Loading Kynthai…
How Kynthai collects, uses, and protects your health data.
Last updated: July 13, 2026
Kynthai is a health-management platform operated by Kynthai Health Technologies. We comply with the Health Insurance Portability and Accountability Act . Health data is treated as Protected Health Information (sensitive health data) under US privacy law, with additional safeguards applied.
Note: We regularly review this policy to keep it aligned with applicable rules. Consult qualified US legal counsel to confirm section numbering and applicability before relying on this policy for regulatory compliance.
We collect only the data necessary to operate Kynthai for you and your family:
We process Protected Health Information (sensitive health data) under the Health Insurance Portability and Accountability Act , the Health Information Technology for Economic and Clinical Health (HITECH) Act, and applicable US federal and state law as a Covered Entity or Business Associate, as applicable:
Because health data is classified as Protected Health Information (sensitive health data) under US privacy law, we obtain your explicit Privacy-compliant Authorization before using or disclosing sensitive health data for purposes beyond treatment, payment, and healthcare operations (TPO). Revocation does not affect uses or disclosures made in reliance on the earlier authorization prior to revocation.
Kynthai operates in the United States and is governed primarily by the Health Insurance Portability and Accountability Act (US privacy, 45 CFR Parts 160 & 164) and the Health Information Technology for Economic and Clinical Health (HITECH) Act, along with applicable US federal and state law. As a Covered Entity and/or Business Associate under US privacy law:
For users in the United States, US privacy and the HITECH Act are the primary governing frameworks. California residents are additionally protected by the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA). For users in other jurisdictions, Kynthai complies with applicable local data protection laws to the extent required.
At registration, you are presented with a Privacy-compliant Notice of Privacy Practices (NPP). For uses and disclosures of sensitive health data beyond treatment, payment, and healthcare operations (TPO), a written US privacy Authorization is required. AI features may require a separate optional data-use consent. You may revoke any authorization or consent at any time via your account settings or by emailing privacy@kynthai.app. Revocation takes effect promptly (typically within 72 hours) but does not apply to uses or disclosures made prior to revocation in reliance on the earlier authorization. Withdrawing AI consent disables AI features but retains your medication reminders and health records. Withdrawing TPO consent may require account deletion.
under US privacy law, the HITECH Act, and — for California residents — the CCPA/CPRA, you have the following rights:
If you are a California resident, you have additional rights under the CCPA/CPRA, including the right to know, delete, and opt out of the sale of personal information. We do not sell your personal information. We will respond to valid requests within 30 days (extendable by 30 days for complex requests, with notice).
Health data is classified as Protected Health Information (sensitive health data) under US privacy law. The following safeguards apply:
US users are primarily protected by US privacy and the HITECH Act. California residents have CCPA/CPRA rights. Users in other jurisdictions retain rights under applicable local privacy laws to the extent required.
In addition to US privacy and CCPA/CPRA, Kynthai complies with the following state-level privacy statutes that grant consumers rights over their personal information:
Nondiscrimination: We will not discriminate against you for exercising any of your privacy rights under these laws.
We implement layered technical and organisational controls appropriate to the sensitivity of the data we process.
Access to production systems is restricted to authorised personnel. We follow secure deployment practices and review our infrastructure configurations regularly.
Kynthai is not a medical device. Kynthai is a health-technology platform that provides general wellness and health-management tools (medication reminders, appointment scheduling, lab bookings, prescription management, AI chat, symptom analysis, medicine identification, drug-interaction checking, and health insights). These features provide informational content only and do not constitute medical advice, diagnosis, treatment, or a substitute for professional healthcare under applicable federal and state law.
Because our AI features are not intended to diagnose, cure, mitigate, treat, or prevent disease, they are not regulated as Software as a Medical Device (SaMD) under 21 CFR Part 870, nor do they require FDA 510(k) clearance, De Novo classification, or PMA approval. Kynthai makes no claims of FDA clearance or approval for diagnostic, therapeutic, or monitoring functions. The FDA may regulate health software in the future; Kynthai will comply with any applicable FDA requirements as they develop.
Independent healthcare professionals: Doctors and labs available through Kynthai are independent healthcare providers. Kynthai does not employ, supervise, or control their medical decision-making. These professionals are solely responsible for compliance with applicable federal and state healthcare laws, including but not limited to EMTALA, Medicare/Medicaid conditions of participation, and state medical-board regulations.
Data storage (Privacy-compliant): sensitive health data of US users is stored and processed on Privacy-compliant cloud infrastructure with Business Associate Agreements (BAAs) in place with all subprocessors that handle sensitive health data. Cross-border data transfers (where applicable) are subject to appropriate safeguards (BAA provisions and Standard Contractual Clauses) to ensure continued comprehensive protection of sensitive health data.
Kynthai may transfer data to cloud service providers and subprocessors operating outside the United States for data processing purposes. Such transfers are protected by appropriate contractual safeguards including standard data protection clauses and encryption in transit and at rest.
As an individual whose sensitive health data is held by Kynthai, you have the following rights under US privacy law, HITECH, and applicable US state law:
If you are a California resident, you have additional rights under the CCPA/CPRA, including the right to know, delete, and opt out of the sale of personal information. We do not sell your personal information. California residents have rights under CCPA/CPRA (we do not sell personal info). Other jurisdictions: you may also have additional rights under applicable laws in your jurisdiction. We will respond to valid requests within 30 days (extendable by 30 days for complex requests, with notice).
Health data is classified as Protected Health Information (sensitive health data) under US privacy law. We apply heightened safeguards:
US users are primarily protected by US privacy and the HITECH Act. California residents are additionally protected by the CCPA/CPRA. Users in other jurisdictions retain rights under applicable local privacy laws to the extent required. (Note: All regulatory references in this section reflect US/US privacy standards.)
Kynthai shares personal data only with the minimum number of processors necessary to deliver the service. Each sub-processor listed below has executed (or in the case of open-source components, is covered by) a data-processing agreement imposing obligations no less protective than those in this policy. You may request a current copy of any DPA in force by emailing privacy@kynthai.app.
| Sub-processor | Role | Data shared | Jurisdiction |
|---|---|---|---|
| Stripe, Inc. | Payment processing | Billing email, subscription tier, payment-intent amount. Card data never reaches Kynthai servers. | US |
| NVIDIA Corporation / NVIDIA NIM (or equivalent AI-inference provider) | AI inference (chat, symptom analysis, drug-interaction checking, medicine identification, prescription scanning) | De-identified chat inputs and symptom text; output returned to Kynthai. Health data is not used to train vendor models. | US |
| Upstash (or equivalent serverless data store) | Background job queue / rate-limit / session store | Anonymised session identifiers, rate-limit counters. No health data. | US |
| Twilio, Inc. / SendGrid (Twilio) / WhatsApp (Meta) | Communication delivery (SMS, email, WhatsApp messages) | Message content (dose reminders, lab-result notifications, SOS alerts) and recipient mobile number / email address. Health summaries are minimised to what is necessary for the reminder. | US |
| PostHog / Vercel Analytics | Product analytics & performance monitoring | Anonymised usage events (page views, feature interactions, error logs). IP addresses are truncated or hashed. No health data. | US |
Cloud infrastructure providers (primary hosting, databases, object storage) operate under data-processing agreements with encryption-in-transit and access-control requirements. Government-issued identity fields (Tax ID/SSN) are end-to-end encrypted before they reach storage, so cloud infrastructure providers cannot read these values under strict data protection agreement requirements.
Doctors and labs you choose to consult or order from receive only the data necessary for that consultation or order. They act as independent data controllers for that data once received.
Authorities may receive data where required by law, court order, or to protect the rights, property, or safety of Kynthai, our users, or others.
We never sell your personal or health data. We never share health data for advertising purposes.
Kynthai uses:
kynthai_session HttpOnly, Secure, SameSite cookie used for authentication. This cookie expires 30 days after your last activity; if fewer than 7 days remain it is automatically refreshed for a further 30 days. You can terminate the session at any time by logging out or changing your password. (No consent is required for this strictly necessary session cookie under applicable US and state privacy law.)We do not use third-party advertising cookies, tracking pixels, or cross-site advertising networks. You can clear all cookies and local storage via your browser settings at any time.
Kynthai is not directed at children under 16. Family profiles for minors may be created and managed by a parent or legal guardian who consents to the processing on the child's behalf. The parent may request deletion of a minor's profile at any time. We do not knowingly collect data from children under 16 without verified parental consent, consistent with the Children's Online Privacy Protection Act (COPPA, 15 U.S.C. §§ 6501–6506) and applicable US child-protection framework. If you believe we have collected data from a child without consent, contact hello@kynthai.app for immediate deletion.
We will not send you marketing emails or SMS without your explicit consent. You can opt in or out at any time via your account settings or by clicking the unsubscribe link in any email. Your consent status is stored and audited.
In the event of a breach of unsecured Protected Health Information (sensitive health data), Kynthai will act in accordance with the HITECH Act Breach Notification Rule (45 CFR §§ 164.400–414):
Kynthai uses AI to provide health information, identify medicines, check drug interactions, and offer insights. AI outputs are advisory only and do not constitute medical advice. You always have the option to consult a qualified healthcare professional through Kynthai.
AI Incident Reporting: If you believe an AI response was incorrect, misleading, or potentially harmful, report it immediately toai-incidents@kynthai.app. Include the AI feature used, the query/input, and the output received. We review all reports, track patterns, and use findings to improve AI accuracy. All reports are logged and reviewed within 72 hours.
Kynthai uses AI (large language models, vision models, speech recognition) for chat, symptom analysis, medicine identification, prescription scanning, drug-interaction checking, and insights. These features provide advisory information only and do not make automated decisions with legal or similarly significant effects about you. All AI outputs are clearly labelled as AI-generated, and a qualified healthcare professional should be consulted before making medical decisions. You may request human review of any AI-generated output by contacting your doctor or hello@kynthai.app.
We may update this policy from time to time. We will notify you of material changes via email and in-app at least 30 days before they take effect. Continued use after the effective date constitutes acceptance. A version history is available at kynthai.app/privacy/history.
Kynthai Health Technologies
Address (United States): United States (correspondence via email)
Email: hello@kynthai.app
Support: hello@kynthai.app
Privacy Officer:
Name: Privacy Officer
Email: privacy@kynthai.app
Address: United States
Privacy Officer / Privacy Contact:
Name: Privacy Officer
Email: privacy@kynthai.app
Address: United States
Acknowledgment: all complaints are acknowledged within 5 business days. Standard complaints are resolved within 30 calendar daysof acknowledgement. Where a complaint is complex or requires additional investigation, we will notify you in writing of any delay, the reason, and the expected final resolution date. Escalation: unresolved complaints may be referred to the HHS Office for Civil Rights (OCR).
Correspondence is handled primarily via email at privacy@kynthai.app. Physical correspondence may be directed to the registered US address in the Terms of Service.