Legal

Terms & Conditions

Effective Date: June 12, 2026  ·  Last Updated: June 12, 2026

1. Acceptance of Terms

By downloading, installing, or using the KinPass mobile application or any associated services (collectively, the "Service"), you agree to be bound by these Terms and Conditions ("Terms"). If you do not agree to these Terms, do not use the Service.

These Terms constitute a legally binding agreement between you and KinPass ("we," "us," or "our"). Your continued use of the Service after any modification to these Terms constitutes your acceptance of the revised Terms.

You must be at least 18 years of age to create an account and use KinPass. By using the Service, you represent and warrant that you are 18 years of age or older.


2. About KinPass

KinPass is a mobile care coordination application designed to help families and authorized caregivers securely share critical care information about dependents — including children, individuals with special needs, and elderly family members.

The Service provides tools to create and manage care profiles containing information such as:

  • Medications, dosages, and schedules
  • Allergies and adverse reactions
  • Medical conditions and health history
  • Daily routines, behavioral notes, and care instructions
  • Emergency contacts and protocols
  • Activity logs and caregiver handoff notes
  • Secure messaging between household members and caregivers

KinPass is not a healthcare provider, medical practice, or clinical service. The Service is a communication and coordination tool only.


3. Accounts and Households

Account Creation

To use KinPass, you must create an account using a valid email address and password. You are responsible for maintaining the confidentiality of your account credentials and for all activity that occurs under your account.

Households

When you register, KinPass automatically creates a Household — the primary container for your care profiles, caregivers, and subscription. You are the Household owner and have full administrative control over all data, users, and settings within your Household.

Accuracy of Information

You agree to provide accurate, current, and complete information when creating your account and care profiles. Inaccurate care information — particularly regarding medications, allergies, and emergency contacts — may create risk. You are solely responsible for the accuracy of information you enter into KinPass.


4. Caregiver Access and Permissions

Inviting Caregivers

As a Household owner, you may invite caregivers to access your care profiles by email. Each caregiver is assigned one of three permission roles at the time of invitation:

  • View — read-only access to care profile information
  • Log — ability to view profiles and add activity log entries
  • Full — ability to view, log, and edit care profile information

Your Responsibility for Caregiver Access

You are solely responsible for who you invite to your Household and what permissions you grant. KinPass does not verify the identity, credentials, or suitability of individuals you invite as caregivers. You must only invite people you trust with access to sensitive care information.

Revoking Access

You may revoke caregiver access at any time through your Household settings. Upon revocation, the caregiver will no longer be able to access your care profiles. It is your responsibility to manage caregiver access promptly when circumstances change.

Important

KinPass is not responsible for any actions taken by individuals you have authorized as caregivers within your Household. Access control is entirely in your hands as the Household owner.


5. Your Data and Care Profiles

Ownership

You own the data you enter into KinPass. We do not claim any ownership rights over the content of your care profiles, activity logs, or messages.

License to Operate the Service

By using KinPass, you grant us a limited, non-exclusive license to store, process, and transmit your data solely for the purpose of providing the Service to you and the caregivers you authorize. We do not use your data for advertising, sell your data to third parties, or share it with any party other than those you explicitly authorize.

Data Storage

Your data is stored on servers located in the United States using Google Firebase (Firestore and Firebase Storage), which are operated by Google LLC. Data is transmitted over encrypted connections (TLS) and stored at rest with encryption provided by Google Cloud infrastructure.

Data Retention

Your data is retained for as long as your account remains active. Activity logs are intentionally immutable — they cannot be deleted — to preserve an accurate record of care activity for safety purposes. Other profile data can be edited or removed by you at any time within the app.


6. MyChart and Health Record Integration

Premium Feature

MyChart integration is available on Premium and Family subscription plans only. Free accounts do not have access to health record sync.

How the Integration Works

KinPass offers an optional integration with Epic MyChart, allowing you to import health record data — including active medications, allergies, conditions, and immunizations — directly into your care profiles. This integration is built on the SMART on FHIR standard (HL7 FHIR R4), an open healthcare interoperability protocol used by major health systems and platforms including Apple Health.

The connection uses OAuth 2.0 with PKCE (Proof Key for Code Exchange), a security standard designed for mobile applications. You will be redirected to your MyChart login to authenticate directly with your health provider. KinPass never sees or stores your MyChart username or password.

What Data Is Imported

When you initiate a MyChart sync, KinPass retrieves the following data from your health provider's Epic system:

  • Active medication orders (name, dose, instructions)
  • Allergy and intolerance records (substance, severity, reaction)
  • Active medical conditions and diagnoses
  • Immunization records

Before any data is written to your care profile, you will be presented with a review screen showing exactly what was found. You must explicitly confirm which items to import. Nothing is written to your profile without your direct approval.

How We Handle Health Record Data

Data Handling Commitment

Raw FHIR data from your health provider is never stored by KinPass. It exists in memory only during your active session and is discarded immediately after you confirm your import selections.

Only the specific fields that map to existing KinPass care profile fields are retained — for example, a medication name and dose. All other data returned by the health system is discarded. Imported fields are tagged with a syncedAt timestamp so you and your caregivers know when the information was last pulled from your health record.

Access Tokens

The access token issued by Epic during the MyChart authorization flow is used only to fetch your health data during that session. It is never stored to disk, never written to our database, and is not accessible after your session ends. To sync again in the future, you will be asked to authenticate with MyChart again.

Data Accuracy and Responsibility

Data imported from MyChart reflects what is recorded in your health provider's system at the time of the sync. KinPass does not verify, validate, or supplement this data. Your health provider's records may not always be current or complete. You are responsible for reviewing imported data for accuracy before relying on it for care decisions.

Subscription Lapse and Imported Data

If your subscription lapses or you downgrade to a free account, previously imported MyChart data remains in your care profile and is fully editable by hand. However, the ability to re-sync or pull updated information from MyChart requires an active Premium or Family subscription. Data imported during a paid subscription period is never deleted upon downgrade.

HIPAA Notice

KinPass is not a HIPAA-covered entity and does not currently operate under a Business Associate Agreement (BAA) with Epic Systems or any health provider. The MyChart integration is a patient-initiated data access feature under the 21st Century Cures Act and FHIR interoperability regulations, which permit patients to share their own health data with third-party applications of their choosing. By connecting your MyChart account, you are exercising your right as a patient to access and share your own health information. You accept responsibility for how that information is used within KinPass.

We state explicitly: data pulled from MyChart is imported into KinPass at your direction and is not independently stored or managed by KinPass as a healthcare record.


7. Data Security

We take the security of your information seriously, particularly given the sensitive nature of care and health data. Our security practices include:

  • Encryption in transit: All data transmitted between the KinPass app and our servers uses TLS (Transport Layer Security).
  • Encryption at rest: Data stored in Firebase Firestore and Firebase Storage is encrypted at rest by Google Cloud infrastructure.
  • Role-based access control: Firestore security rules enforce household-scoped access. Caregivers can only access the profiles and data their role permits. No user can access another household's data.
  • Authentication: User authentication is handled by Firebase Authentication. Passwords are never stored in plain text.
  • No raw FHIR storage: Health record data fetched via MyChart integration is never written to our database in raw form.
  • Immutable activity logs: Care activity logs cannot be modified or deleted after creation, preserving an accurate audit trail.

No method of electronic transmission or storage is 100% secure. While we use commercially reasonable means to protect your data, we cannot guarantee absolute security. In the event of a data breach that affects your information, we will notify you as required by applicable law.


8. Subscriptions and Billing

Subscription Tiers

KinPass offers the following subscription plans:

  • Free — 1 care profile, 1 caregiver, 7 days of log history, basic features
  • Premium ($4.99/month) — unlimited care profiles, up to 5 caregivers, unlimited log history, CSV export, MyChart sync, document storage (1 GB)
  • Family ($7.99/month) — everything in Premium, unlimited caregivers, document storage (5 GB), AI care assistant

Billing

Subscriptions are billed on a monthly basis through the Apple App Store or Google Play Store, depending on your platform. All billing, refunds, and subscription management are handled by the respective platform. KinPass does not directly process payment card information.

Cancellation

You may cancel your subscription at any time through your device's subscription management settings. Cancellation takes effect at the end of the current billing period. You will retain access to paid features until that date. Upon cancellation, your account reverts to the Free tier. Your data is not deleted upon cancellation.

Price Changes

We reserve the right to modify subscription pricing with reasonable advance notice. Continued use of the Service after a price change constitutes acceptance of the new pricing.


9. Prohibited Use

You agree not to use KinPass to:

  • Enter false, misleading, or fabricated care information that could endanger the health or safety of a dependent
  • Invite caregivers without the knowledge or consent of the person being cared for where applicable
  • Share account credentials with unauthorized individuals
  • Attempt to access another user's household or data without authorization
  • Use the Service for any commercial purpose other than as permitted by your subscription
  • Reverse engineer, decompile, or attempt to extract source code from the application
  • Violate any applicable local, state, national, or international law or regulation
  • Use the Service in any manner that could damage, disable, or impair our infrastructure

10. Medical Disclaimer

Not Medical Advice

KinPass is a care coordination and communication tool. It is not a medical device, clinical decision support system, or substitute for professional medical advice, diagnosis, or treatment.

Nothing in KinPass — including care profile data, activity logs, imported health record information, or any AI-generated summaries — constitutes medical advice. Always consult a qualified healthcare professional regarding medical conditions, medications, allergies, or treatment decisions.

In an emergency, call 911 or your local emergency number immediately. Do not rely solely on information in KinPass during a medical emergency.

Medication and allergy information stored in KinPass, whether entered manually or imported from MyChart, may not reflect the most current state of a person's health. It is your responsibility to keep care profiles up to date and to communicate critical medical information directly to caregivers and healthcare providers.


11. Account Termination and Data Deletion

Termination by You

You may request deletion of your account and associated data at any time by contacting us. Upon receiving a verified deletion request, we will remove your personal information and care profile data from our active systems within 30 days, subject to any legal obligations to retain certain records.

Note that activity logs are immutable by design and may be retained in anonymized or aggregate form for internal safety and audit purposes even after account deletion.

Termination by KinPass

We reserve the right to suspend or terminate your account if you violate these Terms, engage in fraudulent activity, or use the Service in a manner that creates risk or harm to others. In such cases, we will provide notice where reasonably practicable.

Effect of Termination

Upon termination, your right to access the Service ceases immediately. Caregiver access linked to your Household is also revoked. Subscription fees paid prior to termination are non-refundable except where required by applicable law.


12. Limitation of Liability

To the maximum extent permitted by applicable law, KinPass and its officers, directors, employees, and agents shall not be liable for any indirect, incidental, special, consequential, or punitive damages — including but not limited to loss of data, personal injury, or harm resulting from reliance on information stored in or transmitted through the Service.

Our total liability to you for any claim arising out of or relating to these Terms or the Service shall not exceed the greater of (a) the amount you paid us in the three months prior to the event giving rise to the claim, or (b) $50 USD.

Some jurisdictions do not allow the exclusion of certain warranties or limitation of liability. In those jurisdictions, our liability is limited to the greatest extent permitted by law.

The Service is provided "as is" and "as available" without warranties of any kind, express or implied, including but not limited to warranties of merchantability, fitness for a particular purpose, or non-infringement.


13. Changes to These Terms

We may update these Terms from time to time. When we make material changes, we will update the "Last Updated" date at the top of this page and, where appropriate, notify you via email or in-app notification.

Your continued use of the Service after the effective date of any revised Terms constitutes your acceptance of the changes. If you do not agree to the revised Terms, you must stop using the Service.

We encourage you to review these Terms periodically. The current version will always be available at kinpass.io/terms.


14. Contact Us

If you have questions about these Terms, your data, or the MyChart integration, please contact us:

KinPass
Email: Click to reveal email

We aim to respond to all inquiries within 2 business days.