Privacy Policy
Last updated: September 2026
Overview
Kinosis is a product of Minimalistech, Inc., a Delaware corporation with offices at 3000 El Camino Real, Building 4, Suite 200, Palo Alto, CA 94306, United States ("Minimalistech", "we", "our", or "us"). Minimalistech is the data controller for the information described in this policy. This Privacy Policy explains how we collect, use, and safeguard your personal and health information when you use the Kinosis health protocol management platform: the mobile app, the WhatsApp assistant, connected data sources such as wearables and health platforms, the assistant connectors you may enable, and the Providers Portal used by care teams.
By using Kinosis, you agree to the collection and use of information in accordance with this policy.
Information We Collect
We collect information that you voluntarily provide through the WhatsApp assistant or the mobile app, and — only with your explicit authorization — data from health platforms and wearables you choose to connect:
- Health Information: Symptoms, meals, activities, moods, medications, and life events you share with us
- Reproductive Health Data: If you choose to track it, menstrual cycle information (period dates, flow, cycle-related symptoms) and fertility information (fertile-window and ovulation estimates, LH test results, basal body temperature, and whether you are trying to conceive or pregnant). This is sensitive health data and is subject to the additional protections described in the "Reproductive Health Data" section below
- Medical Documents: Lab reports, medical images, and other documents you upload
- Connected Sources: With your consent, health and fitness data from wearables and platforms you link — including Oura, WHOOP, Apple Health, and the Google Health API (see the "Google Health API Data" section below)
- Contact Information: Your phone number
- Location Data: If you enable it, approximate location (latitude/longitude) used to add daily weather, UV, and air-quality context to your health history
- Usage Data: Conversation history, timestamps, and interaction patterns
- Care Team Information: If you join a clinic or program on Kinosis by entering its join code, the organization you joined, the roles you consented to, and a log of every access to your record by its team
- Provider Account Information: If you are a member of a care team using the Providers Portal, your name, email address, credentials, password (stored hashed), role, and your activity in the portal
- Billing Information (clinic accounts): The plan, billing email, and the Stripe customer and subscription identifiers. Card details are entered on Stripe's pages and never reach our servers
How We Use Your Information
We use your information to:
- Provide and maintain the Kinosis platform: your health record, your protocol, and the adherence, efficacy, and signals computed from it
- Share your record with a care team you have joined, only to the extent of the consent you have given for each role
- Remember and organize your health information
- Generate summaries and reports at your request
- Improve and personalize our service
- Send you reminders and check-ins (with your consent)
- Operate clinic accounts: manage subscriptions, billing, and support
Data Storage and Security
We take the security of your health information seriously:
- All data is encrypted in transit and at rest
- We use secure cloud infrastructure with industry-standard protections
- Access to your data is strictly limited to authorized systems
- We do not sell or share your personal health information with third parties for marketing purposes
AI Processing
We use artificial intelligence (Claude by Anthropic) to understand your messages and extract health information. Voice messages are first transcribed to text by OpenAI. Your conversations are processed to:
- Identify symptoms, meals, activities, and other health data
- Analyze food photos for nutritional estimates
- Extract information from medical documents
- Generate conversational responses
Your data is not sold and is not used to train third-party AI models.
Assistant Connectors
If you choose to connect Kinosis to an assistant you already use (for example ChatGPT, Claude, or Siri Shortcuts), the messages you send through that assistant are also processed by its provider under that provider's terms before they reach Kinosis. Kinosis receives only what you send to it and treats it like any other message. You can disconnect a connector at any time from that assistant's settings.
Care Teams and the Providers Portal
Kinosis lets a clinic, program, or practitioner ("care team") see and manage the records of members who join it. Nothing is shared with a care team unless you join it and consent:
- Joining. You join a care team by entering its join code in the app or on WhatsApp. Joining alone shares nothing; the team sees that you have been invited and nothing else until you consent.
- Consent per role. Before any access, we show you the team's roles (for example physician, health coach, care coordinator) and what each can see, and you consent to each one separately. A coordinator sees status and scheduling only, never your health details; a coach sees your record but not medications in editable form and no clinical notes; a physician sees everything.
- What the team can do. With your consent, team members can view your record, set and adjust your protocol (targets, supplements, medications, reminders), and message you. Every protocol change and message appears in your own Kinosis conversation, attributed to the person who made it. Nothing is changed silently.
- Every access is logged. Each time a team member reads your record we record who, when, and what. You can see the last 30 days of access in the app under "My team".
- You can revoke at any time. From "My team" you can withdraw consent for any role or leave the team. Revocation is immediate and complete; the team keeps only the notes it wrote for itself, which are never visible to other members, sold, or exported.
- Responsibility. The care team and its professionals, not Kinosis, are responsible for their clinical decisions and for their own records. For the portal features, we process your data on the care team's behalf as well as for you; the care team is independently responsible for complying with the health-privacy laws that apply to it.
Google Health API Data
If you choose to connect a Google account through the Google Health API, Kinosis reads only the health data types you consent to, and only to provide features you have requested. Specifically, we may access:
- Sleep — sleep sessions, stages, and duration, to build your sleep history and track sleep-related protocol targets.
- Activity and fitness — steps, workouts, active energy, and distance, to track physical-activity targets and your adherence score.
- Health metrics and measurements — such as weight, body fat, blood pressure, blood glucose, resting heart rate, heart-rate variability, and blood oxygen, to build your biomarker history and measure whether your protocol is working over time.
- Nutrition — logged meals, calories, and macro/micronutrients, to complete your dietary history and correlate nutrition with your other health data.
- Exercise location (GPS) — route and location data associated with your workouts, to add geographic and environmental context to your activity history.
- Irregular rhythm notifications — heart-rhythm alerts recorded by your device, stored as part of your cardiovascular history.
- ECG — electrocardiogram readings recorded by your device, stored as part of your cardiovascular history.
- Basic profile — a user identifier and basic attributes, to link the connection to your Kinosis account and personalize evidence-based targets.
We access this data on a read-only basis. We use it solely to provide and improve the user-facing features of Kinosis described in this policy — your personal health history, protocol adherence and efficacy metrics, and personalized insights. We do not use Google Health API data for advertising, we do not sell it, and we do not transfer it to third parties except as necessary to provide or improve these features, to comply with applicable law, or as part of a merger or acquisition with your consent. We do not allow humans to read this data unless we have your affirmative consent to do so, it is necessary for security purposes (such as investigating abuse), to comply with applicable law, or the data has been aggregated and anonymized.
Kinosis's use of information received from the Google Health API and/or Google Developer Tools will adhere to the Google Health API Developer and User Data Policy, including the Limited Use requirements.
You can disconnect your Google account at any time from the Kinosis app. On disconnection we stop accessing new Google Health data. You may also request deletion of previously imported Google Health data, which we will remove from your Kinosis account. Data already synced remains part of your health history until you disconnect or request its deletion.
Data Retention
We retain your health information for as long as your account is active or as needed to provide you services. You can delete your account and all of its data at any time from the app (Settings → Delete account) or by contacting us. Leaving a care team ends its access immediately. When a clinic account is cancelled, the clinic's organization data is retained for 90 days and then deleted; its members keep their own accounts and records. Health data imported from connected sources (including the Google Health API) is deleted when you disconnect the source and request its removal, or when you delete your account.
Your Rights
You have the right to:
- Access your personal data
- Request correction of inaccurate data
- Request deletion of your data, including your reproductive-health data specifically
- Withdraw your consent to health-data or cycle/fertility tracking at any time
- Revoke a care team's access to your record, per role, at any time from the app
- Export your data in a portable format
- Opt out of promotional communications
U.S. state privacy rights (including consumer health data). Depending on your state (for example under Washington's My Health My Data Act, Nevada SB 370, and the California Consumer Privacy Act as amended), you may have additional rights over your "consumer health data," including the right to confirm whether we collect or share it, to have it deleted, and to withdraw consent to its collection and sharing. We collect and share consumer health data only with your consent and only with the processors described above, and we do not sell it. To exercise any of these rights, contact us using the details below.
European Union. If you are in the European Union (GDPR), health data is treated as special-category data that we process only with your explicit consent, and you have rights of access, rectification, deletion, and objection, and the right to lodge a complaint with your data protection authority.
Third-Party Services and Data Processors
To provide the service we share data with the processors listed below. We do not sell your personal health information, and we do not share it for advertising. Each processor receives only the data needed for its function:
- Twilio — delivers our WhatsApp and SMS messages and one-time login codes. Message content you send and receive passes through Twilio.
- WhatsApp (Meta) — the messaging channel itself. Messages you exchange with us over WhatsApp are also processed by Meta under its own terms; if you prefer not to use WhatsApp, you can use the mobile app instead.
- Anthropic — provides the AI (Claude) that understands your messages and extracts health information. Your conversation content and relevant health context are sent to Anthropic to generate responses. Anthropic does not use this data to train its models.
- OpenAI — transcribes voice messages you send (speech-to-text) so we can log what you said.
- Amazon Web Services (AWS) — cloud hosting, database, and file storage (documents, photos, reports) in the United States.
- Push notification providers — when you use the mobile app, reminders and check-ins are delivered through Expo and the Apple Push Notification service (iOS) or Firebase Cloud Messaging (Android).
- OpenWeatherMap — receives only approximate coordinates (no identity) to return local weather, UV, and air-quality data.
- Connected health platforms and wearables — where you link them: the Google Health API, Oura, WHOOP, and Apple Health.
- Stripe — payment processing for clinic accounts. Card details are entered on Stripe's pages; we store only the plan, billing email, and Stripe identifiers.
- Assistant providers you connect — if you use Kinosis through ChatGPT (OpenAI), Claude (Anthropic), or Siri Shortcuts (Apple), your messages also pass through that provider under its own terms.
These third parties have their own privacy policies, and we encourage you to review them.
Reproductive Health Data
Menstrual cycle and fertility data are among the most sensitive information we handle, and we treat them accordingly:
- We never ask for it unprompted. Cycle tracking begins only when you bring it up, or if you accept a single, clearly optional offer. You are never required to track it.
- Separate, affirmative consent. The first time you track cycle or fertility data, we show you a short notice and ask you to confirm ("yes"/"ok"). We record this data only after you agree.
- Not contraception. Fertility and cycle estimates are provided for awareness and conception planning only. Kinosis is never a method of birth control, and we always state the basis and confidence of any estimate.
- Your control. You can stop tracking, and ask us to delete your cycle and fertility data, at any time — separately from the rest of your account.
- We do not sell it, use it for advertising, or share it for those purposes, and we will not disclose it to third parties except as strictly required by law. If we ever receive a legal demand for reproductive health data, we will resist over-broad requests to the extent permitted by law.
International Data Transfers
Kinosis stores and processes data on servers in the United States, and several of our processors (above) are located in the United States. If you use Kinosis from outside the United States, your information — including sensitive health data — is transferred to and processed in the United States. By using the service and, where applicable, providing your consent, you authorize this transfer. We apply appropriate contractual and security safeguards to data transferred internationally.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new policy on this page and updating the "Last updated" date.
Contact Us
If you have any questions about this Privacy Policy or our data practices, or wish to exercise any of your rights, please contact us at:
Minimalistech, Inc. (Kinosis)
3000 El Camino Real, Building 4, Suite 200
Palo Alto, CA 94306, United States
hello@kinosis.ai