Last updated: 2026-05-25
Who we are
Kitrus is operated by Amplify Media Inc Ltd, a private limited company incorporated in England and Wales, registered office at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ. We provide a consumer wellness organizer that helps users collect, track, and review information about their own health and wellness.
Questions about this policy: hello@kitrus.ai.
How this policy is structured
This policy covers everything Kitrus processes on the iOS app and on the website at kitrus.ai. The two platforms use different sets of processors. We call out the differences in plain language where they matter.
For Washington residents, our standalone Washington Consumer Health Data Privacy Policy applies in addition to this policy.
For account deletion specifics, see the Account Deletion page.
How you can access Kitrus
Kitrus is available on three surfaces:
- The iOS app, distributed through the Apple App Store
- The website at kitrus.ai
- The Kitrus Telegram Mini App, accessible inside Telegram
The Telegram Mini App is the Kitrus web app rendered inside the Telegram client. When you use the Mini App, the same processors listed below apply. See the Data sources (not processors) subsection below for what Telegram itself receives as part of how its platform works.
Clinical use and HIPAA
Kitrus is a consumer wellness and educational tool. Amplify Media Inc Ltd is not a HIPAA covered entity or business associate by default, and Kitrus is not a regulated medical device.
You can use Kitrus for personal wellness organization and to prepare better conversations with your healthcare provider. HIPAA-covered clinical deployments require a separate Business Associate Agreement (BAA) with Amplify Media Inc Ltd and a different deployment configuration. Clinicians interested in that should contact hello@kitrus.ai before using Kitrus for covered patient workflows.
iOS app: a strict subset of these processors
The Kitrus iOS app uses a strict subset of the processors listed below. The iOS binary contains:
- No advertising SDKs
- No IDFA
- No cross-app tracking
- No marketing pixels
Vendors marked web only below do not receive any data from the iOS app.
Affiliates
Amplify Media Inc Ltd does not currently share personal data or consumer health data with any corporate affiliates. If that changes, we will update this policy and, where the law requires, obtain fresh affirmative consent before sharing with any affiliate.
What we collect
Account data: email address, password (hashed) when you sign up with email/password, Apple Sign-In identifier when you sign up with Sign in with Apple, Google Sign-In identifier when you sign up with Sign in with Google, optional name, optional date of birth, optional sex at birth, your Kitrus user ID.
Health and wellness data you enter: lab results, uploaded medical documents and lab images, medications and supplements, dosage history, symptoms, journal entries and wellness notes, menstrual and cycle data, fertility-window logs, hormone-related symptoms, conditions or treatments you describe to give Kitrus context.
Wearable data: with your explicit permission inside the app, Kitrus reads Apple Health data — sleep, heart rate, resting heart rate, heart-rate variability, steps, blood-oxygen saturation. You can revoke this in iOS Settings → Privacy & Security → Health → Kitrus.
Chat data: the questions you send to Kitrus's AI assistant and the responses Kitrus returns, including the wellness-profile context Kitrus includes with each turn.
Uploaded documents: PDFs and images of labs, prescriptions, or other health documents you upload.
Usage and device data: session identifiers, device type and OS version, app version, in-app navigation events, notification delivery and open events, onboarding funnel events, subscription product and entitlement identifiers.
Network identifiers: IP address, approximate city-level location derived from IP for security and fraud prevention, and similar technical identifiers required to deliver the service.
Derived data: patterns, themes, and inferences Kitrus surfaces from your data through algorithms — described in WA MHMDA's statutory terms as "proxy, derivative, inferred, or emergent" data.
Sources of personal data
We collect the data above:
- Directly from you when you sign up, complete onboarding, log
data, upload documents, send chat messages, or use cycle-tracking surfaces
- From documents you upload, which may originate from your
healthcare providers, laboratories, or other clinical sources
- From Apple Health, only after you grant explicit permission
inside the app
- Automatically from your device when you use Kitrus — session,
device, app version, IP address
- Generated by our own systems as patterns and inferences derived
from the data you provide
How we use it
We use your data to:
- Organize your wellness profile inside Kitrus
- Surface patterns in your own data for you to review
- Power AI-assisted conversations and prepare discussion prompts you
can bring to a qualified healthcare provider
- Provide features you have asked for, including labs review,
medication tracking, symptom logging, cycle tracking, and clinician handoff briefs
- Send transactional messages about your account, subscription, and
data
- Maintain platform security, prevent fraud, debug errors, and meet
legal obligations
We do not use health data for third-party advertising, third-party marketing, data-broker disclosure, or to build profiles for cross-context behavioural advertising.
AI processing and consent
Kitrus uses OpenAI for AI-assisted reasoning. When you use Kitrus's chat or AI-driven features, the content you send and the wellness- profile context Kitrus includes for that turn are sent to OpenAI's API for inference. OpenAI processes these requests under our agreement. Inputs and outputs sent through Kitrus's API are not used to train OpenAI's models.
Kitrus treats health-data processing and AI processing as separate, explicit, affirmative consents, captured at the moments described in the What we collect and AI processing sections. Both meet the standard of a clear affirmative act — freely given, specific, informed, opt-in, voluntary, and unambiguous. You can withdraw either at any time in Profile → Privacy & Data; withdrawing AI consent stops further AI processing for your account. Continued use of Kitrus is not consent. We record each consent grant and withdrawal.
We do not currently use any other LLM provider.
Subprocessors
Below is the list of processors Kitrus uses to operate the product. Each is governed by a written data-processing agreement and is restricted to processing data only for Kitrus's instructions. The Platforms column shows which Kitrus platform sends data to each processor. Apple HealthKit is an OS framework, not a subprocessor; it is listed separately under "Data sources" because the data flow is fundamentally different.
| Processor | Purpose | Platforms | Data sent | Location |
|---|---|---|---|---|
| Supabase | Database, file storage, authentication | iOS + Web | All account and health data | EU (Ireland, eu-west-1) |
| OpenAI | AI inference for chat and wellness analysis | iOS + Web | Chat content + wellness-profile context, under explicit consent | USA |
| Vercel | Website + backend serverless functions | iOS + Web | Kitrus's serverless functions execute server-side on payloads that include health data while preparing requests for OpenAI inference and persisting data to Supabase. Health data is encrypted in transit (TLS 1.2+) into and out of Vercel. | USA |
| Apple Sign in with Apple | Authentication (one of three sign-in paths) | iOS + Web | Apple ID identifier | USA |
| Google Sign-In | Authentication (one of three sign-in paths) | iOS + Web | Google account identifier | USA |
| Apple App Store / StoreKit | Subscription billing | iOS only | Subscription identifier and status only | USA |
| RevenueCat | Subscription state management | iOS only | Subscription identifier and entitlement status only — no health content | USA |
| Sentry | Crash and error diagnostics | iOS + Web | Scrubbed technical error data only — PHI stripped before send | USA / EU |
| Expo | Mobile build infrastructure | iOS only | Build metadata; no user data | USA |
| Upstash | Caching and queueing | Web only | Operational state | USA |
| Cloudflare Turnstile | Bot protection on website forms | Web only | Form-submission challenge data | USA / global edge |
| Customer.io | Transactional and lifecycle email | iOS + Web | Account email + non-health lifecycle event metadata | USA |
| Meta (Facebook) | Advertising conversion measurement | Web only | App-install + subscription-conversion events; no consumer health data | USA |
| TikTok (pixel + CAPI) | Advertising conversion measurement | Web only | App-install + subscription-conversion events; no consumer health data | USA |
| Pinterest (pixel + CAPI) | Advertising conversion measurement | Web only | App-install + subscription-conversion events; no consumer health data | USA |
| Google Analytics 4 | Website analytics | Web only | Event metadata, client-side identifiers, page paths; no consumer health data | USA |
| PropellerAds | Advertising postback measurement | Web only | App-install + subscription-conversion events; no consumer health data | USA |
| PayPal | Alternative payment processing (website checkout only) | Web only | Payment metadata; no health content | USA |
| Whop | Alternative payment processing (website checkout fallback) | Web only | Subscription identifier and payment metadata; no health content | USA |
Data sources (not processors):
- Apple HealthKit — an Apple operating-system framework. With your
permission, the iOS app reads HealthKit data on-device and syncs it to Supabase under your Kitrus account. Apple does not act as a Kitrus subprocessor here; HealthKit is the source of the data.
- Telegram (Mini App platform) — when you launch the Kitrus
Telegram Mini App, Telegram receives standard Mini App init data (your Telegram user ID, your Telegram language, optionally your first name and username, auth data). This is part of how Telegram works. Kitrus does not send additional data to Telegram, and Telegram does not receive your labs, medications, symptoms, Apple Health data, chat content, or uploaded documents.
Health data restriction: Health data is stored in Supabase and sent to OpenAI only when you have given AI-processing consent. Vercel processes encrypted web/API requests in transit and runs Kitrus's serverless functions on those payloads to operate the website and backend. We do not send health data to advertising, marketing, analytics, billing, or lifecycle-email vendors.
If we add a new processor or change an existing one materially, we update this table, change the "Last updated" date, and notify you where the law requires it.
Data security
Health data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Access to production data is scoped by role and audited. Personal health information is excluded from logs by configuration and verified by automated tests on the error-diagnostics scrubber. Uploaded documents are stored in encrypted object storage with signed-URL access that expires.
Data retention
We retain different categories of data for different periods:
- Account profile: while your account is active.
- Health and wellness data: while your account is active. On
account deletion, removed from active production systems immediately and from operational backups within 7 days.
- Chat history: while your account is active, deleted on the
same timeline as health data.
- Uploaded documents: while your account is active, deleted on
the same timeline as health data.
- Subscription and billing records: retained where required by US
tax law for up to 7 years after the transaction, in a form that excludes health data.
- Security and abuse-prevention logs: retained for fraud
prevention, platform security, and legal defense. We minimize these records and exclude health content from them.
Two response timelines you should know:
- Privacy-right requests (access, deletion, opt-out, etc.) are
handled within 45 days of receipt where required by law.
- Account deletion requests are completed within 30 days of
verification, as described on our Account Deletion page.
Legal basis (GDPR)
For users to whom GDPR applies, the legal bases on which we process your data are:
- Contract — to provide the service you signed up for.
- Explicit consent (Article 9) — for the processing of health
data you enter into Kitrus.
- Explicit consent (Article 9) — for AI processing of health
data by OpenAI.
- Legitimate interest — for security, fraud prevention, and
product improvement, balanced against your rights.
EU and UK launch is deferred to a later Kitrus version; this section is maintained for forward readiness.
Automated decision-making
Kitrus uses algorithms to surface patterns and themes in your data. None of these produce a legal effect or similarly significant effect on you. All patterns and themes are informational and intended to support conversations with a qualified healthcare provider.
Your rights
Wherever you live, you have the following rights over the personal data Kitrus processes about you. The fastest path is in-app:
- Access / export: Profile → Privacy & Data → Export my data
- Delete: Profile → Privacy & Data → Delete Account
- Withdraw AI consent: Profile → Privacy & Data → AI consent toggle
You can also email hello@kitrus.ai to exercise any right.
The rights themselves:
- Access the personal data we hold about you, including a list
of the third parties with whom we have shared or sold your data and a contact method for those parties.
- Rectify inaccurate or incomplete personal data.
- Export / portability — receive your data in a structured,
machine-readable format.
- Delete your account and personal data. We will delete the data
from active production systems, notify processors, contractors, and other third parties with whom we shared it, and remove it from operational backups within 7 days.
- Restrict processing in certain circumstances.
- Object to processing based on legitimate interest.
- Withdraw consent at any time, including AI-processing consent
and HealthKit access.
- Complain to a supervisory authority.
We respond to verified requests within 45 days of receipt. If we need more time, we will tell you in writing within that window and explain why, and we will respond within an additional 45 days.
If you need this policy or a privacy-rights response in an accessible format, contact hello@kitrus.ai.
US state privacy rights
If you are a resident of California, Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nevada, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia, or Washington, you may have specific rights under your state's privacy law in addition to the rights above. The rights listed above cover the substantive rights granted by each of those state laws. To exercise a state-law right, use the in-app paths or email hello@kitrus.ai.
Washington residents are also covered by our standalone Washington Consumer Health Data Privacy Policy.
Maryland residents: under the Maryland Online Data Privacy Act (MODPA), Kitrus processes sensitive personal information (including consumer health data) only where strictly necessary to provide or maintain the products and services you have requested. Kitrus does not sell sensitive personal information about Maryland residents. Kitrus does not use geofencing within 1,750 feet of mental-health, reproductive, or sexual-health facilities for any purpose.
California Notice at Collection
This California Notice at Collection complies with the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA / CPRA), Cal. Civ. Code §§1798.100, 1798.130, 1798.135, 1798.140, and 1798.121.
Categories of personal information we collect, disclose, and share
| Statutory category (Cal. Civ. Code §1798.140(v)) | Collected | Disclosed for a business purpose to | Sold | Shared for cross-context behavioural advertising |
|---|---|---|---|---|
| (A) Identifiers (name, email, IP address, Apple Sign-In identifier, Google Sign-In identifier, Kitrus user ID) | Yes | Supabase, Customer.io, RevenueCat, Apple Sign in with Apple, Google Sign-In, Sentry, Vercel, Cloudflare; for cross-context advertising (web only): Meta, TikTok, Pinterest, GA4, PropellerAds | No | Yes (website only) |
| (B) Personal information categories listed in Cal. Civ. Code §1798.80(e) (name, signature where collected, account login, financial-account-routing identifiers via payment processors, medical information you enter) | Yes | Supabase, Apple Sign in with Apple, Google Sign-In, Apple App Store, PayPal, Whop, RevenueCat | No | No |
| (C) Protected classification characteristics (age, sex at birth — when you choose to provide them) | Yes | Supabase | No | No |
| (D) Commercial information (subscription purchase records, transaction history) | Yes | Apple App Store, RevenueCat, PayPal, Whop, Supabase | No | Yes (website only — non-health conversion events) |
| (E) Biometric information (sleep, heart rate, resting heart rate, heart-rate variability, steps, and blood-oxygen saturation when linked to your Kitrus user ID — California treats this as biometric information under Cal. Civ. Code §1798.140) | Yes | Supabase; OpenAI under explicit consent where included in AI context | No | No |
| (F) Internet or other electronic network activity (browsing, in-app navigation, session events, device metadata) | Yes | Supabase, Sentry, Vercel, Upstash, GA4 | No | Yes (website only) |
| (G) Geolocation data (IP-derived, approximate, city-level) | Yes | Cloudflare, Vercel, Sentry for security | No | No |
| (H) Audio, electronic, visual, or similar information (uploaded lab images, scanned medical documents, document PDFs) | Yes | Supabase, OpenAI (under explicit consent) | No | No |
| (I) Professional or employment-related information | Not collected | — | — | — |
| (J) Education information | Not collected | — | — | — |
| (K) Inferences (patterns, themes, derived signals) | Yes | Supabase, OpenAI (under explicit consent) | No | No |
| Sensitive PI — health (labs, medications, supplements, symptoms, cycle/fertility logs, hormone data, conditions, treatments, wearable metrics, chat content relating to health, uploaded health-document images) | Yes | Supabase, OpenAI (under explicit consent) | No | No |
| Sensitive PI — account log-in credentials (password hash) | Yes | Supabase | No | No |
| Sensitive PI — sex life or sexual orientation (cycle and fertility-window data are treated under SPI — health above; no separate sex-life or sexual-orientation data is collected) | Treated within SPI-health | Supabase, OpenAI (under explicit consent) | No | No |
| Sensitive PI — precise geolocation | Not collected | — | — | — |
| Sensitive PI — racial/ethnic origin, religious beliefs, union membership, citizenship status, contents of communications not directed to Kitrus, genetic data | Not collected | — | — | — |
Retention. Account profile, health data, chat history, and uploaded documents are retained while your account is active and deleted on the schedule above. Billing records are retained for up to 7 years for tax compliance. Security logs are retained for fraud prevention and legal defense. We retain inferences for as long as the underlying data is retained.
Sale, share, and Limit Use of Sensitive Personal Information
Sale. Kitrus does not sell personal information for money.
Share for cross-context behavioural advertising. On the website only, Kitrus discloses limited personal information (identifiers, commercial events, internet activity) to advertising platforms (Meta, TikTok, Pinterest, Google Analytics, PropellerAds) for conversion measurement and behavioural advertising. This qualifies as a "share" under Cal. Civ. Code §1798.140(ah). The Kitrus iOS app does not share any personal information for cross-context behavioural advertising.
You can opt out of this sharing at any time using any of the following:
- The "Do Not Sell or Share My Personal Information" link in
the website footer.
- A Global Privacy Control (GPC) signal from your browser.
Kitrus honours `Sec-GPC: 1` as a valid opt-out request and applies it in a frictionless manner per 11 CCR §7025(g)(2) — without requiring account creation, additional verification, or any further action by you. GPC is applied both client-side (no advertising or analytics pixels fire) and server-side (every marketing and analytics fanout route consults the same opt-out signal before any event is sent).
- Emailing
hello@kitrus.ai with the subject line "Do Not Sell or Share".
You can confirm your opt-out has been processed by re-visiting the "Do Not Sell or Share" link in the website footer; the page displays your current opt-out status (per CPPA regulations effective January 1, 2026).
We do not share any health data, Apple Health data, labs, medications, symptoms, cycle logs, uploaded documents, chat content, or health-topic-derived identifiers (such as quiz route names or quiz responses) for advertising on any platform.
Sensitive Personal Information — Limit Use. Kitrus uses Sensitive Personal Information only for the purposes permitted under Cal. Civ. Code §1798.121(a) — to provide the service you signed up for and the related operational and security purposes listed under "How we use it." We do not use SPI to infer characteristics about you for purposes outside that scope. As a result, the affirmative "Limit Use of Sensitive Personal Information" right under §1798.121 applies on a Cal. Civ. Code §1798.121(d) basis, and where you wish to further limit our use of SPI, you may email hello@kitrus.ai with the subject line "Limit use of sensitive PI".
Your California rights
- Right to know what categories of personal information we
collect, use, disclose, and share, and the specific pieces of personal information we have collected about you.
- Right to delete personal information we have collected about
you (subject to statutory exceptions for completion of transactions, security, debugging, and legal obligations).
- Right to correct inaccurate personal information.
- Right to opt out of sale or sharing for cross-context
behavioural advertising.
- Right to limit use of Sensitive Personal Information.
- Right to non-discrimination for exercising these rights. We
do not charge a different price or provide a different level of service for Californians who exercise their rights.
- Right to data portability — receive a copy of your data in a
structured, machine-readable format.
Authorized agents
You may designate an authorized agent to make a CCPA / CPRA request on your behalf. We will ask the authorized agent to provide signed written permission from you and may verify your identity directly with you. If the agent cannot provide signed written permission, or if we are unable to verify the agent's authority, we will deny the request and tell the agent and you what additional information is needed.
How to exercise California rights
Use the in-app paths described in Your rights above, the "Do Not Sell or Share My Personal Information" link in the website footer, or email hello@kitrus.ai.
We respond to verified requests within 45 days of receipt. We may extend this period once by an additional 45 days if reasonably necessary and will tell you in writing if we do.
We do not offer financial incentives in exchange for personal information.
Washington — My Health My Data Act
If you are a Washington resident, our standalone Washington Consumer Health Data Privacy Policy applies in addition to this policy. It covers your rights under RCW 19.373, the categories of consumer health data we process about you, how we share it, how to exercise your rights, the geofencing prohibition, and the appeal path.
Children
Kitrus is intended for adults aged 18 and over. We do not knowingly collect personal information from children under 13 (United States) or under 16 (European Economic Area, where GDPR applies). If you believe a child has provided us with personal information, contact hello@kitrus.ai and we will delete it.
Lab uploads
When you upload a lab result or medical document, Kitrus parses the file to extract structured data into your wellness profile, then stores both the original file and the parsed data in encrypted storage. The original file is retained as part of your wellness profile and is removed on account deletion under the timelines above.
International transfers
Kitrus is operated by Amplify Media Inc Ltd, a UK private limited company. Production data is primarily stored in the European Union (Supabase, Ireland — eu-west-1). Some processors are based in the United States (OpenAI, Vercel, RevenueCat, Sentry, Customer.io, Apple, Google). Where data crosses borders, we rely on Standard Contractual Clauses (SCCs), the UK International Data Transfer Agreement (UK IDTA) where applicable, and Transfer Impact Assessments (TIAs) maintained for each US-based processor.
EU and UK launch is deferred to a later Kitrus version. This section is maintained for forward readiness.
Cookies and similar technologies
The Kitrus website uses essential, analytics, and marketing cookies and similar technologies. You can manage your preferences from the cookie banner the first time you visit, and at any time from the Cookie preferences link in the website footer.
The Kitrus iOS app uses no cookies, no IDFA, and no cross-app tracking technologies.
Do Not Track (DNT). Some browsers send a "Do Not Track" signal. There is no industry-standard interpretation of DNT, so Kitrus does not respond to DNT signals at this time. We do honour the Global Privacy Control (GPC) signal as described in the California section above.
For full per-cookie disclosure, see our Cookie Policy.
Third-party links
The Kitrus website and app may link to third-party websites and services that are not operated by Kitrus. We are not responsible for the privacy practices of those third parties. We encourage you to review their privacy policies before providing them with personal information.
Incident response and breach notification
Kitrus is a vendor of personal health records under the US Federal Trade Commission's Health Breach Notification Rule (16 CFR Part 318, as amended effective July 29, 2024). If we become aware of a breach of unsecured personal health record identifiable health information affecting you, or of any other personal data breach affecting you, we will:
- FTC Health Breach Notification Rule (16 CFR Part 318): notify
affected US individuals without unreasonable delay and no later than 60 calendar days after discovery, by first-class mail or, where you have specified electronic communication as a reasonable means of contact, by email plus an additional electronic method (such as text message, in-app notification, or electronic banner). Where direct contact information is insufficient or out of date for 10 or more affected individuals, we will provide substitute notice through either a conspicuous posting on the kitrus.ai home page for at least 90 days or major print or broadcast media reasonably calculated to reach the affected individuals, with a toll-free number active for at least 90 days. We will notify the FTC contemporaneously with individual notice for breaches involving 500 or more individuals, and maintain an annual log of breaches involving fewer than 500 individuals, submitted to the FTC by March 1 of the following year. We will notify prominent media outlets serving any area where the breach affects 500 or more residents of a state or territory.
- GDPR / UK GDPR: notify the relevant supervisory authority
within 72 hours of becoming aware where required.
- US state breach-notification laws: notify affected
individuals on the timelines those state laws require.
- Provide a description of the data involved, what we have done in
response, and the steps you can take to protect yourself.
Business transfers
If Amplify Media Inc Ltd or Kitrus is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of business assets, your personal information may be transferred or disclosed as part of that transaction. The acquiring entity will be required to honour the commitments in this Privacy Policy, and we will notify you (by email and a prominent notice on the website) of any change in ownership or material use of your personal information, along with any choices you may have. Washington residents: see our standalone Washington Consumer Health Data Privacy Policy for the WA-specific corporate-change posture.
Material changes to this policy
If we introduce a new category of personal data, a new purpose, a new category of third party, or any new sharing arrangement, we update this policy, change the "Last updated" date, and — where the law requires — obtain fresh affirmative consent before processing under the change. Continued use of Kitrus is not consent.
Contact
- Privacy questions and DSR requests:
- Security disclosures:
Amplify Media Inc Ltd 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ
See also: Washington Consumer Health Data Privacy Policy · Cookie Policy · Account Deletion · Terms of Use · Subprocessors
---
Footer disclaimer (preserved)
Kitrus is a wellness and educational tool. It does not provide medical advice, diagnosis, treatment, or emergency support. Always consult a qualified healthcare provider before making medical decisions.
---