Legal
Kinmetry is built on the principle that your health data belongs to you — not us. This policy explains what we collect, why, and how you can control it.
Your health data is yours
We do not sell, rent, or share your personal health data. We do not use your data to train AI models. You can export or delete everything, at any time.
Account information
When you create an account, we collect your name, email address, and password (stored as a one-way hash). Optionally, you may provide date of birth, biological sex, and blood type to improve the relevance of health context.
Health records data
We store the lab reports you upload (as files), the metrics extracted from those reports (e.g. blood glucose, cholesterol), reference ranges, status flags, and any manual edits you make during review. This data is associated with your account and any family member profiles you create.
Medication records
Medication names, dosages, frequencies, scheduled times, purposes, and administration logs you voluntarily enter.
AI conversation data
Messages you send to the AI Health Assistant and the responses generated. Conversations are used solely to provide continuity within a session and to generate responses; they are never used to train AI models.
Usage data
Basic server-side logs (request timestamps, HTTP status codes) for security monitoring and debugging. We do not use third-party analytics trackers.
We use your data exclusively to provide and improve the Kinmetry service:
We do not sell, rent, or share your personal health data with any third party for commercial purposes.
The information you upload to Kinmetry — including lab report files, extracted biomarker values, medication records, and any AI conversation containing health context — constitutes "special category" personal data under Article 9 of the EU General Data Protection Regulation (GDPR) and equivalent laws in other jurisdictions. We treat this data with the highest level of protection.
Legal basis for processing
We process your special category health data solely on the basis of your explicit consent (Article 9(2)(a) GDPR), given when you create an account. You may withdraw this consent at any time by deleting your account from Settings → Privacy & Security, which permanently erases all your health data within 30 days.
What health data we process
Specifically, this includes:
Third-party transmission of health data
To provide OCR extraction and AI-powered explanations, a minimum necessary subset of your health data is transmitted to our sub-processors (OCR service and AI provider). The AI provider used depends on your location: users in mainland China are served by DeepSeek (Hangzhou DeepSeek Artificial Intelligence Co., Ltd.), whose servers are located in China; users in all other countries are served by OpenAI (United States), governed by OpenAI's Data Processing Addendum and Standard Contractual Clauses (SCCs) approved by the European Commission. Data is never used for model training. If you prefer not to have your health data transmitted to external AI services, you may use Kinmetry without the AI Health Assistant feature.
No automated decision-making
Kinmetry does not use your health data for automated decision-making or profiling that produces legal or similarly significant effects. The AI assistant provides educational explanations only and is not a medical diagnostic tool.
To provide core functionality, Kinmetry passes a minimum necessary subset of your data to the following sub-processors:
All sub-processors are contractually bound to process data only on our behalf and in accordance with applicable data protection law.
While we implement industry-standard safeguards, no system is completely immune to security risks. We encourage you to use a strong, unique password and to contact us immediately if you suspect unauthorised access to your account.
Depending on your location, you may have the following rights regarding your personal data. We honour these rights for all users regardless of jurisdiction:
To exercise any of these rights, use the controls in Settings or contact us at [email protected]. We will respond within 30 days.
We retain your data for as long as your account is active. When you delete your account, all personal data — including health records, uploaded files, and conversation history — is permanently erased within 30 days. Anonymised, aggregated usage statistics (which cannot be linked back to you) may be retained for service improvement.
Kinmetry is not directed at children under the age of 16. We do not knowingly collect personal data from children under 16 without verified parental consent. If you believe a child's data has been submitted without consent, please contact us and we will delete it promptly.
Your data may be transferred to and processed in countries outside your country of residence, including the United States, where our infrastructure providers operate. When transferring data from the European Economic Area (EEA), we rely on Standard Contractual Clauses (SCCs) approved by the European Commission to ensure an adequate level of protection.
We may update this Privacy Policy from time to time. When we make material changes, we will notify you via a prominent notice in the application at least 14 days before the change takes effect. Your continued use of Kinmetry after the effective date constitutes your acceptance of the updated policy.
Kinmetry is the data controller for personal data processed under this policy. If you have questions, concerns, or requests relating to your privacy, please contact us:
If you are located in the EEA and are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority.
© 2026 Kinmetry. All rights reserved.