Consumer Health Data Privacy Policy

Kite Labs, Inc. · Effective August 4, 2026

This is Kite’s dedicated policy for “consumer health data.” It describes how Kite (operated by Kite Labs, Inc.) collects, uses, shares, and protects consumer health data and the rights you have over it. It is provided to meet Washington’s My Health My Data Act and similar consumer-health-data laws (including Nevada’s and Connecticut’s), and it supplements our Privacy Policy. We are not a HIPAA covered entity; we protect this data under these consumer laws and the FTC Health Breach Notification Rule.

What we mean by consumer health data

Information, linked or reasonably linkable to you, that identifies your (or a person you manage care for) past, present, or future physical or mental health status. For Kite, that is the health context you put in your texts, the few basics you ask us to remember, and, if you connect them, the Apple Health, calendar, and reminder data on your phone (through the Kite iPhone app), the history held by a wearable service you authorize (Oura, WHOOP, or Strava), and the observations we derive from any of it.

Categories of consumer health data we collect, and why

We collect the following categories, in each case to provide the service you asked for:
  • Health information you share in conversation — symptoms, conditions, medications and doses, allergies, vaccines, providers you see, and the contents of bills, lab results, or insurance documents you choose to send — so your agent can remember it, answer your questions with educational context, and help with logistics.
  • Photos and voice notes you choose to send (for example, a skin photo), stored as part of your record so your agent has the context you gave it.
  • Measurements and vitals you choose to log over time (for example, blood pressure, weight, blood sugar, or lab values), kept as a trend so your agent can show changes and help you prepare for visits.
  • A coarse demographic baseline you ask us to remember — your general home area (city and state), your year of birth, and, only when relevant to a screening, your sex — used to help find care near you and to surface age- and sex-appropriate preventive-screening information.
  • Care logistics you ask us to handle — reminders, referrals, and appointments (including, if you connect it, the calendar entries Kite adds and your free/busy availability) — used to carry out the tasks you request.

If you use the Kite iPhone app

The Kite app is optional. It exists to bring the health data already on your phone into your Kite conversation, so Kite can find patterns across it, text you a snapshot of what it noticed, and answer questions about your own numbers. You choose each source separately on the setup screen, you can continue without any of them, and iOS asks for its own permission on top of that. If you connect nothing, nothing on this list is collected.

Apple Health. When you grant Health access, we read and store the following sample types from the last 90 days and keep them current in the background: time asleep and sleep stages, heart rate, resting heart rate, heart rate variability, respiratory rate, steps, walking and running distance, active energy burned, exercise minutes, workouts (activity type, duration, and average heart rate), body mass, and mindful minutes. That is the whole list. Kite never writes anything to Apple Health.

Your device calendar. Events from every calendar account set up on your phone (iCloud, Google, Exchange, and any other), from the last 90 days through the next 30: the event title, the location field as you typed it, start and end time, whether it is all day, how many people are invited, whether it repeats, and its status. Kite never adds to or changes your calendar from the app.

Your reminders. Reminders from every list on your phone: the title, the due date, and when you completed it, including reminders you completed in the last 90 days.

What we derive from it. Daily summaries (for example your average sleep or steps for a day), and observations that describe a pattern across these sources, such as how your resting heart rate compares on days after a busy schedule. These observations are consumer health data too, and we treat them as such. They describe patterns, never causes, and they are not a diagnosis.

Event titles, event locations, reminder titles, and the text of every observation are encrypted at rest with keys we hold, separately from the rest of the record. We do not store the names of your calendars or reminder lists.

If you connect a wearable (Oura, WHOOP, Strava, Dexcom)

Wearable connections are optional and separate from the Kite app. You approve each one on the service’s own authorization page, and if you connect nothing, nothing here is collected. When you connect one, we read about 90 days of your history from that service and keep it current: from Oura and WHOOP, time asleep and sleep stages, resting heart rate, heart rate variability, respiratory rate, activity and energy burned, workouts, and body weight where the service provides it; from Strava, workouts and exercise time; from Dexcom, if you connect a continuous glucose monitor, your glucose readings and their trend. Kite only reads. It never writes to these services and never sends them anything we hold about you.

We derive the same daily summaries and pattern observations from this data as from the Kite app’s sources, and those observations are consumer health data too. The sign-in tokens the service gives us are encrypted at rest, and the text of every observation is encrypted at rest. To stop collection, tell your agent to disconnect the service or revoke Kite’s access in that service’s own account settings; to erase what we already hold, text DELETE, which also revokes our access with the service.

What we do not collect

We deliberately keep the profile you give us coarse. We do not ask for or store your street address, ZIP code, or full date of birth, we do not collect your device location, and we do not use geofences around any location that provides in-person health services. One honest exception: if you connect your device calendar in the Kite app, an event’s location field is imported exactly as you typed it, and people often type a street address there. Those values are encrypted at rest, are used only as part of that event record, and are erased when you delete your data.

Categories of sources

Every source is you. There are three categories:
  • You, directly: the text messages, photos, voice notes, and documents you send us, and the consent and details you provide at signup.
  • Your own device, through the optional Kite iPhone app and only after you connect each source: Apple Health (the HealthKit types listed above), the calendars set up on your phone, and your reminders. Apple's system permission prompts sit in front of all three, and you can revoke any of them in iOS Settings at any time.
  • A wearable service you authorize (Oura, WHOOP, Strava, or a Dexcom glucose monitor), which sends us the history described above only after you approve the connection on that service's own page. You can revoke the connection at any time, from Kite or from the service.

We also derive consumer health data from those sources, which is its own kind of collection under these laws: the daily summaries and pattern observations described above. We do not buy consumer health data about you, we do not obtain it from data brokers, and we do not receive it from anyone other than you, the device you connect, and the wearable services you authorize.

How we use it

To provide the service you asked for: to remember your information so you don’t repeat it, answer your health questions with educational context, help find care near you, surface age- and sex-appropriate preventive-screening information, and run the reminders, appointments, and logistics you request. If you connect the Kite iPhone app or a wearable service, we also use the data they send to compute your daily summaries and pattern observations, to text you those observations, and to answer your questions about your own numbers. We do not use it for anything else, and we do not use it to make decisions about you that produce legal or similarly significant effects. A small number of authorized team members may also review conversations when needed to support, troubleshoot, or secure the Service, under access controls, confidentiality obligations, and access logging. Separately, and only with your opt-in consent (we ask you directly, saying no changes nothing, and you can withdraw at any time), our team may review conversations to improve the Service, assisted by an AI analysis tool that is contractually barred from training on your data. We do not use your consumer health data for advertising, for profiling to serve ads, to train generalized AI models, or for any unrelated purpose.

Whether we sell or share consumer health data

We do not sell your consumer health data, and we never seek “authorizations” to sell it. We do not share it with advertisers, data brokers, or affiliates for marketing.

We share consumer health data only with the service providers (processors) that operate the Service on our behalf, by contract and strictly to deliver it. The categories of third parties are:

  • Cloud hosting, file storage, and database providers that store or serve the data (Amazon Web Services; Supabase; Railway; Vercel, which runs our website and renders the symptom charts we make for you).
  • AI model-processing providers that generate your agent’s replies and, only if you separately opt in, assist our team's review of conversations to improve the Service (Amazon Web Services / Amazon Bedrock, and Anthropic); both operate under commercial terms that prohibit using your messages to train their models.
  • Messaging providers that deliver the texts between you and your agent (Twilio for SMS; Sendblue for iMessage).
  • Where relevant to a task you request: a transcription and email provider for your own voice notes and documents (Amazon Web Services), and, only when you ask Kite to book an appointment, a browser-automation provider (Browserbase) and a computer-use AI model (Anthropic or OpenAI) used to submit the booking details you authorize (such as your name and phone number, plus your date of birth or insurance if the office requires them) to a provider’s scheduling page.
  • When you ask Kite to find or compare nearby care: Google’s Places service, which receives a provider’s name and address (never your health data) and returns that office’s public ratings and reviews.
  • When you ask to see what a condition looks like: Wikimedia Commons, which receives only the condition name (never your health data) and returns a public medical illustration.
  • If you connect Google Calendar: Google, limited to the appointments Kite adds and your free/busy availability, used only to provide those features. If you connect Gmail: Google, used only to send the specific emails you approve from your own address (a send-only permission; Kite cannot read your inbox).
  • Product-analytics and error-monitoring providers that receive only event counts and technical diagnostics — never the content of your messages or your health data.

This includes the data the Kite iPhone app sends. The daily summaries and pattern observations we derive from your Apple Health, calendar, and reminder data are sent to the AI model providers named above so your agent can write your snapshot in the thread and answer your follow-up questions. Every provider above is bound by contract to use your consumer health data only to deliver the Service to you, to protect it at least as well as this policy promises, and to delete it when we tell them to.

When a question needs current information, a third-party search provider receives only a generalized query with your name and identifying details removed — not your full messages. Where we work with de-identified data, we commit to never attempt to re-identify it, and we require the same commitment from anyone who receives it. We do not use geofences around any location that provides in-person health services.

Consent

We ask for your explicit opt-in consent to collect and use your consumer health data during signup, before we collect it, and we record that consent. We will not collect or share consumer health data beyond what is necessary to provide the Service you asked for without your separate consent, and we will never sell it.

The Kite iPhone app asks separately. Before it collects anything, it shows you what it will read, what it is for, the categories of providers that will handle it, and how to stop, and you tick a box to agree. We record that consent against your account with the version of the wording you saw. Ticking the box does not give any source access on its own: you pick each source afterward, and iOS asks its own permission for each one.

You may withdraw consent at any time. In the Kite app, tap “Disconnect this device” on the status screen and that phone immediately stops sending anything new. You can also turn off Kite’s access to Health, Calendars, or Reminders in iOS Settings, or delete the app. To erase what we already hold, text DELETE to your agent (see Your rights).

How long we keep it

For as long as your account is active, so your agent can remember it for you. Raw message transcripts and operational logs age out on a rolling basis; your distilled health memory, records, photos, logs, and the Apple Health, calendar, and reminder data the Kite app sends persist until you delete them or close your account. Disconnecting a device or turning a source off stops new data arriving; it does not by itself erase what we already have, so use the deletion right below for that. When you delete data, it also ages out of routine encrypted backups within 30 days.

Your rights

At any time, you can:
  • Confirm whether we collect, share, or sell your consumer health data, and access it.
  • Obtain a copy of your consumer health data.
  • Obtain a list of all third parties with whom we have shared your consumer health data, with a way to contact them.
  • Correct it — just tell your agent, and it updates.
  • Delete it. Text DELETE to your agent and your messages, health memory, saved basics, photos, logs, reminders, calendar events, and everything the Kite iPhone app sent us (Apple Health samples, device calendar events, device reminders, your daily summaries and observations, and the app's access to your account) are erased from our systems and from our encrypted backups within 30 days, and we direct our service providers to delete it as well.
  • Withdraw your consent to our collection and sharing of your consumer health data. For the Kite iPhone app, "Disconnect this device" on the status screen stops collection immediately, and you can also turn Kite's access off in iOS Settings. For a connected wearable, tell your agent to disconnect it, or revoke Kite's access in that service's own settings.
  • Appeal a denial of any of these requests.

To exercise any right, text your agent or email privacy@heykite.app. We will verify your request (typically by confirming control of your account phone number) and respond within the timeframes the applicable law requires. An authorized agent may submit a request on your behalf with proof of authorization. If we deny a request, you may appeal by replying with “Appeal” in the subject line; if we deny an appeal, you may complain to your state Attorney General.

Security

We restrict access to your consumer health data to what is needed to run the Service, protect it with encryption in transit and at rest, apply a second layer of encryption to the most revealing free text (event titles and locations, reminder titles, and the wording of your observations), and keep the demographic basics coarse on purpose so that, even in the unlikely event of a breach, the data is far less identifiable. The Kite app holds your sign-in credential in the iOS Keychain, on that device only, and stores no health data of its own once it has been sent. We never put health information in iCloud. If a breach affecting your health data occurs, we will notify you and the Federal Trade Commission (and, where required, the media) as the FTC Health Breach Notification Rule requires.

Contact

Kite Labs, Inc. · Texas, USA · privacy@heykite.app