This policy applies to Washington residents and to consumer health data processed by Kitrus about Washington residents, as defined under the Washington My Health My Data Act (RCW 19.373). It is in addition to our general [Privacy Policy](https://kitrus.ai/privacy), not a replacement for it.
Who we are
Kitrus is operated by Amplify Media Inc Ltd, a private limited company incorporated in England and Wales, registered office at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ. We provide a consumer wellness organizer that helps users collect, track, and review information about their own health and wellness.
Contact for Washington consumers: hello@kitrus.ai, subject line "WA MHMDA request".
Affiliates
Amplify Media Inc Ltd does not currently share consumer health data with any corporate affiliates. If that changes, we will update this policy and, where the law requires, obtain fresh affirmative consent before sharing consumer health data with any affiliate.
What we mean by consumer health data
Under Washington law, "consumer health data" includes personal information that identifies a consumer's past, present, or future physical or mental health status. For Kitrus, the categories of consumer health data we collect or process about Washington residents include:
- Lab results and uploaded medical or health documents
- Medications, supplements, and dosage history you enter
- Symptoms, journal entries, and wellness notes you log
- Menstrual, cycle, and fertility-window information when you use cycle
tracking
- Hormone-related symptoms and wellness signals when you enter them
- Wearable data synced from Apple Health with your permission, including
sleep, heart rate, resting heart rate, heart-rate variability, steps, and blood-oxygen saturation
- Information about health conditions, treatments, or diagnoses you enter
to give Kitrus context
- Chat content you exchange with Kitrus's AI assistant where it relates to
the information above
- Account and profile identifiers — such as email address, Apple Sign-In
identifier, date of birth, sex at birth if provided, and your Kitrus user ID — when linked to your wellness profile or other consumer health data
- App, device, and session identifiers when connected to your use of
Kitrus's health and wellness features, including security logs, consent records, and system audit records
- Information Kitrus derives through proxy, derivative, inferred, or
emergent means — including patterns surfaced by our algorithms — from the data you provide
Kitrus does not collect precise location information about Washington consumers and does not infer health-related location patterns.
Where this data comes from
We collect consumer health data:
- Directly from you when you sign up, complete onboarding, log information,
upload documents, send chat messages, or use cycle-tracking surfaces
- From documents you choose to upload, which may originate from your
healthcare providers, laboratories, or other clinical sources
- From Apple Health, only after you grant explicit permission inside the
app
- Generated by our own systems as patterns and inferences derived from the
data you provide
Why we collect and use it
We use consumer health data to:
- Organize your wellness profile inside the Kitrus app
- Surface patterns in your own data for you to review
- Power AI-assisted conversations and prepare discussion prompts you can
bring to a qualified healthcare provider
- Provide product features you have asked for, such as labs review,
medication tracking, symptom logging, cycle tracking, and clinician handoff briefs
- Send transactional messages relating to your account, subscription, and
data
- Maintain platform security, prevent fraud, debug errors, and comply with
our legal obligations
We do not use consumer health data for third-party advertising, third-party marketing, data-broker disclosure, or cross-context behavioural advertising.
Who we share it with
We share consumer health data only with the limited categories of service providers needed to operate the product, under written contracts that restrict their use of the data:
- Cloud database and storage provider (Supabase) — encrypted storage
of your account and health data, hosted in the European Union
- AI inference provider (OpenAI) — processes the content you send to
Kitrus's AI assistant under our agreement and only when you have given explicit consent. Inputs and outputs are not used to train OpenAI's models.
- Crash and error diagnostics (Sentry) — receives scrubbed technical
error data only, configured to strip personal health information from logs
- App Store billing (Apple, RevenueCat) — subscription identifiers and
status only; no health content
- Authentication (Apple Sign in with Apple) — sign-in identifiers only;
no health content
For our website only (not the iOS app), we also share limited operational events with marketing platforms — Meta, TikTok, Pinterest, Google Analytics, Customer.io, PropellerAds. These events are scoped to subscription confirmations, app installs, and aggregate funnel metrics. They do not contain consumer health data: no labs, medications, symptoms, cycle logs, Apple Health data, chat content, uploaded documents, or health-topic identifiers derived from quiz responses, page URLs, or event labels.
The iOS app contains no marketing pixels, no advertising SDKs, and no cross-app tracking. The full subprocessor list and platform tags are at `https://kitrus.ai/sub-processors`.
We do not share consumer health data with data brokers, advertising networks, or any party outside the operational service-provider list above.
What categories of consumer health data we share
We share only the categories needed for the service each provider performs:
- Supabase: stores all categories of consumer health data listed above
— labs, uploads, medications, supplements, symptoms, cycle logs, Apple Health data, chat history, account profile linked to health data, and patterns Kitrus derives.
- OpenAI: receives only the content of AI chat turns you initiate,
plus the wellness-profile context Kitrus includes for that turn, and only when you have given AI-processing consent.
- Sentry: receives no consumer health data. Configured to strip
personal health information before any error event is sent.
- Apple / RevenueCat: receives subscription identifiers, product
identifiers, entitlement status, and transaction status only. Receives no labs, symptoms, medications, notes, chat content, Apple Health data, or uploaded documents.
- Sign in with Apple: receives sign-in identifiers needed to create
and access your Kitrus account. Receives no health content.
- **Meta / TikTok / Pinterest / Google Analytics / Customer.io /
PropellerAds** (website only): receive no consumer health data. Receive only the limited operational events described above.
We do not sell consumer health data
Kitrus does not sell consumer health data and has not sold consumer health data in the past twelve months. Kitrus does not license, rent, disclose, or otherwise exchange consumer health data for money, advertising services, research partnerships, data enrichment, model training, analytics partnerships, or other valuable consideration.
Because we do not sell consumer health data, we do not require valid authorization under RCW 19.373.070 for sale. If our practices ever change, we will obtain valid authorization in advance and update this policy.
Your rights as a Washington consumer
Under the Washington My Health My Data Act you have the right to:
- Confirm whether Kitrus is processing consumer health data about you
- Access the consumer health data Kitrus holds about you, including a
list of the third parties and affiliates with whom Kitrus has shared or sold your consumer health data and an active email address or other online contact method for those parties
- Withdraw consent for Kitrus's continued collection or sharing of your
consumer health data
- Delete the consumer health data Kitrus holds about you. Kitrus will
delete the data from its active production systems, notify affiliates, processors, contractors, and other third parties with whom we shared it of your deletion request, and remove it from operational backups within 7 days.
- Appeal a denial of any of the rights above
You may also exercise the other consumer-privacy rights described in our general Privacy Policy.
How to exercise your rights
The fastest path for most rights is inside the Kitrus app:
- Access / export: Profile → Privacy & Data → Export my data
- Delete: Profile → Privacy & Data → Delete Account (see also our
separate account deletion page)
- Withdraw AI consent: Profile → Privacy & Data → AI consent toggle
If you cannot access the app, email hello@kitrus.ai with the subject line "WA MHMDA request" and tell us which right you are exercising.
We respond to verified requests within 45 days of receipt. If we need more time, we will tell you in writing within that window and explain why, and we will respond within an additional 45 days.
How we verify it's really you
To protect your data, we verify your identity before acting on a request:
- Requests made inside the app are authenticated by your active session.
- Requests made by email are verified by sending a confirmation message to
the email address on the Kitrus account.
- For sensitive requests, we may ask for additional verification
information already associated with your account. We will not require you to create a new account in order to make a request.
- If you used Apple's Hide My Email when signing up and we cannot
reliably match your request to an account, we will tell you and ask for the additional information needed to verify. We will not require you to disclose your real (non-relay) email address; if your Apple Relay address has been disabled and we cannot reach you, we will say so and stop the request rather than refuse.
- If we cannot reasonably verify that a request is being made by you or on
your behalf, we may decline to act on it and will tell you why. We will let you know what additional information would allow us to verify you in the future.
How to appeal
If we deny a request, we will explain why in writing and tell you how to appeal. To appeal, email hello@kitrus.ai with the subject line "WA MHMDA appeal" within 45 days of our decision and include the original request and the reason you believe our decision was wrong.
We respond to appeals within 45 days. If the appeal is denied, you may contact the Washington State Attorney General at www.atg.wa.gov/file-complaint.
Geofencing
Kitrus does not implement, and does not knowingly enable any processor, contractor, advertising partner, or other third party to implement, a geofence within 2,000 feet of an in-person healthcare facility to identify or track consumers seeking health-care services, collect consumer health data, or send health-related notifications, messages, or advertisements, as prohibited by RCW 19.373.080.
Corporate changes
If Kitrus or Amplify Media Inc Ltd is involved in a merger, acquisition, or similar corporate transaction, any consumer health data transferred as part of the transaction will be handled as Washington law requires, including obtaining fresh affirmative consent where required before any new collection, use, or sharing.
Changes to this policy
If we introduce a new category of consumer health data, a new purpose, a new category of third party, or any new sharing arrangement, we will obtain fresh affirmative consent from Washington consumers — meeting RCW 19.373.010(6) — before collecting or sharing consumer health data under the change. Continued use of Kitrus is not consent. Material changes are posted at this URL and the "Last updated" date below is updated.
Contact
For any questions about this policy, your rights under the Washington My Health My Data Act, or to make a request:
Amplify Media Inc Ltd 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ
See also: Privacy Policy · Account Deletion · Terms of Use.
Last updated: 2026-05-25
---