Privacy Policy
This Privacy Policy explains how Kai Research Inc. ("Kai," "we," "us," or "our") collects, uses, discloses, and retains personal information when you use Kai's websites, apps, AI features, and related services (collectively, the "Services").
1. Information we collect
Account and profile information
- Name, email address, profile image, and identifiers received from sign-in providers such as Apple and Google through WorkOS
- An Apple Declared Age Range when the operating system requires the request and you share a usable result; otherwise, your date of birth during web sign-in or required native setup. Kai converts these inputs into an account eligibility result and age group, and does not display your birthday on your public profile
- Sex, height, phone number, and other profile details you provide to personalize health and fitness features
- Goals, preferences, and product settings
Health, fitness, and wellness information
Depending on the Kai products and features you use, this may include:
- height, weight, body measurements, body composition, and progress information;
- nutrition, meals, ingredients, dietary preferences, allergies, restrictions, and food images;
- exercises, training plans, sets, repetitions, loads, workouts, activity, pace, distance, route and sensor samples, energy expenditure, and recovery;
- sleep, heart rate, steps, mobility, cycle, symptoms, mood, mindfulness, and other wellness information;
- medical conditions, medications, injuries, pregnancy status, or other sensitive details you choose to tell Kai; and
- information you authorize from Apple HealthKit, Health Connect, wearables, or connected health services.
Kai collects only the connected-health categories you authorize through the applicable platform controls. You can revoke platform access in your device settings, but previously imported information remains in Kai until deleted under our normal controls or account-deletion process.
Content and communications
- AI prompts, conversations, feedback, and Outputs
- Posts, Post replies, messages, progress photos, food photos, videos, voice notes, voice or video call media, and other uploads
- Support requests, enforcement appeals, surveys, and communications with Kai
- Metadata associated with content, such as timestamps, audience, and technical upload details
Location information
We may infer an approximate location from an IP address. Features that record outdoor activity or routes may collect precise location, latitude, longitude, speed, altitude, and timestamps when you grant device permission and use the feature. Profile, calendar, or planning features may send a city or place search to Google Places and store the place you select. You can manage device location permission in system settings; disabling it may prevent route-based features from working.
Device, usage, and diagnostic information
- IP address, device and browser type, operating system, app version, locale, and device identifiers
- pages and features used, declared product events, referring pages, timestamps, session identifiers, and experiment or feature-flag assignments; optional web analytics is collected only after you allow it
- logs, network and request metadata, performance information, crash and error diagnostics, and security signals
- cookies, local storage, SDK identifiers, and similar technologies described in our Cookie Policy
Payments and subscriptions
We receive subscription, paid-membership, plan, entitlement, transaction, billing status, country, tax, fee, refund, dispute, transfer, and limited payment-related identifiers from Stripe, Apple, and Google Play. Payment providers process payment-card or store-account details; Kai does not receive complete payment-card numbers from those providers.
If you create a paid membership, Stripe hosts payout onboarding and may collect identity, business, tax, bank-account, and other verification information. Kai receives the resulting account status, outstanding requirements, settlement amounts, payout readiness, and provider identifiers needed to operate the offering and reconcile payments.
2. How we use information
We use personal information to:
- create and secure accounts, authenticate users, and maintain sessions;
- confirm age eligibility and apply age-appropriate protections;
- provide the features you request, including health and fitness tracking, plans, connected integrations, social features, communications, and AI coaching;
- personalize Kai according to your data, instructions, preferences, and optional Memory controls;
- process purchases and paid memberships, verify subscriptions, restore entitlements, administer creator payouts, reconcile taxes and provider fees, prevent fraud, and provide billing support;
- send service messages, requested notifications, and marketing communications where permitted;
- provide support, moderate content, enforce our Terms and Community Rules, and protect people and the Services;
- operate, debug, secure, analyze, and improve Kai, including product analytics, feature flags, and controlled experiments;
- comply with law, respond to lawful requests, and establish, exercise, or defend legal claims; and
- create aggregate or de-identified information that cannot reasonably be linked to you.
We ask for permission before accessing device capabilities and connected-health sources where required.
3. AI conversations and model providers
Kai sends the Inputs and context needed to answer a request to AI and retrieval providers. Depending on the feature, these providers include OpenAI and xAI for model inference, Google Gemini for shared-Memory embeddings, and Turbopuffer for Memory retrieval indexes. Information sent may include conversation text, relevant profile or health context, tool results, and remembered facts permitted by your settings.
Kai also keeps bounded Agent Quality evidence about proposed AI actions, validation results, accepted or corrected outcomes, and the software, model, prompt, policy, schema, and rubric versions involved. Authorized operators use this evidence to investigate failures and improve Kai. For semantic Agent Quality search, Kai sends bounded evidence text to Google Gemini to create search embeddings and stores a rebuildable search projection in Turbopuffer; operators retrieve the full authorized record from Kai before reviewing it.
Kai does not use personal AI conversations to train its own general-purpose foundation model. AI and retrieval providers process information under their business or API terms and Kai's account configuration. Their treatment of information may vary by provider and capability, including for service operation, safety, abuse prevention, or legal compliance. We will update this Policy before making a material change to how Kai uses personal AI conversations.
Memory is off until you enable it. Enabling Memory initially permits same-product and account-wide recall; you can narrow those scopes, and sensitive Memory requires a separate choice. You can inspect remembered facts, prevent a fact or source from future learning, erase facts, or disable Memory. Disabling or narrowing Memory removes affected facts from recall promptly; deletion from derived indexes completes through our asynchronous cleanup processes.
4. When we disclose information
We do not sell personal information. We do not use health information or AI conversations for third-party advertising, and we do not currently serve third-party behavioral advertising in Kai.
We disclose information to vendors that process it for us, including:
- Identity, notifications, and communications: WorkOS, Apple, Google, Firebase Cloud Messaging, Telnyx, and Amazon SES;
- AI and retrieval: OpenAI, xAI, Google Gemini, and Turbopuffer;
- Payments and creator payouts: Stripe, Apple, and Google Play;
- Media and calls: Mux for uploaded-media processing and delivery, and LiveKit Cloud for Group voice and video call transport;
- Location search: Google Places for city and place search;
- Hosting and operations: Google Cloud, Cloudflare, Temporal Cloud, and other database, storage, delivery, security, and observability providers; and
- Product analytics: PostHog for selected analytics events, feature flags, and experiments. We do not intentionally send health records, AI conversation content, passwords, or payment details as analytics-event properties.
We may also disclose information:
- when you direct us to, such as through a connected integration or a post audience;
- to protect users, enforce our agreements, investigate fraud or abuse, or secure the Services;
- to comply with law or a valid legal process;
- to professional advisers under confidentiality obligations; or
- in connection with a financing, merger, acquisition, reorganization, or sale of assets, subject to appropriate safeguards.
We may disclose aggregate or de-identified information that cannot reasonably identify you.
5. Analytics and advertising
Kai uses pageviews and selected product events rather than unrestricted content capture to understand whether features work and measure engagement. On public and authenticated web pages, PostHog stays off unless you grant performance cookies. A consented anonymous journey may connect to your account when you sign in. You can decline or later withdraw through Cookie Settings without losing ordinary product access; withdrawal stops analytics and removes the browser identifier. Our web configuration disables feature flags, experiments, automatic interaction capture, replay, heatmaps, performance capture, and exception capture. We do not intentionally place health data, precise location, AI conversation text, uploaded content, network bodies, or payment details in analytics-event properties.
Kai does not currently use third-party advertising networks, retargeting pixels, or cross-context behavioral advertising. If that changes, we will update this Policy and provide controls required by law before enabling it.
6. Retention
We retain personal information only as long as reasonably necessary for the purposes described here, including while your account is active and for limited periods needed for security, support, dispute resolution, and legal compliance. Retention varies by data type:
- active account, profile, content, health, and product data generally remain until you delete the item or account;
- age-eligibility records may retain a date of birth when you supplied one, normalized platform age ranges, source, declaration type, status, and verification time while needed to operate the account and demonstrate compliance; Kai does not retain a platform provider's complete response when normalized evidence is sufficient;
- security, fraud, and operational logs are kept for limited periods based on their purpose and risk;
- model-provider copies follow the provider and configuration limits described in Section 3;
- transaction, creator-payout, tax, reconciliation, refund, dispute, enforcement, and legal records may be retained as required by law or to establish or defend claims.
We may retain de-identified information that can no longer reasonably be linked to you.
7. Account availability and data deletion
You can delete individual content through supported features and request account deletion in supported app settings or through the web and email process on our Account Deletion page. We may verify your identity before processing an email request.
You may deactivate your account without deleting it. Deactivation makes product access unavailable, signs out current Kai sessions, and preserves account content, settings, and relationships. A later provider sign-in provides recovery-only access; the account becomes active only after you explicitly reactivate it. Reactivation creates a fresh product session and does not restore previously revoked sessions.
After you confirm account deletion, Kai immediately makes the account unavailable, signs out current sessions, and starts permanent deletion work. A confirmed deletion cannot be cancelled. Kai deletes or de-identifies account-owned information across our product systems. Some processing is asynchronous, so copies may remain temporarily in provider systems and derived indexes. Limited non-identifying transaction, security, enforcement, and legal records may remain where required or reasonably necessary.
Deleting your Kai account does not cancel a subscription billed by Apple, Google Play, or another external provider. Cancel through that provider before deleting your account if you do not want the subscription to renew. See our Account Deletion page for direct provider-management links.
8. Your privacy choices and rights
Depending on where you live, you may have rights to access, correct, delete, or receive a copy of personal information; object to or restrict certain processing; withdraw consent; or appeal a denied request. You may also:
- manage Memory and remembered facts in Data Controls;
- change HealthKit, Health Connect, location, photo, camera, notification, and similar permissions in device settings;
- manage post audiences and delete content through supported features;
- unsubscribe from marketing email or SMS using the message instructions; and
- control optional web functional, performance, and advertising/marketing preferences through Kai's Cookie Settings, and control cookies and local storage through browser or device settings.
For signed-in users, the latest web cookie preference is stored with the account and restored on new browsers. Kai also retains consent-change events recording the choices, source, time, and material policy version. Browser-level or account-level rejection takes precedence over a grant.
Email [email protected] to make a privacy request. Tell us the right you want to exercise and the Kai account involved. We may verify your identity. Authorized agents may submit requests where applicable law permits, subject to proof of authority. You may appeal a denial by replying to our decision. We will not discriminate against you for exercising a privacy right.
9. International transfers
Kai is based in the United States, and we and our vendors may process information in the United States and other countries whose data-protection laws may differ from those where you live.
10. Security
We use administrative, technical, and organizational safeguards designed to protect personal information, including access controls, secure authentication, encryption in transit and at rest where applicable, logging, and monitoring. No system is completely secure. Keep your devices and account access secure and contact [email protected] if you suspect unauthorized access.
11. Children and teens
Kai is available to users who are at least 13 years old. We use age information for eligibility and age-related safety, not advertising.
On the web, Kai asks for a birthday before provider sign-in, and an under-13 result stops account and session creation. On supported Apple devices, Kai may request Apple's Declared Age Range when the operating system says it is required. A usable under-13 range stops sign-in, and a usable eligible range lets Kai determine an age group without collecting an exact birthday. If the Apple request is not required, is unavailable, is declined, or does not establish eligibility, provider sign-in continues and Kai asks for a birthday during required setup. Android also asks for a birthday during required setup after provider sign-in. These native fallback paths can create a provider-backed Kai account and session before Kai receives age information, but an under-13 birthday cannot complete setup.
Kai does not currently provide a parental-consent or guardian-authorization flow. If applicable law requires that authorization for a person to use Kai, that person may not use Kai until Kai offers an appropriate process.
Accounts identified as belonging to people ages 13 through 17 receive the protections described on our Teen Safety page. If we learn that personal information belongs to a child under 13, we will block use and take steps to delete the information. A parent or legal guardian who believes a child under 13 has provided personal information to Kai may contact us at [email protected].
12. Changes to this Policy
We may update this Policy as our practices or legal requirements change. The updated Policy will show its effective date. We will provide additional notice of material changes where appropriate.
13. Contact
Kai Research Inc. Email: [email protected]