Consumer Health Data Privacy Policy
This notice explains how Kai Research Inc. collects, uses, and shares consumer health data and how you can exercise applicable rights under US state consumer health privacy laws, including Washington's My Health My Data Act and Nevada's consumer health data law. It covers information linked or reasonably linkable to you that identifies health status, health-related activities, or other information protected by those laws, including relevant inferences.
Kai's products are in development. The categories below apply to the available features you use, information you provide, and connections you authorize. A product description does not mean every category is collected from every person. This notice does not itself give consent to collect or share information.
1. Consumer health data we collect and why
| Category | Purposes |
|---|---|
| Body and training information, including measurements, body composition, progress photos, workouts, activity, routes, sensor readings, and performance | Record your activity, support your plans, review progress, and provide the training features you request |
| Nutrition information, including meals, images, hydration, dietary restrictions, allergies, and nutritional goals | Provide food logging, planning, estimates, and nutrition insights you request |
| Sleep, heart rate, recovery, symptoms, mood, cycle history, pregnancy-related information, and other wellness records you provide or authorize | Provide the relevant tracking, reminders, descriptive insights, and permitted assistance |
| Health-related reflections, habits, sobriety or recovery records, and information you provide about conditions, medications, injuries, or treatment | Maintain your chosen personal records and provide the relevant features or assistance |
| Health-related AI conversations, permitted Memory, tool results, and inferences derived from those records | Answer requests, personalize authorized assistance, carry out supported actions, and investigate or correct service failures |
| Location, calendar entries, purchases, or shared content to the extent they reveal health status or seeking health services | Provide the particular activity, schedule, purchase, sharing, or support service you request |
| Identity-verification information protected as consumer health or biometric data under applicable law | Verify identity and adult eligibility and prevent fraud; Stripe Identity processes document/selfie matching, while Kai receives identity fields, verification status, and references |
These purposes also include securing the requested service, handling support and privacy requests, and meeting applicable legal obligations. Uses and sharing remain subject to the permissions and legal limits described below. Health-related inferences retain the protections that apply to the information from which they are derived.
2. Sources of consumer health data
We receive consumer health data from:
- you, when you enter records, upload content, communicate with Kai, or select a feature;
- your device and the health platforms, wearables, or other connections you authorize;
- people or businesses involved in a service or sharing arrangement you request, such as a coach or shared activity;
- providers that support requested services, such as identity verification or purchase processing; and
- calculations or inferences generated from the information above, including permitted AI assistance.
A planned connection to an external calendar, financial account, or other source does not authorize access. Before introducing an additional category or purpose, we will update the relevant disclosure and obtain consent as required by applicable law.
3. Consumer health data shared and recipients
We share only the categories needed for the service or purpose involved, subject to required consent and other legal limits:
- AI and retrieval providers: relevant conversation text, health context, tool results, permitted remembered facts, and limited quality evidence may be processed by OpenAI, xAI, Google Gemini, and Turbopuffer for the assistance or investigation described above.
- Hosting, storage, delivery, and operational providers: records and associated technical information are processed by providers such as Google Cloud, Cloudflare, Temporal Cloud, and database, security, and observability services to operate and protect the requested features.
- Media and communications providers: chosen health-related uploads, messages, call media, and necessary delivery details may be processed by media, calling, and communications providers, including Mux, LiveKit Cloud, Firebase Cloud Messaging, Telnyx, and Amazon SES.
- Identity and transaction providers: Stripe Identity processes verification information; payment providers, sellers, and fulfillment providers receive information needed for a requested transaction to the extent that information qualifies as consumer health data.
- People and services you choose: a coach, a selected audience, another participant, or a connected service receives the particular records or content you authorize for that purpose. Buying a service or joining a Group does not itself authorize access to all your health records.
- Legal and safety recipients: information may be disclosed to authorities, advisers, or other recipients where disclosure is required or permitted by the applicable consumer health privacy law, including for valid legal process or qualifying safety purposes.
All Kai products covered here are operated by Kai Research Inc. We do not share consumer health data with separate affiliated companies.
We do not sell consumer health data or use it for third-party advertising. Our general privacy notice's description of a possible business transfer does not override the permissions or restrictions that apply to consumer health data. We do not intentionally send health records, health-related AI conversations, or precise location as analytics-event properties.
4. Consent and control
Where the applicable law requires consent, we obtain it before collecting consumer health data for the specified purpose. Consent to sharing is separate from consent to collection. Applicable laws can also permit collection or sharing to the extent necessary to provide a product or service you request; this does not authorize unrelated uses.
A required request for consent explains the categories, purpose, recipients, and how to withdraw. Device access, sensitive Memory, use across products, proactive assistance, and sharing with another person have distinct choices. A permission for training or recovery does not authorize unrelated dating, shopping, or advertising use.
You can withdraw consent through the relevant available controls or by emailing [email protected]. You can also revoke device and connected-service permissions. Withdrawal stops the future collection or sharing covered by that consent, subject to applicable law, and may prevent the related feature from working. Use the deletion process below to remove previously collected information. Withdrawing consent does not require you to waive other privacy rights.
5. Your rights and requests
Where the applicable consumer health privacy law gives you these rights, you can:
- confirm whether Kai collects, shares, or sells your consumer health data and access that data;
- obtain the recipient information required by law, including a list of third parties and affiliates with whom it was shared or sold and an active contact mechanism;
- withdraw consent to collection and sharing; and
- request deletion of your consumer health data, including data held by recipients to the extent required by law.
Email [email protected] with the subject Consumer Health Data Request, the right you want to exercise, and enough information to identify your account or records. You do not need to create a new account. We may ask for information reasonably needed to authenticate you or an authorized representative; do not send unnecessary medical records or identity documents.
For Washington requests, we respond without undue delay and within 45 days of receiving the request. Where the law permits a 45-day extension, we explain the reason within the initial period. Authentication does not reset that Washington deadline. Other applicable state deadlines and requirements also apply. Responses are free to the extent required by law; any permitted response to an excessive or unfounded request must follow that law.
For a valid deletion request, we delete covered information and notify the processors and other recipients required by law. Where Washington law allows delayed deletion from archives or backups, that delay will not exceed six months after authentication. Any exception to deletion must be allowed by the applicable law; general account-retention language does not create an additional exception.
If we deny a request, reply to the decision with the subject Consumer Health Data Appeal. We will explain the appeal outcome in writing within the time required by law. For Washington and Nevada consumer health appeals, we respond within 45 days of receipt. If the appeal is denied, you may contact the Washington Attorney General or Nevada Attorney General, as applicable. We will not unlawfully discriminate against you for exercising these rights.