Privacy Policy

KinVitals Privacy Policy
Aug 18, 2026

Effective date: October 3, 2026

Policy version: 2026-10-03

KinVitals (kinvitals.app) is a family health record tool operated under the KinVitals name by Dynamics Tech Ignite Inc., a federally incorporated Canadian company ("we," "us," or "our"). This Policy explains what information we collect, why we collect it, who can see it, and how you can access, correct, export, or delete it.

This pilot is available only to adults who reside in Canada but not in Quebec. Account holders and profile owners must be at least 18 years old. The Service currently has no process for a guardian, agent, or other substitute decision-maker to provide consent on another person's behalf.

We comply with applicable Canadian private-sector privacy laws, including the Personal Information Protection and Electronic Documents Act (PIPEDA) and, where applicable, substantially similar provincial legislation.

We put one principle first: the person whose health is recorded controls that health data. All of the rules below follow from this principle.

1. Information We Collect

1. Account Information

When you register, you provide your name (or preferred name) and email address. You may sign in with a password or, when enabled, a one-time sign-in link sent to your email address. If you use a password, it is stored as a one-way hash, and we cannot see your original password. After you sign in, we place a session cookie in your browser to keep you signed in.

To protect sign-in security, we record the browser User-Agent for each session and store it with the session record.

The system also records when the account was created and updated, and your interface language.

2. Care Recipient Profiles

When you create a profile for a family member (or yourself), you enter a display name, year of birth, gender, and time zone. Year of birth and gender are optional. The time zone is used to display the correct day for a health observation.

Before creating a basic profile for another adult, the profile creator must have that adult's permission to create it.

With the person's permission, you may also provide a phone number for the profile to support family access requests.

This lets another family member ask to join the same family profile, but it does not grant access.

The server normalizes the number and uses a server-side secret to generate a derived identifier that is not directly reversible through HMAC-SHA256. The original phone number is sent to the server over HTTPS and processed only transiently. After the derived identifier is generated, we do not persist the original phone number, write it to application logs, or return it in a response. The derived identifier is stored with the profile to find possible matches; a person who manages the basic profile may replace or remove it.

Only a signed-in user with a verified email address may submit an access request using a phone number. Whether or not the number matches a profile, the submission response is the same. The response does not reveal whether a profile exists, any profile information, the number of matches, or which profile owners received a request. After a profile owner approves a request, the requester can see the approved profile.

An access request does not itself grant any permission; the requester receives access only if the profile owner approves the request.

3. Health Observations

You or an authorized family member manually enter blood pressure, blood glucose, blood oxygen, heart rate, uric acid, body temperature, and body weight values and units; the time and context of the measurement (such as fasting or after a meal); notes; and who entered the observation.

Some fields and codes in our internal data model correspond to HL7 FHIR concepts such as Patient and Observation. However, we do not represent that our internal storage or current export is a complete FHIR resource or Bundle that can be imported directly into another health system. See Section 7 for export details.

4. Invitation Information

When you invite a family member to view a profile, or invite the person described in a profile to claim it, the Service generates an invitation link for you to send through a channel you choose. We store necessary information such as the invitation type, permissions, status, and creation and use timestamps. The credential in the link is stored in our database only as a hash, so we cannot reconstruct the original link from the database. The current product interface does not ask you to provide a recipient's email address or phone number to send an invitation.

5. Access Request and Grant Records

A submission may create a pending request for one or more eligible matching profiles. The owner of a profile that receives a request can see the requester's verified email address and display name, if provided, to decide whether to approve it. The submission response does not reveal the number of matches, the matching profiles, or which profile owners received a request. After a profile owner approves a request, the requester can see the approved profile.

We retain the requester, profile, status, and creation and decision timestamps for access requests to deliver and decide requests, enforce access controls, prevent misuse, and support security audits. The current interface shows profile owners only pending requests. Separately, we retain records of who granted access to whom and when, and who revoked access and when. These grant and revocation records form the access-grant history that a profile owner can review and export.

An access request record does not itself provide access. If the profile owner approves it, the requester may view the profile and assist with record-keeping within their permissions. The profile owner may revoke that access later.

6. Access Logs

Our hosting providers may record standard access logs, such as IP addresses and access times, for security and operational purposes.

The Service now supports uploading original medical reports (see Section 1, item 7) and recording Chinese herbal prescriptions (see Section 1, item 8), and it still does not connect to any third-party health platform. Apple Health, Health Connect, and Bluetooth device integrations remain planned features and are not currently available. However, notes are free text. If you enter diagnoses, medications, or other health information in a note, we will handle the information you actually enter under this Policy. Please do not enter information that is unnecessary for the purpose of the record.

7. Uploaded Medical Report Originals

You or an authorized family member may upload original medical reports as photos or PDFs, such as lab reports, imaging reports, discharge summaries and prescriptions.

When you upload a photo, your browser first removes the EXIF metadata the camera wrote, including GPS, converts the image to JPEG (longest edge at most 2,000 pixels, compressed to under 2 MB), and makes a small thumbnail for the list; what we keep is that converted version. PDFs are stored exactly as uploaded.

We keep the files as uploaded and do not recognize or extract the values in them, and do not interpret them. An original may carry identifying information such as a name, date of birth, medical record number, government identification number, hospital, and department. We handle what a file actually contains under this Policy. Please upload only the reports needed for care.

We record who uploaded the file and when, together with the title, category, report date, hospital, department, and note you enter.

Only the profile owner and authorized family members may view these files. Until the profile owner confirms viewing access, a family member assisting with record-keeping may see only the reports they uploaded. A report marked "uploaded by mistake" is hidden from the report list, and from then on only the profile owner can still see the record and can obtain the file through an export. The profile owner may permanently delete such a report; the file and its thumbnail are then removed from storage, and it no longer appears in exports.

8. Chinese Herbal Prescription Records

You or an authorized family member may record Chinese herbal prescriptions: the date of each prescription and, for each herb, its name and quantity (packets or grams). A herb entered without a quantity is saved as 1 packet. We keep the text exactly as it was typed, the herb name as confirmed, who recorded it, and when.

Herb names and the typed text are free text; please enter only the prescription itself. We use these records only to store and display them, compare a prescription with the one before it, show which prescriptions each herb appeared on and the periods between them, and mark prescription dates on the trend charts. We do not judge combinations, doses, or effects, and do not infer that any change in measurements is related to a prescription.

Editing a prescription creates a new version and keeps the earlier one; a prescription marked "entered in error" is hidden from the list and keeps the reason given, who marked it, and when. Viewing follows the same rules as health observations: until the profile owner confirms viewing access, a family member assisting with record-keeping may see only the prescriptions they recorded, and earlier versions and prescriptions marked "entered in error" are visible to the profile owner only.

2. Who Controls the Data

Each health profile is controlled by the adult it describes.

With the person's permission, a family member may first create an unclaimed profile that contains only basic information such as a display name, year of birth, gender, and time zone. Before a person claims the profile, becomes the profile owner, and consents to the then-current Privacy Policy, no one may write a health observation to that profile.

  • Before the profile is claimed, the family member who created it may view and correct the basic profile information and generate a claim link.
  • After the profile is claimed and the person consents to the Privacy Policy, the family member who created the profile may assist with record-keeping within the permissions available to them. Until the profile owner confirms viewing access, that family member may see only the observations they entered. The profile owner may approve access to the complete record, refuse it, or revoke it later.
  • Whenever we require consent to a new version of the Privacy Policy, both the profile owner and the person actually entering the observation must consent to the new version before they can write another health observation or prescription record.

Except for the limited situation above, where a family member awaiting approval may see only the observations they entered, the reports they uploaded, and the prescriptions they recorded, only the profile owner and family members or caregivers expressly authorized by the profile owner may view the complete record. If the profile owner refuses or revokes access, the other person can no longer read any health observation in that profile.

3. You Can Stop Sharing at Any Time

The profile owner may revoke any access grant at any time. Revocation takes effect immediately: from that moment, the other person can no longer see any observation in the profile, including observations that person previously entered.

An authorized family member may also leave a profile and revoke their own access to it.

We retain a historical record of the revocation, including who revoked whose access and when, but that record does not provide any continuing access.

4. How We Use the Information

We use this information only as necessary to provide and protect the Service, including to:

  • create accounts, authenticate sign-ins, maintain sessions, and protect account security;
  • store profiles, health observations, and prescription records and show records and trends to profile owners and people they authorize;
  • generate phone-derived identifiers, receive access requests, and let profile owners approve or reject them;
  • generate and verify claim or sharing invitations, and carry out access grants, revocations, exports, and deletion requests; and
  • troubleshoot problems, respond to support requests, prevent misuse, and comply with applicable law.

We do not:

  • sell or rent your health data or provide it to third parties for marketing;
  • use your health data for advertising; or
  • allow any other user to see your data without authorization.

5. Storage, Processing, and Security

  • Vercel provides application hosting and runtime infrastructure for the Service, Supabase provides the hosted PostgreSQL database, and Resend is the transactional email provider configured for the Service. As our service providers and data processors, they process information on our behalf as needed to provide the Service and may use their own subprocessors. Transactional emails may include email verification, one-time sign-in links, and service notifications.
  • Vercel, Supabase, and their subprocessors may store or process your information outside your province or Canada, where it may be subject to lawful access under foreign laws.
  • Resend and its subprocessors may also process information relating to transactional emails outside your province or Canada, where it may be subject to lawful access under foreign laws.
  • Cloudflare provides object storage (R2) for uploaded medical report originals. These files are configured to be stored in Cloudflare storage facilities in North America, are reachable only through the expiring links the Service issues, and have no public address. Cloudflare and its subprocessors may store or process these files outside your province or Canada, where they may be subject to lawful access under foreign laws.
  • Information is encrypted in transit using HTTPS. Sign-in uses a session cookie. Credentials in claim and sharing invitation links are stored in the database only as hashes.
  • We retain your health observations until the profile owner deletes the profile or closes the account, or until the law requires us to handle them differently. Health observations support long-term trends, and we do not make them expire solely because time has passed.

If a breach of security safeguards involving personal information occurs, we will keep required records and, when legally required, report it to the appropriate privacy regulator and notify affected individuals.

6. Access, Correction, and Deletion

Access and Correction Requests

You may contact the Privacy Officer listed in Section 11 in writing to request access to personal information we hold about you or correction of inaccurate or incomplete information. We may need to verify your identity before processing a request. We will respond within the time required by applicable law. Under PIPEDA, the usual response period is 30 days after we receive a request, subject to statutory exceptions or extensions. If the law prevents us from fulfilling all of a request, we will explain the reasons and available next steps to the extent the law permits.

Correcting Health Observations

Health observations cannot currently be edited directly in the application. To request a correction, contact the Privacy Officer in writing. We may verify your identity and ask for verifiable facts supporting the requested correction. We will handle the request in accordance with applicable law.

A Chinese herbal prescription can be edited in the application by the person who recorded the current version or by the profile owner (the earlier version is kept, and the new version is recorded under the person who made the edit), or marked "entered in error" (the reason given, who marked it, and when are kept).

Deleting a Profile in the Application

The profile owner can first archive a profile and then permanently delete it in the application. Its observations, Chinese herbal prescription records, uploaded original medical reports and access grants are then deleted from our active systems together, family members who had access lose it immediately, and the deletion cannot be undone. The owner can export the profile's data first. The limits on provider backups and legally retained records described below for account closure apply in the same way.

Account Closure and Deletion

You may request account closure by emailing hello@kinvitals.app. After closure, health profiles for which you are the profile owner, the associated observations, and account information we no longer need will be deleted from our active systems. Family members who previously had access will also lose access. Uploaded original medical reports and Chinese herbal prescription records are deleted together with the profile they belong to.

Deletion does not mean that every copy disappears from every location at the same moment. Limited information may remain in provider backups until they rotate in the ordinary course. It may also remain in security logs, breach of security safeguards records retained as required by law, or other records we must retain for legal reasons. In these circumstances, we restrict its use and delete or de-identify it through the applicable process once the retention purpose no longer applies.

7. Exporting Your Data

The profile owner may export the profile's information, health observations, and access grant history. The current export is structured JSON aligned with selected FHIR concepts and codes, not a FHIR Bundle that can be imported directly into a clinical system. The data may need to be mapped, validated, or converted before another system can import it. The export includes the record information for original medical reports and a download link for each original that is valid for 24 hours. It also includes every Chinese herbal prescription, including earlier versions and prescriptions marked "entered in error".

8. Adult Pilot

This pilot is available only to people who are at least 18 years old as both account holders and profile owners. An unclaimed profile may be created only for an adult who has agreed to the creation of the basic profile. The Service currently does not offer accounts for children or a process for a guardian, agent, or other substitute decision-maker to provide privacy consent or claim a profile on another person's behalf.

9. Important Limitations

KinVitals is for recording, organizing, and displaying health trends. It does not provide medical diagnosis or treatment advice, is not a medical device, and is not for emergencies. Consult a qualified health professional about health concerns. In an emergency, call your local emergency number immediately.

Any numerical indicator shown in the interface merely presents the information you entered and is not a medical judgment. Trend charts may show a published general adult reference interval alongside your readings, for reference only; the Service does not compare any reading against it and raises no alerts from it. Trend charts may also mark the dates Chinese herbal prescriptions were issued, for reference only; the Service does not judge whether any change in readings is related to a prescription, and makes no judgment about a prescription's combinations, doses, or effects.

10. Policy Updates

We will notify you by email or through the application before material changes to this Policy take effect, particularly changes to the scope of information collection or how information is shared. Each update will show a new effective date on this page. When consent to an updated Policy is required, the Service will require the profile owner and the person actually entering an observation to consent separately before another health observation or prescription record can be written.

11. Contact Us and Make a Complaint

If you have questions about this Policy or wish to exercise access, correction, or other privacy rights, contact the Privacy Officer of Dynamics Tech Ignite Inc. in writing at hello@kinvitals.app.

If you are dissatisfied with our response, please contact the Privacy Officer first so we can investigate and respond. You may also make a complaint to the Office of the Privacy Commissioner of Canada or, where applicable, the relevant provincial privacy commissioner.