Trust
Privacy policy
Last updated September 24, 2026
Kairos (“we”) is a perioperative operations and value platform in beta, operated by its founding team. This policy explains what we collect, why, who else touches it, and what you can do about it.
No patient information in the demonstration
- Every patient, surgeon, facility and organization in the demonstration is synthetic: generated from a fixed seed, with obviously fictional names, and marked as synthetic in the database. Nothing is derived from a real record.
- Do not enter real patient information into the demonstration. If you do by mistake, tell us and we will delete it.
- Before any hospital uses Kairos with real patient data, the hospital (a HIPAA covered entity) and Kairos (its business associate) sign a business associate agreement and a data-use agreement. Those agreements, not this page, govern patient data.
What we collect from users
- Account: name, work email, role, organization and facility, and a password hash (never the password itself).
- Security records: each sign-in attempt with its time, outcome and network address; session start, activity and end.
- Audit records: the actions you take in the product (for example, validating a savings line), as HIPAA audit controls require.
- Cookies: three strictly necessary cookies —
kairos_session(the session, httpOnly),kairos_idle(your idle-timeout setting) andkairos_facility(the facility you selected). No advertising or third-party tracking cookies.
How we use it
- To run the product: sign you in, show the facility you work in, and record who did what.
- To keep it secure: detect repeated failed sign-ins, lock accounts, and investigate incidents.
- We do not sell or share personal information, do not advertise, and do not use your data to train AI models.
AI use
When you ask the copilot a question or open a brief, Kairos sends your question and de-identified aggregates — counts, rates, durations, age bands, never names or record numbers — to an AI model provider. A guard blocks anything that looks like an identifier before the call leaves the platform. The answer and the tool calls that produced it are stored so you, and a reviewer, can see how it was reached. AI outputs are estimates you check; nothing is applied automatically. The provider may not use this data to train models.
Retention
- Account records are kept while the account is active and deleted or anonymised after it is closed, except as below.
- Audit, PHI-access and sign-in logs are kept for at least six years, the HIPAA documentation-retention period.
- The synthetic demonstration dataset may be regenerated or reset at any time.
- In a pilot, retention of hospital data follows the hospital's agreement and its state requirements; disposal is by key destruction.
California privacy rights
If you are a California resident, the California Consumer Privacy Act (as amended by the CPRA) gives you the right to know what personal information we hold about you, to correct it, to delete it, and to opt out of its sale or sharing (we do neither), and not to be discriminated against for using these rights. Medical information from a hospital is governed separately by the California Confidentiality of Medical Information Act and HIPAA, through that hospital.
Send any request to the founding team. We confirm receipt within 10 business days and respond within 45 days. We will verify your identity before acting on a request.
Security, changes and contact
How data is protected, and the categories of providers that process it, are on the security page. We will post changes here with a new date and tell account holders about material changes by email. Questions: the founding team.