Kinali

Privacy Policy

Effective Date: 02/17/2026

Last Updated: 10/05/2026

Version: 1.5

Privacy Policy

Last Updated: October 5, 2026

This Privacy Policy explains how Tesselabs LLC, operating as Kinali ("we," "us," or "our"), collects, uses, shares, and protects your personal information when you use our family caregiving coordination platform ("Service"). This policy applies to all users worldwide, with jurisdiction-specific provisions for users in the European Union (including Spain), Argentina, Mexico, and the United States.

By using the Service, you consent to the data practices described in this Privacy Policy.

1. Introduction and Scope

Kinali processes highly sensitive information, including:

  • Protected Health Information (PHI): Medical records, diagnoses, medications, lab results, appointment notes
  • Personal Identifiable Information (PII): Names, photos, identity documents, voice recordings
  • Children's data: Health and personal information of minors
  • AI-processed data: Voice transcriptions, OCR from documents, AI-extracted medical data

We take your privacy seriously and are committed to transparency about our data practices.

2. Data Controller Information

Data Controller: Tesselabs LLC 1209 Mountain Road PL NE, STE R, Albuquerque, NM 87110, USA hello@tesselabs.com

Data Protection Officer (DPO) — EU/Spain Users: Guillermo Pascual dpo@tesselabs.com

Privacy Contact: For privacy questions or to exercise your rights, contact us at hello@tesselabs.com.

We process your personal data under the following legal bases, depending on your jurisdiction:

For EU/EEA/Spain Users (GDPR):

  • Consent: For processing health data, children's data, and AI processing
  • Contract Performance: To provide the Service you've subscribed to
  • Legitimate Interests: To improve the Service, prevent fraud, ensure security

For Argentina Users (LPDP 25.326):

  • Explicit Consent: Required for sensitive data (health records)
  • Written Consent: For international data transfers

For Mexico Users (LFPDPPP):

  • Express Written Consent: Required for sensitive data processing
  • Implied Consent: For non-sensitive operational data

For US Users (CCPA, COPPA, State Laws):

  • Consent: For data collection and sharing
  • Parental Consent: For children under 13 (COPPA requirement)

You may withdraw consent at any time by contacting us, but this may affect your ability to use the Service.

4. Types of Data We Collect

4.1 Account and Profile Data

  • Email address (required for account creation)
  • Name and profile information
  • Preferred language/locale (es-AR, es-MX, es-ES, en-US)
  • Account settings and preferences
  • Date of consent to Terms and Privacy Policy

4.2 Health Information (Highly Sensitive)

  • Medical diagnoses and conditions
  • Medications, dosages, and prescriptions
  • Allergies and adverse reactions
  • Medical appointment notes and summaries
  • Lab results and test reports
  • Healthcare provider information
  • Medical history and treatment plans
  • Symptoms and health observations

Important: This data is considered "sensitive personal data" or "special category data" under GDPR, LPDP, LFPDPPP, and other privacy laws. We collect it only with your explicit consent. For documents, Kinali also records a health-data acknowledgment for each dependent (see §17.1).

4.3 Personal Documents and Images

  • Identity documents (IDs, passports, insurance cards)
  • Medical records (PDFs, images, scanned documents)
  • Photos of medications, medical equipment, or care environments
  • Medical certificates and prescriptions
  • Copies on your device: Documents you open or save are kept in the app's temporary storage on that phone so you can view them without signal. They are deleted when you sign out (if the app closes before that finishes, deletion completes the next time you open it); the system or clearing the app's data can also delete them, and they are not included in device backups. Anyone who controls the unlocked phone, or a compromised device, can read them.
  • Available offline: Documents you mark "Available offline" are kept in the app's storage on that phone (not its temporary storage): the system does not delete them to free up space, and clearing the app's cache does not affect them. They are removed when you unmark them, when you sign out, or — if the document was deleted or you lost access to that person — the next time the app loads that person's documents with a connection; until then, a phone with no connection keeps showing them. They are also deleted if you clear the app's data or uninstall it, and they are not included in device backups. Like the other copies, anyone who controls the unlocked phone, or a compromised device, can read them.
  • Files as you upload them: We store each file exactly as you upload it, including the metadata embedded in it (for example, where a photo was taken or a PDF's author); we do not remove it.
  • Documents you add: Documents you add from Documents (scanned, from the gallery or from Files) are not sent to Google (Vertex AI) and no AI reads them: you enter the title, type and date yourself. Only the images you scan in Capture are sent to Google (Vertex AI) to read their content (§17.1).
  • Acknowledgment per dependent: Before a dependent's documents are first saved or viewed, we ask for a health-data acknowledgment; we describe it in Section 17.1 (§17.1).

4.4 Voice Recordings and Transcriptions

  • Audio recordings you create in the app
  • AI-generated transcriptions of voice notes (processed by Google Gemini via Vertex AI)
  • Text extracted from audio

4.5 AI-Processed and Extracted Data

  • Text extracted from images via OCR (processed by Google Gemini via Vertex AI)
  • Structured medical data extracted by AI from unstructured notes
  • AI-generated summaries or categorizations

4.6 Care Circle and Sharing Data

  • Care Circle membership information
  • Permissions and access levels granted to other users
  • Shared health records and documents
  • If you create a history-share link, whoever holds it can view the records and documents that link covers and request their files

4.7 Usage and Analytics Data

  • Device information (type, OS, browser)
  • IP address and geolocation (for regional settings)
  • Usage patterns (features used, pages visited, time spent)
  • Error logs and crash reports
  • Session recordings of the Android app, with all text and all images masked on your device before they are sent

4.8 Cookies and Tracking Technologies

  • Session cookies (to maintain login state)
  • Preference cookies (language, theme settings)
  • Analytics cookies (to understand Service usage)

See Section 14 for details on cookies and tracking.

4.9 Professional Contact Details of Third Parties

Users can save the professionals involved in someone's care — a doctor, a therapist, a teacher. When a user does that, we hold data about a person who is usually not a Kinali user and who did not give us the data themselves.

What we collect:

  • Name
  • Contact type (for example: doctor, therapist, teacher)
  • Specialty
  • Phone number
  • Email address
  • Address (whatever the user types: it may be an office or a private home, and we do not verify it)
  • Hours (free text, for example the days and times the contact is available)
  • Notes (free text the user types to help coordinate care; we do not control what is written there)

Who enters it: A Kinali user, typing it into the app. The contact does not enter it, is not asked to approve it, and is not notified when it is added. No account is created for them.

Legal basis: We rely on Legitimate Interests — a caregiver needs to be able to reach the professionals involved in the care of the person they look after, know when and where they can be seen, and keep at hand the context needed to coordinate that care. Holding their contact details, their hours, and the free-text notes a caregiver writes alongside the contact is the ordinary way to do it. We act as a data controller for these details; this is not something we treat as the responsibility of the user who entered them.

What we use it for: Showing the contact on the profile of each person it is linked to, to anyone with access to one of those people. The same contact can be linked to people in more than one Care Circle, so more than one Care Circle may see it. We also link it to appointments and records so a caregiver can tell who an entry refers to. The address is there so a caregiver knows where the contact can be seen; although we say "professionals", it may be an office or a private home — for example, someone who sees patients at home — and we treat it the same either way. Hours are there so a caregiver knows when the contact can be seen or called, and notes are there to record whatever a caregiver needs to coordinate care. We do not use these details for marketing, and we do not send messages to a contact. Beyond the people described above, we do not share them with anyone other than the processors listed in Section 7.

Retention: See Section 9.1. In short: we keep a contact for as long as it is linked to at least one person. Closing an account does not delete it — the same professional may be saved by other families. It is deleted on a verified request to our Data Protection Officer, or in a periodic review that today is manual and not automated.

It appears in data exports: These details are part of the JSON export that any Care Circle member with access to that person can request (Section 10.5). Once exported, the file is in that member's hands and outside our systems.

If you are one of these contacts: Write to dpo@tesselabs.com. You do not need an account. Section 10.6 explains what happens next.

5. How We Collect Data

We collect data through:

  • Direct Input: Information you manually enter into the Service
  • File Uploads: Documents, images, and audio files you upload
  • Voice Recording: Audio captured through the app's recording feature
  • AI Processing: Data extracted automatically from your voice recordings and the images you scan in Capture (transcription, OCR)
  • Automatic Collection: Usage data, device information, cookies
  • Third-Party Integrations: Data from third-party service providers used to deliver the Service

6. How We Use Your Data

We use your personal data for the following purposes:

6.1 Service Provision

  • Create and maintain your account
  • Store and organize your health information
  • Process voice recordings and transcribe audio (via Google Gemini)
  • Extract text from images and documents (via Google Gemini OCR)
  • Structure and categorize medical data using AI
  • Enable Care Circle sharing and collaboration
  • Provide calendar and appointment management
  • Send service-related notifications

6.2 Communication

  • Send important service updates
  • Respond to support requests
  • Notify you of policy changes
  • Send marketing communications (with your consent, opt-out available)

6.3 Service Improvement and Analytics

  • Analyze usage patterns to improve features
  • Identify and fix bugs
  • Conduct research and development
  • Improve AI accuracy

6.4 Security and Fraud Prevention

  • Detect and prevent unauthorized access
  • Investigate security incidents
  • Comply with legal obligations
  • Respond to lawful requests from authorities
  • Enforce our Terms of Service
  • Comply with court orders or regulatory requirements

7. Third-Party Data Sharing and Processors

We share your data with the following third-party service providers. Each processor operates under a Data Processing Agreement (DPA) and is contractually required to protect your data.

7.1 Google Cloud (Gemini via Vertex AI) — Multimodal AI Processing

  • What we share: Voice recordings, images, documents, and text data you submit for AI processing
  • Purpose: Voice transcription, OCR, medical data extraction and structuring
  • Data location: United States
  • DPA: Google Cloud Data Processing Addendum (last modified November 8, 2023)
  • BAA: HIPAA Business Associate Addendum in place (covers Vertex AI as a Covered Service)
  • AI Training: Google does not use customer data to train its AI models under the Cloud Data Processing Addendum
  • Retention: Data is processed transiently and not retained by Google beyond processing

7.2 Supabase — Database, Storage, and Authentication

  • What we share: All data stored in the Service (health records, documents, account data)
  • Purpose: Database hosting, file storage, user authentication
  • Data location: United States (us-east-1, North Virginia)
  • Retention: Ongoing while you use the Service
  • DPA: Supabase User DPA, signed March 12, 2026. Acknowledges processing of special categories of personal data including health data and data of minors
  • Subprocessors: AWS (Amazon Web Services) — as set out in Schedule 3 of the DPA

7.3 Cloudflare — Web Hosting and Security

  • What we share: Web traffic and API requests
  • Purpose: Host web application, provide CDN and security services
  • Data location: Global edge network (with data residency options)
  • DPA: Cloudflare Customer DPA v6.3 (June 20, 2025). Includes EU Standard Contractual Clauses, UK International Data Transfer Addendum, and Data Privacy Framework certification

7.4 Resend — Transactional Email

  • What we share: Email addresses and email content (service notifications, OTP codes)
  • Purpose: Send transactional emails (account verification, notifications)
  • Data location: United States
  • DPA: Resend Data Processing Addendum (December 31, 2025). Includes EU and UK Standard Contractual Clauses
  • Subprocessors: Listed at resend.com/legal/subprocessors

7.5 PostHog — Product Analytics

  • What we share: Usage patterns, device information, and anonymized interaction data, plus session recordings of the Android app in which all text and all images are masked on your device before they are sent
  • Purpose: Understand how users interact with the Service, improve features
  • Data location: United States
  • DPA: PostHog Data Processing Agreement, signed April 2, 2026. Includes EU Standard Contractual Clauses (Module 2, controller-to-processor)
  • Note: We do not send health data, medical information, or personally identifiable health records to PostHog

8. International Data Transfers

8.1 Where Your Data is Stored and Processed

Your data is transferred to and processed in the United States, regardless of where you are located. This includes:

  • Google Cloud (Vertex AI) processing — United States
  • Supabase hosting (database and storage) — us-east-1 East US (North Virginia)
  • Cloudflare Workers (web hosting) — Global edge network
  • Resend email processing — United States
  • PostHog analytics — United States

8.2 Safeguards for International Transfers

For EU/EEA/Spain Users (GDPR Article 46):

  • We rely on Standard Contractual Clauses (SCCs) approved by the European Commission for transfers to the US. SCCs are incorporated into DPAs with all processors:
    • Google Cloud: Cloud Data Processing Addendum includes SCCs (Appendix 3 — covering European Data Protection Law and CCPA)
    • Supabase: User DPA includes EU Standard Contractual Clauses (Module 2, controller-to-processor)
    • Cloudflare: Customer DPA v6.3 includes EU SCCs, UK International Data Transfer Addendum, and Data Privacy Framework certification
    • Resend: Data Processing Addendum includes EU and UK Standard Contractual Clauses
    • PostHog: Data Processing Agreement includes EU Standard Contractual Clauses (Module 2, controller-to-processor)
  • Transfer Impact Assessments should be conducted for all processors handling EU data

For Argentina Users (LPDP Article 12):

  • We obtain your explicit written consent for cross-border transfers
  • We ensure processors provide adequate data protection safeguards

For Mexico Users (LFPDPPP Article 37):

  • We obtain your express consent for international transfers
  • We inform you of the countries where your data will be processed

8.3 Your Rights Regarding International Transfers

You have the right to:

  • Know where your data is stored and processed (see Section 8.1)
  • Object to international transfers (may limit Service functionality)
  • Request a copy of the safeguards in place (SCCs, DPAs)
  • Withdraw consent for transfers (may result in account termination)

9. Data Retention and Deletion Policies

9.1 How Long We Retain Your Data

Data TypeRetention PeriodLegal Basis
Account dataActive account + 30 days after terminationContract performance
Health recordsActive account + 30 days after deletionUser consent
Voice recordingsActive account + 30 days after deletionUser consent
Images and documents (scanned or uploaded files)Kept while the record exists. A document you delete stops being shown in Kinali to every caregiver and stops being served by share links at once (copies already stored on a phone follow §4.3); its file and data (title, type, date, extracted text, and the title copied into caregivers' in-app notifications) are kept until deleted manually on a verified request to our DPO (see §10). Deletion of stored files after a record, dependent or account is deleted is also currently processed manually on a verified request to our DPO, until the automated process shipsUser consent
Health-data acknowledgmentKept while the dependent's profile exists; the identifier of the person who confirmed it is removed when that person deletes their accountRecord of the acknowledgment (see §17.1)
Copies on your deviceUntil you sign out, clear the app's data, or the system evicts them (see §4.3). Copies marked "Available offline" are not evicted by the system: they are removed when you unmark them, sign out or clear the app's data, or — if the document was deleted or you lost access — the next time the app loads that person's documents with a connection (see §4.3)User consent
AI transcriptions/OCRActive account + 30 days after deletion (for a deleted document's extracted text, see the Images and documents row)User consent
Payment records7 years after last transactionTax/legal compliance
Usage logs12 monthsLegitimate interests (security)
Audit logs3 yearsLegal compliance
Professional contact details (third parties who are not users), including address, hours, and notesKept while linked to at least one person; closing an account does not delete them; removed on a verified request to our DPO, or in a periodic review that today is manual and not automatedLegitimate interests

9.2 Soft Deletes vs. Hard Deletes

Current Implementation (as of February 17, 2026):

  • Our database uses "soft deletes" — deleted records are marked with deleted_at timestamp but NOT permanently removed
  • Storage files (images, audio) currently persist even after record deletion

IMPORTANT - GDPR/LPDP Compliance Issue: This soft delete approach does NOT fully comply with GDPR Article 17 ("Right to Erasure") or Argentina LPDP Article 16 (deletion rights), which require actual deletion.

Our Commitment:

  • We are implementing a true hard delete process
  • When you exercise your "Right to be Forgotten," we will permanently delete your data within 30 days (except data we are legally required to retain). For stored document and image files, until the automated process ships, deletion is processed manually on a verified request to our DPO
  • Until hard delete is implemented, you can request manual permanent deletion by contacting our DPO

9.3 Data Deletion Upon Account Termination

When you delete your account:

  • You have 30 days to change your mind or export your data
  • After 30 days, your data will be permanently deleted (except legally required records and the files described below)
  • Shared data in Care Circles may be retained if other members still have access rights
  • Files of scanned documents and images (including scans that earlier versions of the app uploaded to the legacy care-images storage) are not deleted automatically after the 30 days; their deletion is processed manually on a verified request to our DPO (see §9.1)

9.4 Third-Party Data Retention

We cannot control how long third-party processors (Google Cloud, Supabase, Cloudflare, Resend, PostHog) retain your data. See Section 7 for each processor's retention policies.

Your Rights: You can request deletion from third-party processors directly or ask us to facilitate the request.

10. Your Privacy Rights (By Jurisdiction)

Your rights vary based on your location. Below are the rights available to you under applicable laws.

Sections 10.1 through 10.5 assume you have a Kinali account. If you do not — for example, a caregiver saved you as a professional contact (Section 4.9) — Section 10.6 is the route for you.

10.1 Rights for EU/EEA/Spain Users (GDPR)

You have the right to:

  1. Access: Request a copy of your personal data
  2. Rectification: Correct inaccurate or incomplete data
  3. Erasure ("Right to be Forgotten"): Request deletion of your data
  4. Restriction of Processing: Limit how we use your data
  5. Data Portability: Receive your data in a machine-readable format
  6. Object to Processing: Object to data processing based on legitimate interests
  7. Withdraw Consent: Withdraw consent for data processing at any time
  8. Automated Decision-Making: Not be subject to decisions based solely on automated processing (including AI)

Response Time: We will respond to requests within 1 month (extendable to 3 months for complex requests).

How to Exercise Rights: Email our DPO at dpo@tesselabs.com or use the data export/deletion features in your account settings.

Complaint Rights: If you believe we have violated your rights, you may lodge a complaint with your national data protection authority:

10.2 Rights for Argentina Users (LPDP 25.326)

You have the ARCO Rights:

  1. Access (Acceso): Request information about what data we hold about you
  2. Rectification (Rectificación): Correct inaccurate data
  3. Update (Actualización): Update outdated data
  4. Deletion (Supresión): Request deletion of your data

Response Time: We will respond to requests within a reasonable timeframe (best practice: 10 business days).

How to Exercise Rights: Email hello@tesselabs.com with your request.

Complaint Rights: File a complaint with Argentina's Data Protection Authority:

10.3 Rights for Mexico Users (LFPDPPP)

You have the ARCO Rights:

  1. Access (Acceso): Request access to your personal data
  2. Rectification (Rectificación): Correct inaccurate or incomplete data
  3. Cancellation (Cancelación): Request deletion of your data
  4. Opposition (Oposición): Object to certain data processing

Response Time: We will respond within 20 business days of receiving your request.

How to Exercise Rights: Email hello@tesselabs.com or use our ARCO Rights Request Form [TBD: create form].

Complaint Rights: File a complaint with Mexico's Data Protection Authority:

  • Instituto Nacional de Transparencia, Acceso a la Información y Protección de Datos Personales (INAI): www.inai.org.mx

10.4 Rights for California (US) Users (CCPA/CPRA)

You have the right to:

  1. Know: Request disclosure of what personal information we collect, use, and share
  2. Access: Request a copy of your personal information
  3. Delete: Request deletion of your personal information
  4. Opt-Out of Sale: We do NOT sell personal information, but you can opt-out if we ever do
  5. Non-Discrimination: We will not discriminate against you for exercising your rights

Response Time: We will respond within 45 days (extendable to 90 days for complex requests).

How to Exercise Rights: Email hello@tesselabs.com or call [toll-free number, TBD].

Do Not Sell My Personal Information: We do not sell personal information. If this changes, we will update this policy and provide an opt-out mechanism.

10.5 Data Export and Portability

All users (regardless of location) can request a machine-readable export of their data in JSON format. Contact us at hello@tesselabs.com to request an export.

10.6 Requests From People Without a Kinali Account

You may have rights over data we hold even if you have never used Kinali — most often because a caregiver saved you as a professional contact (Section 4.9).

There is no in-app route for this, and you do not need to create an account. The route is email:

  • Write to dpo@tesselabs.com.
  • Tell us your name, the phone number, email address, or postal address you believe we hold, and, if you know it, who listed you.

What happens next. A person at Kinali handles the request by hand. There is no self-service portal and no automated process.

  1. We search our records for the details you gave us.
  2. If nothing matches, we say so, and we keep nothing from your request beyond what we need to answer you and to record that we answered.
  3. If more than one record matches — the same professional can be saved by several unrelated families — we ask you for something that tells them apart before deleting anything. Deleting on a name alone would erase another family's records.
  4. Once we have a single confirmed match, we delete the contact record, clear the references to it in the appointments and records of each family it is linked to, and review free-text fields where your name may have been typed by hand.
  5. We confirm by email when it is done.

Response times: We aim for the timeframes in Sections 10.1 through 10.4, depending on where you are.

One limit, stated plainly: Deleting our copy does not reach copies a user already exported (Section 10.5) or wrote down elsewhere. Those are outside our systems and we cannot delete them.

11.1 Age Requirements

  • Users 18 and older: May use the Service independently
  • Users under 18: May use the Service only with parental/guardian involvement and consent
  • Children under 13 (US/COPPA): Require verifiable parental consent

For Children Under 13 (US Users):

  • We comply with COPPA (Children's Online Privacy Protection Act)
  • Parents must provide verifiable parental consent before we collect a child's data
  • COPPA Compliance Deadline: April 22, 2026 (new COPPA rules take effect)
  • Parents can review, request deletion, or refuse further collection of their child's data

For Children Under 13-16 (EU Users):

  • GDPR requires parental consent for children under the age of consent (13-16, varies by country)
  • In Spain, the age of consent is 14 years
  • Parents must consent to data processing for children under the applicable age

Current Status (as of February 17, 2026):

  • Age verification mechanism: [TBD — implement before launch]
  • Parental consent process: [TBD — implement before launch]

11.3 Parental Rights

Parents/guardians have the right to:

  • Access their child's data
  • Request deletion of their child's data
  • Withdraw consent at any time
  • Control who can access the child's information in Care Circles

11.4 Age Transition Policies

When a child reaches the age of majority (13, 16, or 18, depending on jurisdiction):

  • [TBD — define process for transitioning account control to the individual]
  • Notify parents and the individual of the transition
  • Obtain consent from the now-adult individual for continued data processing

11.5 Sensitive Health Data for Minors

Special considerations for adolescent health data (reproductive health, mental health):

  • [TBD — define policies for adolescent privacy rights in sensitive health matters]
  • Balance parental rights with adolescent privacy as required by law

12. Data Security Measures

We implement industry-standard security measures to protect your data:

12.1 Technical Safeguards

  • Encryption at Rest: All data stored in Supabase is encrypted using AES-256
  • Encryption in Transit: All data transmitted over HTTPS/TLS 1.3
  • Access Controls: Row-Level Security (RLS) policies in Supabase to restrict data access
  • Authentication: Secure user authentication via Supabase Auth
  • Password Protection: Passwords hashed using bcrypt

12.2 Organizational Safeguards

  • Access Restrictions: Only authorized personnel can access production data
  • Data Minimization: We collect only data necessary for the Service
  • Regular Security Audits: [TBD — define audit schedule]
  • Employee Training: Staff trained on data protection and privacy

12.3 Limitations

No system is 100% secure. Despite our efforts, we cannot guarantee absolute security. You acknowledge that:

  • Unauthorized access, breaches, or data loss may occur
  • You use the Service at your own risk
  • You are responsible for maintaining the security of your account credentials

13. Data Breach Notification

In the event of a data breach that affects your personal information:

13.1 Notification to Authorities

  • EU/Spain: We will notify the relevant supervisory authority within 72 hours (GDPR Article 33)
  • US (HIPAA, if applicable): Notification to HHS within 60 days for breaches affecting 500+ people
  • Mexico: Notification "without delay" if the breach has significant impact (LFPDPPP)

13.2 Notification to Users

  • We will notify affected users without undue delay via email or in-app notification
  • Notification will include:
    • Nature of the breach
    • Types of data affected
    • Steps we are taking to address the breach
    • Steps you can take to protect yourself

14. Cookies and Tracking Technologies

14.1 Types of Cookies We Use

  • Essential Cookies: Required for login, session management, and core functionality (cannot be disabled)
  • Preference Cookies: Remember your language, theme, and settings
  • Analytics Cookies: Help us understand how the Service is used (PostHog)

14.2 Third-Party Cookies

We may use third-party analytics providers that set their own cookies. See their privacy policies:

  • EU/Spain Users: We will obtain your consent before placing non-essential cookies (ePrivacy Directive)
  • All Users: You can manage cookie preferences in your browser settings
  • Disabling cookies may affect Service functionality

15. Automated Decision-Making and Profiling

15.1 AI-Powered Features

The Service uses AI to:

  • Transcribe voice recordings (Google Gemini via Vertex AI)
  • Extract text from images (Google Gemini via Vertex AI)
  • Categorize and structure medical data

15.2 Human Review

AI outputs are suggestions only and are NOT used for:

  • Automated medical decision-making
  • Automated decisions that significantly affect you

You always have the opportunity to review, correct, and override AI-generated content.

15.3 Right to Object (GDPR)

EU users have the right to object to automated processing and request human review. Contact our DPO to exercise this right.

16. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we make changes:

  • We will update the "Last Updated" date at the top of this policy
  • For material changes, we will notify you via email or in-app notification at least 30 days in advance
  • Continued use of the Service after changes take effect constitutes acceptance of the updated policy

We encourage you to review this policy periodically.

  • Account Creation: You provide consent by accepting this Privacy Policy and our Terms of Service during signup
  • Granular Consent: You can control specific consents (e.g., AI processing, analytics) in account settings [TBD: implement consent management UI]
  • Health-data acknowledgment for documents: Before a dependent's documents are first saved or viewed, a person with access to their profile confirms a health-data notice. Kinali records who confirmed it, when, and the notice version; any person with access may confirm it for everyone else. In Capture, the notice appears when you save, after the scan's images have already been sent to Google (Vertex AI) to read them; choosing Back discards the save and nothing is stored in Kinali, but it does not undo that processing.

You may withdraw consent at any time by:

Effect of Withdrawal: Withdrawing consent may limit Service functionality or require account termination.

18. Health Data and HIPAA

Kinali is designed for families coordinating care for loved ones. Kinali is not a healthcare provider, health plan, or healthcare clearinghouse, and is not a "Covered Entity" or "Business Associate" under the U.S. Health Insurance Portability and Accountability Act (HIPAA).

We recognize that the information you store in Kinali — including medications, medical notes, and health observations — is sensitive. We protect it with industry-standard security measures including encryption in transit and at rest, role-based access controls, and contractual data protection obligations with our service providers.

We have executed a HIPAA Business Associate Addendum (BAA) with Google Cloud Platform, which processes AI-related features (voice transcription, OCR, data structuring) through Vertex AI. We maintain Data Processing Agreements with all other infrastructure providers (Supabase, Cloudflare, Resend, PostHog).

However, Kinali does not represent itself as HIPAA-compliant. Full HIPAA compliance requires organizational policies, workforce training, risk assessments, and audit controls beyond the scope of a BAA. Additionally, not all of our service providers have executed BAAs.

If you are a healthcare professional, do not use Kinali to store or process Protected Health Information (PHI) that you handle in your professional capacity.

Kinali complies with applicable consumer health data protection obligations, including the FTC Health Breach Notification Rule, which applies to consumer health data maintained by non-HIPAA entities.

19. Contact Information and Complaints

19.1 General Privacy Questions

Email: hello@tesselabs.com Registered Office: 1209 Mountain Road PL NE, STE R, Albuquerque, NM 87110, USA

19.2 Data Protection Officer (EU/Spain Users)

Name: Guillermo Pascual Email: dpo@tesselabs.com

19.3 Supervisory Authorities

You have the right to lodge a complaint with your local data protection authority:

19.4 US State-Specific Contacts

  • California Attorney General (CCPA): oag.ca.gov/privacy
  • FTC (COPPA): www.ftc.gov

By using the Service, you acknowledge that you have read and understood this Privacy Policy and consent to the collection, use, and sharing of your personal information as described herein.