Consumer Health Data Privacy Policy
Kite Labs, Inc. · Effective August 4, 2026
This is Kite’s dedicated policy for “consumer health data.” It describes how Kite (operated by Kite Labs, Inc.) collects, uses, shares, and protects consumer health data and the rights you have over it. It is provided to meet Washington’s My Health My Data Act and similar consumer-health-data laws (including Nevada’s and Connecticut’s), and it supplements our Privacy Policy. We are not a HIPAA covered entity; we protect this data under these consumer laws and the FTC Health Breach Notification Rule.
What we mean by consumer health data
Categories of consumer health data we collect, and why
- Health information you share in conversation — symptoms, conditions, medications and doses, allergies, vaccines, providers you see, and the contents of bills, lab results, or insurance documents you choose to send — so your agent can remember it, answer your questions with educational context, and help with logistics.
- Photos and voice notes you choose to send (for example, a skin photo), stored as part of your record so your agent has the context you gave it.
- Measurements and vitals you choose to log over time (for example, blood pressure, weight, blood sugar, or lab values), kept as a trend so your agent can show changes and help you prepare for visits.
- A coarse demographic baseline you ask us to remember — your general home area (city and state), your year of birth, and, only when relevant to a screening, your sex — used to help find care near you and to surface age- and sex-appropriate preventive-screening information.
- Care logistics you ask us to handle — reminders, referrals, and appointments (including, if you connect it, the calendar entries Kite adds and your free/busy availability) — used to carry out the tasks you request.
If you use the Kite iPhone app
The Kite app is optional. It exists to bring the health data already on your phone into your Kite conversation, so Kite can find patterns across it, text you a snapshot of what it noticed, and answer questions about your own numbers. You choose each source separately on the setup screen, you can continue without any of them, and iOS asks for its own permission on top of that. If you connect nothing, nothing on this list is collected.
Apple Health. When you grant Health access, we read and store the following sample types from the last 90 days and keep them current in the background: time asleep and sleep stages, heart rate, resting heart rate, heart rate variability, respiratory rate, steps, walking and running distance, active energy burned, exercise minutes, workouts (activity type, duration, and average heart rate), body mass, and mindful minutes. That is the whole list. Kite never writes anything to Apple Health.
Your device calendar. Events from every calendar account set up on your phone (iCloud, Google, Exchange, and any other), from the last 90 days through the next 30: the event title, the location field as you typed it, start and end time, whether it is all day, how many people are invited, whether it repeats, and its status. Kite never adds to or changes your calendar from the app.
Your reminders. Reminders from every list on your phone: the title, the due date, and when you completed it, including reminders you completed in the last 90 days.
What we derive from it. Daily summaries (for example your average sleep or steps for a day), and observations that describe a pattern across these sources, such as how your resting heart rate compares on days after a busy schedule. These observations are consumer health data too, and we treat them as such. They describe patterns, never causes, and they are not a diagnosis.
Event titles, event locations, reminder titles, and the text of every observation are encrypted at rest with keys we hold, separately from the rest of the record. We do not store the names of your calendars or reminder lists.
If you connect a wearable (Oura, WHOOP, Strava, Dexcom)
Wearable connections are optional and separate from the Kite app. You approve each one on the service’s own authorization page, and if you connect nothing, nothing here is collected. When you connect one, we read about 90 days of your history from that service and keep it current: from Oura and WHOOP, time asleep and sleep stages, resting heart rate, heart rate variability, respiratory rate, activity and energy burned, workouts, and body weight where the service provides it; from Strava, workouts and exercise time; from Dexcom, if you connect a continuous glucose monitor, your glucose readings and their trend. Kite only reads. It never writes to these services and never sends them anything we hold about you.
We derive the same daily summaries and pattern observations from this data as from the Kite app’s sources, and those observations are consumer health data too. The sign-in tokens the service gives us are encrypted at rest, and the text of every observation is encrypted at rest. To stop collection, tell your agent to disconnect the service or revoke Kite’s access in that service’s own account settings; to erase what we already hold, text DELETE, which also revokes our access with the service.
What we do not collect
Categories of sources
- You, directly: the text messages, photos, voice notes, and documents you send us, and the consent and details you provide at signup.
- Your own device, through the optional Kite iPhone app and only after you connect each source: Apple Health (the HealthKit types listed above), the calendars set up on your phone, and your reminders. Apple's system permission prompts sit in front of all three, and you can revoke any of them in iOS Settings at any time.
- A wearable service you authorize (Oura, WHOOP, Strava, or a Dexcom glucose monitor), which sends us the history described above only after you approve the connection on that service's own page. You can revoke the connection at any time, from Kite or from the service.
We also derive consumer health data from those sources, which is its own kind of collection under these laws: the daily summaries and pattern observations described above. We do not buy consumer health data about you, we do not obtain it from data brokers, and we do not receive it from anyone other than you, the device you connect, and the wearable services you authorize.
How we use it
Whether we sell or share consumer health data
We do not sell your consumer health data, and we never seek “authorizations” to sell it. We do not share it with advertisers, data brokers, or affiliates for marketing.
We share consumer health data only with the service providers (processors) that operate the Service on our behalf, by contract and strictly to deliver it. The categories of third parties are:
- Cloud hosting, file storage, and database providers that store or serve the data (Amazon Web Services; Supabase; Railway; Vercel, which runs our website and renders the symptom charts we make for you).
- AI model-processing providers that generate your agent’s replies and, only if you separately opt in, assist our team's review of conversations to improve the Service (Amazon Web Services / Amazon Bedrock, and Anthropic); both operate under commercial terms that prohibit using your messages to train their models.
- Messaging providers that deliver the texts between you and your agent (Twilio for SMS; Sendblue for iMessage).
- Where relevant to a task you request: a transcription and email provider for your own voice notes and documents (Amazon Web Services), and, only when you ask Kite to book an appointment, a browser-automation provider (Browserbase) and a computer-use AI model (Anthropic or OpenAI) used to submit the booking details you authorize (such as your name and phone number, plus your date of birth or insurance if the office requires them) to a provider’s scheduling page.
- When you ask Kite to find or compare nearby care: Google’s Places service, which receives a provider’s name and address (never your health data) and returns that office’s public ratings and reviews.
- When you ask to see what a condition looks like: Wikimedia Commons, which receives only the condition name (never your health data) and returns a public medical illustration.
- If you connect Google Calendar: Google, limited to the appointments Kite adds and your free/busy availability, used only to provide those features. If you connect Gmail: Google, used only to send the specific emails you approve from your own address (a send-only permission; Kite cannot read your inbox).
- Product-analytics and error-monitoring providers that receive only event counts and technical diagnostics — never the content of your messages or your health data.
This includes the data the Kite iPhone app sends. The daily summaries and pattern observations we derive from your Apple Health, calendar, and reminder data are sent to the AI model providers named above so your agent can write your snapshot in the thread and answer your follow-up questions. Every provider above is bound by contract to use your consumer health data only to deliver the Service to you, to protect it at least as well as this policy promises, and to delete it when we tell them to.
When a question needs current information, a third-party search provider receives only a generalized query with your name and identifying details removed — not your full messages. Where we work with de-identified data, we commit to never attempt to re-identify it, and we require the same commitment from anyone who receives it. We do not use geofences around any location that provides in-person health services.
Consent
We ask for your explicit opt-in consent to collect and use your consumer health data during signup, before we collect it, and we record that consent. We will not collect or share consumer health data beyond what is necessary to provide the Service you asked for without your separate consent, and we will never sell it.
The Kite iPhone app asks separately. Before it collects anything, it shows you what it will read, what it is for, the categories of providers that will handle it, and how to stop, and you tick a box to agree. We record that consent against your account with the version of the wording you saw. Ticking the box does not give any source access on its own: you pick each source afterward, and iOS asks its own permission for each one.
You may withdraw consent at any time. In the Kite app, tap “Disconnect this device” on the status screen and that phone immediately stops sending anything new. You can also turn off Kite’s access to Health, Calendars, or Reminders in iOS Settings, or delete the app. To erase what we already hold, text DELETE to your agent (see Your rights).
How long we keep it
Your rights
- Confirm whether we collect, share, or sell your consumer health data, and access it.
- Obtain a copy of your consumer health data.
- Obtain a list of all third parties with whom we have shared your consumer health data, with a way to contact them.
- Correct it — just tell your agent, and it updates.
- Delete it. Text DELETE to your agent and your messages, health memory, saved basics, photos, logs, reminders, calendar events, and everything the Kite iPhone app sent us (Apple Health samples, device calendar events, device reminders, your daily summaries and observations, and the app's access to your account) are erased from our systems and from our encrypted backups within 30 days, and we direct our service providers to delete it as well.
- Withdraw your consent to our collection and sharing of your consumer health data. For the Kite iPhone app, "Disconnect this device" on the status screen stops collection immediately, and you can also turn Kite's access off in iOS Settings. For a connected wearable, tell your agent to disconnect it, or revoke Kite's access in that service's own settings.
- Appeal a denial of any of these requests.
To exercise any right, text your agent or email privacy@heykite.app. We will verify your request (typically by confirming control of your account phone number) and respond within the timeframes the applicable law requires. An authorized agent may submit a request on your behalf with proof of authorization. If we deny a request, you may appeal by replying with “Appeal” in the subject line; if we deny an appeal, you may complain to your state Attorney General.