KapiHealth Privacy Policy (Overseas)

Effective and last updated: July 30, 2026

TETRAS.AI HONGKONG CO., LIMITED (“TETRAS”, “we”, “us” or “our”) is the controller of personal information processed through the overseas version of the KapiHealth mobile application and related services (“KapiHealth” or the “Service”).

Health and fitness information is sensitive personal information. We process it only after you authorize the relevant Apple Health permissions and provide any consent required by applicable law. KapiHealth is not a medical device and does not provide diagnosis, treatment, or emergency services.

1. Information we collect

CategoryExamplesPurpose
Account and profileName or nickname, mobile number, email address, verification code, user ID, avatar, age or birthday, sex where providedCreate and secure your account, personalize the Service, provide support
Health and fitnessApple Health data you authorize, such as steps, workouts, energy, heart rate, resting heart rate, HRV, blood oxygen, sleep, respiratory rate, body measurements, environmental sound and menstrual-cycle information where applicableDisplay your health history and generate requested summaries, trends, scores and insights
Content you provideChat messages and prompts, food and mood records, goals, feedback, status photos or other photos and videos you choose to uploadProvide the feature you request, generate responses, maintain records and handle support
Device and identifiersDevice model, operating-system and app version, language, time zone, IP address, network information, IDFV, and IDFA only where App Tracking Transparency permission has been grantedOperate, secure and troubleshoot the Service; measure first-party product performance
Usage and diagnosticsFeature interactions, screen and button events, timestamps, crash reports, launch and performance measurements, memory, freeze, out-of-memory and network diagnosticsUnderstand product interaction, prevent abuse, diagnose crashes and improve reliability
Subscription informationProduct purchased, subscription status, transaction identifier and renewal or expiry state received from Apple; we do not receive your full card numberProvide paid features, restore purchases and keep transaction records
Communications and permissionsSupport correspondence and your notification, photo-library, camera and Health permissionsRespond to you and enable optional device features

We obtain information directly from you, from your device and Apple Health with your permission, from Apple for subscriptions, and from service providers acting for us. If you do not provide information required for a requested feature, that feature may not work; unrelated basic features remain available where practicable.

2. How and why we use information

Depending on the law that applies to you, we rely on one or more of the following legal bases:

We do not use HealthKit data for advertising. We do not use your health information, chats or photos to train a general-purpose AI model unless you separately opt in through a clear, specific choice. Declining such an optional choice will not prevent use of the core Service.

3. AI features

When you request an AI feature, the information needed to answer your request—such as your prompt and relevant health context—may be sent to contracted AI inference providers acting as processors for us. We require providers to process this information only to deliver and secure the requested service, subject to contractual confidentiality, security, deletion and use restrictions. AI output may be inaccurate and must not replace professional medical advice.

4. When we disclose information

We disclose only what is reasonably necessary to:

We do not sell personal information. The overseas app is configured not to use personal information for cross-app tracking or cross-context behavioural advertising. We do not disclose HealthKit data to advertising platforms, data brokers or information resellers.

5. International transfers

Our primary overseas service infrastructure is hosted in Tokyo, Japan. TETRAS is established in Hong Kong, and contracted processors may operate in other countries disclosed through the Service or this Policy. These locations may have different data-protection laws from your country.

Where applicable law requires a transfer mechanism, we will use an approved mechanism—such as an adequacy decision, standard contractual clauses or another lawful safeguard—and conduct any required transfer assessment. You may request information about the safeguard that applies to your data by contacting us.

6. Retention and deletion

We keep personal information only as long as needed for the purposes above, including while your account is active. After a verified account-deletion request, operational account, content and health data are scheduled for deletion or irreversible anonymization within 30 days, and ordinary backup copies roll off within a further 30 days. A shorter period applies where required by law.

We may retain limited transaction, security, consent and dispute records for the period required by applicable tax, accounting, fraud-prevention or limitation laws. We isolate retained information and do not use it for unrelated purposes. Deleting KapiHealth does not delete the original data held by Apple Health.

7. Security and incidents

We use access controls, encryption in transit, protected storage, logging, least-privilege practices and vendor review designed to protect personal information. No system is completely secure. If an incident creates a notification duty, we will notify affected individuals and regulators in the manner and time required by applicable law.

8. Your rights and choices

Subject to local law, you may request access, correction, deletion, restriction, portability or a copy of your information; object to certain processing; withdraw consent; or complain to your local supervisory authority. You may manage Health, photo, camera, notification and tracking permissions in iOS Settings, and may delete your account through Me → Account Settings → Deactivate Account.

Email ivanli@sensetime.com to exercise a right. State your request and the account identifier needed for verification. We may ask for proportionate proof of identity and will respond within the period required by applicable law. You may also contact us for the details of any data-protection representative applicable to your location.

9. Children

The overseas Service is not directed to anyone under 16, and people under 16 must not create an account or use the Service. We do not knowingly collect their personal information. If you believe a child has provided information, contact us and we will investigate and delete it where required.

10. Regional notices

EEA and United Kingdom

You may complain to the supervisory authority where you live or work. Where Article 27 of the EU GDPR or UK GDPR applies, details of our appointed representative will be made available through this Policy or the Service before the Service is offered in that jurisdiction.

United States

Depending on your state, you may have additional rights, including the right to appeal a denied request. KapiHealth is not a HIPAA-covered health plan or healthcare provider merely because it processes consumer health information. Consumer-health-data and breach-notification laws may still apply.

11. Changes

We may update this Policy to reflect changes in the Service or law. We will post the revised date and provide prominent or in-app notice where a change materially affects your rights or requires renewed consent.

12. Contact us

Controller: TETRAS.AI HONGKONG CO., LIMITED
Address: Suite 6503, 65/F, Central Plaza, 18 Harbour Road, Wan Chai, Hong Kong
Email: ivanli@sensetime.com