Privacy Policy
How Kindred Space handles patient, staff, and hospital information.
1. Who this policy covers
This policy explains how Kindred Space handles information for the three kinds of people who use the platform: patients using a hospital-provided tablet during a stay, clinical staff who support them, and hospital administrators who configure the platform for their organization.
Kindred Space is provided to hospitals. Each hospital remains responsible for the clinical decisions it makes and for how it uses the platform within its own policies and applicable law. This page is maintained by the Kindred Space team to answer common privacy questions; it is not an independent certification or an audit result.
2. Information we handle
The platform handles a deliberately narrow set of information:
- Patient account details entered by staff at admission — display name, patient identifier, unit, room, and a PIN used to sign in on a shared device.
- Content patients create in the app, such as journal entries, artwork, letters, goals, favorites, and Hope Box items.
- Requests and messages patients send to staff, such as comfort requests, questions, and song requests.
- Staff and administrator account details — name, work email, job title, role, unit assignments, and permissions.
- Operational records — device checkouts, session activity, schedules, announcements, visitor information, music approvals, and audit entries.
3. What stays private from staff
Journals, artwork, letters, and Hope Box items are private to the patient. Staff and administrators can see that a private activity is in progress, which supports safety checks, but they cannot read or view the content itself.
Patients may choose to share a specific item with their care team. Nothing is shared automatically.
4. Separation between hospitals
Every record belongs to exactly one hospital. Information is never pooled, compared, or shared across organizations. Staff see only patients within their assigned units unless their role grants hospital-wide scope, and access is checked on the server for every request rather than being hidden in the interface.
5. How information is used
Information is used to operate the platform for the hospital that entered it: signing patients in on shared devices, delivering approved music and schedules, routing requests to staff, keeping an audit trail for administrators, and keeping the service secure and reliable.
Kindred Space does not sell information, does not use patient content for advertising, and does not use patient content to train machine-learning models.
6. Shared devices
Patient tablets are hospital-owned and shared. A session is tied to a device checkout, and when the session ends the temporary information on that device is cleared so the next patient never sees the previous patient's space.
7. Service providers
Kindred Space relies on a small number of providers to run the service: cloud hosting and database services, an email delivery service used for invitations, password resets, and support messages, and a music streaming service used only when a hospital connects its own account. These providers process information on behalf of the hospital and only to deliver the service.
8. Retention and deletion
Patient accounts are archived at discharge. Before discharge, a patient can ask their care team for a discharge package containing their own journals, letters, and artwork. Hospitals can request deletion of their organization's information; audit entries are retained in read-only form for the period the hospital's own record-keeping policy requires.
9. Security
Access is role-based and enforced on the server. Staff and administrator accounts are invitation-only and cannot be self-created. Passwords and PINs are stored as salted hashes and are never visible to administrators or to the Kindred Space team. Sign-in sessions use secure, http-only cookies, and administrative actions are recorded in an audit log that cannot be edited or deleted.
No platform can promise that a security incident will never occur. If one affects a hospital's information, we will notify that hospital promptly with what we know and what we are doing about it.
10. Your choices
Patients can ask their care team about the information held in their account, request a copy of their own content, or ask that something be removed. Staff and administrators can update their own profile details and password at any time. Requests that concern the clinical record are handled by the hospital under its own health-information procedures.
11. Children
Kindred Space is provided to hospitals, and any use by a minor is arranged and supervised by the hospital and the patient's care team under the hospital's own consent process. Accounts are never created directly by patients.
12. Changes and contact
If this policy changes in a way that materially affects how information is handled, hospitals using Kindred Space will be notified. For privacy questions, use the Contact Kindred Space form linked in the footer of every page.
Kindred Space is a supportive tool, not a medical device, and is never used for emergencies. See also the Terms of Use.