Kindred — Privacy Notice

Status: v0.15 · Testing stage: Kindred is used by the founder’s family and invited testers only. Last updated: 2026-10-07


In short — the 30-second version

The full notice is below. Read it once. The short version above is what most caregivers need to know.


1. Who we are

Kindred is operated by Ajay Gaur, an individual based in India, acting as the Data Fiduciary under the Digital Personal Data Protection Act, 2023 (“DPDPA”).

If Kindred incorporates as a legal entity in future, this notice will be updated and you will be asked to consent again.

For everything in this notice, “we” / “Kindred” means the data fiduciary above. “You” means the person whose personal data is being processed — what DPDPA calls the Data Principal.

2. What we collect

We only collect data we actually need to run the app. Today, that means:

Account data

Health-record data you upload

Vital readings you log

Caregiver-relationship data

WhatsApp data (only if you use Kindred on WhatsApp)

AI readings

Questions you ask Kindred

Phone notifications (Kindred Android app)

Operational logs

What we do not collect today

3. Why we collect it

What we collect Why
Account data To let you sign in, recognise you across devices, and contact you if needed.
Health-record data To store records on your behalf and show them back to you and the caregivers you authorise.
Vital readings To track day-to-day measurements, show trends to caregivers, and alert co-caregivers when a reading crosses a threshold the family has set.
Caregiver-relationship data To deliver invites, grant access to the records and vitals you’ve chosen to share, and keep an honest audit trail of who agreed to what and when.
WhatsApp data To receive reports you send on WhatsApp, file them under the right family member, and reply to you.
AI readings To explain a report in plain words, flag results that need attention, and show trends across reports.
Questions you ask, visit briefs To answer questions about your family’s records and prepare a one-page brief for a doctor visit.
Reports of AI answers To check AI answers that people flag as wrong, harmful or offensive, and to make Kindred’s AI answers better.
Phone notification tokens To tell you on your phone when someone else adds a report or a reading for a person you look after, and when a home check for them is due.
Operational logs To keep the service secure, diagnose problems, and detect abuse.
App error reports To find and fix what goes wrong in the Kindred app, for example why a sign-in failed on a certain phone.

We do not use any of this data for advertising, marketing profiling, or sale to third parties.

We process your personal data on the basis of your consent (DPDPA Section 6). When you sign in for the first time, the line right under the Continue with Google button says that continuing means you agree to this notice and that AI explains your reports, with a link to this notice; tapping the button is your agreement. Nothing is pre-ticked, and Kindred stores or files nothing for you before that. AI reading is on for a new account, and you can turn it off at any time in Profile (see AI reading of reports). Whenever what you agree to changes, Kindred shows you once that the notice was updated, and you tap Agree and continue; your AI choice stays as it was. Records you add for the people you care for are added by you, as their caregiver, on their behalf. Operational logs and app error reports are processed on the basis of legitimate uses (security and service operation) under DPDPA Section 7.

You can withdraw consent at any time — see Your rights. Withdrawal applies going forward and does not affect processing that has already happened.

5. Where your data is stored

6. How long we keep your data

Type of data Retention
Account data (name, email, profile picture, Google ID) Until you delete your account. Your account is locked at once and erased 24 hours later (you can undo until then). What remains is an anonymous placeholder with no name, email, Google ID or picture, so that reports you added for people others look after stay with those people.
Patient records you uploaded Until you delete the record, or delete your account. A deleted record is hidden at once and erased 24 hours later, file first (you or another caregiver of that person can undo until then). Deleting a person hides and then erases all of their records the same way.
Vital readings you logged Until the person they belong to is deleted, or you delete your account (if no one else looks after that person). Erased 24 hours after the request, like records.
Caregiver invites and acceptance records Until you remove the caregiver, or delete your account. Consent attestations linked to these events are retained for 3 years after the share ends, as a privacy / DPDPA audit trail.
AI readings and the test results taken from them As long as the record they came from. Deleting the record deletes them.
WhatsApp link (your number ↔ your account) Until you send STOP, or until 90 days pass with no message from you, or you delete your account.
WhatsApp message log (type, time, outcome; no text) 30 days, then deleted.
A WhatsApp file waiting for you to say whose report it is 24 hours, then deleted if you don’t choose.
One-time join links Until used, or 7 days, whichever comes first. The record of who created and used it stays with the caregiver audit trail.
Your chat with Kindred (questions, answers, the AI’s working copy) 30 days from each message, then deleted. Deleted at once when you tap Clear chat or delete your account, and when a person or report it used is deleted. Hidden while you can no longer see a person it used, or they turned AI reading off.
AI answers you report (your reason, your note, and the answer’s text) 90 days, then deleted. Also deleted with the report it is about, or with your account.
Your consent choices (which version of this notice, AI reading yes or no, when) While your account exists, and 3 years after it is erased, as the record of your consent. They hold no name or email address.
Push token for your phone Until you sign out on that phone, Google tells us the token no longer works (for example, the app was removed), or you delete your account.
Server logs (incl. IP address) 90 days, then deleted. Retained for security and debugging.
App error reports 30 days, then deleted. Also deleted with your account.
Sign-in audit logs 90 days, then deleted.
Operational backups Up to 30 days on a rolling window. Deletion requests propagate to backups within 35 days of the request.

If a deletion request reaches us via email, we treat it as a formal right-to-erasure request under DPDPA and the timelines above apply.

7. Who we share it with

We share your data with a small number of service providers (called Data Processors under DPDPA), strictly to operate the service:

We also share data with other caregivers you choose to invite:

We do not share your data with:

We do not sell your data. There is no business model that involves selling data, and we have no intention of building one.

8. Your rights

Under DPDPA, you have the following rights as a Data Principal. They apply to you whenever Kindred is processing your personal data.

For data about a patient you care for (e.g., your aging parent), the patient is the Data Principal. If the patient is able to use Kindred themselves, they can sign up and claim their record — at which point they can exercise these rights directly. Until then, you exercise these rights as their lawful caregiver.

9. How to use these rights

Three ways:

We respond to all requests within 30 days. Most are completed within 7 days.

We will not charge a fee for these requests, unless they are manifestly unfounded or excessive (e.g., the same request repeated many times in a short period) — in which case DPDPA permits a reasonable fee or a refusal.

10. Data about children

DPDPA defines a child as anyone under 18 (Section 9).

11. Grievance redressal

If you have a complaint about how we are handling your personal data, write to:

Email: ajaygaur319@gmail.com For the attention of: Grievance Officer, Kindred Response time: Acknowledgement within 7 working days; resolution within 30 days.

If you are not satisfied with our response, you can complain to the Data Protection Board of India under DPDPA Section 13. The Board’s contact details and complaint process will be published on the Government of India’s official channels once the Board is fully constituted.

12. AI reading of reports

When a report is uploaded (in the app, on the web or on WhatsApp) and you have said yes to AI reading, Kindred asks an AI model to read it and explain it.

Asking Kindred and visit briefs

13. Using Kindred on WhatsApp

14. Future changes

When a new feature processes your data in a way this notice does not describe, we will:

  1. Update this notice to describe exactly what the feature does, what data it processes, where it runs, and what it returns.
  2. Ask you to consent again, specifically for that processing. You can refuse, and the feature will stay off for your account.

For other changes (e.g., adding a new feature, switching a service provider), we will update this notice and post the change date at the top. Material changes will be communicated by email and through an in-app prompt.

15. How to reach us

For anything in this notice — questions, rights requests, grievances, corrections — write to:

ajaygaur319@gmail.com

For everything else (product feedback, bug reports, general questions), use the in-app feedback option once it ships, or the same email above.


Appendix — for the developer wiring this in Phase 0.5

This appendix is not part of the user-facing notice. Strip it from the in-app screen.

Stable section anchors

These anchors are part of the contract. Don’t rename them — Phase 0.5 in-app deep links and any future settings cards will link to them.

Things that must be true before this notice is shown to any external user

The notice makes promises Kindred has to actually keep. Block Internal Testing publication (and all later tracks) until each of these is true:

  1. ajaygaur319@gmail.com is a monitored inbox. A 7-day acknowledgement and 30-day resolution SLA is stated; the inbox must reach Ajay reliably and have a triage process. (Tracker: Phase 0.5 r94 grievance contact row.) Phase 0.5 contact is Ajay’s personal Gmail; will swap to privacy@kindred.in when kindred.in is registered (R238).
  2. Account deletion actually erases data, including S3 record bytes and all object versions. Done for files on the Kindred server (testing stage), 2026-09-30: DELETE /auth/me erases files and data 24 hours after the request. Still open: all object versions once files move to a versioned S3 bucket. (Tracker: Phase 0.5 r14 DPDPA hard-delete + r95 R12 S3 cascade rows.)
  3. Per-record deletion erases all S3 versions, not just adds a delete-marker. (Tracker: Phase 1.5 record-deletion + delete-version row.)
  4. The in-app privacy notice screen is wired — first-launch overlay + permanent link from Profile screen. (Tracker: Phase 0.5 r93 in-app privacy screen row.)
  5. The web-based account deletion mechanism is live — done 2026-09-30: Profile → Delete my account on the web app (§9). Required by Google Play Policy for any app with account creation, and required for the §9 promise to be honest. (Tracker: Phase 0.5 R236 web-based deletion row.)
  6. Consent is captured affirmatively — a tap on a clearly-labelled control with the agreement stated next to it, not a pre-ticked checkbox or implicit consent from continuing to use the app. (DPDPA Section 6.) Done 2026-09-30: consent screen in the app and web app (unticked “I agree”), stored per version; the API refuses everything else until then. Changed 2026-10-05 (v0.13): the agreement line sits under every Continue with Google button and the tap is recorded as consent (version, AI choice, source); updates use a one-tap Agree and continue screen.
  7. Patient-controlled creator-revocation is implemented for Scenario A (when a patient self-claims their record). The §7 promise that “if you are the patient yourself, you can revoke any caregiver — including the person who originally added you — without their cooperation” is currently true for non-creator caregivers but needs to extend to the creator when Scenario A ships. (Tracker: Phase 1 R234 patient-controlled creator-revocation row.)
  8. Consent for AI reading and for WhatsApp is captured before any person outside the testing group uses Kindred (§12). Until then, AI reading is on for all testers. (Added in v0.4.) Done 2026-09-30: AI reading is a separate unticked choice, enforced by the server for report reading, Ask and briefs; WhatsApp files nothing before consent.
  9. Photos and scans are redacted before AI reading, or the notice keeps saying they are sent as images (§12). OCR with in-code redaction is planned. (Added in v0.4.)

If any of these is not yet true when Internal Testing or any wider track is being considered, do not publish. Either complete the row, or revert the notice to “internal use only” and gate publication behind the dependency.

Decisions deferred to a later notice version

These are honest gaps that will be filled when the corresponding feature lands. Don’t try to address them in this version — they don’t exist yet.

Things this draft deliberately does not promise

To keep the notice honest and avoid commitments Kindred can’t yet keep:

When to bump the version