Back to KithITH

Privacy Policy

Last updated: July 8, 2026

Draft notice: this policy was prepared to accurately describe how Kith actually works today. It has not yet been reviewed by a lawyer. Do not treat it as final legal advice — have it reviewed before relying on it for compliance purposes.

This Privacy Policy explains how Kith (“Kith”, “we”, “us”) collects, uses, stores, and shares information through the Kith clinical workspace application (the “Service”). Kith is operated by Anurag Chaudhary, a sole proprietor based in India, until such time as a registered corporate entity is formed. This policy is written with reference to India’s Digital Personal Data Protection Act, 2023 (“DPDP Act”), and applies to anyone who creates a Kith account (“Practitioner”, “you”) or whose information a Practitioner enters into Kith as a patient/client (“Patient”).

1. Who is responsible for what

Kith is a tool that mental health practitioners use to manage their practice. For a Patient’s clinical information, the Practitioner is the data fiduciary (the party who decides why and how the data is processed) — Kith acts as a data processor, handling that information only on the Practitioner’s instructions and only to provide the Service. If you are a Patient with questions about your own clinical records, your practitioner — not Kith — is the right first point of contact, though we are glad to help route a request.

For a Practitioner’s own account information (name, email, phone, billing details), Kith is the data fiduciary.

2. What we collect

Account & practice information you provide at signup and afterward: name, work email, password (hashed by our authentication provider, never stored in plain text), phone number, clinic name and address, professional designation, and billing details processed by our payment provider.

Patient information entered by a Practitioner: name, contact details, date of birth, gender, diagnosis, therapy modality, medications, treatment goals, and any other clinical notes the Practitioner chooses to record.

Session content: audio is transcribed in real time and is not retained as an audio recording by Kith once transcribed (in-person sessions), except where an online session is recorded via a third-party meeting bot as described in Section 4, where the bot provider may briefly hold recording data before it is transcribed and discarded. Transcripts, AI-generated clinical notes, suggestions, and homework assignments are stored so the Practitioner can review and rely on them.

Usage and device information: log data, browser/device type, and general diagnostic information used to keep the Service running and secure.

We do not knowingly collect information directly from Patients — all Patient information is entered by the Practitioner using the Service.

3. How we use information

We do not sell personal data or clinical information, and we do not use Patient clinical content to train our own AI models. Where third-party AI providers are used (Section 4), we rely on their commercial API terms, which contractually exclude using submitted data to train their models.

4. AI processing & sub-processors

Kith is built on top of the following third-party services, each of which processes a limited slice of data strictly to provide their part of the Service:

Some of these providers process data on servers outside India. Where that happens, it is solely to deliver the specific function described above (e.g., generating a note, sending a message), under that provider’s own data-processing terms.

5. Security

Data is encrypted in transit (TLS) and at rest at the infrastructure level via our database provider. Access to Patient data is restricted per-Practitioner using row-level security, so one Practitioner’s account cannot read another’s patients or sessions. We are working toward additional application-level encryption of clinical content as a further safeguard. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

6. Data retention

We retain account and Patient data for as long as the Practitioner’s account is active, since clinical continuity depends on historical session notes remaining available. If a Practitioner deletes their account (available from Settings), their account, patients, sessions, notes, and appointments are permanently deleted, other than records we are legally required to retain (e.g., billing records for tax purposes).

7. Your rights

Consistent with the DPDP Act, you may:

Practitioners can exercise most of these rights directly from within the app (editing patient records, exporting notes, deleting the account). For anything else, or if you are a Patient, contact hello@kith.space and we will respond within a reasonable time.

8. Your responsibility as a Practitioner

Using Kith to record or transcribe a session means that session’s audio is being processed by the third-party providers listed in Section 4. You are responsible for informing your patient that the session is being recorded and AI-assisted, and for obtaining whatever consent is required under your jurisdiction and professional code of conduct before you begin. Kith does not verify or manage patient consent on your behalf.

9. Children’s data

Kith is intended for use by licensed/practicing mental health professionals, not by children. Patient records may relate to a minor if a Practitioner treats one, in which case the Practitioner is responsible for obtaining any parental/guardian consent required by law before entering that minor’s information.

10. Changes to this policy

We may update this policy as the Service evolves. Material changes will be reflected by updating the “Last updated” date above, and, where appropriate, communicated directly to Practitioners.

11. Contact

Questions, requests, or grievances relating to this policy can be sent to hello@kith.space.