← Back to home

Evidence & privacy

Maintained by the Knya AI team. Not an independent certification.

Women's wellness is a space where marketing claims often outrun what a product can actually prove. This page explains what we verify inside Knya, how we measure it, and the claims we deliberately do not make.

What we verify

  • Your account is only accessible to you
    How: Row-level access rules on every table; sign-in required for personal data.
  • Your chat, cycle, symptom and pregnancy logs sync to your account
    How: Reads and writes are scoped to your user ID and confirmed via automated typecheck and route tests.
  • You can export or delete your data
    How: Tools → Privacy exposes a JSON export and a deletion action that runs against your records.
  • Notification preferences are respected
    How: Reminder jobs read your channel + quiet-hours settings before sending; failures are logged in Tools → Notifications.
  • OTP sign-in has spam controls
    How: 30s resend cooldown, per-minute and per-day caps, and a 10-minute lockout after repeated failures.

How we measure it

  • Automated typechecks and route smoke-tests run on every change.
  • Delivery attempts (push + SMS/OTP) are recorded with masked identifiers and surfaced in-app so you can see what actually happened.
  • AI responses stream from a single provider we can rate-limit and audit; abuse triggers 429 responses instead of silent failures.
  • Claims on the homepage are limited to capabilities we can point to in the product.

What we deliberately do not claim

  • No user counts, ratings, or testimonials we can't attribute
    How: Homepage stats stay on capability language (free, no card, privacy first) until we have real, sourced numbers.
  • No HIPAA, GDPR, SOC 2, or ISO badge language
    How: Knya is privacy-first by design, but we do not hold those certifications and won't imply we do.
  • No medical diagnosis or treatment
    How: Knya is a wellness companion. For anything urgent or clinical, we point you to a qualified professional.
  • No 'end-to-end encrypted' claim
    How: Data is encrypted in transit and at rest by our hosting provider, which is not the same as E2EE — so we don't say it is.

Shared responsibility

Knya runs on a managed backend (auth, database, hosting) and an AI provider. Those platforms provide baseline security controls; Knya is responsible for how they're configured, what data we ask for, and how we present results to you. You control what you log, which reminders you enable, and what the assistant is allowed to use for recommendations via Tools → Privacy.

Report a claim concern

Spotted a claim inside Knya that looks incorrect, unverifiable, or unsafe? Flag it here and it goes straight to the team for review.

Reports go to the Knya team. We don't share your identity with anyone.

See also our Privacy Policy and Terms.