Skip to main content
Back to Learn
How We Keep Your Medical Conversations Private
Marcus Webb

How We Keep Your Medical Conversations Private

Medical information is among the most sensitive data people generate. A recording of a doctor's appointment can contain a diagnosis, a medication list, a frank conversation about symptoms you have not told anyone else about, and details about your family history. We understand that asking someone to record that conversation requires real trust, and we take the responsibility seriously.

This article explains in plain language what happens to your recordings and summaries, how they are stored, who can access them, and what controls you have over your own data. We are not going to bury the answer in legal language. You deserve to know exactly how this works.

How the recording travels from your phone to your summary

When you start a recording in Kin, the audio is captured on your device. When your appointment ends and you close the recording, it is transmitted to our processing pipeline over an encrypted connection. The encryption in transit uses current industry-standard protocols, which means the data cannot be read by a third party during transmission.

Once the recording arrives in our processing environment, it is processed to generate your visit summary. The audio goes through speech processing and natural language analysis to extract the clinically relevant content described elsewhere in these guides. After the summary is generated and delivered to your account, the raw audio recording is deleted from our processing environment. We keep the structured summary. We do not keep the raw recording.

The summary is stored in your account in an encrypted database. Your account is protected by your password and any two-factor authentication you choose to enable. Our team does not have routine access to your individual summaries. Access to health data is restricted by role and logged, so any time someone on the Kin team accesses records, that access is recorded.

What HIPAA alignment means for you

Kin is designed with HIPAA-aligned controls, which means we apply the technical, administrative, and physical safeguards that the HIPAA Security Rule describes for covered entities and their business associates. We want to be precise about what this means and what it does not mean.

HIPAA as a legal framework applies specifically to covered entities: healthcare providers, health plans, and healthcare clearinghouses, along with the business associates who work directly with those entities. Kin is a consumer-facing application that patients use to record their own appointments. In most scenarios, you are recording your own conversation as a participant, which is a different legal situation than a covered entity handling protected health information under the HIPAA framework.

We use HIPAA-aligned controls because we think they represent an appropriate standard for health data, not because we are making a claim to full HIPAA certification as a covered entity. If you have specific compliance questions related to your situation, your own legal counsel can help you understand what applies.

What this practically means for you: your data is handled with controls designed for sensitive health information, not with the weaker protections of a general consumer app that happens to touch health topics.

Who can see your summaries

Your summaries are yours. Only you can see them in your account by default. If you are on a Family plan and you have granted access to a caregiver or family member, that person can see the summaries for the specific family members whose records they have been given access to. You control who has access and can revoke that access at any time from your account settings.

We do not sell your data to third parties. We do not share your health information with insurers, employers, or marketers. If you are ever uncertain about whether data was shared with a specific party, you can request a data access log from us at [email protected] and we will provide it.

There are two scenarios where we would share data without your direct consent: a valid legal requirement, such as a court order or subpoena, and a situation where disclosure is necessary to prevent serious harm. These are narrow circumstances and we will tell you about any disclosure that we are legally permitted to disclose to you.

Your control over your data

You can delete your account and all associated data at any time from your account settings. When you request deletion, your summaries, recording history, and account information are deleted from our active systems. There may be a short period during which backups that contain your data are rotated out according to our standard backup schedule, which is described in our Privacy Policy.

You can also export your data before deleting. If you want a copy of your appointment history to share with a provider or keep in your own records, you can download all your summaries in PDF or text format from your account.

Consent and recording laws

Recording laws vary by state and country. In some places, all parties to a conversation must consent to being recorded. In others, only one party (typically the person making the recording) is required to consent. In the United States, federal law requires one-party consent for recordings, but several states require two-party or all-party consent.

We recommend informing your doctor or care provider that you are recording the appointment. Most providers are comfortable with it when asked, particularly when you explain that the recording is for your own recall. If a provider declines, please respect that decision. Recording someone without their knowledge or consent, in states where consent is required, creates legal exposure and is not something we encourage.

The habit of disclosing that you are recording at the start of an appointment is good practice regardless of legal requirements. It puts the conversation on a clear footing and tends to produce a more relaxed, open discussion than a recording made without disclosure.

An honest note about the limits of any system

No security system is perfect, and we will not tell you otherwise. What we can tell you is that we have designed Kin with privacy as a foundational constraint, not an afterthought. We chose to delete raw recordings rather than store them, even though storing them would make certain product features easier to build. We chose encryption at rest and in transit from the beginning. We built access controls before we had the scale that would make them feel urgent.

If you ever have concerns about how your data is being handled, or if you notice anything that does not look right in your account, please contact us at [email protected]. We will respond directly and tell you what we find.

Your health conversations are yours. Try Kin Health free and see how we protect your data from the start.