Your identity
Use Catina with a made-up username.
A made-up username is enough to create an account. Providing your real name, location, and other identifying details is optional. Any email address you provide is used for account access and support.
Catina keeps supported health records in encrypted local storage and excludes them from sale and advertising use. Sensitive AI bodies use a separate verified enclave path with explicit metadata limits.
Use Catina with a made-up username.
A made-up username is enough to create an account. Providing your real name, location, and other identifying details is optional. Any email address you provide is used for account access and support.
Storage and AI processing use different protected paths.
Supported health records are stored in an encrypted local Health Vault. Standard protection uses backend-assisted unlock. Extra Local Protection separately adds a passphrase-gated local encryption layer. Sensitive AI features may send encrypted request bodies to an attested enclave for processing.
Sensitive request and response bodies use a verified enclave path.
For current sensitive AI features, the browser verifies an attested Trusted Execution Environment before establishing a secure session. The protected request and response bodies are encrypted end to end to the enclave.
A verified secure session may be reused for up to 30 minutes. Operational headers and metadata required for account authentication, routing, limits, billing, and reliability remain visible to the applicable service providers.
A verification failure stops the sensitive request before transmission. Conversation history stored in the supported local vault can be deleted through the app.
Only basic, anonymous usage signals needed to keep the app working well.
We may collect anonymous technical data such as crash reports, performance information, and feature usage. This information supports product reliability and remains separate from health records and identifying details.
Personal health records are excluded from sale and advertising use.
We use service providers for functions such as authentication, infrastructure, payments, support, analytics, and private AI processing. They receive the limited data needed for those functions under their applicable terms. We may also disclose information when legally required. See the Privacy Architecture page for the current feature map.
Most rights are already met by design.
Because we collect so little, many access, correction, and deletion rights are handled directly through your in-app controls. For anything else please contact us.
Significant policy changes receive at least 14 days of advance notice. Any change to privacy protections will be explained clearly before it takes effect.
By using Catina, you confirm that you have read this policy. It forms part of our Terms of Service.
If anything is unclear or you have a concern, contact us at support@catina.box. We read every message.