KuraPath
know your health
Privacy Policy.
KuraPath is committed to protecting your privacy and handling your personal and health information responsibly, in accordance with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
Transparency
We are clear about what data we collect, why we collect it, and how it is used. AI-generated health insights are clearly labelled as educational only.
Data Minimisation
We collect only the data necessary to provide our services. We do not build shadow profiles, purchase third-party data, or track you across the web.
Your Control
You own your data. You can access, correct, or delete it at any time. We will never sell your personal or health information to third parties.
1. Who We Are
KuraPath Pty Ltd (ACN pending) ("KuraPath", "we", "us", or "our") operates the KuraPath platform, including our website, mobile applications, APIs, and related services. KuraPath is a health education and information platform. We do not provide medical advice, diagnosis, or treatment.
For all privacy-related inquiries, you may contact our Privacy Officer at privacy@kurapath.com or support@kurapath.com.
2. Information We Collect
We collect the following categories of personal information:
| Category | Examples | Purpose |
|---|---|---|
| Identity information | Name, email address, date of birth, gender | Account creation, authentication, personalisation |
| Health information * | Pathology results, laboratory reports, biometric data, on-device sensor measurements (heart rate, SpO2, focus, balance, etc.), wearable data | AI-powered health education, journey tracking, longevity insights |
| Location data | City/suburb (user-provided or browser geolocation with consent) | Biosphere environmental intelligence (AQI, UV, pollen, disease surveillance) |
| Usage data | Pages visited, features used, journey progress, device type | Platform improvement, analytics, error monitoring |
| Communication data | Support requests, feedback submissions | Customer support, service improvement |
| Conversation data | Kura Guide chat history, KuraBridge translation session transcripts, voice transcripts, AI interaction logs | Persistent AI companion context, personalised health education continuity |
| Hotline Call Translation Audio | Transient live call audio streams (1800MEDICARE/healthdirect translation sessions) | Processed strictly transiently in-memory for real-time translation. Zero audio recording is stored, zero voice data is retained on external servers, and zero call streams are used for AI training. Downloadable transcripts are generated locally on device. |
| Simulation data | Simulation inputs, hypothetical scenarios, risk levels, delta calculations, confidence scores, and model audit records | Biosphere "what if" simulations and counterfactual analysis |
* Health information is classified as "Sensitive Information" under the Privacy Act 1988 (Cth) and is collected only with your explicit, informed consent.
3. How We Use Your Information
We use your personal information for the following purposes:
- To provide, maintain, and improve the Platform and its features;
- To generate AI-powered health education insights from your uploaded data;
- To provide Biosphere environmental intelligence based on your location;
- To provide Kura Guide persistent AI companion services, including storing conversation history for continuity;
- To track your health journey progress and longevity metrics;
- To communicate with you about your account, support requests, and service updates;
- To detect, prevent, and address technical issues, fraud, or security incidents;
- To comply with legal obligations, including the Privacy Act 1988 and Australian Privacy Principles;
- To generate de-identified, aggregated analytics to improve our AI models and service quality (your identity is never included in aggregated datasets);
- To query cached satellite data using your location coordinates to generate environmental health metrics for Biosphere features. Satellite lookups are performed against data cached on KuraPath infrastructure (VentraIP R2) — no user data is sent to Google or any third-party satellite data provider;
- On-device audio processing via Perch 2.0 (noise health classification) runs entirely in your browser and does not transmit audio recordings to any server;
- No personally identifiable information (PII) is transmitted to satellite data providers. All satellite data queries are resolved against self-hosted cached datasets.
We use your data only to help you understand your health better and to keep the platform running. We never sell your data, and we never will.
4. AI and Machine Learning
KuraPath uses AI models to process your health data and generate educational insights. We are committed to transparency in how AI is used:
- AI-generated outputs are clearly labelled as educational and are not medical advice;
- Identity separation: Before any data is processed by AI models, personally identifiable information is separated from clinical values;
- No third-party training: Your personal health data is never used to train third-party AI models;
- Evidence anchoring: AI insights are grounded in peer-reviewed clinical research using retrieval-augmented generation (RAG) to ensure explainability;
- Hallucination monitoring: We actively monitor AI outputs for accuracy and maintain logs of potential inaccuracies for continuous improvement.
Privacy Architecture: On-Device vs Cloud
KuraPath uses a hybrid processing architecture designed to give users and enterprise buyers maximum control over where sensitive health data is processed:
- Cloud (default): RAG pipeline (Gemini), Voice AI (Gemini Live API), document ingestion, and embedding generation. De-identified health values only are sent to cloud AI services.
- On-device (optional, for compatible devices): TensorFlow.js biomarker forecasting, MedGemma health classification, Bayesian digital health twin inference, and federated learning local training. When enabled, these features run entirely in the browser and no health data leaves the device.
Note: On-device features are optional and depend on device compatibility (WebGPU/WebGL support, sufficient memory). Cloud-first is the default experience. On-device capabilities provide an additional privacy layer for users and enterprise buyers who require zero-data-transmission options.
Automated Decision-Making Disclosure
In compliance with the Australian Privacy Act 1988 (Cth), as amended by Tranche 1 reforms, we provide the following disclosure about automated decision-making on the Platform:
- What is automated: KuraPath uses artificial intelligence (AI) to process uploaded health documents, generate educational explanations of health results, provide environmental health insights, and personalise health education content. These processes run automatically when you upload data or interact with the platform.
- Logic involved: Our AI system uses retrieval-augmented generation (RAG) grounded in peer-reviewed clinical literature, combined with a five-layer safety pipeline that checks outputs for accuracy, hallucination risk, and scope compliance.
- Nature of outputs: All AI outputs are educational only and are not medical advice, diagnosis, or treatment recommendations. KuraPath is a health education platform, not a Software as a Medical Device (SaMD). AI-generated content is clearly labelled as such.
- No consequential decisions: KuraPath does not make decisions that produce legal effects or similarly significant impacts on individuals. The platform provides information to support your health literacy — all healthcare decisions remain with you and your healthcare provider.
- Human oversight: AI outputs are reviewed for quality by our clinical advisory framework. You can contact us at any time to request a human review of any AI-generated content.
- Your right to opt out:You can use the Privacy Mode toggle to process your health documents entirely on-device, with zero data transmitted to cloud AI services. You can also choose not to upload health documents and use the platform's non-AI features.
Quantum-Safe Encryption & Pseudonymization
KuraPath implements a defence-in-depth encryption architecture designed for long-term protection of health data, including future quantum computing threats:
- AES-256-GCM field-level encryption:Sensitive health fields are individually encrypted at rest using NIST-approved AES-256-GCM (FIPS 197), which is quantum-resistant — Grover's algorithm reduces the effective key size to 128-bit equivalent, still beyond brute force.
- Crypto-agility: All encrypted data is version-tagged to enable future algorithm upgrades (including post-quantum algorithms ML-KEM-768 and ML-DSA-65 per NIST FIPS 203/204) without re-encrypting existing data.
- Pseudonymization: Health data is pseudonymized using HMAC-SHA256 tokenization compliant with GDPR Article 4(5). User identifiers are replaced with cryptographic tokens, and the mapping keys are stored separately from the pseudonymized data with strict access controls.
- AI content signing: AI-generated health education content is digitally signed to verify integrity and prevent tampering. This creates a verifiable chain of trust from AI model to user display.
- IP address hashing: IP addresses are one-way hashed using SHA-256 before storage, ensuring they cannot be reversed to identify individuals.
- Post-quantum cryptography: We have implemented active ML-KEM-768 hybrid key encapsulation and active ML-DSA-65 signatures, protecting all personal health data and verifying AI content authenticity against harvest-now-decrypt-later threats.
5. Disclosure of Information
We may disclose your personal information to:
- Service providers: Trusted third parties who assist us in operating the Platform (e.g. cloud hosting, authentication, email delivery, error monitoring). These providers are contractually bound to protect your data;
- Healthcare providers: Only with your explicit consent, if you choose to share your health profile with a connected provider via KuraBridge;
- Legal authorities: Where required by law, court order, or to protect the safety of individuals;
- Business transfers: In the event of a merger, acquisition, or sale of assets, your data may be transferred, subject to the same privacy protections.
We do not sell, rent, or trade your personal or health information to third parties for their marketing or commercial purposes.
6. Data Security
We implement robust, layered security measures to protect your data, including post-quantum cryptographic controls that exceed standard industry practice:
- Encryption at rest: All data, including health records, AI-generated insights, and personal information, is encrypted using AES-256-GCM, classified by NIST as quantum-resistant. Sensitive health fields receive additional field-level encryption with unique initialisation vectors per field, providing defence-in-depth beyond database-level encryption;
- Encryption in transit:All data transmitted between your device and our servers uses TLS 1.3 with hybrid post-quantum key encapsulation (ML-KEM-768) and active ML-DSA-65 signatures. This protects against both current interception and future "harvest now, decrypt later" attacks by adversaries who may attempt to decrypt intercepted traffic using future quantum computers;
- Post-quantum cryptography (PQC):KuraPath's cryptographic architecture is fully aligned with the NIST Post-Quantum Cryptography standards (FIPS 203 & 204). All network traffic and field-level operations employ hybrid post-quantum key encapsulation (ML-KEM-768) and active ML-DSA-65 digital signatures, combining classical and quantum-resistant algorithms for absolute, long-term privacy protection;
- Access control: Row Level Security (RLS) at the database level ensures your data is architecturally isolated from all other users. Cross-tenancy access is structurally impossible;
- Authentication: Industry-leading identity protection via Clerk, supporting multi-factor authentication (MFA), biometric passkeys, and WebAuthn for secure account access;
- Monitoring: Continuous security monitoring, error tracking, and anomaly detection across all authentication and data access events;
- Incident response: Documented incident response procedures aligned with the Notifiable Data Breaches scheme, with defined escalation paths and 48-hour breach notification timelines.
Why post-quantum cryptography matters
Quantum computers, when sufficiently powerful, could break classical key exchange methods like RSA and ECDH. By implementing hybrid post-quantum key exchange today, we ensure that encrypted health data cannot be retroactively decrypted even if such capabilities emerge in the future.
For full technical details on our security architecture, please see our Security Disclosure.
7. Cross-Border Data Transfers
Some of our service providers may process data outside Australia. In accordance with APP 8, before disclosing personal information to an overseas recipient, we take reasonable steps to ensure the recipient complies with the Australian Privacy Principles or is subject to a substantially similar privacy regime.
Where our cloud infrastructure or AI processing services are hosted outside Australia, we ensure appropriate contractual safeguards are in place and data remains encrypted in transit and at rest.
8. Data Retention
We retain your personal information only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. Specifically:
- Active accounts: Data is retained for the duration of your account;
- Simulation History: Individual simulation inputs, delta values, and projected risk profiles are stored with your account and protected by the same field-level encryption. You may request the deletion of your simulation history at any time without deleting your entire account;
- Cohort Simulations: Policy-level cohort simulations for enterprise dashboards run exclusively on de-identified, aggregate population data. Individual simulation results are never exposed in cohort reports;
- Deleted accounts: Upon account deletion or data erasure request, personal data is removed from production systems within 30 days and from backup systems within 90 days;
- Legal obligations: Certain records may be retained for up to 7 years where required by Australian tax, corporate, or health record legislation;
- De-identified data: Aggregated, de-identified data that cannot be linked back to you may be retained indefinitely for research and service improvement.
9. Your Rights
Under the Australian Privacy Principles and applicable law, you have the right to:
- Access: Request access to the personal information we hold about you (APP 12);
- Correction: Request correction of inaccurate, incomplete, or out-of-date personal information (APP 13);
- Deletion: Request the deletion of your personal data, including your Biosphere simulation history. We will action erasure requests promptly, subject to any legal obligations to retain certain records;
- Data portability: Request a copy of your data in a commonly used, machine-readable format;
- Withdraw consent: Withdraw your consent for the collection or use of sensitive information at any time. Note that withdrawal of consent may affect your ability to use certain Platform features;
- Opt out of marketing: Unsubscribe from marketing communications at any time via the link in our emails or by contacting us.
To exercise any of these rights, contact us at support@kurapath.com. We will respond to requests within 30 days.
10. Notifiable Data Breaches
We maintain a rigorous data breach response plan in accordance with Part IIIC of the Privacy Act 1988 (Notifiable Data Breaches scheme). In the event of a data breach that is likely to result in serious harm:
- We will notify the Office of the Australian Information Commissioner (OAIC) as soon as practicable;
- We will notify affected individuals with clear information about the breach, the type of data involved, and recommended actions;
- We will take immediate steps to contain the breach and mitigate any potential harm.
11. Children's Privacy
KuraPath is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have inadvertently collected data from a child under 18, we will take steps to delete that information promptly. If you believe a child has provided us with personal information, please contact us at support@kurapath.com.
12. Cookies and Analytics
KuraPath uses cookies and similar technologies for:
- Essential cookies: Required for authentication, session management, and security. These cannot be disabled;
- Analytics cookies: Used to understand how the Platform is used and to improve the user experience. We use privacy-respecting analytics tools;
- Error monitoring: We use Sentry for error tracking to maintain platform reliability. Error reports may include technical metadata but not health data.
We do not use advertising cookies or engage in cross-site behavioural tracking.
13. Complaints
If you believe we have breached the Australian Privacy Principles or handled your personal information inappropriately, you may lodge a complaint by contacting us at support@kurapath.com.
We will acknowledge your complaint within 7 days and aim to resolve it within 30 days. If you are not satisfied with our response, you may escalate your complaint to the Office of the Australian Information Commissioner (OAIC).
14. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. Material changes will be communicated via email or a prominent notice on the Platform at least 14 days before taking effect. Your continued use of the Platform after such notification constitutes acceptance of the updated policy.
We encourage you to review this Privacy Policy periodically. This policy is also available at kurapath.com/privacy.
Questions About Your Privacy?
Contact us at support@kurapath.com