> ## Content Index
> Fetch the complete content index at: https://launch.ghostcms.templates.codememory.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Kinder Health: analytics for a health app, without health data
- URL: https://launch.ghostcms.templates.codememory.com/kinder-health-analytics-for-a-health-app-without-health-data/
- Published: 2026-06-18T14:00:00.000Z
- Updated: 2026-06-18T14:00:00.000Z
- Description: A strict rule, a short list of allowed events and an ID that changes every thirty days.
- Author: Priya Nair
- Tags: Customers, Privacy, #Import 2026-10-02 15:41

Kinder Health runs an app that helps parents book appointments at forty family clinics. The team wanted to understand where parents give up in the booking flow. They also had a strict rule: no health information, and no names, could ever reach their analytics tool. This is how they set up Tally to answer their questions without breaking the rule.

![Most bookings are made on a phone, often while doing something else.](https://launch.ghostcms.templates.codememory.com/content/images/2026/10/kind-phone.jpg)

Most bookings are made on a phone, often while doing something else.

## The rule first

Health data is some of the most sensitive data there is. Kinder's privacy lead, Dr. Lena Okafor, wrote the rule before anyone wrote a line of tracking code: "Analytics may know that someone booked. It may never know who, or why."

That ruled out the usual approach of sending everything and filtering later. Every event had to be designed so that, even if the analytics data leaked, it would say nothing about any person's health.

## How they did it

The team made a short list of allowed events and allowed properties. Anything not on the list is dropped by their own code before it is sent.

| Sent to Tally                          | Never sent                   |
| -------------------------------------- | ---------------------------- |
| Step reached in the booking flow       | The reason for the visit     |
| Clinic region (one of six)             | The clinic name              |
| Device type                            | Names, emails, phone numbers |
| A random ID that changes every 30 days | The account ID               |

The random ID is the clever part. It lets Tally connect the steps of one booking and measure retention within a month, but it cannot be linked back to an account, and it changes every thirty days.

> We wanted to measure the flow, not the families.  
>  
> **Dr. Lena Okafor**

![Kinder's tracking plan is reviewed by their privacy lead every quarter.](https://launch.ghostcms.templates.codememory.com/content/images/2026/10/kind-lock.jpg)

Kinder's tracking plan is reviewed by their privacy lead every quarter.

## What they found

The funnel showed one step losing a third of parents: choosing a time. On a phone, the calendar showed a whole month, and most slots were full. Parents scrolled, found nothing and gave up.

The team changed the screen to show the next five available times first, with the calendar one tap away. Completed bookings rose by 24% in the first month. Calls to clinic reception, from parents who had given up on the app, fell by a fifth.

## What other teams can learn

You do not need personal data to improve a flow. You need to know which step people reach, on which device, and whether they finish. Decide what you will never send before you decide what you will send.

🔒

Kinder sends data to Tally's European region, and their contract includes our standard data processing agreement.

#### Can Tally be used for health apps?

Yes, if you send no health data. We help customers design a tracking plan like Kinder's.

#### Does the changing ID break retention charts?

Only for periods longer than thirty days, which Kinder decided was the right trade.