book): a browser-automation provider (Browserbase) and a computer-use AI model (from Anthropic or OpenAI) used to submit the booking details you authorize (such as your name and phone number, plus your date of birth or insurance if the office requires them) to a provider’s scheduling page.
The Kite iPhone app
The Kite app is optional, and everything it collects is something you connect on purpose. It brings health data that is already on your phone into your Kite conversation so your agent can find patterns across it, text you a snapshot of what it noticed, and answer questions about your own numbers. Each source is a separate choice, you can continue without any of them, and iOS asks for its own permission on top of ours. The app never writes to Apple Health and never adds to or changes your calendar.
Apple Health. With your permission we read and store these sample types, from the last 90 days and then kept current in the background: time asleep and sleep stages, heart rate, resting heart rate, heart rate variability, respiratory rate, steps, walking and running distance, active energy burned, exercise minutes, workouts (activity type, duration, and average heart rate), body mass, and mindful minutes. That is the complete list.
Device calendar. Events from every calendar account set up on your phone, covering the last 90 days through the next 30: title, the location field as you typed it, start and end time, all-day flag, number of invitees, whether it repeats, and status.
Reminders. Reminders from every list on your phone: title, due date, and completion time, including ones completed in the last 90 days.
What we do with it. We compute daily summaries and pattern observations, and your agent texts you about them and answers your questions. Producing those messages means the observations are processed by the AI model providers named above, under contracts that bar training on your data. We never use any of it for advertising, never sell it, never share it with data brokers, and never put it in iCloud. Event titles, event locations, reminder titles, and the wording of your observations are encrypted at rest. We do not store the names of your calendars or reminder lists.
Stopping and deleting. Tap “Disconnect this device” on the app’s status screen and that phone stops sending immediately. You can also turn off Kite’s access to Health, Calendars, or Reminders in iOS Settings, or delete the app. To erase what we already hold, text DELETE to your agent, which removes the health samples, calendar events, reminders, summaries, and observations along with the rest of your data.
Connected wearables (Oura, WHOOP, Strava, Dexcom)
You can connect a wearable service to Kite from your conversation: you tap a link we text you, approve access on that service’s own page, and Kite then reads about 90 days of your history and keeps it current. Each connection is optional, separate, and yours to revoke. Kite only reads; it never writes anything to these services, and it never sends them your Kite conversations or any other data we hold about you.
What we read. From Oura and WHOOP: time asleep and sleep stages, resting heart rate, heart rate variability, respiratory rate, activity and energy burned, workouts, and body weight where the service provides it. From Strava: workouts and exercise time. From Dexcom, if you connect a continuous glucose monitor: your glucose readings and their trend. We store the sign-in tokens these services give us in encrypted form, and we use the data exactly as we use Apple Health data from the Kite app: to compute your daily summaries and pattern observations and to answer your questions. It is never used for advertising, never sold, and never shared with data brokers.
Disconnecting. Tell your agent to disconnect the service (for example, “disconnect my Oura”) and collection stops immediately: we revoke our own access with the service where it supports that, and stop all syncing either way. You can also revoke Kite’s access from your account settings at the service itself. Disconnecting stops new data; to erase what we already hold, text DELETE. Your relationship with the wearable service itself is governed by that service’s own privacy policy.
Google user data (Calendar, Gmail, and Places)
How we protect your privacy by design
How long we keep your information
- Your distilled health memory and records (the saved facts, symptom and measurement logs, photos, profiles, and reminders that ARE the service) are kept for the life of your account, so your agent can remember them — until you delete them or close your account.
- Data from the Kite iPhone app (Apple Health samples, device calendar events, device reminders) and from connected wearables (Oura, WHOOP, Strava), plus the daily summaries and observations we derive from it, are kept for the life of your account, so your agent can compare what is happening now with your own history. Disconnecting a device or service stops new data arriving; text DELETE to erase what we already hold.
- Raw message transcripts age out on a rolling basis (currently about 18 months); operational logs are kept for about 90 days.
- Short-lived caches (such as general web-search and drug-information lookups, which are not tied to your identity) expire on their own within days.
- Billing records are retained as required for tax, accounting, and legal purposes.
Security
Deleting your data and withdrawing consent
You can erase your data at any time by texting DELETE to your agent. This erases your messages, health memory, saved details, photos, symptom and measurement logs, reminders, and calendar events from our systems, along with everything the Kite iPhone app sent us: Apple Health samples, device calendar events, device reminders, your daily summaries and observations, and that device’s access to your account. It also erases everything a connected wearable sent us and revokes Kite’s access with the wearable service itself. We direct our service providers to delete it as well, and it ages out of routine encrypted backups within 30 days. You can also email privacy@heykite.app.
To withdraw consent without deleting: reply STOP in the thread to stop the texts; in the Kite iPhone app tap “Disconnect this device” on the status screen, or turn off Kite’s access to Health, Calendars, or Reminders in iOS Settings; and for a connected wearable, tell your agent to disconnect it or revoke Kite’s access in that service’s own settings. Any of these stops further collection right away.
Your privacy rights
Depending on where you live, you may have rights to know about and access the personal information we hold about you, to obtain a copy (portability), to correct it, to delete it, to withdraw consent, and to opt out of any sale, sharing for targeted advertising, or certain profiling. We do not sell or share your information for targeted advertising or use it for such profiling, so there is nothing to opt out of — but you may still exercise your other rights. California residents have the right to limit the use of sensitive personal information (we already limit health data to providing the Service) and, under “Shine the Light,” to ask about disclosures for third-party direct marketing — we make none.
To exercise any right, text your agent or email privacy@heykite.app — two reliable methods to reach us. We will verify your request (typically by confirming control of your account phone number) and respond within the time the applicable law requires (generally 45 days, extendable once when reasonably necessary). An authorized agent may submit a request with proof of authorization.
Appeals. If we deny your request, you may appeal by emailing privacy@heykite.app with “Appeal” in the subject line. We will respond in writing within 60 days. If we deny your appeal, Texas residents may submit a complaint to the Texas Attorney General at texasattorneygeneral.gov, and residents of other states may contact their state Attorney General.
California residents (CPRA notice)
The categories of personal information we collect are described in “Information we collect” above. This includes sensitive personal information — your health information and your coarse demographic baseline. We collect it from you directly, (if you install the Kite iPhone app and connect them) from the Apple Health, calendar, and reminder data on your own device, and (if you connect them) from the wearable services you authorize, and use it only for the business purposes of providing and supporting the Service described above, retain it for the periods described in “How long we keep your information,” and do not sell or share it, and do not use or disclose it to infer characteristics about you.
Because we use sensitive personal information only for those permitted purposes, California’s right to limit its use does not change our practices — but you may still contact us to make any California privacy request, including a request to know, access, correct, delete, or limit, at privacy@heykite.app, and we will not discriminate against you for exercising your rights. Under California’s “Shine the Light” law, we do not disclose personal information to third parties for their own direct marketing.