Privacy policy
Last updated 5 August 2026. Kin Health, Inc.
- Your family’s records are private to your account and to the people you explicitly share them with.
- We never sell your data, and we never use it to train AI models — ours or anyone else’s.
- It is encrypted in transit and at rest, and held in US infrastructure.
- You can export it or delete it — a single document, one person’s record, or the whole account — whenever you want.
The rest of this page is the detail behind those four sentences. Where a summary and the detail could be read differently, the detail is what we do.
Who this policy covers
Kin is made by Kin Health, Inc. This policy covers thekincare.com, the Kin web app and the Kin mobile apps. It explains what we collect from the person holding the account, what we collect about the family members they care for, and what happens to all of it.
Most of the information in Kin is not about you. It is about your mother, your child, your partner. When you add someone to Kin you are telling us you have the standing to hold their health paperwork — as their parent, their guardian, their carer, or because they asked you to. We treat their information with exactly the care described here, and we give you the tools to remove it as easily as you added it.
Whether HIPAA applies
We think you deserve a straight answer to this rather than a reassuring one.
HIPAA governs health plans, healthcare providers and the companies working on their behalf. Kin is none of those: it is an app you use for your own family, so in ordinary use Kin is not a covered entity and not a business associate, and the records you keep here are generally not protected health information under HIPAA. That is true of essentially every consumer health app, and it is worth knowing rather than assuming otherwise.
What that changes is which law is doing the work — not how we behave. We hold your family’s records to the commitments on this page, and consumer health privacy and breach-notification laws apply to us. We do not claim a HIPAA certification, and we will not imply one; if we ever operate in a way that makes us a business associate, this section will say so and we will sign the agreements that go with it.
What we collect
Almost all of it is something you handed us on purpose. Specifically:
- Your account. Your name and email address, and the credentials you sign in with. Passwords are stored only as a cryptographic hash by our authentication provider — nobody at Kin can read your password.
- The people you add. Name, relationship to you, date of birth, photo and similar details for each family member whose care you are keeping track of.
- Health information you give us. Documents you upload — discharge summaries, prescriptions, lab reports, insurance cards, bills — and the details we read out of them: medications, lab values, insurance policies and benefits, appointments, care plans, bills and timeline entries.
- Calls we place for you. The clinic’s phone number, what we were asked to arrange, and the outcome. Where the call provider returns them, we also keep a transcript and a recording, and we show them to you in the app.
- Your calendar, only if you connect it. If you connect Google Calendar, we hold an access token for it and write the appointments we book. We read your free/busy times to avoid double-booking. We do not read the contents of your other events.
- Your conversations with Ask Kin. The questions you type and the answers we return, together with the record details used to answer them.
- Waitlist details. If you ask for early access from our home page, your name, email address and country until you are invited or ask us to remove you.
- Ordinary technical logs. IP address, browser or device type and timestamps, written by our servers, used to keep the service running and to investigate abuse and outages.
We do not buy information about you from data brokers, and we do not collect your location or your contacts.
What we use it for
To do the job you are asking Kin to do, and to keep it working:
- Filing what you upload into the right person’s record, so the paperwork is findable later.
- Calling clinics, pharmacies and insurers on your behalf, and booking what they confirm.
- Reminding you about appointments, refills and follow-ups, by email and in the app.
- Answering your questions about a record when you ask Ask Kin.
- Sharing what you choose to share with the family members you invite.
- Keeping the service secure, debugging faults, and meeting our legal obligations.
And a short list of things we will not do, which we consider part of the product rather than a policy position: we do not sell your information, we do not rent or share it with advertisers, we do not use it to train AI models, and we do not use your health information to target you with anything.
How AI is used, and what it is not used for
Two parts of Kin use AI models: reading the documents you upload so their contents can be filed, and answering the questions you ask Ask Kin. Both send the relevant content to Anthropic, our AI provider, which processes it to return a result under commercial terms that do not permit training on it.
Your records are not used to train any model, ours or a third party’s. We do not make automated decisions about you that have legal or similarly significant effects.
Kin is not a medical provider and does not give medical advice. What the app extracts and summarises is an aid to keeping track of care, not a clinical judgement — check anything that matters against the original document and with the clinician treating the person.
The calls we make for you
When you ask Kin to arrange something, we place a real phone call to that office. The call identifies itself as an assistant calling on your behalf, and it gives the office only what they need to find the patient and book the slot. Where a recording is kept, a notice is spoken at the start of the call so everyone on the line knows — some US states require the consent of every party, and this is how we get it.
Recordings and transcripts are attached to the request they belong to and are visible to you. They are deleted when you delete the request, the person’s record, or your account.
How it is protected
- Encrypted in transit and at rest. Every connection to Kin is over TLS, and stored data and uploaded files are encrypted at rest by our infrastructure providers.
- Separated at the database, not just the screen. Row-level security rules mean a query can only reach the households an account actually belongs to. Access is enforced where the data lives.
- Calendar keys encrypted separately. The access tokens for a connected calendar are encrypted with AES-256-GCM under a key held outside the database, so a copy of the database alone does not open your calendar.
- Held in the United States. Kin’s infrastructure runs in US regions.
- Kept small. Kin is invite-only while we are early, and staff access to production data is limited to the few people who need it to run the service and support you.
No service can promise perfect security, and we will not pretend otherwise. If a breach affects your information we will notify you and the relevant regulators as the law requires, and tell you what we know.
How long we keep it, and how to get rid of it
We keep what is in your account for as long as your account exists, because the point of Kin is that last year’s discharge summary is still there when this year’s specialist asks about it. You decide when that ends:
- Delete a single document, appointment or record from the app, and it goes.
- Remove a person, and their record and files go with them.
- Ask us to close your account and we delete it, including uploaded files, call recordings and transcripts.
Deletions propagate to our backups as those backups age out, within 30 days. We keep the minimum we are legally required to keep — billing records, for instance — and nothing beyond it. Server logs are retained for a short operational period and then discarded.
Your rights over this information
Wherever you live, you can ask us to show you what we hold, correct it, export it in a portable form, or delete it. If you are in California, that includes the right to know, to delete, to correct, to portability, and to be free from discrimination for exercising them — and note that we do not sell or share personal information for cross-context behavioural advertising, so there is no such sale to opt out of. If you are in the UK or EEA, it includes access, rectification, erasure, restriction, objection and portability, and the right to complain to your supervisory authority.
Most of this you can do yourself in the app. For anything else, email us at support@thekincare.com and we will respond within 30 days. We will not charge you for it, and we will not make the service worse because you asked.
Children
You must be 18 or older to hold a Kin account. Kin is built for families, so a child’s health records are often in it — added by their parent or guardian, who controls them and can delete them at any time. Kin is not directed at children for their own use, and we do not knowingly let anyone under 18 create an account. If you believe a child has created one, email us and we will remove it.
Where your information is held
Kin stores and processes information in the United States. If you use Kin from outside the US, you are asking us to hold your information there, and US law will apply to it. Where we transfer information out of the UK or EEA, we rely on the appropriate safeguards, including standard contractual clauses.
Changes to this policy
When we change this policy we update the date at the top. If a change materially affects how we handle your information — a new category of data, a new company receiving it, a new purpose — we will tell you by email or in the app before it takes effect, rather than quietly editing this page and calling it notice.
Contact us
Questions about this policy, or about anything we hold, go to support@thekincare.com. A person reads that mailbox.
Kin Health, Inc.