Terms & Conditions
Effective August 19, 2026
KidPoints turns the tests, scans and procedures a child has already been through into Courage Points. To do that, it can read the child's hospital chart β but only if a parent or guardian signs in and says yes. Here is exactly what that means, in plain words.
The short version
- We read three things: who the patient is, their visits, and their procedures.
- We only read. KidPoints never changes anything in the hospital chart.
- The chart data stays on the device it was opened on and is only used to add up points in this demo.
- Close the tab or tap Disconnect this chart and it is gone.
This is a demo
KidPoints is a working demonstration of a pediatric engagement platform. It is not a medical device, not a medical record, and not medical advice. Points, badges and rewards shown here are illustrative β they are not redeemable for anything, and nothing in this app should be used to make a care decision. Always talk to the care team about the care itself.
What we ask your hospital for
When you tap Connect my chart, you are sent to Epic's own MyChart sign-in page. KidPoints never sees the password β Epic does the sign-in and then asks you whether to let KidPoints read the items below. This demo connects to Epic's sandbox (test) environment.
- Who the patient isPatient.readBasic demographics β the name and details Epic returns for the patient whose chart you signed in with. KidPoints uses the first name to say βthese are Emma's pointsβ.
- Hospital visitsEncounter.readThe visits in the chart β the kind of visit, its date, and why it happened β so points can be grouped by the day they were earned.
- Tests and proceduresProcedure.readThe procedures recorded in those visits and their medical codes. This is what the points are actually calculated from β a more involved procedure is worth more points.
The technical scopes requested are launch/patient openid fhirUser patient/Patient.read patient/Encounter.read patient/Procedure.read. Your hospital grants only what it has approved, and KidPoints shows you what was actually granted. We do not ask for notes, medications, lab results, imaging, billing, or anything about anyone other than the patient who signed in.
Read-only, and only for points
Access is read-only. KidPoints can look at the three things listed above and nothing else β it cannot add, edit, or delete anything in the hospital record. Your care team's chart is untouched.
What we read is used for exactly one purpose: working out Courage Points for the procedures already in the chart, and showing them back to the child and parent in this demo. It is not used for advertising, profiling, research, model training, or scoring of any other kind, and it is never sold.
What we keep β and what we don't
KidPoints has no server and no database in this demo. The chart is read straight from your hospital into the browser on your device, added up there, and shown to you there. Nothing about your health is sent to KidPoints, stored by KidPoints, or shared with anyone else.
- The sign-in tokenLives only in memory while the chart is being read, then is dropped. It is never saved to the device.
- The points resultA trimmed-down summary β the patient's name, visit type, date, procedure codes and points β is held in the browser's session storage so the screen survives the hop back from the sign-in page. Names of doctors, locations and other chart links are dropped before anything is held at all.
- How it endsIt is erased when you tap Disconnect this chart, and automatically when you close the browser tab. There is no copy anywhere else to delete.
Because the summary sits in the browser session, sign out or close the tab when you finish on a shared or hospital device.
Who may connect a chart
A chart may only be connected by the patient's parent or legal guardian, or by an adult patient for their own chart, using their own hospital sign-in. Please do not connect someone else's chart. You can stop at any time β either decline on Epic's consent screen, or disconnect afterwards in KidPoints.
The page your hospital sends you back to after sign-in is /smart-callback/ on this site.
Changes to these terms
If what KidPoints reads or does with the data changes, this page changes with it and the effective date above is updated. Because nothing is stored, the terms that matter are always the ones on this page when you connect.
Questions or concerns
Write to us and a human answers β about the data, about a connection you want removed, or about anything on this page.
Effective August 19, 2026.