Legal

Privacy Policy

Kinmetry is built on the principle that your health data belongs to you — not us. This policy explains what we collect, why, and how you can control it.

Effective date: 13 May 2026·Version 1.0

Your health data is yours

We do not sell, rent, or share your personal health data. We do not use your data to train AI models. You can export or delete everything, at any time.

1. Information We Collect

Account information

When you create an account, we collect your name, email address, and password (stored as a one-way hash). Optionally, you may provide date of birth, biological sex, and blood type to improve the relevance of health context.

Health records data

We store the lab reports you upload (as files), the metrics extracted from those reports (e.g. blood glucose, cholesterol), reference ranges, status flags, and any manual edits you make during review. This data is associated with your account and any family member profiles you create.

Medication records

Medication names, dosages, frequencies, scheduled times, purposes, and administration logs you voluntarily enter.

AI conversation data

Messages you send to the AI Health Assistant and the responses generated. Conversations are used solely to provide continuity within a session and to generate responses; they are never used to train AI models.

Usage data

Basic server-side logs (request timestamps, HTTP status codes) for security monitoring and debugging. We do not use third-party analytics trackers.

2. How We Use Your Information

We use your data exclusively to provide and improve the Kinmetry service:

  • Display your health records, metric trends, and medication schedule within your account.
  • Send your report text or health context to our AI provider to generate report summaries, metric explanations, and assistant responses.
  • Send uploaded files to our OCR service to extract structured data from lab reports.
  • Generate clinical health summaries you choose to share with a physician.
  • Send you transactional emails (e.g. password reset). We do not send marketing emails without explicit consent.
  • Detect and prevent fraudulent or abusive use of the service.

We do not sell, rent, or share your personal health data with any third party for commercial purposes.

3. Special Category Health Data (GDPR Article 9)

The information you upload to Kinmetry — including lab report files, extracted biomarker values, medication records, and any AI conversation containing health context — constitutes "special category" personal data under Article 9 of the EU General Data Protection Regulation (GDPR) and equivalent laws in other jurisdictions. We treat this data with the highest level of protection.

Legal basis for processing

We process your special category health data solely on the basis of your explicit consent (Article 9(2)(a) GDPR), given when you create an account. You may withdraw this consent at any time by deleting your account from Settings → Privacy & Security, which permanently erases all your health data within 30 days.

What health data we process

Specifically, this includes:

  • Uploaded lab report files (PDF, images)
  • Extracted biomarker values, reference ranges, and status flags
  • Medication names, dosages, frequencies, and administration logs
  • Health context included in AI Health Assistant conversations
  • Optional profile data you voluntarily provide (date of birth, biological sex, blood type)

Third-party transmission of health data

To provide OCR extraction and AI-powered explanations, a minimum necessary subset of your health data is transmitted to our sub-processors (OCR service and AI provider). The AI provider used depends on your location: users in mainland China are served by DeepSeek (Hangzhou DeepSeek Artificial Intelligence Co., Ltd.), whose servers are located in China; users in all other countries are served by OpenAI (United States), governed by OpenAI's Data Processing Addendum and Standard Contractual Clauses (SCCs) approved by the European Commission. Data is never used for model training. If you prefer not to have your health data transmitted to external AI services, you may use Kinmetry without the AI Health Assistant feature.

No automated decision-making

Kinmetry does not use your health data for automated decision-making or profiling that produces legal or similarly significant effects. The AI assistant provides educational explanations only and is not a medical diagnostic tool.

4. Third-Party Sub-processors

To provide core functionality, Kinmetry passes a minimum necessary subset of your data to the following sub-processors:

  • OCR Service — receives the file you upload in order to extract text. The file is not retained after processing.
  • AI Provider — receives relevant health context (metric values, report summaries) to generate responses. Mainland China users: DeepSeek (China), servers located in China, subject to Chinese data protection law (PIPL). All other users: OpenAI (United States), governed by OpenAI's Data Processing Addendum and EU Standard Contractual Clauses. Data is never used for model training by either provider.
  • Cloudflare R2 — stores uploaded report files. Files are encrypted at rest. Cloudflare does not access file contents.
  • Google OAuth (optional) — if you choose to sign in with Google, we receive your name, email, and profile picture from Google.

All sub-processors are contractually bound to process data only on our behalf and in accordance with applicable data protection law.

5. Data Storage & Security

  • Your data is stored in a PostgreSQL database hosted in a secure cloud environment.
  • Uploaded report files are stored in Cloudflare R2 object storage with server-side encryption.
  • All data in transit between your browser and our servers is encrypted via TLS 1.2 or higher.
  • Passwords are hashed with bcrypt and never stored in plain text.
  • Access to production systems is restricted to authorised personnel via key-based authentication.

While we implement industry-standard safeguards, no system is completely immune to security risks. We encourage you to use a strong, unique password and to contact us immediately if you suspect unauthorised access to your account.

6. Your Privacy Rights

Depending on your location, you may have the following rights regarding your personal data. We honour these rights for all users regardless of jurisdiction:

  • Right of access — you may request a copy of all personal data we hold about you.
  • Right to rectification — you may correct inaccurate or incomplete data at any time in Settings.
  • Right to erasure — you may permanently delete your account and all associated data from Settings → Privacy & Security.
  • Right to data portability — you may request an export of your health data in a structured, machine-readable format.
  • Right to object — you may object to any processing of your data that you believe is not justified.
  • Right to withdraw consent — where processing is based on consent, you may withdraw it at any time.

To exercise any of these rights, use the controls in Settings or contact us at [email protected]. We will respond within 30 days.

7. Data Retention

We retain your data for as long as your account is active. When you delete your account, all personal data — including health records, uploaded files, and conversation history — is permanently erased within 30 days. Anonymised, aggregated usage statistics (which cannot be linked back to you) may be retained for service improvement.

8. Children's Privacy

Kinmetry is not directed at children under the age of 16. We do not knowingly collect personal data from children under 16 without verified parental consent. If you believe a child's data has been submitted without consent, please contact us and we will delete it promptly.

9. International Data Transfers

Your data may be transferred to and processed in countries outside your country of residence, including the United States, where our infrastructure providers operate. When transferring data from the European Economic Area (EEA), we rely on Standard Contractual Clauses (SCCs) approved by the European Commission to ensure an adequate level of protection.

10. Cookies

Kinmetry uses only essential session cookies necessary to keep you signed in. We do not use advertising cookies, tracking pixels, or fingerprinting technologies. No cookie consent banner is required because we use no non-essential cookies.

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you via a prominent notice in the application at least 14 days before the change takes effect. Your continued use of Kinmetry after the effective date constitutes your acceptance of the updated policy.

12. Contact & Data Controller

Kinmetry is the data controller for personal data processed under this policy. If you have questions, concerns, or requests relating to your privacy, please contact us:

If you are located in the EEA and are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority.

© 2026 Kinmetry. All rights reserved.

Terms of Service·Back to Home