KinPath Privacy Policy

Effective Date: August 28, 2026

Company: KinPath, Inc. (“KinPath,” “we,” “us”)

Services: KinPath mobile applications (iOS and Android), our website and web portal, and related services (collectively, the “Services”).

1) What This Policy Covers

This Privacy Policy describes how we collect, use, disclose, and protect information when you use the Services. The Services are designed for older adults, friends and family who support them, and care providers.

2) Information We Collect

Account and Contact Information: name, email address, and sign-in credentials. We do not ask for or store a phone number, and we do not send text messages.

Profile Information: information you choose to provide about yourself (or an older adult you support), such as age range, preferences, routines, goals, and caregiving context.

User Content: messages, notes, reminders, and your profile photo if you add one.

Health Information: what you tell Ava about your health, and the summaries Ava writes from those conversations for the people in your circle. We do not ask you to enter readings, and nothing connects to a medical device or to Apple Health.

Support Communications: information you provide when you contact support or submit feedback.

If you enable voice features or record audio in the Services:

Location: if you grant location permission, the app sends your coordinates and the surrounding city, state, postal code, and country so Ava can answer questions about local weather and what is nearby. Location is not used to alert anyone, is not shown to the people in your circle, and is never sold or shared for advertising. You can refuse or revoke the permission in your device settings; Ava keeps working without it.

Device and App Data: device type, operating system, app version, language settings, and identifiers associated with your device or app instance.

Usage Data: which screens were opened and which features were used, with counts and durations. These records never contain what you said, what Ava replied, anyone’s name, or anything you typed. Section 6 describes them in full.

Diagnostics: we do not currently collect crash reports or performance diagnostics. Apple and Google may show us their own aggregate crash reports for the app; those come from them, not from anything we run.

Website/Portal Data: cookies that keep you signed in, and, where a link carried them, the campaign tags in the address (for example utm_source) and the host name of the site you came from. Never the full address you came from, which can contain what you searched for.

3) How We Use Information

We use information to:

4) Health-Related and Sensitive Information

The Services may process information that could be considered sensitive, including information about physical or mental health and daily functioning, depending on what you share. Audio recordings and transcripts may also be sensitive in some jurisdictions.

Not Emergency Services / Not Medical Care: The Services are not a substitute for professional medical advice, diagnosis, or treatment, and are not intended for emergencies. If you believe someone is experiencing an emergency, call local emergency services immediately.

5) How We Disclose Information

We disclose information in the following circumstances:

We may disclose information:

No Advertising Sale of Data: We do not use advertising targeting pixels and we do not sell personal information for targeted advertising purposes.

6) Cookies and Analytics

Our website and web portal use cookies for basic functionality such as keeping you signed in. You can control cookies through browser settings; some features may not function without certain cookies.

The app and this website send usage information — which screens were opened, which features were used, how long something took, how many times it happened — to our own servers, and to no one else. It is stored in our own database alongside the rest of the Services.

What those records can hold is limited by the system that writes them: every value is a number, a yes/no, a duration, or one of a fixed list of words. They cannot hold what you said to Ava, what she said back, a message, a name, a search, or a location. That is not a promise about how we behave; a record that carried any of it would be rejected before it was stored.

We do not record your screens. No advertising or tracking identifier is collected. The app does not ask for permission to track you because it does not track you.

Until August 2026 the app included PostHog, a third-party analytics service. It was removed — the code, the keys, and the dependency — and nothing replaced it except the first-party records described above.

7) Data Retention

We retain information as long as necessary to provide the Services and for legitimate business purposes such as security, compliance, dispute resolution, and enforcement of our agreements.

When you delete your account, this happens straight away: the account stops working on the next request, nobody can sign back into it, the phone stops receiving notifications, and the people in your circle are told you have gone — so that nobody is left waiting on an update that will never come.

Thirty days later the rows are erased. Your conversations with Ava, your reminders, your memories, your profile and photo, your health context and the summaries written from it, and your place in every circle. Thirty days is the window in which a deletion made by mistake can still be undone by writing to us; after that it cannot.

Some things are not ours alone to erase. An invitation you accepted stays part of the record of whoever sent it, with your name removed. Something you contributed to another member’s memory stays theirs, with your name removed. Billing records — plan, dates, amounts, and the id they were charged under — are kept as financial records; they contain no health information and no conversation.

And some things are erased for everybody. A direct message thread between you and another person goes when you do, including their copy of it. There is no version of that thread that belongs to only one of you.

The usage records in Section 6 are kept. They say that something happened and when — never what was said, by whom, or about what — and they are what tells us whether the product works at all.

If you cannot open the app — the phone is gone, the account is locked, or you are acting for someone who has died — write to privacy@kinpath.app and we will do it for you. We will need to establish that the account is yours, or yours to act for, before we do.

We may retain and use aggregated or de-identified information that cannot reasonably be used to identify you.

8) Your Choices and Requests

You may have choices and rights depending on where you live, including requesting access, correction, or deletion of certain information.

Deleting your account: you can do this yourself, in the app, at Settings → Delete Account. The app shows you who else is affected before you confirm.

How to request: Email privacy@kinpath.app with the subject “Privacy Request.” We may need to verify your identity before fulfilling requests.

9) Security

We use reasonable administrative, technical, and organizational safeguards designed to protect information. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

10) Children

The Services are not directed to children under 13 (or the minimum age required by local law). If you believe a child has provided personal information without appropriate consent, contact us to request deletion.

11) International Users

If you access the Services from outside the United States, your information may be processed in the United States and other locations where we or our service providers operate.

12) Changes to This Policy

We may update this Policy from time to time. We will update the Effective Date and, if changes are material, we will provide notice through the Services or by other means.

13) Contact

KinPath, Inc.
710 Lakeway Drive, Suite 200
Sunnyvale, CA 94085

Email: privacy@kinpath.app