Privacy
Last updated September 6, 2026
Who we are
Kinetic Alignment Labs (“the practice”, “we”) is a New York strength-and-conditioning practice. This site is the practice’s own platform: a public page, a consultation inquiry form, and the records system the practice works in, with a portal where clients read what the practice shares with them. This page describes what the platform actually does with information — no more and no less. Questions go to scott.kirchner@kinetic-alignment-labs.io.
Visiting the site
- There are no analytics, no advertising, no tracking pixels, and no third-party scripts on any page. Fonts are served from this site’s own servers, so page views are not reported to a font network.
- The only cookie this site sets is the sign-in session cookie, created when you sign in. It is inaccessible to page scripts, sent only over encrypted connections in production, and expires 7 days after your last visit — using the site extends it. There are no cookies for visitors who do not sign in.
- Like any host, our hosting provider keeps short-lived operational request logs for running the service. The application itself does not record your browsing.
Consultation inquiries
- The inquiry form collects three things: your name, your email address, and your message. The form asks you to keep medical specifics for the consultation itself.
- To limit abuse of the form, the platform computes a keyed one-way code from the submitting network address and keeps only that code — never the address itself. The code is erased with the inquiry.
- If you do not become a client, your inquiry is permanently deleted after 90 days. If you do, the captured text is erased on the same clock; only the link between the inquiry and your record, and the date it was submitted, remain.
- Email sent to the practice address travels through our mail forwarding (Cloudflare) to the practice’s mailbox (hosted by Google), and is handled there like any correspondence with the practice.
Client records
If you become a client, the practice keeps a clinical record of your care: contact details, assessments and measurements, session notes, posture photographs and other media, appointments, home-exercise assignments, and progress reports. Portal accounts are created by the practice — there is no self-registration — and activated through a single-use link handed to you personally. Your password is stored only as a one-way hash.
How records are protected
- All traffic between your browser and this site is encrypted (HTTPS).
- Who may read what is enforced on the server on every request: a client can read only their own record, and practitioner-only material — internal session notes among it — is never sent to the portal.
- Records live in a managed database that encrypts stored data at rest, with row-level security denying direct database-API access to every table.
- Photographs and documents sit in a private storage bucket. The only way to read one is a time-limited signed link (15 minutes) that the platform mints after checking you may see that file.
- Changes to clinical records are recorded in an audit trail the application only ever appends to — who changed what, when. Passwords and activation secrets are excluded from that trail by construction.
- No client data is sent to any analytics service. Posture estimation runs in the practitioner’s browser and search runs on our own servers.
- AI-assisted note drafting, when the practitioner asks for it, sends a structured text summary of your record — measurements, findings, goals, home programme and the previous plan — to Anthropic’s Claude API to produce a first draft of the practitioner’s own session note. That summary never includes your name, contact details, photographs or raw posture data. The practitioner reviews and edits every draft before anything is saved, and no AI-generated text is ever shown to you. Anthropic processes that text only to return the draft and does not use it to train its models.
Who else touches data
The platform runs on two infrastructure providers: Vercel (application hosting) and Supabase (database and file storage). Anthropic receives only the drafting summaries described above, only when the practitioner requests a draft. Mail to the practice address passes through Cloudflare and Google as described above. These providers process data only to run the service — we do not give any of them data for its own use. We do not sell personal information, share it for advertising, or disclose it to anyone else except as required by law.
Retention
- Inquiries: the 90-day clock above.
- Clinical records: retained through your relationship with the practice and for at least seven years after it ends, per the practice’s records-retention policy. A record deleted in the app is hidden from use but retained, with its audit history, through that period.
- Sign-in sessions expire 7 days after your last activity.
Your choices
Write to the practice to ask what is held about you, to correct something, or to ask for deletion. Deletion requests are honored consistent with the record-keeping obligations above — clinical records the practice must keep are kept, and everything else goes.
Adults only
The practice serves adults. This site is not directed at children, and we do not knowingly collect information from anyone under 18.
Where this stands legally
The practice is cash-pay and does not bill insurance, so it is not a HIPAA covered entity. What governs this data is New York’s SHIELD Act, which requires reasonable safeguards for private information — including medical information — and breach notification. The protections described above are what we actually run; if that ever changes, this page changes with it.
Changes
If this policy changes materially, the new version is posted here with a new date at the top.