Privacy Policy
Last Updated:
This Privacy Notice for Oculi Medical Corp. (doing business as Kim) ("we," "us," or "our"), describes how and why we might access, collect, store, use, and/or share ("process") your personal information when you use our services ("Services"), including when you:
Visit our website at Oculimedical.com or any website of ours that links to this Privacy Notice
Download and use our mobile application (Kim), or any other application of ours that links to this Privacy Notice
Use Kim. Kim is an AI-powered health assistant mobile app with a conversational AI interface (voice and text) powered by Anthropic (Claude) and Inworld. Kim reads health and fitness data from Apple HealthKit only after you give permission. This may include data written to Apple Health by compatible devices and apps such as Apple Watch, Oura, Whoop, Garmin, Fitbit, and others, but Kim can only access the specific data types available in Apple Health and authorized by you. Kim helps users track food, supplements, mood, exercise, sleep, activity, and other wellness inputs, and may provide general wellness context based on the information you provide. Kim supports photo-based calorie and food tracking, and enables food, supplement, mood, and exercise logging through both manual entry and conversation. Kim provides personalized wellness insights, dashboards, self-experiment tracking, morning briefings, weekly reports, wellness Q&A using web search and source citations, and illustrative wellness trend estimates based on user-provided data. Kim is not a medical device and does not provide medical diagnoses or treatment recommendations.
Engage with us in other related ways, including any marketing or events
Questions or concerns? Reading this Privacy Notice will help you understand your privacy rights and choices. We are responsible for making decisions about how your personal information is processed. If you do not agree with our policies and practices, please do not use our Services. If you still have any questions or concerns, please contact us at info@oculimedical.com.
SUMMARY OF KEY POINTS
This summary provides key points from our Privacy Notice.
What personal information do we process? When you visit, use, or navigate our Services, we may process personal information depending on how you interact with us and the Services, the choices you make, and the products and features you use.
Do we process any sensitive personal information? Yes, we process health data when you provide it through the App or authorize Apple HealthKit access. We process sensitive personal information when necessary with your consent or as otherwise permitted by applicable law.
Do we collect any information from third parties? We collect information from Apple HealthKit when you authorize access. This may include data written to Apple Health by compatible third-party apps or wearable devices.
How do we process your information? We process your information to provide, improve, and administer our Services, communicate with you, for security and fraud prevention, and to comply with law.
In what situations and with which parties do we share personal information? We share information with specific third-party service providers who help us deliver the Services.
How do we keep your information safe? We have organizational and technical processes in place to protect your personal information, though no system can be guaranteed 100% secure.
What are your rights? Depending on your location, applicable privacy law may give you certain rights regarding your personal information.
How do you exercise your rights? By contacting us at info@oculimedical.com or through your account settings.
TABLE OF CONTENTS
1. WHAT INFORMATION DO WE COLLECT?
Personal information you disclose to us
In Short: We collect personal information that you provide to us.
We collect personal information that you voluntarily provide to us when you register on the Services, express an interest in obtaining information about us or our products and Services, when you participate in activities on the Services, or otherwise when you contact us.
Personal Information Provided by You. The personal information that we collect depends on the context of your interactions with us and the Services, the choices you make, and the products and features you use. The personal information we collect may include the following:
names
email addresses
contact or authentication data
health and fitness data
food and nutrition logs
supplement logs
photos (food photo logging)
voice recordings (when you use voice features)
Sensitive Information. When necessary, with your consent or as otherwise permitted by applicable law, we process the following categories of sensitive information:
health data
Apple Sign-In Data. We offer you the ability to register and log in using Apple Sign-In. When you choose to use Apple Sign-In, we receive limited profile information from Apple, such as your name and email address (which may be a private relay email). See "HOW DO WE HANDLE YOUR APPLE SIGN-IN?" below.
Application Data. If you use our application, we also may collect the following information if you choose to provide us with access or permission:
Mobile Device Access. We may request access or permission to certain features from your mobile device, including your camera, microphone, photo storage, and Apple HealthKit. If you wish to change our access or permissions, you may do so in your device's settings.
Mobile Device Data. We may automatically collect limited technical information needed to maintain the security, reliability, and operation of the Services, such as device type, operating system version, app version, IP address, crash or diagnostic logs, and basic server logs.
Push Notifications. We may request to send you push notifications regarding your account or certain features of the application. If you wish to opt out, you may turn them off in your device's settings.
This information is primarily needed to maintain the security and operation of our application, for troubleshooting, and for our internal analytics and reporting purposes.
All personal information that you provide to us must be true, complete, and accurate, and you must notify us of any changes to such personal information.
Information automatically collected
In Short: Some information — such as your IP address and/or browser and device characteristics — is collected automatically when you visit our Services.
We automatically collect certain information when you visit, use, or navigate the Services. This information does not reveal your specific identity (like your name or contact information) but may include device and usage information, such as your IP address, browser and device characteristics, operating system, language preferences, referring URLs, device name, country, location, information about how and when you use our Services, and other technical information. This information is primarily needed to maintain the security and operation of our Services, and for our internal analytics and reporting purposes.
Like many businesses, we also collect information through cookies and similar technologies on our website.
The information we collect includes:
Log and Usage Data. Service-related, diagnostic, usage, and performance information our servers automatically collect when you access or use our Services.
Device Data. Information about your computer, phone, tablet, or other device used to access the Services.
2. HOW DO WE PROCESS YOUR INFORMATION?
In Short: We process your information to provide, improve, and administer our Services, communicate with you, for security and fraud prevention, and to comply with law.
We process your personal information for a variety of reasons, depending on how you interact with our Services, including:
To facilitate account creation and authentication. So you can create and log in to your account, as well as keep your account in working order.
To deliver and facilitate delivery of services. To provide you with the requested service.
To respond to user inquiries. To respond to your inquiries and solve any potential issues.
To send administrative information. To send you details about our products and services, changes to our terms and policies, and other similar information.
To request feedback. To contact you about your use of our Services.
To protect our Services. Including fraud monitoring and prevention.
To identify usage trends. To better understand how our Services are being used so we can improve them.
To save or protect an individual's vital interest. To prevent harm.
To provide personalized wellness insights. We process your health and fitness data, food logs, supplement logs, mood logs, exercise logs, and other wellness inputs through AI services to generate personalized wellness insights, suggestions, and data visualizations.
3. WHAT LEGAL BASES DO WE RELY ON?
In Short: We only process your personal information when we believe it is necessary and we have a valid legal reason to do so under applicable law.
If you are located in the EU or UK, this section applies to you.
The General Data Protection Regulation (GDPR) and UK GDPR require us to explain the valid legal bases we rely on. We may rely on the following legal bases to process your personal information:
Consent. We may process your information if you have given us permission to use your personal information for a specific purpose. You can withdraw your consent at any time.
Performance of a Contract. We may process your personal information when we believe it is necessary to fulfill our contractual obligations to you.
Legitimate Interests. We may process your information when reasonably necessary to achieve our legitimate business interests, including to analyze how our Services are used, diagnose problems, prevent fraud, and improve user experience.
Legal Obligations. We may process your information where necessary for compliance with our legal obligations.
Vital Interests. We may process your information where necessary to protect your vital interests or those of a third party.
If you are located in Canada, this section applies to you.
We may process your information if you have given us specific permission (express consent), or in situations where your permission can be inferred (implied consent). You can withdraw your consent at any time.
4. WHEN AND WITH WHOM DO WE SHARE YOUR INFORMATION?
In Short: We may share information with the following third parties.
We may share your data with third-party vendors, service providers, contractors, or agents who perform services for us or on our behalf and require access to such information to do that work. We have contracts in place with our third parties to safeguard your personal information.
The third parties we may share personal information with are as follows:
Anthropic (Claude) — AI conversational chat, wellness insights, food photo analysis (health data processed with your consent)
Inworld — voice transcription, voice processing, and AI voice features
Google Cloud Platform (Google Cloud) — Cloud infrastructure and storage
MongoDB Atlas — Database storage
Apple Sign-In — User authentication
Google Analytics — Website analytics (no app data)
Framer — Website hosting
Apple TestFlight — Beta testing distribution
Anthropic (web search) — web search and source retrieval for user-requested wellness questions. When web search is used, Kim may share the minimum necessary query context with Anthropic's web search functionality to retrieve relevant public sources for your requested wellness question.
We also may need to share your personal information in the following situations:
Business Transfers. We may share or transfer your information in connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company.
5. DO WE USE COOKIES AND OTHER TRACKING TECHNOLOGIES?
In Short: We may use cookies and other tracking technologies on our website.
We may use cookies and similar tracking technologies (like web beacons and pixels) to gather information when you interact with our website. Some online tracking technologies help us maintain the security of our Services, prevent crashes, fix bugs, save your preferences, and assist with basic site functions.
We also use Google Analytics on our website to understand how visitors interact with our content. Please note: As stated in Section 17, health data and any data obtained through Apple HealthKit APIs are never used for advertising, marketing, or data mining purposes.
Specific information about how we use such technologies and how you can refuse certain cookies is set out in our Cookie Notice.
6. DO WE OFFER ARTIFICIAL INTELLIGENCE-BASED PRODUCTS?
In Short: Yes. We offer products, features, or tools powered by artificial intelligence, machine learning, or similar technologies.
As part of our Services, we offer products, features, or tools powered by artificial intelligence, machine learning, or similar technologies (collectively, "AI Products"). The terms in this Privacy Notice govern your use of the AI Products within our Services.
Use of AI Technologies
We provide the AI Products through third-party service providers ("AI Service Providers"), including Anthropic (Claude) and Inworld. As outlined in this Privacy Notice, your input, output, and personal information will be shared with and processed by these AI Service Providers to enable your use of our AI Products.
Our AI Products
Our AI Products are designed for the following functions:
AI conversational chat
AI wellness insights
Image analysis for food photo logging
Natural language processing
voice transcription, voice processing, and AI voice features
We do not use your personal or health data to train or improve the underlying AI models of our service providers. All data sent to Anthropic and Inworld is processed solely to deliver the requested AI features for you and is subject to strict contractual safeguards.
How We Process Your Data Using AI
All personal information processed using our AI Products is handled in line with our Privacy Notice and our agreements with third parties.
How to Opt Out
To opt out, you can:
Log in to your account settings and update your user account
Contact us using the contact information provided
7. HOW DO WE HANDLE YOUR APPLE SIGN-IN?
In Short: If you choose to register or log in to our Services using Apple Sign-In, we may have access to certain information about you.
Our Services offer you the ability to register and log in using Apple Sign-In. Where you choose to do this, we will receive limited profile information from Apple, which may include your name and an email address (which may be a private relay email that forwards to your real address).
We will use the information we receive only for the purposes that are described in this Privacy Notice or that are otherwise made clear to you on the relevant Services. We do not control, and are not responsible for, other uses of your personal information by Apple. We recommend that you review Apple's privacy notice to understand how they collect, use, and share your personal information.
8. IS YOUR INFORMATION TRANSFERRED INTERNATIONALLY?
In Short: We may transfer, store, and process your information in countries other than your own.
Our servers are located in the United States. Regardless of your location, please be aware that your information may be transferred to, stored by, and processed by us in our facilities and in the facilities of the third parties with whom we may share your personal information (see "WHEN AND WITH WHOM DO WE SHARE YOUR INFORMATION?" above), including facilities in the United States and other countries.
If you are a resident in the European Economic Area (EEA), United Kingdom (UK), or Switzerland, then these countries may not necessarily have data protection laws or other similar laws as comprehensive as those in your country. However, we will take all necessary measures to protect your personal information in accordance with this Privacy Notice and applicable law, including through Standard Contractual Clauses with our third-party providers where required.
9. HOW LONG DO WE KEEP YOUR INFORMATION?
In Short: We keep your information for as long as necessary to fulfill the purposes outlined in this Privacy Notice unless otherwise required by law.
We will only keep your personal information for as long as it is necessary for the purposes set out in this Privacy Notice, unless a longer retention period is required or permitted by law. No purpose in this notice will require us keeping your personal information for longer than the period of time in which users have an account with us.
When we have no ongoing legitimate business need to process your personal information, we will either delete or anonymize such information.
For users who have deleted their account, we will delete or irreversibly anonymize personal data within 30 days, except where retention is required by law (for example, accounting, fraud prevention, or backup copies).
10. HOW DO WE KEEP YOUR INFORMATION SAFE?
In Short: We aim to protect your personal information through a system of organizational and technical security measures.
We have implemented appropriate and reasonable technical and organizational security measures designed to protect the security of any personal information we process. These measures include encryption in transit, encryption at rest, access controls, and periodic security reviews. However, despite our safeguards and efforts to secure your information, no electronic transmission over the Internet or information storage technology can be guaranteed to be 100% secure.
In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the applicable supervisory authority as required by law.
11. DO WE COLLECT INFORMATION FROM MINORS?
In Short: We do not knowingly collect data from or market to children under 13 years of age.
We do not knowingly collect, solicit data from, or market to children under 13 years of age, nor do we knowingly sell such personal information. Users between 13 and 17 years of age must have parental or guardian consent to use the Services where required by applicable law (including GDPR in the EU/UK, which generally requires parental consent for users under 16, and PIPEDA in Canada). By using the Services, you represent that you are at least 13 years old (or the minimum age in your jurisdiction), and if you are between 13 and 17, that you have the consent of your parent or guardian to use the Services. If we learn that personal information from children under 13 years of age has been collected, we will deactivate the account and take reasonable measures to promptly delete such data from our records. If you become aware of any data we may have collected from children under age 13, please contact us at info@oculimedical.com.
12. WHAT ARE YOUR PRIVACY RIGHTS?
In Short: Depending on your state of residence in the US, or in some regions such as the EEA, UK, Switzerland, and Canada, you have rights that allow you greater access to and control over your personal information.
In some regions (like the EEA, UK, Switzerland, and Canada), you have certain rights under applicable data protection laws. These may include the right (i) to request access and obtain a copy of your personal information, (ii) to request rectification or erasure; (iii) to restrict the processing of your personal information; (iv) if applicable, to data portability; and (v) not to be subject to automated decision-making.
If you are located in the EEA or UK and you believe we are unlawfully processing your personal information, you also have the right to complain to your Member State data protection authority or UK data protection authority.
Withdrawing your consent: You have the right to withdraw your consent at any time by contacting us using the contact details provided in Section 20.
Account Information
If you would at any time like to review or change the information in your account or terminate your account, you can:
Log in to your account settings and update your user account.
Contact us using the contact information provided.
Upon your request to terminate your account, we will deactivate or delete your account and information from our active databases.
You can request deletion of your Kim account and associated personal data by contacting info@oculimedical.com or through the in-app account deletion option. After deletion, we will delete or anonymize your personal data unless retention is required by law, security, fraud prevention, or legitimate backup or archive obligations. Deletion of HealthKit data on your device is governed by your device settings; revoking HealthKit access in your device Settings prevents Kim from accessing future HealthKit data.
If you have questions or comments about your privacy rights, you may email us at info@oculimedical.com.
13. CONTROLS FOR DO-NOT-TRACK FEATURES
Most web browsers include a Do-Not-Track ("DNT") feature you can activate to signal your privacy preference not to have data about your online browsing activities monitored and collected. At this stage, no uniform technology standard for recognizing and implementing DNT signals has been finalized. As such, we do not currently respond to DNT browser signals.
14. DO UNITED STATES RESIDENTS HAVE SPECIFIC PRIVACY RIGHTS?
In Short: If you are a resident of a US state with applicable privacy laws, you may have the right to request access to your personal information, correct inaccuracies, get a copy of, or delete your personal information.
Categories of Personal Information We Collect
The table below shows the categories of personal information we have collected in the past twelve (12) months.
Category | Examples | Collected |
|---|---|---|
A. Identifiers | Real name, email address, IP address, account name, unique personal identifier | YES |
B. Protected classification characteristics | Gender, age, date of birth, demographic data | NO |
C. Commercial information | Transaction information, purchase history, payment information | NO |
D. Biometric information | Fingerprints and voiceprints | NO |
E. Internet or other similar network activity | Basic device, log, usage, and diagnostic information | YES |
F. Geolocation data | Device location | NO |
G. Audio, electronic, sensory, or similar information | Photos and voice recordings created in connection with our Services | YES |
H. Professional or employment-related information | Job title, work history, professional qualifications | NO |
I. Education Information | Student records and directory information | NO |
J. Inferences drawn from collected personal information | Wellness insights, profile or summary about preferences and characteristics | YES |
K. Sensitive personal information | Health data | YES |
We have not sold or shared any personal information to third parties for a business or commercial purpose in the preceding twelve (12) months. We have disclosed the following categories of personal information to third parties for a business or commercial purpose: Category A (Identifiers), Category E (Internet Activity), Category G (Sensory Data), Category J (Inferences), and Category K (Sensitive Personal Information).
Your Rights
You have rights under certain US state data protection laws, including:
Right to know whether or not we are processing your personal data
Right to access your personal data
Right to correct inaccuracies in your personal data
Right to request the deletion of your personal data
Right to obtain a copy of the personal data you previously shared with us
Right to non-discrimination for exercising your rights
Right to opt out of the processing of your personal data if it is used for targeted advertising, the sale of personal data, or profiling
How to Exercise Your Rights
To exercise these rights, you can contact us by emailing us at info@oculimedical.com, or by referring to the contact details at the bottom of this document.
15. DO OTHER REGIONS HAVE SPECIFIC PRIVACY RIGHTS?
In Short: You may have additional rights based on the country you reside in.
Australia and New Zealand
We collect and process your personal information under the obligations and conditions set by Australia's Privacy Act 1988 and New Zealand's Privacy Act 2020.
At any time, you have the right to request access to or correction of your personal information by contacting us using the contact details provided in Section 20.
If you believe we are unlawfully processing your personal information, you have the right to submit a complaint to the Office of the Australian Information Commissioner or the Office of the New Zealand Privacy Commissioner.
Republic of South Africa
At any time, you have the right to request access to or correction of your personal information by contacting us using the contact details provided in Section 20.
If you are unsatisfied with the manner in which we address any complaint, you can contact The Information Regulator (South Africa).
16. HEALTH INFORMATION DISCLAIMER
Kim is not a medical device and does not provide medical diagnoses, treatment recommendations, or professional medical advice. The wellness insights, suggestions, and any informational trend estimates provided through Kim are generated using artificial intelligence, including services provided by Anthropic and Inworld, and are for informational purposes only. Forecasts are illustrative projections based on patterns in your current data and should not be interpreted as medical predictions, prognoses, or guarantees of future outcomes. These insights and forecasts should not be used as a substitute for professional medical advice, diagnosis, or treatment. Always consult a qualified healthcare provider with any questions regarding a medical condition. Kim does not claim to detect, diagnose, treat, cure, or prevent any disease or health condition.
17. APPLE HEALTHKIT DATA
Kim integrates with Apple HealthKit to read and display health and fitness data from your device, only with your explicit permission. The specific HealthKit data types Kim may request access to include: step count, workouts, active energy, resting energy, heart rate, resting heart rate, heart rate variability, sleep analysis, respiratory rate, blood oxygen, weight, body temperature, mindful minutes, nutrition data, and any additional HealthKit data types clearly shown to you in the Apple Health permission screen before you grant access. This data may originate from Apple Watch or third-party apps and devices (such as Oura, Whoop, Garmin, or Fitbit) that write data into Apple Health on your device. Data obtained through Apple HealthKit APIs is used solely to provide personalized wellness insights within the Kim app. We do not use HealthKit data for advertising, marketing, or data mining purposes. HealthKit data is not sold to or shared with third parties for advertising, marketing, or data brokerage purposes. We do not store HealthKit data in iCloud. HealthKit data may be processed by our AI service providers, including Anthropic, strictly for the purpose of generating personalized wellness insights for you. You may revoke HealthKit access at any time through your device Settings under Health > Data Access & Devices. Revoking access will not delete previously processed insights stored in your Kim account.
18. THIRD-PARTY AI DATA PROCESSING
Kim uses third-party artificial intelligence services to process your personal and health information in order to provide personalized wellness insights and suggestions. These services include Anthropic (Claude) for conversational AI, wellness analysis, and food photo analysis, and Inworld for voice transcription, voice processing, and AI voice features. Your data is transmitted securely to these providers and is processed in accordance with their respective privacy policies. We do not permit these providers to use your personal data for their own purposes beyond providing services to Kim. Data processed by these AI services may be transferred to and stored on servers located in the United States.
Voice recordings captured during your use of voice features are transmitted to Inworld for transcription and processing in real time. Raw voice audio is not retained long-term by Kim; only the resulting text transcript and any AI-generated response are stored in your account history.
When you ask a question that uses web search, Kim may use Anthropic's built-in web search to retrieve publicly available information from the web to provide source-backed wellness context. Web search results are used for informational purposes only and should not be treated as medical advice.
Before any of your health or personal data is transmitted to our AI service providers, you will be presented with a clear in-app consent prompt explaining what data will be shared and for what purpose. The consent prompt will clearly state, in substance: "To generate AI wellness insights, Kim will securely send selected health data, food logs, wellness inputs, and your message to our AI provider, Anthropic. This data is used only to provide the requested insight and not for advertising. You can decline and still use non-AI features." You may decline this consent and still use the non-AI features of the app.
19. DO WE MAKE UPDATES TO THIS NOTICE?
In Short: Yes, we will update this notice as necessary to stay compliant with relevant laws.
We may update this Privacy Notice from time to time. The updated version will be indicated by an updated "Last updated" date at the top of this Privacy Notice. If we make material changes to this Privacy Notice, we may notify you either by prominently posting a notice of such changes or by directly sending you a notification. We encourage you to review this Privacy Notice frequently to be informed of how we are protecting your information.
20. HOW CAN YOU CONTACT US?
If you have questions or comments about this notice, you may contact us by post at:
Oculi Medical Corp.
2201, 3008 Glen Drive
Coquitlam, British Columbia V3B 0J5
Canada
Email: info@oculimedical.com
21. HOW CAN YOU REVIEW, UPDATE, OR DELETE THE DATA WE COLLECT FROM YOU?
Based on the applicable laws of your country or state of residence in the US, you may have the right to request access to the personal information we collect from you, details about how we have processed it, correct inaccuracies, or delete your personal information. You may also have the right to withdraw your consent to our processing of your personal information. These rights may be limited in some circumstances by applicable law. To request to review, update, or delete your personal information, please contact us at info@oculimedical.com.