Skip to content
kindoc
Pricing
Sign inStart for free
kindoc
Pricing
Start for freeSign in
  1. Home
  2. Privacy

Privacy

Updated October 8, 2026

In short

  • Kindoc keeps your consultations, the health records and notes of the people you ask about, and your visit summaries in your account, until you delete them.
  • To write each reply, Kindoc sends what the reply needs to an AI model, through OpenRouter, only to companies that commit not to keep it or train AI on it. PDF documents are first turned into text by Cloudflare.
  • We use your health information only to answer you and to keep Kindoc safe. We never sell it, show you ads, or use it to train AI models.
  • You can delete a consultation, a person or your whole account yourself, at any time.

Deleting your data

You can delete your account and everything stored with it at any time, yourself: in the app, open Profile and choose Delete account, or do the same in the web app at https://app.kindochealth.com. The account deletion page explains what is deleted and what is kept. You can also delete a single consultation, a person, a health record entry or a note (see "How long we keep it").

You can also ask us by email: write to support@kindochealth.com from the email address of your account. We delete the account within one month and confirm it to you.

Apple and Google keep their own records of App Store and Google Play purchases and of signing in with them. Ask them to delete those.

What this policy covers

This policy explains what Kindoc collects, why, who helps us run it, and what you can do about your data. It covers:

  • The Kindoc apps for iPhone, iPad and Android.
  • The web app at https://app.kindochealth.com.
  • The website at https://kindochealth.com.

If you live in Washington, Nevada or Connecticut, the section "Consumer health data" is our consumer health data privacy policy.

Who is responsible

Kindoc is run by JartaApps, Morlans, San Sebastián, Spain. We decide how your data is used, so we are responsible for it: the "controller" under the EU and UK GDPR.

Your data is yours. We use it only as this policy says.

Privacy questions and requests: support@kindochealth.com. Help with the app: support@kindochealth.com.

What we collect

Your account

  • Sign-in: your email address, and a password if you set one. It is stored in a form we cannot read.
  • Signing in with Apple or Google: if you use them, we receive what they share with us for sign-in: an account identifier, your email address (with Apple, you can hide it behind a relay address) and, if they share them, your name and profile picture. We do not get your Apple or Google password, and we do not read anything else in those accounts.
  • Your consent: when you agree to Kindoc using your health information and confirm that you are 18 or older, we keep a record of it: the version of the text you accepted, the AI provider it named, and when.

Your health information

This is the information you give us to get answers, and what the care team writes for you from it. We treat all of it as health data.

  • About you and the people you add: a first name, the relation to you (such as child, partner or parent), birth year, sex, whether a person is pregnant, and any notes you write.
  • Health records: each person's conditions, medicines and allergies, current or past, with optional dates and details, where each came from (you, a consultation or a document), and a history of the changes the team made, so that you can undo them.
  • Consultations: your messages, the photos and PDF documents you send, which person a consultation is about, the characters' replies, and its title.
  • Visit summaries: what you told the team, what you talked about, what to do now, the care level and where to get care, signs to watch for, and questions for your doctor.
  • Notes: things the team noted about a person for later, such as a habit or what helps.
  • Check-ins: the day you chose and the character's question.
  • Help cards: whether a consultation showed an emergency or a crisis help card.
  • Reports: when you report a reply, the reason you chose and a copy of the reply's text.

Photos can show your body, and documents such as lab reports can hold your name, your doctor's name and other details. The photos are made smaller, and their hidden details, such as the place where they were taken, are removed before they are uploaded. Documents are stored as you send them.

What we collect automatically

  • Country: the country your device is set to, saved with each consultation, so that a help card shows the right emergency number and crisis line. Kindoc does not use your location.
  • Language and time zone: your app language and time zone. We use them to write emails and replies in your language, and to know when your day starts for the daily limits.
  • Sessions and security logs: your sign-in session, your IP address and your device's browser or app information, which our database provider keeps in its sessions and security logs. An account can be signed in on one device at a time: signing in on a new device signs out the others.
  • Checks that calls come from the real app: to stop abuse, each call to our server functions carries a short-lived pass that shows it comes from Kindoc. To get it, the web app runs a Cloudflare Turnstile check in your browser; on iPhone and iPad, Apple's App Attest makes a key on your device, and we keep its public part with your account; on Android, Google Play Integrity checks the app and the device. These checks see device and browser signals, never your health information.
  • Push tokens: a token for each device where notifications are on, linked to the sign-in session that registered it.
  • Plan and purchases: which plan you have, when it renews, and your purchase history. We never see your card details.
  • Daily counts: how many messages you sent today, to apply the limits.
  • Crash reports: when the app crashes or hits an error, what went wrong, the app version, and the device and system version, with performance measurements and error logs. Reports carry your account's random identifier. We do not put your messages, health information, email or name in them.
  • Usage data: how the app is used. See "Usage data" below.

Feedback and emails to us

  • Feedback in the app: what you send from Tell us on the rating screen: the topics you pick, your message if you write one, the app version, your platform (iOS or Android) and your app language. Please do not put health information in it: it is not part of a consultation.
  • Emails to us: what you write, and the details the app adds to a message you start from Contact us: the app version, your device model and system version, your app language and your account's email address.

What is stored on your device or in your browser

  • Sign-in and settings: the apps keep your sign-in session (encrypted) and your settings, such as your language and whether usage data is shared, on your device. The web app keeps them in your browser's storage. They are needed for Kindoc to work.
  • Check-ins: on iPhone, iPad and Android, a check-in you asked for is scheduled on your device, with the character's question as its text. Signing out cancels it.
  • Usage data: while Share usage data is on, PostHog keeps an analytics identifier and the usage events waiting to be sent: on your device in the apps, and in your browser's storage in the web app.

Kindoc uses no advertising identifiers and no advertising or cross-app tracking tools, and it does not recognise faces. The web app sets no cookies of its own. The marketing website at https://kindochealth.com uses no cookies at all (see "This website" below).

Permissions on your device

Kindoc asks for these only when you use the feature that needs them. You can refuse, or change your answer in your device's settings.

  • Camera: to take a photo for a consultation.
  • Photo library: to pick photos for a consultation, through the system's photo picker.
  • Files: you pick each PDF document yourself, through the system's file picker. Kindoc sees only the files you pick.
  • Notifications: for the check-ins you ask for.
  • Network: to reach our servers. Kindoc needs an internet connection.

Usage data

While Share usage data is on, the app sends usage events to PostHog: which screens you open, when the app is installed, opened or closed, and events such as these:

  • a consultation started: with which character, whether it is about you or someone you added, and whether it is your free one;
  • a consultation finished: how many messages and characters it had, and whether it has a check-in;
  • a character brought in another: which ones;
  • a help card shown: whether it was for an emergency or a crisis;
  • a person added, and a health record entry saved or removed: only its section (condition, medicine or allergy);
  • a note forgotten, a check-in scheduled or opened, a summary shared or printed, consent given, a suggested reply tapped, a message sent (with how many photos and documents), a reply reported (with the reason), the rating screen and feedback sent (its topics, never its message), and the paywall and purchases.

These events carry your account's random identifier, your app language, the app version, and the device and system version. They never carry your messages, photos, documents, names, email, or the health information you enter, such as what a record entry or a note says. But they show that you use a health app, and some of them say something about how, for example that a crisis help card was shown to you.

PostHog also gets your device's IP address with them, and discards it: it does not store IP addresses. Before discarding it, PostHog may work out an approximate location (such as the country and city) from it, and keeps only that.

Usage data is on unless you turn it off: in Profile, turn off Share usage data, and the app records and sends no more usage events from that device.

How we use it, and why we may

  • To answer you (your explicit consent, and our contract with you): your health information, to write the team's replies, notes, health record entries and visit summaries, to show help cards and to schedule check-ins. Health data is a special category of data under the GDPR, so we use it only with your explicit consent (Article 9(2)(a)), which you give before your first consultation.
  • To provide Kindoc (our contract with you): your account and sign-in, your plan and its limits, and the check-ins you ask for.
  • To answer your messages (our contract with you, or our legitimate interest in helping you): your emails and requests.
  • To keep Kindoc working and safe (our legitimate interests): crash reports, fixing errors, checking that calls come from the real app, preventing fraud and abuse, the one-device sign-in rule, and reading the replies you report.
  • To improve Kindoc (our legitimate interest in learning how Kindoc is used, with an easy way to say no): usage data. It is on from the start, and you can turn it off at any time: in Profile, turn off Share usage data. From then on, the app records and sends no usage data from that device.
  • To meet legal duties: for example keeping tax and accounting records, and answering lawful requests from authorities.
  • To tell you about Kindoc: important changes to Kindoc, these terms or this policy, by email or in the app.
  • If Kindoc changes hands: in a merger, sale or reorganisation, the data passes to the new owner, who must keep this policy.

We do not sell your data. Kindoc shows no ads, and we never use your health information for advertising, for marketing or to train AI models. We do not make decisions about you that have legal or similarly significant effects by automated means: the team's replies and care levels are suggestions for you to discuss with a professional.

Withdrawing your consent

You can withdraw your consent at any time. Without it, the care team cannot answer you, because every reply needs your health information. To withdraw, delete your account (Profile, then Delete account), which deletes your health information, or write to support@kindochealth.com from the email address of your account, and we delete your health information and your account and confirm it to you. Withdrawing does not make what we did before it unlawful.

Who looks at your data

People who work on Kindoc can reach the stored data only to keep Kindoc working and safe, when you ask us for help, or when the law requires it, and they open your consultations only when one of these needs it. We read the replies you report, to check them and improve the team's answers, and the feedback you send.

Data about other people

When you ask about someone else, such as your child, partner or parent, Kindoc stores what you tell us about them: their first name, relation to you, birth year, sex, notes, health record and the consultations about them. We use it only to answer you, in the same way as your own, and send it to the same providers.

You may share it only if you have the right to: as the parent or legal guardian of a child, or with an adult's agreement (terms, section 9).

If you believe someone added your health information to Kindoc without the right to, write to support@kindochealth.com and we will delete it.

AI processing

Every reply is written by an AI model that other companies run for us. For each reply, Kindoc sends the model:

  • the consultation so far: its messages, up to 12 of its photos, and its PDF documents;
  • about the person it is about: their first name, relation to you, age, sex, whether they are pregnant, your notes about them, their health record (current entries, recent past ones, and what you undid in the last 30 days), up to 20 of the team's notes, and the titles and care levels of their 3 most recent consultations;
  • the country your device is set to, and our instructions for the team.

Kindoc also sends the model the first message of a consultation, to write its title; a whole consultation, with the details above, when you ask for its visit summary; and a message's text when it would be refused because you reached a limit or sent a photo or a document on the free plan, to check whether it describes an emergency, so the team can answer it anyway.

How it gets there:

  • Kindoc's server sends each request to OpenRouter, which passes it to a company that runs the model. Today the model is DeepSeek V4.1 Flash, with another DeepSeek model in reserve for when it is unavailable. The companies are those that OpenRouter lists, on the basis of their own policies, as keeping no data at all (zero data retention): they commit not to store the request or the reply, and not to train AI on them. We send no request to any other kind of provider. OpenRouter chooses the company for each request, from a list that changes, and these companies are in several countries, inside and outside the United States.
  • PDF documents are first turned into text by Cloudflare Workers AI, through a tool of OpenRouter's that its zero data retention does not cover. Cloudflare's terms, which it gives OpenRouter, say that it does not keep the documents or train AI on them. It reads only the text stored in a PDF, so a scanned document may give the team little or nothing to read.
  • OpenRouter does not train AI on the requests. It keeps details about each request, such as the time, the model and the amount of text, but not the messages, photos, documents or replies, except where its own privacy policy lets it keep data to prevent abuse, for security or to meet the law. It looks at a small sample of requests to sort them into categories for its own statistics, and stores those categories without linking them to our account or to you.

No one at the AI providers sees your account details: requests carry no email and no account identifier, but they do carry the names and health information listed above.

Who we share it with

We share data only with the companies below, who process it for us to run Kindoc, and only what each needs:

  • Hosting, database and storage: Supabase, in Frankfurt, Germany; and Cloudflare, which hosts the web app and this website.
  • AI models: OpenRouter, the companies that run the model behind it, and Cloudflare Workers AI for documents (see "AI processing").
  • Payments: RevenueCat, Stripe, Apple and Google.
  • Crash reports and usage data: Sentry and PostHog.
  • Checks that calls come from the real app: Cloudflare, Apple and Google.
  • Notifications and email: Expo, Apple and Google for notifications, and Resend for the codes and account emails we send you.

The full list, with what each does and its privacy policy, is under "The services we use" below. Apple and Google, as app stores and sign-in providers, handle data under their own privacy policies.

When you share or print a visit summary, it goes where you send it, and is handled under that person's or service's own rules.

We may also share data when the law requires it, to protect people's safety or our rights, or with a new owner if Kindoc is sold.

Kindoc and this website link to other services, such as the App Store, Google Play and the websites of help lines. This policy does not cover them.

The services we use

  • Supabase (Supabase, Inc.): our database, file storage, sign-in and server functions, in its Frankfurt region (Germany). It holds your account, sessions, health records, notes, consultations with their photos and documents, and summaries. Privacy policy
  • OpenRouter (OpenRouter, Inc., United States): connects Kindoc to the AI model, run by providers that keep no data (zero data retention), and sends documents to Cloudflare Workers AI. It receives what is listed under "AI processing". Data collection is off in our OpenRouter account, so OpenRouter does not store the messages, photos, documents or replies. Privacy policy
  • The model's providers: the companies that run the model for OpenRouter, chosen per request among those that keep no data. They receive what is listed under "AI processing", only to write the reply. OpenRouter lists them on each model's page at openrouter.ai.
  • Cloudflare (Cloudflare, Inc.): hosts this website and the web app, runs the Turnstile check in the web app, and, through OpenRouter, Workers AI reads the text of the PDF documents you send. It handles your IP address to deliver the pages and protect them. Privacy policy
  • RevenueCat (RevenueCat, Inc.): manages purchases, subscriptions and the web checkout. It knows your account's random identifier and your purchases, and, for a web purchase, what you enter at its checkout. Privacy policy
  • Stripe (Stripe, Inc. and its affiliates): processes card payments on the web. Privacy policy
  • Sentry (Functional Software, Inc.): crash and error reports, stored in its EU region. Privacy policy
  • PostHog (PostHog, Inc.): usage data from the app while Share usage data is on, and visit counts for this website, stored in its US region. It discards IP addresses. Privacy policy
  • Expo (650 Industries, Inc.): sends push notifications to your device, through Apple and Google. Check-ins do not go through it: your device schedules and shows them itself. Privacy policy
  • Apple (Apple Inc.): Sign in with Apple, the App Store and its payments, App Attest, and notifications on Apple devices. Privacy policy
  • Google (Google LLC): Sign in with Google, Google Play and its payments, Play Integrity, and notifications on Android. Privacy policy
  • Resend (Plus Five Five, Inc.): sends the codes (sign-up, password reset and password change) and other account emails, from noreply@kindochealth.com, through its EU region (Ireland). It receives your email address and the email it sends you. Privacy policy

International transfers

Your account and health information are stored in the European Union (Frankfurt, Germany). Some of our providers process data outside your country, including in the United States, and the companies that run the AI model may be in other countries too. When data leaves the EU, the UK or Switzerland, we rely on safeguards the law accepts, such as the European Commission's standard contractual clauses or an adequacy decision.

How long we keep it

We keep data only as long as we need it for the purposes above.

  • Account, people, health records, notes, consultations and summaries: until you delete them or your account. Nothing is deleted on a schedule.
  • Deleting a consultation (its menu, then Delete consultation) deletes its messages, photos, documents, summary and check-in. What the team noted or saved to the health record during it stays until you delete it.
  • Removing a person (Profile, then People, then the person, then Remove) deletes their consultations, health record and notes.
  • Notes: you can forget one or all of them on the person's page. The team keeps up to 200 notes per person: a new one replaces the oldest.
  • Health record history: the record of the changes the team made, kept so that you can undo them, stays until you remove the person or delete your account. When you delete an entry yourself, its history goes with it.
  • Reported replies: the copy of a reply you reported stays, with the reason, until you delete your account, even if you delete the consultation.
  • Backups: our database provider keeps daily backups of the database for 7 days, so deleted data leaves them within 7 days. Photos and documents are not in these backups.
  • Push tokens: until you sign out on that device or it stops receiving notifications. We keep the 20 devices you used most recently.
  • Crash reports: Sentry deletes them after at most 90 days (Sentry's retention periods).
  • Usage data: PostHog keeps usage events for 7 years, the retention period of our PostHog plan (PostHog's retention periods), then deletes them. They carry your account's random identifier, never your email or name.
  • Purchase records: RevenueCat's record is deleted with your account. Apple and Google keep their own records under their policies. We keep what tax and accounting law requires, for as long as it requires.
  • Feedback in the app: until you delete your account.
  • Emails to us: as long as we need them to help you, and as the law requires.

Security

We protect your data with encryption in transit and on our database provider's servers, private storage for your photos and documents that only your account can read, rules in the database that let each account read only its own data, and access limited to what each part of Kindoc needs. In the iPhone, iPad and Android apps, your sign-in session is stored encrypted on the device. No system is completely secure, so we cannot promise that your data will never be accessed without permission. If a breach puts your data at risk, we tell you and the authorities as the law requires.

Notifications on your lock screen

A check-in shows the character's name and question, which can mention a symptom, such as "How's the rash today?". Like any notification, it can show on your lock screen and to anyone who can see your screen. To hide it, turn off notification previews for Kindoc in your device's settings, or do not ask for check-ins. Signing out of Kindoc on a device cancels the check-ins scheduled on it.

Your rights

Wherever you live, you can ask us to:

  • See the data we hold about you, and get a copy, with the list of the companies that received it.
  • Correct it if it is wrong. You can edit your people and their health records yourself.
  • Delete it. You can delete consultations, people, notes, health record entries and your account yourself at any time.
  • Withdraw your consent to the use of your health information (see "Withdrawing your consent").
  • Stop usage data: turn off Share usage data in Profile.

Write to support@kindochealth.com from the email address of your account, so we know the request is yours. We answer within one month (45 days where a US state law gives that time), and it is free unless a request is clearly unfounded or excessive.

In the EU and the UK

Under the GDPR you also have the right to:

  • Restrict our use of your data.
  • Object to uses based on our legitimate interests.
  • Receive your data in a portable format, or have it sent to another company.
  • Complain to the data protection authority where you live or work, or where we are established. We would like to hear from you first.

In California

Under the CCPA you have the right to know what personal information we collect, use and disclose, and why; to get a copy of it in a portable format; to correct it; to delete it; and to limit our use of sensitive personal information, such as health information, to what is needed to provide Kindoc. You can ask twice in 12 months. We do not sell your personal information or share it for cross-context behavioral advertising. We will not treat you differently, charge you more or give you a worse service for using these rights. You can ask through someone you authorise, and we may need to confirm who you are and that they may act for you.

In other US states

If you live in a US state with a consumer privacy law, you have the rights it gives you, such as to see, correct, delete and get a copy of your data, and to opt out of its sale, targeted advertising and profiling (we do none of these). If we refuse a request, you can appeal by replying to our answer, and we answer the appeal within the time the law sets.

Consumer health data

This section is our consumer health data privacy policy under Washington's My Health My Data Act, Nevada's consumer health data law (SB 370) and Connecticut's Data Privacy Act. It applies to consumer health data: information that identifies you, or the people you add, and is about physical or mental health, including what the care team derives from what you tell it.

HIPAA, the US law on the records of doctors, hospitals and health insurers, does not cover Kindoc. These state laws do.

What we collect

  • What you tell us about yourself and the people you add: birth year, sex, pregnancy and your notes about them.
  • Health records: conditions, medicines and allergies.
  • Consultations: your messages, photos and PDF documents, and the replies.
  • What the team derives from them: visit summaries with care levels and where to get care, notes, health record entries, consultation titles, and whether a help card for an emergency or a crisis was shown.
  • Check-ins: the day and the character's question.
  • Usage events that may show that you use a health app, and some of how (see "Usage data").

Where it comes from

  • From you: what you type, the photos and documents you send, and what you enter in the app.
  • From the care team: the AI model's replies, summaries, notes and health record entries, made from what you gave us.
  • From your device: the country it is set to, and, while Share usage data is on, usage events.

Why we collect and use it

To answer you: to write the team's replies, notes, health record entries and visit summaries, to show help cards, and to schedule check-ins. To keep Kindoc working and safe. And, while Share usage data is on, to learn how Kindoc is used (see "Usage data": it is on until you turn it off). We use your health information to answer you only with your consent, which you give before your first consultation.

Who receives it

  • Hosting and storage: Supabase.
  • AI models: OpenRouter, the companies that run the model behind it, and Cloudflare Workers AI for documents, only to write replies, titles and summaries and to check for emergencies (see "AI processing").
  • Usage data (the events described under "Usage data"): PostHog.
  • Error reports, which can show that an error happened in a consultation, but not its content: Sentry.
  • People you choose: when you share or print a visit summary.
  • Authorities: when the law requires it.

We have no affiliates that receive it. We do not sell consumer health data, we do not use it for advertising, and we do not use geofences. No third party collects consumer health data about your activity over time and across other websites or apps through Kindoc.

Your rights

You can:

  • See whether we collect, use or share your consumer health data, get a copy of it, and get the list of every company that received it, with their contact details.
  • Correct it: edit people and their health records in the app, or write to us.
  • Delete it: delete consultations, people or your account in the app, or write to us. When you write to us, we also delete it from our providers, including your usage events at PostHog, and it leaves our backups within 7 days.
  • Withdraw your consent (see "Withdrawing your consent").

Write to support@kindochealth.com from the email address of your account. We answer within 45 days, and may extend that once by 45 more days when needed, telling you why. If we refuse a request, you can appeal by replying to our answer: we answer the appeal within 45 days and, if we still refuse, tell you how to complain to your state's Attorney General.

We will not treat you differently for using these rights. This policy takes effect on the date at its top.

Children

Kindoc is not for anyone under 18, and we do not knowingly collect data from them. A parent or legal guardian may add a child as a person a consultation is about and ask about them, but a child may not use Kindoc. Photos of intimate parts of a child's body may not be uploaded. If you believe a child uses Kindoc, write to support@kindochealth.com and we will delete the account.

Images made with AI

The care team's portraits are made with AI and show no real person. On this website, every image made with AI is marked as made with AI in the image file. The main pictures also carry a visible "Made with AI" label, and the footer of every page says that its pictures are made with AI.

This website

This website does not use cookies. It counts visits with PostHog without cookies and without storing anything in your browser; PostHog gets your IP address, as described under "Usage data" above. We use the counts only to see which pages people read and which buttons open the app. Cloudflare, which hosts the website, handles your IP address to deliver the pages. Do not send health information through this website: it has no forms.

Changes to this policy

We may update this policy. The date at the top shows the latest version. If a change matters to you, we tell you in the app or by email before it applies. If a change means we would use your health information in a new way, we ask for your consent again first.

Contact

  • Privacy questions and requests: support@kindochealth.com.
  • Help with the app: support@kindochealth.com.
  • By post: JartaApps, Morlans, San Sebastián, Spain.
kindoc

AI health consultations in your own words. The care team is AI, not doctors.

Kindoc

PricingTermsPrivacyDelete your account

© 2026 Kindoc. Pictures on this site are made with AI.

  • Bahasa Indonesia
  • Bahasa Melayu
  • Čeština
  • Dansk
  • Deutsch
  • English
  • Español
  • Filipino
  • Français
  • Italiano
  • Kiswahili
  • Magyar
  • Nederlands
  • Norsk
  • Polski
  • Português
  • Română
  • Suomi
  • Svenska
  • Tiếng Việt
  • Türkçe
  • Ελληνικά
  • Українська
  • עברית
  • اردو
  • العربية
  • हिन्दी
  • বাংলা
  • ไทย
  • 한국어
  • 日本語
  • 繁體中文