Avokay info@kerotech.net

Privacy Policy

Effective date: September 9, 2026 · Operator: Kerotech Ltd., a Colorado limited liability company · Contact: info@kerotech.net

Avokay (the "Service") provides each user a private workspace for storing their own medical records, with an AI assistant that answers questions about them. This policy describes what we collect, how we use it, and the choices you have.

1. Information we collect

We collect no advertising identifiers, run no third-party analytics or advertising trackers, and do not collect information about your activity on other sites.

The public website. The pages at kerotech.net that describe Avokay, this policy included, use Cloudflare Web Analytics to count visits. It sets no cookies, stores nothing in your browser, does not fingerprint you, and does not follow you to other sites; we see only aggregate page views, referring sites, countries, device types and page-load timing. The Service itself runs no analytics.

2. How we use it

To provide, maintain, secure, and troubleshoot the Service for you; to review how the Service is working in real use, so that we can improve, test, and develop it; and to communicate with you about it — and for no other purpose, except a specific additional use you have separately authorized in writing. We do not sell your personal information, do not share it for advertising, and do not allow it to be used to train AI models.

What "improve the Service" means here — stated plainly, because it is broader than you may expect. Kerotech's operator can read Your Data — your conversations with the assistant, the assistant's answers, and the notes and pages the assistant writes into your workspace — in order to decide what to build and what to fix. This does not require you to report a problem first, and we do not ask you each time. Your signed Terms of Service (§ 3.3) and the authorization you sign with it grant that access and set its limits, and those limits bind us: we will not publish, quote, or show your data to anyone; we will not copy it into test material, sample data, documentation, or our issue tracker; we will not disclose it outside Kerotech beyond the providers named in Section 3; we will not sell it; and we will not allow it to train AI models. For California residents, it is handled under the CMIA throughout (Section 6).

A separate, optional programme — the Experimental Program. Participants who sign a separate Experimental Program Addendum, together with a separate written authorization for the disclosure of medical information, have the text of the questions they ask the assistant recorded and converted into generalized question types (a label from a fixed list, plus a one-sentence description of at most fifteen words), which Kerotech uses to decide what to improve and test. This is off for every account unless that paperwork is signed, it can be ended at any time without ending the Service, and the addendum is the complete description of what is recorded. If you have not signed one, nothing about your questions is recorded in that log.

3. Who we share it with

We share personal information only with the service providers needed to run the Service, each limited to its function:

Provider Function
Anthropic, PBC AI processing. AI request inputs/outputs are not used to train models and are deleted from Anthropic's systems within 30 days in the ordinary course (retained up to 2 years if flagged by Anthropic's automated trust-and-safety systems, or longer where law requires). Whether these requests are additionally covered by a Business Associate Agreement depends on the Anthropic organization serving your workspace; your signed Terms of Service states which applies to you, and Kerotech will notify you in writing when your posture strengthens.
DigitalOcean, LLC Cloud hosting (United States).
Cloudflare, Inc. Encrypted off-site backups (encrypted before upload; the provider holds only ciphertext), and cookieless visit counts for the public website only (Section 1).
Payment processor None today — the Service currently has no paid plans. A payment processor will be named here, with notice, before any billing exists.

Beyond these providers, we disclose personal information only with your authorization or where required by law. California residents' medical information is handled under the Confidentiality of Medical Information Act (CMIA) and the written authorization executed at sign-up. Third parties do not collect personal information through the Service.

4. Retention and deletion

Your Data stays in your workspace until you delete it or close your account. On request, we delete your workspace from live systems within 30 days and confirm in writing; encrypted backup copies expire on a rolling schedule no later than 12 months after live deletion. You may export Your Data in portable formats at no charge at any time before deletion.

5. Security and breach notice

We protect personal information with encryption in transit, access controls, and encrypted backups. No system is perfectly secure. If a security breach affects your unsecured personal information, we will notify you without unreasonable delay — and no later than 60 calendar days after discovery — and will notify regulators as applicable law requires.

6. Your choices and rights

7. Do Not Track

The Service does not track users over time or across third-party sites, so it does not respond differently to browser "Do Not Track" signals — there is no tracking to disable.

8. Children

The Service is for adults 18 and older; we do not knowingly collect information from children.

9. Changes to this policy

If we make material changes, we will notify account holders by email at least 30 days before the change takes effect and update the effective date above.