Legal

Privacy Policy

Effective August 17, 2026Last Updated August 17, 2026

KindHealth Insurance Services, LLC ("KindHealth," "we," "us," or "our") respects the privacy and security of the information entrusted to us.

This Privacy Policy describes how we collect, use, disclose, retain, and otherwise process Personal Information when you interact with kindhealth.ai, the KindHealth platform, Kio, and other KindHealth websites, applications, products, and services that link to this Privacy Policy (collectively, the "Services").

KindHealth provides health-plan intelligence, decision-support, governance, benefits-navigation, and related technology to self-funded employers, employee benefit plans, benefits consultants, advisors, brokers, and other organizations ("Customers"). Kio provides authorized employees, plan participants, members, and, where applicable, their dependents ("Members") with personalized assistance concerning their benefits.

This Privacy Policy applies differently depending on whether KindHealth is processing information for its own business purposes or on behalf of a Customer.

1. Our Role and the Scope of This Policy

Information KindHealth Processes for Its Own Purposes

KindHealth may determine the purposes and means of processing information associated with:

  • visitors to our public websites;
  • sales prospects and business contacts;
  • Customer account administration;
  • marketing communications;
  • security and fraud prevention;
  • our own corporate operations; and
  • other activities for which KindHealth determines how and why Personal Information is processed.

Depending on applicable law, KindHealth may be considered a "business," "controller," or similar responsible entity for this information.

Customer Data

A significant portion of the information KindHealth processes through the Services is provided by or on behalf of our Customers.

"Customer Data" may include benefits, eligibility, claims, pharmacy, plan, employee, participant, dependent, vendor, financial, and other information that KindHealth processes to provide Services to a Customer.

For Customer Data, KindHealth generally acts on the Customer's instructions and subject to our agreement with that Customer. Depending on applicable law and the circumstances, KindHealth may act as a service provider, processor, contractor, or HIPAA business associate.

If you access KindHealth through your employer, employee benefit plan, benefits advisor, or another Customer, that Customer's privacy notices and agreements may also apply to the processing of your information.

Where this Privacy Policy conflicts with a Customer agreement or Business Associate Agreement ("BAA") concerning Customer Data, the applicable Customer agreement or BAA controls to the extent of the conflict.

2. Information We Collect and Process

The information we process depends on your relationship with KindHealth, the Services your organization uses, and the features you use.

A. Business and Contact Information

We may collect:

  • name;
  • business email address;
  • telephone number;
  • employer or organization;
  • job title;
  • mailing address;
  • professional information;
  • communications with KindHealth;
  • demo, sales, event, and marketing information; and
  • information concerning your organization's relationship with KindHealth.

B. Account and Authentication Information

When you use the Services, we may process:

  • name;
  • email address;
  • organization;
  • username or account identifier;
  • authentication credentials or tokens;
  • assigned roles and permissions;
  • account settings;
  • login history; and
  • security and authentication information.

We may receive some of this information from a Customer or from Customer-authorized identity and authentication providers.

C. Health Plan, Benefits, Claims, and Customer Data

Depending on the Services purchased or enabled by a Customer, we may process information including:

  • medical claims;
  • pharmacy claims;
  • prescription and specialty-pharmacy information;
  • healthcare utilization information;
  • diagnoses and clinical cost-driver information contained in claims data;
  • high-cost claimant and catastrophic-risk information;
  • deductible, copayment, coinsurance, and out-of-pocket spending information;
  • provider and network information;
  • benefit utilization and care-gap information;
  • stop-loss information and contracts;
  • plan-design and funding information;
  • plan documents, including Summary Plan Descriptions, Summaries of Benefits and Coverage, benefit guides, formularies, FAQs, and policy documents;
  • enrollment and eligibility information;
  • employee and dependent census information;
  • HRIS information;
  • employee location where relevant to benefits eligibility or navigation;
  • family or dependent status;
  • carrier, TPA, PBM, broker, consultant, and vendor information;
  • financial, utilization, and plan-performance information;
  • vendor contracts and performance information;
  • information concerning plan recommendations, decisions, actions, and outcomes; and
  • other information the Customer authorizes KindHealth to process.

Some of this information may constitute Protected Health Information ("PHI"), sensitive Personal Information, or other legally protected health information.

D. Kio Conversations and Personalized Benefits Information

When a Member uses Kio, we may process:

  • questions, prompts, and instructions submitted to Kio;
  • Kio's responses;
  • conversation history and contextual memory where the feature is enabled;
  • feedback concerning Kio responses;
  • documents or information submitted by the Member;
  • plan and benefit information relevant to the Member;
  • enrollment and eligibility information;
  • deductible and benefit-utilization information;
  • claims and pharmacy information;
  • provider and network information;
  • billing or coverage information;
  • benefit deadlines and renewal information; and
  • other Customer Data necessary to provide personalized benefits guidance.

Members should avoid including information about another person unless they are authorized to provide that information.

E. Website, Device, and Usage Information

When you use our websites or Services, we may automatically collect:

  • Internet Protocol address;
  • browser type;
  • device type;
  • operating system;
  • referring and exit pages;
  • pages and features accessed;
  • dates and times of access;
  • clicks and navigation activity;
  • application and system logs;
  • crash and diagnostic information;
  • security events;
  • cookie and similar-technology identifiers; and
  • approximate location inferred from IP address.

We will collect precise device location only where a feature requires it, applicable law permits it, and the user has provided any permission required by the device or service.

F. Information From Other Sources

Depending on the context, we may receive information from:

  • Customers;
  • employers and employee benefit plans;
  • benefits consultants, advisors, and brokers;
  • third-party administrators;
  • health plans and carriers;
  • pharmacy benefit managers;
  • stop-loss providers;
  • HRIS and benefits-administration systems;
  • other Customer-authorized vendors and data sources;
  • authentication providers;
  • service providers;
  • public sources; and
  • marketing and business-information providers with respect to public-site and business-development activities.

3. How We Use Information

We process Personal Information and Customer Data to provide and support the Services and for other purposes permitted by applicable law and our Customer agreements.

These purposes may include:

  • operating and maintaining KindHealth and Kio;
  • authenticating users and administering accounts;
  • integrating and normalizing Customer data sources;
  • analyzing healthcare spending and plan performance;
  • analyzing medical and pharmacy claims;
  • identifying cost drivers and utilization trends;
  • evaluating high-cost claimants and stop-loss exposure;
  • identifying potential billing, coverage, utilization, or plan issues;
  • evaluating plan-design and funding alternatives;
  • supporting vendor and contract oversight;
  • producing reports, findings, recommendations, and alerts;
  • documenting recommendations, decisions, actions, evidence, and outcomes;
  • supporting health-plan governance and audit readiness;
  • providing Members with personalized benefits guidance;
  • explaining plans, claims, bills, networks, pharmacy benefits, and coverage;
  • helping Members understand available and unused benefits;
  • assisting with benefit and plan comparisons;
  • providing authorized reminders and proactive benefit guidance;
  • providing Customer support;
  • maintaining and improving the reliability, quality, security, and usability of the Services;
  • detecting and preventing fraud, abuse, and security incidents;
  • conducting auditing, compliance, and governance activities;
  • communicating with Customers, users, and business contacts;
  • responding to inquiries and requests;
  • conducting business development and marketing activities relating to our public website;
  • complying with applicable law and contractual obligations; and
  • creating aggregated or de-identified information as permitted by applicable law and Customer agreements.

4. Artificial Intelligence and Kio

KindHealth uses artificial intelligence and machine-learning technologies to provide portions of the Services, including Kio and AI-assisted analysis within the KindHealth platform.

How AI Systems Use Customer Data

Customer Data may be processed by KindHealth systems and authorized service providers as necessary to provide AI-enabled functionality. Service providers processing such information on our behalf are subject to contractual confidentiality, security, and data-use restrictions and, where required for PHI, an appropriate BAA.

We do not permit third-party AI providers to use PHI, Customer Data, or identifiable Kio conversations processed on KindHealth's behalf to train their general-purpose models.

Except where expressly authorized by the applicable Customer and permitted by law, KindHealth does not use identifiable Customer Data or identifiable Kio conversations to train general-purpose AI models for unrelated customers.

KindHealth may use Customer-provided plan materials and other Customer Data to configure, ground, retrieve context for, and otherwise operate AI features specifically for the applicable Customer and its authorized users.

Service Improvement

We may use operational telemetry, feedback, and other information to test, secure, evaluate, and improve the Services.

Where permitted by applicable law and the applicable Customer agreement, we may also use aggregated or de-identified information to evaluate and improve our products, analytics, models, and methodologies.

Where PHI is involved, any de-identification or other use will be conducted only as permitted under the applicable BAA and HIPAA.

5. Kio Privacy and Employer Visibility

Kio is designed to give Members personalized assistance while enabling Customers to better understand how their benefits programs are working.

Kio may use Member-specific information to provide personalized answers and recommendations to that Member.

KindHealth may provide Customers with aggregated or de-identified insights concerning matters such as:

  • benefits topics employees commonly ask about;
  • recurring areas of plan confusion;
  • utilization and engagement trends;
  • benefit communication gaps;
  • vendor or network friction;
  • plan-design issues;
  • recurring Member questions or concerns; and
  • other patterns that may help the Customer improve its benefits program.

KindHealth does not make an individual Member's identifiable Kio conversation available to the Member's employer merely because the employer sponsors or provides access to Kio.

Employer-facing conversational analytics are designed to show patterns and trends rather than expose an individual Member's questions or conversation history.

An individual conversation or information relating to it may be disclosed only where appropriate and permitted, such as:

  • when the Member requests or authorizes an escalation or disclosure;
  • when necessary to provide technical or customer support requested by the Member;
  • when necessary to investigate misuse, fraud, or a security incident;
  • where disclosure is required by law; or
  • as otherwise specifically authorized under the applicable Customer agreement and applicable law.

6. How We Disclose Information

We may disclose Personal Information in the following circumstances.

Customers and Authorized Users

We may make Customer Data available within a Customer's KindHealth environment to individuals authorized by that Customer and consistent with their assigned permissions.

Service Providers and Subprocessors

We use service providers that support functions such as:

  • cloud infrastructure and hosting;
  • data storage and processing;
  • AI and machine-learning infrastructure;
  • authentication and identity management;
  • cybersecurity;
  • monitoring and logging;
  • communications;
  • customer support;
  • product development and testing;
  • website analytics;
  • professional services; and
  • other operational services.

These providers may process information only as necessary to perform services for KindHealth and subject to appropriate contractual restrictions.

Where a service provider creates, receives, maintains, or transmits PHI on our behalf and HIPAA requires a BAA, we require the appropriate contractual protections.

Customer-Authorized Third Parties

At a Customer's direction, KindHealth may exchange Customer Data with organizations such as:

  • benefits consultants, advisors, and brokers;
  • carriers and health plans;
  • TPAs;
  • PBMs;
  • stop-loss providers;
  • HRIS and benefits-administration providers;
  • other benefits vendors; and
  • other entities designated or authorized by the Customer.

Affiliates and Professional Advisors

We may disclose information to our affiliates and to professional advisors, auditors, insurers, accountants, and legal counsel where reasonably necessary for legitimate business, legal, audit, or compliance purposes.

Legal, Compliance, and Safety

We may disclose information where we reasonably believe disclosure is necessary to:

  • comply with applicable law, regulation, subpoena, court order, or other lawful process;
  • respond to lawful governmental requests;
  • establish, exercise, or defend legal claims;
  • protect the security and integrity of the Services;
  • investigate or prevent fraud, abuse, or unlawful activity; or
  • protect the rights, safety, and property of KindHealth, our Customers, users, or others.

Corporate Transactions

Information may be disclosed in connection with an actual or proposed merger, acquisition, financing, restructuring, sale of assets, bankruptcy, or similar corporate transaction, subject to applicable legal and contractual requirements.

Aggregated and De-Identified Information

We may use or disclose information that has been aggregated or de-identified so that it is no longer reasonably linkable to an identifiable individual, as permitted by applicable law and Customer agreements.

Where required, we maintain such information in de-identified form and do not attempt to re-identify it.

7. HIPAA and Protected Health Information

KindHealth may receive, create, maintain, or transmit PHI on behalf of health plans, covered entities, or other business associates.

When KindHealth acts as a HIPAA business associate, our use and disclosure of PHI are governed by HIPAA and the applicable BAA.

KindHealth uses or discloses PHI in that capacity only:

  • as permitted or required by the applicable BAA to provide the contracted Services;
  • for other purposes expressly permitted under the BAA and HIPAA; or
  • as required by law.

KindHealth maintains safeguards designed to protect PHI and electronic PHI and requires subcontractors that process PHI on our behalf to enter into appropriate contractual arrangements where required by HIPAA.

HIPAA Individual Rights

The applicable health plan or other HIPAA covered entity is generally responsible for responding to individual requests to exercise HIPAA rights concerning PHI, including applicable rights of access, amendment, restriction, confidential communications, and accounting of disclosures.

KindHealth assists customers in fulfilling those obligations as required by HIPAA and our BAAs.

If you submit a HIPAA rights request directly to KindHealth regarding information we maintain solely on behalf of a Customer, we may refer the request to the appropriate Customer or coordinate with that Customer as required by our agreement and applicable law.

This Is Not a HIPAA Notice of Privacy Practices

This Privacy Policy is not a HIPAA Notice of Privacy Practices for your employer-sponsored health plan or another HIPAA covered entity.

If a health plan or other covered entity has provided you with a HIPAA Notice of Privacy Practices, that notice describes the covered entity's uses and disclosures of PHI and your HIPAA rights with respect to that entity.

8. Cookies, Analytics, and Online Tracking

Our public websites may use cookies, pixels, local storage, and similar technologies for:

  • website functionality;
  • security;
  • remembering preferences;
  • understanding website usage and performance;
  • analytics; and
  • measuring marketing effectiveness.

Where required by law, we provide mechanisms for users to manage optional cookies and similar technologies.

We do not use Customer Data, PHI, or Kio conversation content for behavioral advertising.

We do not intentionally deploy advertising or retargeting technologies on authenticated Service pages containing PHI or sensitive Customer health information.

9. Sale, Sharing, and Targeted Advertising

KindHealth does not sell PHI, Customer health data, or Kio conversation content for monetary or other valuable consideration.

KindHealth does not use PHI, Customer health data, or Kio conversation content for cross-context behavioral advertising or targeted advertising.

On our public, unauthenticated website, we may use analytics or marketing technologies. Under certain state privacy laws, some disclosures made through those technologies may be defined as a "sale," "sharing," or processing for "targeted advertising," even where no money is exchanged.

Where applicable, we provide legally required opt-out mechanisms.

10. Data Retention

We retain information for periods appropriate to the purposes for which it is processed and consistent with applicable law and our contractual obligations.

Customer Data

Customer Data is retained according to:

  • the applicable Customer agreement;
  • Customer instructions;
  • any applicable BAA;
  • operational requirements;
  • legal and regulatory obligations; and
  • our backup, disaster-recovery, and security processes.

Following termination of a Customer relationship, Customer Data will be returned, deleted, or otherwise handled as required by the applicable agreement, BAA, and law.

Kio Conversations

Kio conversation history is retained according to Customer configuration, the applicable Customer agreement, operational and security requirements, and applicable law.

Where a Customer or Member is entitled to deletion or where deletion is required under an applicable agreement, KindHealth processes the request subject to applicable legal and technical exceptions.

Other Personal Information

Website, business-contact, account, security, and similar information is retained for as long as reasonably necessary for the purposes described in this Privacy Policy and thereafter where required for legitimate legal, security, audit, tax, or business-record purposes.

HIPAA Documentation

KindHealth retains HIPAA documentation for the period required under applicable HIPAA requirements.

This does not mean that all PHI is retained for the same period. Retention of PHI is determined by the applicable Customer agreement, BAA, Customer instructions, and other applicable law.

Backup copies may persist for a limited period according to our backup and disaster-recovery lifecycle before being overwritten or deleted.

11. Information Security

KindHealth maintains an information-security program designed to protect Personal Information and Customer Data against unauthorized access, acquisition, alteration, use, disclosure, or destruction.

Depending on the systems and information involved, our safeguards may include:

  • role-based access controls;
  • authentication controls;
  • encryption in transit and at rest;
  • logging and monitoring;
  • audit controls;
  • vulnerability and security testing;
  • incident-response procedures;
  • workforce security and training;
  • vendor risk-management controls; and
  • business-continuity and disaster-recovery measures.

KindHealth maintains security and compliance practices appropriate to the sensitive health and benefits information processed through the Services.

No system, transmission method, or storage environment is completely secure, and we cannot guarantee absolute security.

If we experience a security incident involving Personal Information, we investigate and provide notifications as required by applicable law and our contractual obligations.

If an incident constitutes a breach of unsecured PHI, KindHealth will provide required notice to the applicable covered entity or business associate and cooperate as required under HIPAA and the applicable BAA.

12. Your Privacy Rights

Depending on where you live, the information involved, and KindHealth's role in processing that information, you may have rights concerning your Personal Information.

These rights may include the right to:

  • confirm whether we process Personal Information about you;
  • access Personal Information about you;
  • obtain a portable copy of certain Personal Information;
  • correct inaccurate Personal Information;
  • request deletion of Personal Information;
  • opt out of certain sales of Personal Information;
  • opt out of certain sharing or targeted advertising;
  • limit certain uses or disclosures of sensitive Personal Information;
  • opt out of certain qualifying profiling activities;
  • withdraw consent where processing is based on consent;
  • appeal certain decisions concerning privacy requests; and
  • exercise your rights without unlawful discrimination or retaliation.

These rights vary by jurisdiction and may be subject to exceptions.

Customer Data Requests

Where KindHealth processes Personal Information solely on behalf of a Customer, the Customer may be responsible for responding to your request.

If you submit such a request directly to KindHealth, we may refer the request to the applicable Customer or assist that Customer in responding.

Submitting a Request

To exercise an applicable privacy right, contact:

hello@heykind.com

We may take reasonable steps to authenticate your identity and verify your request.

Where applicable, an authorized agent may submit a request on your behalf.

If we deny a request and applicable law provides a right to appeal, our response will explain how to submit an appeal.

13. California Privacy Disclosures

This section applies to Personal Information subject to the California Consumer Privacy Act, as amended ("CCPA").

Depending on your interaction with KindHealth, during the preceding 12 months we may have collected the following categories of Personal Information:

  • identifiers and contact information;
  • customer-record information;
  • commercial and business information;
  • internet or electronic-network activity;
  • professional and employment-related information;
  • geolocation information where applicable;
  • health and health-insurance information;
  • sensitive Personal Information;
  • communications and user-generated content; and
  • inferences derived from other Personal Information.

The sources from which we obtain this information are described in Section 2.

The business and commercial purposes for which we process it are described in Section 3.

The categories of recipients to which we disclose Personal Information are described in Section 6.

California residents may have rights to know, access, delete, correct, opt out of sale or sharing, limit certain uses or disclosures of sensitive Personal Information, and receive equal treatment for exercising their privacy rights.

KindHealth does not sell PHI, Customer health data, or Kio conversation content.

To the extent public-website advertising or analytics activity constitutes "sharing" under California law, eligible individuals may exercise applicable opt-out rights by emailing hello@heykind.com or another legally required mechanism.

Certain Personal Information may be exempt from some CCPA requirements under applicable federal or state law.

14. Information About Children and Dependents

KindHealth's public website and business-facing account services are not directed to children under 13, and we do not knowingly invite children under 13 to create independent KindHealth accounts.

Because employer-sponsored health plans may cover children and other dependents, Customer Data processed by KindHealth may include information concerning minor dependents.

When we process dependent information on behalf of a Customer, we process it according to the applicable Customer agreement, BAA where applicable, and applicable law.

15. Third-Party Websites and Services

Our public websites or Services may contain links to websites or services operated by third parties.

Where a third party operates independently from KindHealth, its privacy practices are governed by its own privacy notice rather than this Privacy Policy.

This section does not alter the contractual privacy and security obligations applicable to service providers or subprocessors that process information on KindHealth's behalf.

16. Financial and Insurance Privacy

KindHealth Insurance Services, LLC may be subject to additional federal or state privacy requirements in connection with particular insurance or financial products or services.

Where applicable, we may provide a separate financial privacy notice that governs information collected in connection with those products or services.

If a separate financial privacy notice applies to you, its terms will govern the information within its scope.

17. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes to our Services, technology, privacy practices, or legal requirements.

When we make changes, we will update the "Last Updated" date above.

Where required by applicable law, we will provide additional notice or obtain consent before materially changing how we process Personal Information.

18. Contact Us

Questions, concerns, or privacy requests may be directed to:

KindHealth Insurance Services, LLC
Attn: Privacy
301 S Heatherwilde Blvd #2857
Pflugerville, TX 78691

Email: hello@heykind.com

If your question concerns information KindHealth processes on behalf of your employer, health plan, or another Customer, you may also contact that organization directly.