Privacy Policy
Last updated: June 2026
1. Who we are
Kind Health (“we”, “us”, “our”) is a digital health platform operated by Kind Health Ltd, registered in England and Wales. We are the data controller for personal data processed through this platform. You can contact us at contact@kindnesscommunityfoundation.com.
2. What data we collect
We collect the following categories of personal data:
- Account data: name, email address, password (hashed), and profile information you provide.
- Health information: details you share in AI chats, support sessions, or your profile (including child profiles). This is special category data under UK GDPR.
- Usage data: pages visited, features used, device type, browser, and approximate location (country/region).
- Communications: messages sent through our platform to helpers or the community.
- Payment data: processed by Stripe. We do not store card details.
3. How we use your data
We use your data to:
- Provide and personalise the Kind Health service
- Match you with appropriate helpers and support
- Ensure safety — including detecting crisis situations where intervention may be needed
- Improve the AI model's responses (using anonymised, aggregated data only)
- Send you service-related communications
- Comply with legal obligations
We do not sell your data, use it for advertising, or share it with third parties except as described in section 5.
4. Legal basis for processing
- Contract performance: to provide you with the service you have signed up for
- Legitimate interests: to improve our service, prevent fraud, and ensure platform safety
- Consent: for optional features and marketing communications
- Vital interests: in genuine crisis situations where safety is at risk
- Explicit consent: for processing special category health data
5. Who we share data with
We share data with trusted third-party service providers who process it on our behalf:
- Supabase — database and authentication (EU servers)
- Anthropic — AI processing (messages are not retained for training without consent)
- Stripe — payment processing
- Vercel — platform hosting
We may also disclose data where required by law, court order, or to protect safety in an emergency.
6. Data retention
We retain your account data for as long as your account is active. If you delete your account, we remove your personal data within 30 days, except where retention is required by law. Anonymised, aggregated data may be retained indefinitely.
7. Your rights
Under UK GDPR, you have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Request deletion of your data (“right to be forgotten”)
- Object to or restrict certain processing
- Data portability — receive your data in a machine-readable format
- Withdraw consent at any time
To exercise any of these rights, email contact@kindnesscommunityfoundation.com. We will respond within 30 days.
8. Cookies
We use essential cookies to keep you logged in and remember your preferences. See our Cookie Policy for full details.
9. Children's data
Kind Health is intended for users aged 16 and over. Child profiles (added by a parent or guardian) are treated as the most sensitive category of data and are never shared or used for anything other than providing the service to the parent/guardian who created them.
10. Changes to this policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or by a notice on the platform. The date at the top of this page shows when it was last updated.
11. Contact and complaints
For privacy questions, contact us at contact@kindnesscommunityfoundation.com. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.