Privacy Policy

Kite Labs, Inc. · Effective August 4, 2026

As of July 28, 2026, Kite is operated by Kite Labs, Inc. (previously Grounding LLC). Our privacy practices are unchanged.

Health data is also covered by our Consumer Health Data Privacy Policy, the separate, dedicated policy required by Washington’s My Health My Data Act and similar laws. It describes the health data we collect, why, who we share it with, and your rights over it.

Who we are and what this covers

Kite is operated by Kite Labs, Inc. (“Kite,” “we,” “us”), based in Texas. This policy explains what information we collect when you use Kite — our text-message assistant and website — how we use and protect it, who we share it with, and the choices and rights you have. “Kite” here means the text-message assistant, this website, and the optional Kite iPhone app. It applies to all U.S. users; specific state rights are described below, and health data is detailed in our Consumer Health Data Privacy Policy.

Text-messaging (SMS) program

Kite is delivered primarily over text message, operated by Kite Labs, Inc. You opt in to receive texts by texting Kite first — Kite replies with the program terms and you reply YES to confirm you are 18+ and agree — or by entering your mobile number and checking the consent box on our sign-up page. Your mobile opt-in information and consent — your phone number and the fact that you opted in — are never shared with or sold to any third party, and no mobile information is shared with third parties or affiliates for marketing or promotional purposes. Information is shared only with the service providers that help us deliver the messaging service (such as our SMS carrier), strictly to operate it. Message frequency varies with your use; message and data rates may apply. Reply STOP to opt out, HELP for help; carriers are not liable for delayed or undelivered messages.

Information we collect

We collect only what we need to provide the Service:
  • Account information: your mobile phone number (your account identifier), an optional display name, your time zone, and your messaging channel preference.
  • The content you send: the messages, photos, and voice notes you choose to send, and the documents (such as bills, lab results, or insurance papers) you share.
  • Health information you share in conversation so your agent can remember it for you — for example, symptoms, conditions, medications, allergies, vaccines, and the providers you see. This is also covered by our Consumer Health Data Privacy Policy.
  • A coarse demographic baseline you ask us to remember: your general home area (city and state), your year of birth, and — only when relevant to a screening — your sex. We deliberately keep these coarse and do NOT store your precise street address, ZIP code, or full date of birth, and we do not track your device location.
  • Care logistics you ask us to handle: reminders, referrals, appointments, and (if you connect it) limited Google Calendar data — see below.
  • If you install the optional Kite iPhone app and connect them: Apple Health data, the events on the calendars set up on your phone, and your reminders, plus the daily summaries and pattern observations we derive from them. The exact data types are listed in “The Kite iPhone app” below.
  • If you connect a wearable service (Oura, WHOOP, Strava, or a Dexcom glucose monitor): the health and activity history that service holds for you, retrieved with your authorization through its official interface. The exact data types are listed in “Connected wearables” below.
  • Billing information if you subscribe: handled by our payment processor, Stripe; we store a customer identifier, not your full card number.
  • Limited technical and usage data: counts and events about how the Service is used (never the content of your messages), and consent records (including the time, version, and where you gave it — on our website, or by your reply in the text thread; website consents also record the IP address and device/browser used).

How and why we use your information

We use your information solely to provide and improve the Service for you:
  • To run the conversation and remember what you tell us, so you don’t have to repeat yourself.
  • To answer your questions with educational context, using AI models that process your messages to generate replies.
  • To use your saved home area to help find care near you, and your year of birth and sex to surface age- and sex-appropriate preventive-screening information — never for advertising.
  • To take actions you ask for — finding providers, attempting bookings, calendar events, reminders, and emailing you documents we generate.
  • If you use the Kite iPhone app or connect a wearable service: to compute daily summaries and pattern observations from the data you connect, text you what we noticed, and answer your questions about your own numbers.
  • To operate, secure, troubleshoot, and improve the Service, prevent abuse, and comply with law. A small number of authorized team members may review conversations when needed to support, troubleshoot, or secure the Service, under access controls, confidentiality obligations, and access logging.
  • Reviewing conversations to improve the product happens only if you separately opt in. We ask you directly, saying no changes nothing about the Service, and you can change your mind at any time by telling your agent.

Consent

Before we collect the health information you share, we ask for your explicit opt-in consent when you start — on our website, or by your reply in the text thread when you text Kite first — and we record it. The one exception is that we may hold and act on a message you send us to the extent needed to respond to that message, which is the service you asked for by texting us. The Kite iPhone app asks separately, before it collects anything: it shows you what it will read, what it is for, the categories of providers that will handle it, and how to stop, and you tick a box to agree. We record that consent with the version of the wording you saw. You can withdraw consent at any time (see Your rights and Deleting your data). We will not use your information for a materially new purpose — such as advertising, selling, sharing for others’ marketing, or training generalized AI models — without first obtaining your separate, explicit consent.

What we never do

We do not sell your personal information or your health data. We do not share it with advertisers, data brokers, or affiliates for marketing. We do not show you ads or use your information for targeted advertising or profiling that produces legal or similarly significant effects. We do not use your health information to train generalized AI models. And we do not use geofencing around any health facility.

Who we share information with (service providers)

We share information only with vendors that process it on our behalf, under contract, strictly to operate the Service — never for their own marketing. These fall into the following categories:
  • Cloud hosting, storage, and database: Amazon Web Services (AI processing and file storage), Supabase (our database), Railway (application hosting), and Vercel (our website, including the pages and charts we generate for you).
  • AI model processing: Amazon Web Services (Amazon Bedrock) and Anthropic, which run the models that generate replies and that, only if you separately opt in, help our team review conversations to improve the Service. Both process your messages under commercial terms that prohibit using them to train their models.
  • Messaging delivery: our SMS carrier (Twilio) and our iMessage relay (Sendblue), which deliver texts between you and your agent.
  • Payments: Stripe, which processes subscription billing.
  • Calendar and email (only if you connect them): Google, as described below.
  • Web search for current information: a third-party search provider (Exa), which receives only a generalized query with your name and identifying details removed — not your full messages — and an optional re-ranking provider (Voyage) that re-orders the public search results for relevance and receives the generalized query and those results, not your identity.
  • Finding and comparing care: when you ask Kite to find or compare nearby doctors, we send a provider’s name and address (never your personal information) to Google’s Places service to retrieve that office’s public ratings and reviews.
  • Reference images: when you ask to see what a condition looks like, we send only the condition name (never your personal information) to Wikimedia Commons to fetch a public medical illustration.
  • Voice-note transcription and outbound email of your own documents: Amazon Web Services (Transcribe and SES).
  • Product analytics and error monitoring: providers that receive event counts and diagnostics only, never the content of your messages or your health data.
  • Appointment booking automation (only when you ask us to book): a browser-automation provider (Browserbase) and a computer-use AI model (from Anthropic or OpenAI) used to submit the booking details you authorize (such as your name and phone number, plus your date of birth or insurance if the office requires them) to a provider’s scheduling page.
Every provider above is bound by a written contract to process your information only on our instructions, to protect it at least as well as this policy promises, and to delete it when we tell them to. None of them may use it for their own purposes. We may also disclose information if required by law or to protect the rights, safety, and security of our users or the Service, and we may transfer information as part of a merger, acquisition, reorganization or corporate restructuring, or sale of assets (with notice as required).

The Kite iPhone app

The Kite app is optional, and everything it collects is something you connect on purpose. It brings health data that is already on your phone into your Kite conversation so your agent can find patterns across it, text you a snapshot of what it noticed, and answer questions about your own numbers. Each source is a separate choice, you can continue without any of them, and iOS asks for its own permission on top of ours. The app never writes to Apple Health and never adds to or changes your calendar.

Apple Health. With your permission we read and store these sample types, from the last 90 days and then kept current in the background: time asleep and sleep stages, heart rate, resting heart rate, heart rate variability, respiratory rate, steps, walking and running distance, active energy burned, exercise minutes, workouts (activity type, duration, and average heart rate), body mass, and mindful minutes. That is the complete list.

Device calendar. Events from every calendar account set up on your phone, covering the last 90 days through the next 30: title, the location field as you typed it, start and end time, all-day flag, number of invitees, whether it repeats, and status.

Reminders. Reminders from every list on your phone: title, due date, and completion time, including ones completed in the last 90 days.

What we do with it. We compute daily summaries and pattern observations, and your agent texts you about them and answers your questions. Producing those messages means the observations are processed by the AI model providers named above, under contracts that bar training on your data. We never use any of it for advertising, never sell it, never share it with data brokers, and never put it in iCloud. Event titles, event locations, reminder titles, and the wording of your observations are encrypted at rest. We do not store the names of your calendars or reminder lists.

Stopping and deleting. Tap “Disconnect this device” on the app’s status screen and that phone stops sending immediately. You can also turn off Kite’s access to Health, Calendars, or Reminders in iOS Settings, or delete the app. To erase what we already hold, text DELETE to your agent, which removes the health samples, calendar events, reminders, summaries, and observations along with the rest of your data.

Connected wearables (Oura, WHOOP, Strava, Dexcom)

You can connect a wearable service to Kite from your conversation: you tap a link we text you, approve access on that service’s own page, and Kite then reads about 90 days of your history and keeps it current. Each connection is optional, separate, and yours to revoke. Kite only reads; it never writes anything to these services, and it never sends them your Kite conversations or any other data we hold about you.

What we read. From Oura and WHOOP: time asleep and sleep stages, resting heart rate, heart rate variability, respiratory rate, activity and energy burned, workouts, and body weight where the service provides it. From Strava: workouts and exercise time. From Dexcom, if you connect a continuous glucose monitor: your glucose readings and their trend. We store the sign-in tokens these services give us in encrypted form, and we use the data exactly as we use Apple Health data from the Kite app: to compute your daily summaries and pattern observations and to answer your questions. It is never used for advertising, never sold, and never shared with data brokers.

Disconnecting. Tell your agent to disconnect the service (for example, “disconnect my Oura”) and collection stops immediately: we revoke our own access with the service where it supports that, and stop all syncing either way. You can also revoke Kite’s access from your account settings at the service itself. Disconnecting stops new data; to erase what we already hold, text DELETE. Your relationship with the wearable service itself is governed by that service’s own privacy policy.

Google user data (Calendar, Gmail, and Places)

If you choose to connect Google Calendar to your Kite account, that connection is narrow by design: Kite accesses only your free/busy availability and the events on the dedicated calendar Kite creates in your account, and it cannot read the other calendars in your Google account. That limit describes the Google connection specifically. It is separate from the Kite iPhone app, which reads the calendars set up on your phone when you grant it calendar access, as described above. We use Google Calendar data only to add the appointments you ask us to and to suggest times that don’t conflict with your schedule. We store the access we’re granted in encrypted form, and you can disconnect at any time. If you connect Gmail, Kite can send emails you explicitly approve from your own address (for example, a records request to a provider’s office). It uses a send-only permission, cannot read your inbox, and only sends after you confirm the recipient and the content. Separately, when you ask Kite to find or compare nearby care, it sends a provider’s name and address (never your personal information) to Google’s Places service to retrieve that office’s public ratings and reviews. Kite’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, do not sell it, do not share it except to provide these features to you, and do not use it to train generalized AI models.

How we protect your privacy by design

We minimize what we collect and reduce its sensitivity wherever we can. When a question needs current information, the search query we send out is generalized to remove your name and identifying details and is not your full message text. We keep your demographic baseline coarse on purpose (city/state and birth year rather than precise address or full date of birth) so the data is far less identifiable. And our analytics record only events and counts — never the content of your messages, your health information, or your photos.

How long we keep your information

We keep information only as long as needed to provide the Service:
  • Your distilled health memory and records (the saved facts, symptom and measurement logs, photos, profiles, and reminders that ARE the service) are kept for the life of your account, so your agent can remember them — until you delete them or close your account.
  • Data from the Kite iPhone app (Apple Health samples, device calendar events, device reminders) and from connected wearables (Oura, WHOOP, Strava), plus the daily summaries and observations we derive from it, are kept for the life of your account, so your agent can compare what is happening now with your own history. Disconnecting a device or service stops new data arriving; text DELETE to erase what we already hold.
  • Raw message transcripts age out on a rolling basis (currently about 18 months); operational logs are kept for about 90 days.
  • Short-lived caches (such as general web-search and drug-information lookups, which are not tied to your identity) expire on their own within days.
  • Billing records are retained as required for tax, accounting, and legal purposes.
When you delete data, we also direct our service providers to delete it, and it ages out of routine encrypted backups within 30 days.

Security

We protect your information with administrative and technical safeguards, including encryption in transit and at rest, additional encryption of especially sensitive credentials (such as calendar access tokens), access controls and least-privilege permissions, and signature verification on incoming requests. No system is perfectly secure, but we work to keep your data safe and to limit who can access it to what is needed to run the Service.

Deleting your data and withdrawing consent

You can erase your data at any time by texting DELETE to your agent. This erases your messages, health memory, saved details, photos, symptom and measurement logs, reminders, and calendar events from our systems, along with everything the Kite iPhone app sent us: Apple Health samples, device calendar events, device reminders, your daily summaries and observations, and that device’s access to your account. It also erases everything a connected wearable sent us and revokes Kite’s access with the wearable service itself. We direct our service providers to delete it as well, and it ages out of routine encrypted backups within 30 days. You can also email privacy@heykite.app.

To withdraw consent without deleting: reply STOP in the thread to stop the texts; in the Kite iPhone app tap “Disconnect this device” on the status screen, or turn off Kite’s access to Health, Calendars, or Reminders in iOS Settings; and for a connected wearable, tell your agent to disconnect it or revoke Kite’s access in that service’s own settings. Any of these stops further collection right away.

Your privacy rights

Depending on where you live, you may have rights to know about and access the personal information we hold about you, to obtain a copy (portability), to correct it, to delete it, to withdraw consent, and to opt out of any sale, sharing for targeted advertising, or certain profiling. We do not sell or share your information for targeted advertising or use it for such profiling, so there is nothing to opt out of — but you may still exercise your other rights. California residents have the right to limit the use of sensitive personal information (we already limit health data to providing the Service) and, under “Shine the Light,” to ask about disclosures for third-party direct marketing — we make none.

To exercise any right, text your agent or email privacy@heykite.app — two reliable methods to reach us. We will verify your request (typically by confirming control of your account phone number) and respond within the time the applicable law requires (generally 45 days, extendable once when reasonably necessary). An authorized agent may submit a request with proof of authorization.

Appeals. If we deny your request, you may appeal by emailing privacy@heykite.app with “Appeal” in the subject line. We will respond in writing within 60 days. If we deny your appeal, Texas residents may submit a complaint to the Texas Attorney General at texasattorneygeneral.gov, and residents of other states may contact their state Attorney General.

California residents (CPRA notice)

The categories of personal information we collect are described in “Information we collect” above. This includes sensitive personal information — your health information and your coarse demographic baseline. We collect it from you directly, (if you install the Kite iPhone app and connect them) from the Apple Health, calendar, and reminder data on your own device, and (if you connect them) from the wearable services you authorize, and use it only for the business purposes of providing and supporting the Service described above, retain it for the periods described in “How long we keep your information,” and do not sell or share it, and do not use or disclose it to infer characteristics about you.

Because we use sensitive personal information only for those permitted purposes, California’s right to limit its use does not change our practices — but you may still contact us to make any California privacy request, including a request to know, access, correct, delete, or limit, at privacy@heykite.app, and we will not discriminate against you for exercising your rights. Under California’s “Shine the Light” law, we do not disclose personal information to third parties for their own direct marketing.

Children's privacy

The Service is intended for adults 18 and older and is not directed to children under 13. We do not knowingly collect personal information directly from children under 13. If you use Kite to help manage a dependent’s care, you — the adult account holder — are providing that information and are responsible for it; the dependent is not a user. If we learn we have collected information directly from a child under 13, we will delete it; to request review or deletion of a child’s information, email privacy@heykite.app.

Data breach notification

We are not a HIPAA covered entity. As a consumer service that handles health information, we are subject to the FTC’s Health Breach Notification Rule. If a breach affecting your health information occurs, we will notify you, and the Federal Trade Commission (and, where required, the media), within the timeframes the Rule requires.

Not a healthcare provider

We are not a healthcare provider, and the Service does not provide medical diagnosis or treatment. We are not a HIPAA covered entity or business associate; we protect your information under the consumer protections described here and applicable state and federal law.

U.S. only

The Service is intended for users in the United States, and your information is processed in the United States. We do not offer the Service to users outside the U.S.

Changes to this policy

We may update this policy from time to time. If we make material changes, we will provide reasonable notice (for example, by text, email, or a notice on our website) and update the effective date above. Your continued use of the Service after changes take effect means you accept the updated policy.

Contact

Kite Labs, Inc. · Texas, USA · privacy@heykite.app