KapiHealth Privacy Policy (Overseas)
Effective and last updated: July 30, 2026
TETRAS.AI HONGKONG CO., LIMITED (“TETRAS”, “we”, “us” or “our”) is the controller of personal information processed through the overseas version of the KapiHealth mobile application and related services (“KapiHealth” or the “Service”).
Health and fitness information is sensitive personal information. We process it only after you authorize the relevant Apple Health permissions and provide any consent required by applicable law. KapiHealth is not a medical device and does not provide diagnosis, treatment, or emergency services.
1. Information we collect
| Category | Examples | Purpose |
|---|---|---|
| Account and profile | Name or nickname, mobile number, email address, verification code, user ID, avatar, age or birthday, sex where provided | Create and secure your account, personalize the Service, provide support |
| Health and fitness | Apple Health data you authorize, such as steps, workouts, energy, heart rate, resting heart rate, HRV, blood oxygen, sleep, respiratory rate, body measurements, environmental sound and menstrual-cycle information where applicable | Display your health history and generate requested summaries, trends, scores and insights |
| Content you provide | Chat messages and prompts, food and mood records, goals, feedback, status photos or other photos and videos you choose to upload | Provide the feature you request, generate responses, maintain records and handle support |
| Device and identifiers | Device model, operating-system and app version, language, time zone, IP address, network information, IDFV, and IDFA only where App Tracking Transparency permission has been granted | Operate, secure and troubleshoot the Service; measure first-party product performance |
| Usage and diagnostics | Feature interactions, screen and button events, timestamps, crash reports, launch and performance measurements, memory, freeze, out-of-memory and network diagnostics | Understand product interaction, prevent abuse, diagnose crashes and improve reliability |
| Subscription information | Product purchased, subscription status, transaction identifier and renewal or expiry state received from Apple; we do not receive your full card number | Provide paid features, restore purchases and keep transaction records |
| Communications and permissions | Support correspondence and your notification, photo-library, camera and Health permissions | Respond to you and enable optional device features |
We obtain information directly from you, from your device and Apple Health with your permission, from Apple for subscriptions, and from service providers acting for us. If you do not provide information required for a requested feature, that feature may not work; unrelated basic features remain available where practicable.
2. How and why we use information
Depending on the law that applies to you, we rely on one or more of the following legal bases:
- Contract: to create your account and deliver features you request.
- Consent or explicit consent: for HealthKit access, health and other sensitive information, optional photos, notifications, and any other processing for which consent is required. You may withdraw consent in iOS or KapiHealth settings without affecting earlier lawful processing.
- Legitimate interests: to secure, maintain and improve the Service, prevent fraud, measure first-party product use and respond to support requests, after balancing those interests against your rights.
- Legal obligations and vital interests: where processing is required by law or necessary to protect a person in an emergency. KapiHealth is not an emergency service.
We do not use HealthKit data for advertising. We do not use your health information, chats or photos to train a general-purpose AI model unless you separately opt in through a clear, specific choice. Declining such an optional choice will not prevent use of the core Service.
3. AI features
When you request an AI feature, the information needed to answer your request—such as your prompt and relevant health context—may be sent to contracted AI inference providers acting as processors for us. We require providers to process this information only to deliver and secure the requested service, subject to contractual confidentiality, security, deletion and use restrictions. AI output may be inaccurate and must not replace professional medical advice.
4. When we disclose information
We disclose only what is reasonably necessary to:
- cloud hosting, data-storage, content-delivery and security providers;
- AI inference providers for features you request;
- analytics, crash-diagnostics and customer-support providers acting for us;
- Apple for HealthKit, App Store subscription and platform functions that you choose;
- professional advisers, authorities or courts where required by law or necessary to establish, exercise or defend legal claims; or
- a successor in a merger, financing or sale, subject to appropriate confidentiality and notice requirements.
We do not sell personal information. The overseas app is configured not to use personal information for cross-app tracking or cross-context behavioural advertising. We do not disclose HealthKit data to advertising platforms, data brokers or information resellers.
5. International transfers
Our primary overseas service infrastructure is hosted in Tokyo, Japan. TETRAS is established in Hong Kong, and contracted processors may operate in other countries disclosed through the Service or this Policy. These locations may have different data-protection laws from your country.
Where applicable law requires a transfer mechanism, we will use an approved mechanism—such as an adequacy decision, standard contractual clauses or another lawful safeguard—and conduct any required transfer assessment. You may request information about the safeguard that applies to your data by contacting us.
6. Retention and deletion
We keep personal information only as long as needed for the purposes above, including while your account is active. After a verified account-deletion request, operational account, content and health data are scheduled for deletion or irreversible anonymization within 30 days, and ordinary backup copies roll off within a further 30 days. A shorter period applies where required by law.
We may retain limited transaction, security, consent and dispute records for the period required by applicable tax, accounting, fraud-prevention or limitation laws. We isolate retained information and do not use it for unrelated purposes. Deleting KapiHealth does not delete the original data held by Apple Health.
7. Security and incidents
We use access controls, encryption in transit, protected storage, logging, least-privilege practices and vendor review designed to protect personal information. No system is completely secure. If an incident creates a notification duty, we will notify affected individuals and regulators in the manner and time required by applicable law.
8. Your rights and choices
Subject to local law, you may request access, correction, deletion, restriction, portability or a copy of your information; object to certain processing; withdraw consent; or complain to your local supervisory authority. You may manage Health, photo, camera, notification and tracking permissions in iOS Settings, and may delete your account through Me → Account Settings → Deactivate Account.
Email ivanli@sensetime.com to exercise a right. State your request and the account identifier needed for verification. We may ask for proportionate proof of identity and will respond within the period required by applicable law. You may also contact us for the details of any data-protection representative applicable to your location.
9. Children
The overseas Service is not directed to anyone under 16, and people under 16 must not create an account or use the Service. We do not knowingly collect their personal information. If you believe a child has provided information, contact us and we will investigate and delete it where required.
10. Regional notices
EEA and United Kingdom
You may complain to the supervisory authority where you live or work. Where Article 27 of the EU GDPR or UK GDPR applies, details of our appointed representative will be made available through this Policy or the Service before the Service is offered in that jurisdiction.
United States
Depending on your state, you may have additional rights, including the right to appeal a denied request. KapiHealth is not a HIPAA-covered health plan or healthcare provider merely because it processes consumer health information. Consumer-health-data and breach-notification laws may still apply.
11. Changes
We may update this Policy to reflect changes in the Service or law. We will post the revised date and provide prominent or in-app notice where a change materially affects your rights or requires renewed consent.
12. Contact us
Controller: TETRAS.AI HONGKONG CO., LIMITED
Address: Suite 6503, 65/F, Central Plaza, 18 Harbour Road, Wan Chai, Hong Kong
Email: ivanli@sensetime.com