Kip Privacy Policy

Last updated: August 27, 2026

Kip is a private assistant for your household. This policy explains what Kip stores, where it lives, and what never leaves your family's instance.

Your family gets its own instance

Each household runs on its own isolated instance with its own database. Your family's data is never mixed with another family's, and no family can see another family's information. Joining Kip requires an invite code issued for your household.

What Kip stores

AI processing

Kip is powered by large language models. To answer you, relevant parts of your conversation and context are sent to our AI providers (OpenAI and Anthropic) for processing under their API terms, which do not permit them to train on this data. Apple Health data stays summarized on your instance and is used only to render your private views.

What Kip never does

Storage and security

Your instance runs on servers we operate (currently hosted with DigitalOcean). All traffic between the app and your instance is encrypted with HTTPS. Access requires a per-person login token; invite codes are single-use or capped and expire.

For troubleshooting, the operator of the service can access a read-only support view of an instance to diagnose reported problems. Support access can't change your data, and we only use it when you ask us for help.

Deleting your data

Ask us to delete your household's instance and we will remove it, including databases and backups, within 30 days. Individual items (memories, reminders, conversations) can be deleted in the app or by asking Kip.

Children

Kip accounts are for adults in a household. Facts about children may be stored by their parents, under the parents' control, and are removed with the household's data on request.

Contact

Questions or deletion requests: [email protected]

Kip is in private beta. This policy will be updated as the product evolves; material changes will be announced in the app.