Privacy Policy

Grounding LLC · Effective July 21, 2026

Health data is also covered by our Consumer Health Data Privacy Policy, the separate, dedicated policy required by Washington’s My Health My Data Act and similar laws. It describes the health data we collect, why, who we share it with, and your rights over it.

Who we are and what this covers

Kite is operated by Grounding LLC (“Kite,” “we,” “us”), based in Texas. This policy explains what information we collect when you use Kite — our text-message assistant and website — how we use and protect it, who we share it with, and the choices and rights you have. It applies to all U.S. users; specific state rights are described below, and health data is detailed in our Consumer Health Data Privacy Policy.

Text-messaging (SMS) program

Kite is delivered primarily over text message, operated by Grounding LLC. You opt in to receive texts by texting Kite first — Kite replies with the program terms and you reply YES to confirm you are 18+ and agree — or by entering your mobile number and checking the consent box on our sign-up page. Your mobile opt-in information and consent — your phone number and the fact that you opted in — are never shared with or sold to any third party, and no mobile information is shared with third parties or affiliates for marketing or promotional purposes. Information is shared only with the service providers that help us deliver the messaging service (such as our SMS carrier), strictly to operate it. Message frequency varies with your use; message and data rates may apply. Reply STOP to opt out, HELP for help; carriers are not liable for delayed or undelivered messages.

Information we collect

We collect only what we need to provide the Service:
  • Account information: your mobile phone number (your account identifier), an optional display name, your time zone, and your messaging channel preference.
  • The content you send: the messages, photos, and voice notes you choose to send, and the documents (such as bills, lab results, or insurance papers) you share.
  • Health information you share in conversation so your agent can remember it for you — for example, symptoms, conditions, medications, allergies, vaccines, and the providers you see. This is also covered by our Consumer Health Data Privacy Policy.
  • A coarse demographic baseline you ask us to remember: your general home area (city and state), your year of birth, and — only when relevant to a screening — your sex. We deliberately keep these coarse and do NOT store your precise street address, ZIP code, or full date of birth, and we do not track your device location.
  • Care logistics you ask us to handle: reminders, referrals, appointments, and (if you connect it) limited Google Calendar data — see below.
  • Billing information if you subscribe: handled by our payment processor, Stripe; we store a customer identifier, not your full card number.
  • Limited technical and usage data: counts and events about how the Service is used (never the content of your messages), and consent records (including the time, version, and where you gave it — on our website, or by your reply in the text thread; website consents also record the IP address and device/browser used).

How and why we use your information

We use your information solely to provide and improve the Service for you:
  • To run the conversation and remember what you tell us, so you don’t have to repeat yourself.
  • To answer your questions with educational context, using AI models that process your messages to generate replies.
  • To use your saved home area to help find care near you, and your year of birth and sex to surface age- and sex-appropriate preventive-screening information — never for advertising.
  • To take actions you ask for — finding providers, attempting bookings, calendar events, reminders, and emailing you documents we generate.
  • To operate, secure, troubleshoot, and improve the Service, prevent abuse, and comply with law. A small number of authorized team members may review conversations when needed to support, troubleshoot, or secure the Service, under access controls, confidentiality obligations, and access logging.
  • Reviewing conversations to improve the product happens only if you separately opt in. We ask you directly, saying no changes nothing about the Service, and you can change your mind at any time by telling your agent.

Consent

Before we collect the health information you share, we ask for your explicit opt-in consent when you start — on our website, or by your reply in the text thread when you text Kite first — and we record it. The one exception is that we may hold and act on a message you send us to the extent needed to respond to that message, which is the service you asked for by texting us. You can withdraw consent at any time (see Your rights and Deleting your data). We will not use your information for a materially new purpose — such as advertising, selling, sharing for others’ marketing, or training generalized AI models — without first obtaining your separate, explicit consent.

What we never do

We do not sell your personal information or your health data. We do not share it with advertisers, data brokers, or affiliates for marketing. We do not show you ads or use your information for targeted advertising or profiling that produces legal or similarly significant effects. We do not use your health information to train generalized AI models. And we do not use geofencing around any health facility.

Who we share information with (service providers)

We share information only with vendors that process it on our behalf, under contract, strictly to operate the Service — never for their own marketing. These fall into the following categories:
  • Cloud hosting, storage, and database: Amazon Web Services (AI processing and file storage), Supabase (our database), and Railway (application hosting).
  • AI model processing: Amazon Web Services (Amazon Bedrock) and Anthropic, which run the models that generate replies and that, only if you separately opt in, help our team review conversations to improve the Service. Both process your messages under commercial terms that prohibit using them to train their models.
  • Messaging delivery: our SMS carrier (Twilio) and our iMessage relay (Sendblue), which deliver texts between you and your agent.
  • Payments: Stripe, which processes subscription billing.
  • Calendar and email (only if you connect them): Google, as described below.
  • Web search for current information: a third-party search provider (Exa), which receives only a generalized query with your name and identifying details removed — not your full messages — and an optional re-ranking provider (Voyage) that re-orders the public search results for relevance and receives the generalized query and those results, not your identity.
  • Finding and comparing care: when you ask Kite to find or compare nearby doctors, we send a provider’s name and address (never your personal information) to Google’s Places service to retrieve that office’s public ratings and reviews.
  • Reference images: when you ask to see what a condition looks like, we send only the condition name (never your personal information) to Wikimedia Commons to fetch a public medical illustration.
  • Voice-note transcription and outbound email of your own documents: Amazon Web Services (Transcribe and SES).
  • Product analytics and error monitoring: providers that receive event counts and diagnostics only, never the content of your messages or your health data.
  • Appointment booking automation (only when you ask us to book): a browser-automation provider (Browserbase) and a computer-use AI model (from Anthropic or OpenAI) used to submit the booking details you authorize (such as your name and phone number, plus your date of birth or insurance if the office requires them) to a provider’s scheduling page.
We may also disclose information if required by law or to protect the rights, safety, and security of our users or the Service, and we may transfer information as part of a merger, acquisition, or sale of assets (with notice as required). Grounding LLC has no corporate affiliates with whom we share your data.

Google user data (Calendar, Gmail, and Places)

If you choose to connect Google Calendar, Kite accesses only your free/busy availability and the events on the dedicated calendar Kite creates in your account — it cannot read your other calendars. We use this data only to add the appointments you ask us to and to suggest times that don’t conflict with your schedule. We store the access we’re granted in encrypted form, and you can disconnect at any time. If you connect Gmail, Kite can send emails you explicitly approve from your own address (for example, a records request to a provider’s office). It uses a send-only permission, cannot read your inbox, and only sends after you confirm the recipient and the content. Separately, when you ask Kite to find or compare nearby care, it sends a provider’s name and address (never your personal information) to Google’s Places service to retrieve that office’s public ratings and reviews. Kite’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, do not sell it, do not share it except to provide these features to you, and do not use it to train generalized AI models.

How we protect your privacy by design

We minimize what we collect and reduce its sensitivity wherever we can. When a question needs current information, the search query we send out is generalized to remove your name and identifying details and is not your full message text. We keep your demographic baseline coarse on purpose (city/state and birth year rather than precise address or full date of birth) so the data is far less identifiable. And our analytics record only events and counts — never the content of your messages, your health information, or your photos.

How long we keep your information

We keep information only as long as needed to provide the Service:
  • Your distilled health memory and records (the saved facts, symptom and measurement logs, photos, profiles, and reminders that ARE the service) are kept for the life of your account, so your agent can remember them — until you delete them or close your account.
  • Raw message transcripts age out on a rolling basis (currently about 18 months); operational logs are kept for about 90 days.
  • Short-lived caches (such as general web-search and drug-information lookups, which are not tied to your identity) expire on their own within days.
  • Billing records are retained as required for tax, accounting, and legal purposes.
When you delete data, we also direct our service providers to delete it, and it ages out of routine encrypted backups within 30 days.

Security

We protect your information with administrative and technical safeguards, including encryption in transit and at rest, additional encryption of especially sensitive credentials (such as calendar access tokens), access controls and least-privilege permissions, and signature verification on incoming requests. No system is perfectly secure, but we work to keep your data safe and to limit who can access it to what is needed to run the Service.

Deleting your data

You can erase your data at any time by texting DELETE to your agent. This erases your messages, health memory, saved details, photos, symptom and measurement logs, reminders, and calendar events from our systems, and we direct our service providers to delete it as well. You can also email privacy@grounding.dev.

Your privacy rights

Depending on where you live, you may have rights to know about and access the personal information we hold about you, to obtain a copy (portability), to correct it, to delete it, to withdraw consent, and to opt out of any sale, sharing for targeted advertising, or certain profiling. We do not sell or share your information for targeted advertising or use it for such profiling, so there is nothing to opt out of — but you may still exercise your other rights. California residents have the right to limit the use of sensitive personal information (we already limit health data to providing the Service) and, under “Shine the Light,” to ask about disclosures for third-party direct marketing — we make none.

To exercise any right, text your agent or email privacy@grounding.dev — two reliable methods to reach us. We will verify your request (typically by confirming control of your account phone number) and respond within the time the applicable law requires (generally 45 days, extendable once when reasonably necessary). An authorized agent may submit a request with proof of authorization.

Appeals. If we deny your request, you may appeal by emailing privacy@grounding.dev with “Appeal” in the subject line. We will respond in writing within 60 days. If we deny your appeal, Texas residents may submit a complaint to the Texas Attorney General at texasattorneygeneral.gov, and residents of other states may contact their state Attorney General.

California residents (CPRA notice)

The categories of personal information we collect are described in “Information we collect” above. This includes sensitive personal information — your health information and your coarse demographic baseline. We collect it from you directly, use it only for the business purposes of providing and supporting the Service described above, retain it for the periods described in “How long we keep your information,” and do not sell or share it, and do not use or disclose it to infer characteristics about you.

Because we use sensitive personal information only for those permitted purposes, California’s right to limit its use does not change our practices — but you may still contact us to make any California privacy request, including a request to know, access, correct, delete, or limit, at privacy@grounding.dev, and we will not discriminate against you for exercising your rights. Under California’s “Shine the Light” law, we do not disclose personal information to third parties for their own direct marketing.

Children's privacy

The Service is intended for adults 18 and older and is not directed to children under 13. We do not knowingly collect personal information directly from children under 13. If you use Kite to help manage a dependent’s care, you — the adult account holder — are providing that information and are responsible for it; the dependent is not a user. If we learn we have collected information directly from a child under 13, we will delete it; to request review or deletion of a child’s information, email privacy@grounding.dev.

Data breach notification

We are not a HIPAA covered entity. As a consumer service that handles health information, we are subject to the FTC’s Health Breach Notification Rule. If a breach affecting your health information occurs, we will notify you, and the Federal Trade Commission (and, where required, the media), within the timeframes the Rule requires.

Not a healthcare provider

We are not a healthcare provider, and the Service does not provide medical diagnosis or treatment. We are not a HIPAA covered entity or business associate; we protect your information under the consumer protections described here and applicable state and federal law.

U.S. only

The Service is intended for users in the United States, and your information is processed in the United States. We do not offer the Service to users outside the U.S.

Changes to this policy

We may update this policy from time to time. If we make material changes, we will provide reasonable notice (for example, by text, email, or a notice on our website) and update the effective date above. Your continued use of the Service after changes take effect means you accept the updated policy.

Contact

Grounding LLC · Texas, USA · privacy@grounding.dev