Effective Date: May 13, 2025

Cairns Health Privacy Policy

This Privacy Policy (“Policy”) describes how Cairns Health d/b/a Koko Home (“Cairns Health” “we,”
“our,” “us”) collects, uses, and discloses certain information obtained through use of our mobile
applications (“Apps”), which are available for download on iOS on the Apple App Store and through
Android on the Google Play Store; our clinical portal utilized by our Care Team (“Portal”); and our
digital care companion (“Device”) from users that choose to install the Device into their residences
(“Users”) or from other members of Users’ residences whose information the Device captures.
Collectively, the Apps, Portal, and Device help us provide our digital care services (the “Services”). By
using our Services and by signing the Patient Authorization, you agree to the terms of this Policy on
behalf of yourself and other members of your household.

Information We Collect and Maintain About You

We collect information from you directly when you provide it to us through the Apps or information is
collected through the Device. We may also collect information about you from third parties pursuant to
your permission or consent. We further automatically collect certain information about you and your
smartphone or other device when you use, access, or interact with our Apps.

Personal information provided directly from Users or their Care Team. We collect personal
information from users who create an account within the Apps (“App Users”). We may collect the
following categories of information from App Users:

  • Name, email, and password
  • Location information, such as your city or country
  • Self-reported information you provide through health assessments, including information about
    your health and well-being, hobbies, interests, dietary preferences, and any other information that
    you choose to provide.
  • Contact information, such as email address or phone number
  • Health data, including information contained in your provider’s care plan (e.g. medications,
    medical conditions, diagnoses, symptom assessments, etc.) or electronic health record (e.g., your
    medical tests and medical history), and vital signs and physiological data (e.g. heart rate,
    respiratory rate, blood pressure, weight, sleep history, breathing rate, etc.).

We may also collect any personal information you provide or we obtain through your interactions with
the Services, as well as personal information provided to us by your healthcare provider, caregiver, or
other healthcare representatives designated by you, including your family members (“Care Team”)
through the Apps.

Personal information collected through the Device. The purpose of the Device is to collect information
that can be used to monitor a User’s vitals, symptom assessments, sleep quality, sleep stages, audio
discourse sentiment analysis, and room context and movements. The Device collects radar and sound information, as well as information relating to other external factors, such as temperature, humidity, light,
and vibration. In order for us to obtain the best results, the Device’s default mode is to be “on” is on at all
times and continuously recording data, including sound information.

Given the Device’s default “on” setting, it may also capture information relating to individuals other than
the Users (or members of User households) who have agreed to this Policy. In those instances, we will
process the information we collect consistent with the terms of this Policy. To temporarily or permanently
switch default “on” setting to “privacy” mode (where data collection will cease), please see further details
provided in the Your Choices section below.

Personal information collected through the Portal. If you are a member of the Care Team and you
create an account through the Portal, we will process your personal information in relation to creating and
maintaining your account. This information may include your name, email address, and login
information.

Personal information collected through third-party integrations. To the extent that you integrate a
third-party device to your account on the App(s), such as your Fitbit, Apple Watch, patient monitoring
device, electronic health record, or personal health record, we may collect information about you from
this device. This may include your health information, including information about your sleep patterns,
vitals, and physical activity.

Aggregated or deidentified information. We may also share aggregated or deidentified information
about users of the Services, such as by publishing a report on trends in the usage of the Services. Such
aggregated or deidentified information will not identify you personally.

How We Use Your Information

The purposes for which we use your information include to:

  • Provide you with our Services;
  • Provide you and your Care Team with your health-related information;
  • Respond to your questions or requests concerning the Apps, Portal, and Device;
  • Fulfill the terms of any agreement you have with us;
  • Fulfill your requests for our Apps, Portal, and Device or otherwise complete a transaction that
    you initiate;
  • Improve and train our artificial intelligence, large language models, and machine learning;
  • Deliver confirmations, account information, notifications, and similar operational
    communications;
  • Improve your user experience and the quality of our products and services, including the Device;
  • Comply with legal and/or regulatory requirements;
  • Aggregate and deidentify information;
  • Conduct analytics and research concerning the Services;
  • Create new products and services; and
  • Manage our business.

We may link information gathered through the Apps, Portal, or Device with information that we collect in
other contexts. In that event, we will handle the combined information in a manner consistent with this
Policy.

With Whom and Why We Share Your Information

In order to provide you with our Services, we share your information with third parties for a variety of
purposes, as described below and consistent with the terms of this Policy. We do not sell your information
to third parties.

Research partners. We may share deidentified and aggregated data with healthcare providers, healthcare systems, insurance providers, home care agencies universities and other research partners to evaluate the efficacy of our products and to assist these organizations in learning more about specific health conditions.

Your Care Team and other healthcare service providers. We may share your personal information with
your Care Team and third-party companies that provide services such as Remote Patient Monitoring
(“RPM”), Chronic Care Management (“CCM”), Senior Care Living Services or Home Care agencies on
behalf of your care facility or provider. The agreements between your care facility or provider and these
companies contain confidentiality safeguards regarding the use and disclosure of your personal
information.

Third-party service providers and vendors. We use third-party service providers that perform services on
our behalf, including web-hosting companies mailing vendors, and technology companies that develop
commercially-available AI such as large language models. These service providers may collect and/or use
your information, including information that identifies you personally, to assist us in achieving the
purposes discussed above.

We may also share your information with third parties when necessary to fulfill your requests for our
Services; to complete a transaction that you initiate; to meet the terms of any agreement that you have
with us or our partners; or to manage our business.

Legal purposes. We also may use or share your information with third parties when we believe, in our
sole discretion, that doing so is necessary:

  • To comply with applicable law or a court order, subpoena, or other legal process;
  • To investigate, prevent, or take action regarding illegal activities, suspected fraud, violations of
    our terms and conditions, or situations involving threats to our property or the property or
    physical safety of any person or third party;
  • To establish, protect, or exercise our legal rights or defend against legal claims; or
  • To facilitate the financing, securitization, insuring, sale, assignment, bankruptcy, or other disposal
    of all or part of our business or assets.

Your Choices

If you want to learn more about the personal information that Cairns Health has about you, or if you wish
to access, correct, or delete the personal information we have on file, you may contact us at
contact@cairns.ai.

Users may turn the Device off from recording data by utilizing the “Privacy ” function .
On the back of the base, push the icon to up mode (and see a red stripe visible), and Luna will confirm
“privacy is on”. If there is no button on the back, hold down the middle button on the Device’s main
platform, the “Privacy button” will be turned on and noted by Luna confirming “privacy is on” , you
may pause radar data recording, audio recording, as well as all other contextual sensors (i.e., information
relating to the humidity or temperature of the room) at any time. The Device does not record sensor data
in this muted position. Users need to unmute the Device in order to resume data collection, by re-pressing
the button on the back down or if no button on the back, push the middle button down until Luna
confirms “privacy mode” is off.

If you wish to opt-out of marketing emails you receive from us, you may do so by following the
instructions in those emails or by contacting us at contact@cairns.ai.

If you are a resident of a jurisdiction with an applicable data privacy law, you may have certain rights
available to you in relation to your personal information. These rights may include:

  • The right to access your personal information (including a data portability request);
  • The right to correct or amend any personal information we have on file about you;
  • The right to delete your personal information;
  • The right to limit the use of your “sensitive” personal information;
  • The right to opt-out of the sale or “sharing” of your personal information;
  • The right to opt-out of the use of your personal information for targeted advertising purposes;
  • The right to restrict or object to the processing of your personal information (such as for direct
    marketing purposes);
  • The right to restrict or opt-out of the use of your personal information for certain automated
    decision-making (including profiling in furtherance of decisions that produce legal or similarly
    significant effects);
  • The right to revoke your consent (to the extent applicable);
  • The right to confirm whether personal information about you is being processed;
  • The right to obtain a list of specific third parties (or categories of third parties) to which we have
    disclosed your personal information or any personal information.

To exercise any of the rights listed above, please contact us via email at contact@cairns.ai.
We will respond to your request as soon as reasonably possible and within the timeframe required under
applicable law. We will allow you to appeal any decision we make in response to such request in
accordance with applicable law. Appeals may be submitted to contact@cairns.ai with the subject line
“Appeal of Decision Related to Privacy Rights Request.”

Prior to complying with your request, we will first verify your identity by comparing the information you
provide with the information we have on file for you.

You may authorize an agent to make a request on your behalf. To designate an agent, please provide a
written and signed document by both you and the agent that authorizes the agent to act on your behalf.
You may also use a power of attorney. We will still require you to provide information to allow us to
reasonably verify that you are the person about whom we collected personal information.

External Links

The Apps or Portal may contain links to third-party websites or apps. If you use these links, you will
leave the Apps or Portal. We have not reviewed these third-party sites and do not control and are not
responsible for any of these sites, their content, or their privacy policy. Thus, we do not endorse or make
any representations about them, or any information, software, or other products or materials found there,
or any results that may be obtained from using them. If you decide to access any of the third-party sites
listed on our website, you do so at your own risk.

Data Security

We employ physical, technical, and administrative procedures to safeguard the personal information we
collect and process. However, no mobile app or device is 100% secure, and we cannot ensure or warrant
the security of any information you transmit to the Apps, Device, Portal, or to us, and you transmit such
information at your own risk.

Data Retention

We retain personal information about you necessary to fulfill the purpose for which that information was
collected or as required or permitted by law. We do not retain personal information longer than is
necessary for us to achieve the purposes for which we collected it. When we destroy your personal
information, we do so in a way that prevents that information from being restored or reconstructed.

International Users

The information that we collect through or in connection with the Services is transferred to and processed
in the United States for the purposes described above. We may also subcontract the processing of your
data to, or otherwise share your data with, affiliates or third parties in the United States or countries other
than your country of residence. The data-protection laws in these countries may be different from, and
less stringent than, those in your country of residence. By using the Services or by providing any
information to us, you expressly consent to such transfer and processing.

Children

Content on the Apps and Device is directed at individuals over the age of 18 and is not directed at
children under the age of 13. We do not knowingly collect personally identifiable information from
children under the age of 13.

Changes to this Policy

We may make changes to the Apps, Portal, or Device in the future and as a consequence will need to
revise this Policy to reflect those changes. We will post all such changes on the Apps, so you should
review those pages periodically.

How to Contact Us

Should you have any questions or concerns about this Policy, you can contact us by email at contact@cairns.ai.