Privacy Policy
Kairos ("Kairos", the "app") is published by Neuralway ("we", "us"). This policy explains what the app handles, where it goes, and the controls you have.
The short version: Kairos computes its core readiness, Reserve, sleep, Body and trend features on your devices. Raw Apple Health samples are not uploaded to Neuralway, Reed, or Bloodline. Two optional features use a third-party AI service only after Kairos names the recipient and service, lists the exact data, explains the purpose, and the user turns on an unchecked permission control:
- Reed: the app identifies Amazon Web Services (AWS) as the third-party service provider, Amazon Bedrock as the AI service, and Anthropic Claude as the AI model. It lists the messages, finished health summary, memory facts, or meal photo you may choose to send. Nothing is sent unless you check the permission control and tap Allow AWS AI processing.
- Bloodline: before each upload, the app identifies AWS, Amazon Bedrock, and Anthropic Claude and lists the selected laboratory-report pages and access proof. Nothing is sent unless you check the permission control and tap Allow and read my report.
Choosing Not now sends none of the listed personal data. These AI requests are processed in United States AWS regions solely to return the Reed reply, meal analysis, or Bloodline transcription requested by the user.
Eligible non-health app preferences and purchase state may sync through your private iCloud account. Payments are handled by Apple. Kairos does not ask for an email address inside the app, sell data, serve ads, or use cross-app tracking SDKs.
1. Apple Health and motion data
With your permission, Kairos reads categories including heart rate and heart rate variability (HRV/SDNN), resting and walking heart rate, heart-rate recovery, respiratory rate, sleep, wrist temperature, VO2 max, physical effort, steps, distance, walking speed, step length, double-support time, walking asymmetry and steadiness, stair speed, stand time, active energy, workouts, time in daylight, age, and biological sex. Apple controls the exact categories available on each device and OS version.
Kairos uses these samples on your iPhone and Apple Watch to calculate the morning verdict, readiness, Reserve, sleep views, Body Age, movement trends, and their explanations. Kairos reads from Apple Health and does not write data back to Health.
Raw Apple Health samples stay on your devices. Kairos does not put them in its iCloud key-value store or send them to Neuralway's servers. If you enable Reed, Kairos may create and send the bounded, readable display receipt listed in §2. It contains finished results Kairos has already computed for display, their disclosed explanations and timing/freshness receipts, not the underlying Apple Health rows or raw signal fractions.
The overnight wrist-orientation recording feature used for sleep-position estimates is retired: current versions do not arm the Apple Watch motion recorder. Recordings made by earlier versions remain in protected, backup-excluded local app storage, are never uploaded to Neuralway or the AI services, and are removed by “Erase all data.”
You can review or revoke Health access in iOS Settings → Health → Data Access & Devices → Kairos. Revocation stops future reads; Apple Health retains its own records under Apple's controls.
2. Reed — optional AI coaching and meal photos
Reed is optional and requires a Reed-bearing plan plus consent version 5. Before Kairos sends any message, derived health summary, memory fact, meal photo or note, request identifier, or access proof, the in-app screen says that the recipient is Amazon Web Services (AWS), the third-party AI service is Amazon Bedrock, the AI model is Anthropic Claude, and processing occurs in United States AWS regions. The screen lists every data category below and explains that AWS Bedrock uses it only to generate the Reed reply or meal analysis requested by the user, not for advertising or tracking.
The permission control starts unchecked and states: “I allow Kairos to send the listed personal data to AWS Bedrock for AI processing.” The Allow AWS AI processing button remains disabled until the user checks it. Choosing Not now sends none of the listed data. Kairos shows the screen again if the shared field set, recipient, service, model, purpose, or processing region materially changes. Consent version 5 invalidates earlier Reed consent rather than treating it as permission for the newly named recipient. You can revoke Reed consent in Settings at any time; after revocation, Kairos sends no further Reed content or authenticated requests. Kairos may fetch a signed, content-free feature configuration before consent.
What a Reed chat request sends
- the current finalized reading date, computation time, readiness evidence-window end and its age; displayed readiness score, headline, support, accuracy note, and its exact factor, weight, coverage, and missing-signal receipt;
- displayed morning Reserve and, when settled, request-time Reserve, band, and freshness;
- the canonical main-sleep duration and sleep summary Kairos displays, or that they are unavailable;
- displayed settled resting heart rate, sleeping respiratory rate, wrist-temperature result, adult Body Age, calendar-age comparison and estimate confidence, Heart Health receipt, and walking-steadiness category and note, when available. HRV appears only inside displayed readiness or Heart Health receipts;
- up to seven prior displayed morning records (date, readiness, morning Reserve, canonical sleep, and adult Body Age when available), plus the exact record count and derived averages and ranges;
- today's saved meal count and calorie/protein ranges;
- your name, exact age, onboarding goal, and any facts you add to Reed memory;
- up to 24 recent messages from you and Reed, with their send times;
- one request-time clock receipt: ISO timestamp, local date and time, IANA time-zone identifier, and UTC offset;
- a random on-device request identifier for each logical chat or meal scan, used only to prevent the same request from spending another allowance unit when retried; and
- access credentials, normally an Apple-signed subscription transaction and, when applicable, renewal proof, used only to verify Reed access. A separately compiled owner build may use a revocable owner credential instead; that credential is kept in the device-only Keychain and is not present in App Store or TestFlight builds.
The display receipt is constructed on-device from the finalized values and receipts Kairos shows. It is line-bounded before transmission. It does not contain raw Apple Health rows, unrounded signal fractions, or a separate raw HRV sample. Stored context from an earlier consent version is invalidated rather than silently reused under consent version 5.
What a meal request sends
The resized meal photo you choose, an optional note you type, and the same access proof. The source photo is not saved by Kairos. If you confirm the returned analysis, Kairos stores only the meal log (item names, estimated ranges, and your edits) locally on this iPhone.
Processing and server records
Requests travel over HTTPS to Kairos services on Amazon Web Services (AWS) in United States regions and then to the Amazon Bedrock third-party AI service using the Anthropic Claude AI model. AWS is the recipient and service provider that processes the request; Anthropic develops Claude. Under AWS's current Bedrock service terms and documentation, AWS does not share Bedrock inputs or outputs with model providers, so Neuralway does not currently identify Anthropic as a direct recipient of Reed content. AWS Bedrock uses the listed data only to generate the requested Reed reply or meal analysis. Kairos does not use it for advertising, tracking, or model training.
Neuralway requires AWS to protect Kairos personal data to the same or an equal standard as this policy requires, including purpose limitation, encryption in transit and at rest, access controls, no advertising or cross-app tracking, no use of request content to train models, and deletion or no durable readable retention after the requested processing, subject only to AWS's narrowly described service-security and abuse-detection obligations. Kairos's Reed code does not write message text, context summaries, memory facts, photos, notes, or replies to DynamoDB or application logs. CloudWatch receives numeric usage/cost/latency counts, bounded error types, and the category of a deterministic safety flag — never the triggering words. Kairos's production deployment configuration sets Reed and Bloodline function log groups to 30-day retention and requires release verification. CloudWatch marks older log events for deletion, which AWS says typically takes up to 72 additional hours and may rarely take longer. Content-free aggregate metrics follow AWS's service retention. AWS and ordinary network infrastructure necessarily process standard connection and security metadata, such as source IP address, request time, TLS/routing information, and generic HTTP headers, to deliver and protect these requests. Kairos does not intentionally add Health samples or Reed content to that connection metadata.
The Reed quota ledger stores one-way SHA-256 hashes of the StoreKit subscription lineage and, for transaction-specific refunds, the transaction identifier, plus daily chat/photo counters. For retry safety, it also stores a content-free marker keyed by a one-way hash of the app's random request identifier, with the request type, allowance day, processing state, short recovery lease, and expiry time. It does not store the message, context, photo, note, or reply in that marker. Request markers and daily rows are marked to expire after about three days; DynamoDB deletion is asynchronous and may occur a few days later. Refund/revocation rows also record the App Store environment, product identifier, signed event ordering, and marker category. Refund/revocation markers derived from Apple transactions are retained without an automatic expiry so a refunded entitlement cannot silently return.
Kairos's deployment scripts refuse to enable Reed unless the AWS account reports Bedrock data-retention mode none, and refuse model families that require provider data sharing. This is a deployment control that Neuralway must verify for each production release; it does not change AWS's independent legal obligations or narrowly described abuse-detection processing. Current AWS documentation is available in Amazon Bedrock data protection, data retention, and the Amazon Bedrock FAQ.
Your readable Reed transcript, memory, context summary, and saved meal log are kept in protected, backup-excluded local app storage. They are excluded from Kairos iCloud sync. Settings provides separate controls to erase the conversation or all Reed data; erasure is verified locally and revokes consent before deletion.
Reed is a general-wellness AI coach, not a doctor, therapist, emergency service, or medical device. Deterministic client and server rules route supported crisis, emergency, and medication-dosing language to fixed human-help cards before a model answer is used, but those rules cannot guarantee detection of every possible emergency. Contact local emergency services when immediate help may be needed.
3. Bloodline — optional laboratory-report transcription
Bloodline reads a blood-test/laboratory report you choose to upload and transcribes legible rows. It does not receive Apple Health data or your Bloodline profile. Each upload has its own permission screen. Before a page is sent, the screen names Amazon Web Services (AWS) as the recipient and third-party service provider, Amazon Bedrock as the AI service, Anthropic Claude as the AI model, the United States AWS processing region, the exact data listed below, and the transcription purpose.
The per-upload permission control starts unchecked and states: “I allow Kairos to send these selected report pages and access proof to AWS Bedrock for AI processing. This permission is for this upload only.” The Allow and read my report button remains disabled until the user checks it. Choosing Not now sends no report page or access proof.
Sent: the selected report-page images, a random report identifier, batch coordinates, the app's fixed marker vocabulary, and an Apple-signed StoreKit transaction/renewal proof (or the separately compiled owner credential). The selected pages are transmitted as they appear and may themselves visibly contain a name, date of birth, patient or laboratory identifiers, or other report content. Kairos does not separately add your email, goals, age, sex, or the on-device Bloodline profile to the report request.
Processed by: Kairos's AWS service and an AWS-hosted Anthropic Claude model in Amazon Bedrock in United States regions, solely to return structured transcription. AWS is the service provider; under AWS's current Bedrock terms and documentation, AWS does not share inputs or outputs with Anthropic. The model is instructed to transcribe visible text, units and printed ranges, not diagnose or recommend treatment. Model output can still be wrong; users should compare it with the source report and a qualified clinician. Bloodline is subject to the same Bedrock retention-mode deployment check and qualification described for Reed in §2.
Server records: Kairos does not intentionally persist readable report images, marker names/values/units, lab names, dates, or transcriptions in its application stores or logs. The credit ledger retains Apple transaction/subscription identifiers, product and App Store environment, signed-event ordering and marker category, credit state, a random report identifier, and non-content batch state. A credit held while an upload is attempted may retain its scope key, random report identifier, held time, lease, state, and non-content rejection metadata; an abandoned held-credit row is marked to expire after 30 days. When a held credit is released or a report is rejected without a usable marker, the free slot may retain its scope key, free state, rejection count, and rejection-window end; it is marked to expire seven days after the current 24-hour rejection window ends (about eight days after a new rejection). Temporary batch-attempt rows are marked to expire after seven days. DynamoDB deletion is asynchronous, so any of these expired rows may remain for a few days after its expiry time. Spent-credit and anti-replay rows and revocation markers have no automatic expiry. These records prevent replay, duplicate charging, repeated free rejected uploads, and restored access after a refund.
Readable results are stored in protected, backup-excluded local app storage until you delete a result, erase Kairos data, or remove the app. Bloodline is for general wellness and education, not medical advice or a medical device.
4. App-owned local data and private iCloud sync
Kairos stores profile/preferences, notification choices, and purchase state in app-owned storage. Eligible non-health preferences and purchase state may sync through Apple's private iCloud key-value store so those settings and paid balances survive a reinstall or device change. Neuralway cannot browse that private iCloud store.
The onboarding name, exact age, biological sex, and goal; health-derived readiness/reflection history and feature-use state; Reserve/Body Age state; check-ins; sleep-position data; Bloodline reports/profile; and the entire kairos.reed.* namespace are excluded from Kairos iCloud sync. Their local directories are marked backup-excluded. Apple Health may separately sync Health records under your Apple settings; that is Apple's service, not Kairos app sync.
Settings → Privacy → Erase all Kairos data removes local personal content and non-purchase Kairos iCloud values, with verified deletion for the protected health-bearing stores. Purchase proofs, paid Bloodline credit state, and anti-double-grant allowance records are retained so erasing personal data does not destroy a purchase or grant it twice. Deleting the app removes its local container but does not itself erase Apple Health, Apple's purchase history, or eligible values already held in your private iCloud account; use the in-app erase control first if you want those non-purchase iCloud values removed.
The in-app erase control acts on the device and eligible private-iCloud values; it does not send Neuralway a server-ledger deletion request. The procedure below starts intake for a request concerning the limited server records Neuralway controls; ordinary email does not authenticate it.
Email and the retired signup collector
Kairos and getkairos.fit do not offer a mailing-list signup form. At this policy's effective date, the former /api/signup route was independently verified to return 410 Gone; its Lambda configuration had no environment values or inline data/email policy, the former DynamoDB signup table had zero items, and the API was bounded to five requests per second with a burst of ten. These are deployment-state checks that Neuralway must reverify after relevant infrastructure changes. If you choose to email support or submit a rights request, the message and reply are processed by ordinary email systems and retained as described in §7; do not attach health content or purchase proofs.
5. Consumer Health Data Privacy Notice and requests
This section provides the consumer-health-data notice and current request intake where laws such as the Washington My Health My Data Act and Nevada's consumer-health-data law apply. Ordinary email intake is not yet the secure, reliable authenticated mechanism required for every pseudonymous server-ledger request. Neuralway will not disclose or alter such a record until an appropriate secure mechanism is available. This operational limitation does not waive a right or remedy that cannot lawfully be waived.
Categories, sources, purposes, and recipients
Depending on the features you use, consumer health data may include Apple Health categories and on-device measurements; Kairos's derived readiness, Reserve, sleep, Body Age, movement, meal and wellness results; age, biological sex, name, goal and context you enter; Reed messages, memory facts, derived summaries, meal images and notes; Bloodline report pages and transcription; purchase, entitlement, refund, quota, credit and anti-replay records associated with those features; and connection/security metadata necessarily processed when a request reaches AWS.
These categories come from you; Apple Health with your permission; Apple StoreKit and App Store Server Notifications; calculations performed by Kairos on your devices; and technical/security signals generated when your device contacts Apple, iCloud, or Kairos's AWS services. They are processed only to provide features you request, sync eligible preferences through your private iCloud account, perform a Reed or Bloodline request you initiate, verify purchases and allowances, process refunds, prevent duplicate grants or replay, secure the service, answer support or rights requests, and comply with law.
The following list identifies every current consumer-health-data category handled outside the app, its recipient, and its limited purpose. It does so even where applicable law treats processor handling as necessary to provide the product or service the consumer requested rather than as consent-based “sharing”:
- Apple Health records and permissions → Apple: Apple supplies records to the app under the user's Health permission; Kairos does not upload those raw rows back to Neuralway or Reed/Bloodline.
- Eligible non-health preferences and purchase state → Apple: private iCloud key-value sync and StoreKit/App Store billing. Neuralway cannot browse the user's private iCloud key-value store.
- The exact Reed categories in §2 → Amazon Web Services: authenticate and perform the requested conversation or meal analysis, enforce allowances, return the response, and secure/operate the service.
- The exact Bloodline categories in §3 → Amazon Web Services: authenticate and perform the requested transcription, enforce credits, return the result, and secure/operate the service.
- Purchase, entitlement, quota, credit, refund/revocation, event-ordering, and anti-replay records associated with Reed or Bloodline → Apple and Amazon Web Services: billing, access control, allowance accounting, refund/revocation enforcement, fraud/replay prevention, and reconciliation.
- Request connection and security metadata described in §§2–3 → Amazon Web Services and ordinary network infrastructure: route, protect, rate-limit, diagnose, and operate the requested service.
- Support or rights correspondence you choose to send → your sending email provider and Neuralway's email hosting/delivery providers: transmit, secure, receive, answer, and document the request. Do not include health content or purchase proofs.
Anthropic develops the Claude model used by the AWS-hosted Bedrock service, but AWS states that Bedrock inputs and outputs are not shared with model providers. On that current service contract, Anthropic is not a recipient of Kairos request content. Neuralway has no affiliate that currently receives consumer health data. The complete current third-party list for the app's Apple/Reed/Bloodline flows is therefore Apple and Amazon Web Services; user-initiated correspondence also traverses the sender's and Neuralway's email transport/hosting providers. Apple's and AWS's active privacy contact mechanisms are Apple's privacy contact page and AWS Privacy.
Neuralway does not sell consumer health data or share it for cross-context behavioural advertising. Neither the Kairos app nor getkairos.fit embeds advertising or cross-site tracking technology that permits a third party to collect consumer health data over time across unrelated websites or online services. Neuralway treats each current transfer to AWS as necessary to perform the Reed conversation, meal analysis, or Bloodline transcription the user affirmatively requests. It does not infer health-data consent from general terms. If a future transfer is not necessary to provide the requested service, or applicable law requires consent for collection or sharing, Kairos will not make that transfer until it has obtained the required affirmative consent; any sharing consent will be separate and distinct from a collection consent. A new category, purpose, recipient, or materially different use will be disclosed before it begins.
Your controls and request intake
You may ask Neuralway to confirm whether it collects, shares, or sells consumer health data about you; provide access and, where law requires, a list of all third parties and affiliates with which Neuralway has shared or sold it plus their active email address or other online contact mechanism; correct inaccurate server-held data where possible; withdraw consent and stop future collection or sharing; or delete data Neuralway controls. You do not need to create a Kairos account.
- For local data and eligible non-purchase private-iCloud values, use Settings → Privacy → Erase all Kairos data. Use Apple's Health, iCloud, and purchase controls for records Apple controls.
- For a server-data request, email zero@neuralway.ai with the subject Consumer Health Data Request and identify the right you wish to exercise. Do not attach a health report, Reed transcript, Apple receipt, or raw Health data.
- Email is intake only; ordinary email is not authentication and is not the channel through which Neuralway will disclose a pseudonymous ledger record. Neuralway will reply with the least-data secure verification and response channel available for the requested records. If a secure and reliable method appropriate to the record is unavailable, or identity cannot be authenticated with commercially reasonable efforts, Neuralway will explain why it cannot disclose or alter the affected record. This limitation does not waive a consumer right.
Neuralway responds without undue delay and, where Washington law applies, within 45 days after receipt. Where Nevada law applies, it responds within 45 days after authentication. When reasonably necessary, the period may be extended once by up to 45 days with notice and reasons during the initial period. Nevada deletion requests are completed within 30 days after authentication; other deletion requests follow their applicable legal deadline. Valid deletion requests are propagated to applicable processors and recipients. Backup deletion may be delayed only as law permits—no more than six months under Washington law or two years under Nevada law—and only as necessary to restore a backup.
Limited purchase, refund, security, anti-fraud, or legal records may be retained only when and to the extent an applicable exception permits. Neuralway will identify any responsive data not deleted and explain the basis. Neuralway cannot delete Apple Health, App Store purchase history, or private-iCloud records controlled by Apple.
If a request is refused or partly granted, appeal within a reasonable time by replying with the subject Consumer Health Data Appeal. The appeal uses the same secure process and requires no account. Neuralway will provide a written decision and reasons within 45 days after receiving it. A denial will include the appropriate method to contact the Washington or Nevada Attorney General, or another regulator where applicable.
6. Subscriptions and purchases
Apple App Store/StoreKit handles subscriptions and consumable report credits. Neuralway does not receive payment-card details. Kairos services receive Apple-signed transaction material only to verify access, enforce allowances, and process refunds/revocations. Apple's purchase handling follows Apple's own privacy terms.
7. Retention and deletion summary
- Raw Apple Health samples: not retained by Neuralway; processed locally.
- Reed request content: transiently processed; not intentionally written to Kairos server databases or application logs. Local transcript/memory/meal records remain until erased. Non-content quota/revocation metadata follows §2.
- Bloodline pages and readable output: transiently processed server-side; readable results remain locally until erased. Anti-replay metadata follows §3.
- Private-iCloud app values: remain until changed or erased in-app, except retained purchase state.
- Support and rights correspondence: retained only as reasonably necessary to answer the request, document compliance, secure the service, and meet legal obligations.
No deletion request can erase records independently controlled by Apple, such as App Store purchase history, or data Neuralway does not possess, such as your Apple Health database.
8. Third parties and international processing
Kairos uses:
- Apple — Apple Health, iCloud key-value sync, App Store and StoreKit;
- Amazon Web Services — Lambda/DynamoDB/CloudWatch infrastructure, Amazon Bedrock AI hosting, and service security/operations; and
- Anthropic — developer of the Claude model hosted by AWS; under AWS's current Bedrock terms and documentation, not a recipient of Kairos inputs or outputs; and
- email transport/hosting providers — only for support or rights correspondence a user chooses to send, not as part of the Reed/Bloodline request path.
Reed and Bloodline requests are processed in United States AWS regions. Kairos does not use third-party advertising or cross-app tracking SDKs, and does not sell personal data. We do not intentionally use Reed/Bloodline content to train models or for advertising/profiling.
9. Children
Kairos is not directed to children under 13, and we do not knowingly collect personal data from them.
10. Changes
We update the effective date above and place a conspicuous notice on the getkairos.fit homepage before a material policy change takes effect. If the change affects Reed or Bloodline processing, Kairos also presents the affected feature's updated in-app disclosure before its next request. Where applicable law requires consent for a new category, purpose, recipient, collection, or sharing, Neuralway seeks that consent before the change applies; silence or continued use alone is not that consent.
11. Contact
Neuralway Technologies Private Limited — zero@neuralway.ai
← Back to Kairos