kinnly Privacy Policy
Effective Date: September 21, 2026
At kinnly, we respect your privacy and are committed to protecting the personal data of you and your family. This Privacy Policy describes how we collect, use, and share your information when you use the kinnly mobile application, our website at kinnlyapp.com, and our services.
kinnly is a co-parenting application built for two households that share the responsibility of raising children. Because that context involves sensitive information about you, your co-parent, and your children, we've designed the app so that most of your content is encrypted on your device before it ever reaches our servers. The sections below explain exactly what we collect, how it flows, and who can see it.
1. Information We Collect
We collect information directly from you when you register an account, set up or join a family, and interact with the application.
A. Account & Authentication Information
- Email Address: Used to identify your account and authenticate you.
- Account ID: A unique identifier generated by our authentication provider to secure requests and associate data with your account.
- Passwords: Managed and secured directly by our authentication provider (we do not store or see your plaintext password).
- Sign in with Apple / Sign in with Google: If you choose to sign in with Apple or Google instead of email + password, we receive from that provider an identity token, your name (if you elect to share it), and an email address (which may be a private-relay address in the case of Apple). We use these to create or match your account. Your Apple or Google password never touches kinnly's servers.
- Display Name: If you set a display name during onboarding or from Settings, we store it so we can address you personally in-app and show it to your linked co-parent.
- Your Role: The relationship to the children you choose during onboarding or in Settings (for example Mom, Dad or Stepdad). We store it, encrypted like your display name, and show it to your linked co-parent next to your name, for example in chat.
- Password Resets: If you ask to reset your password, we store your email address with a six-digit code and email the code to you (see Resend in Section 3). The code works for 15 minutes, and the record is deleted within about a day. To stop the reset form being used to flood someone's inbox, we also keep a record of each reset request containing a keyed fingerprint of the email address and of the IP address the request came from — not the address or IP itself. It is used only to limit how often resets can be requested, and is deleted within about a day.
B. Family & Coordinate Data
- Household Names: Names you choose for each household (e.g., "The Snug", "The Asylum").
- Children's Profiles: Names, birthdays, and optional photos of the children in your family, used to coordinate schedules, track milestones, and manage medications. See Section 8 for our treatment of children's data.
- Custody Schedule & Events: Details of handoff days, custody patterns, calendar events, holidays, and schedule exceptions.
- Family Circle Members: If you invite extended family members (e.g., grandparents, nannies, godparents), we store their names, designations, optional contact email/phone you provide, per-feature permission settings you choose for them, and the invite/approval status of the invitation.
- Health Information: Optional per-child allergies, blood type, medications (name, dosage, frequency, dose history), and shared family emergency information (pediatrician, insurance).
- Multiple Families: A single kinnly account may belong to more than one family (for example, a parent co-parenting with two different other parents, or a grandparent in more than one Family Circle). We store the list of families your account is a member of; you switch between them in-app.
C. Media & Documents
- Journal Entries: Photos, videos, tags, and captions uploaded to share memories.
- Vault Documents: Important family files, documents, and records you upload for safekeeping.
- Expense Receipts: Images of receipts uploaded to verify shared costs.
Note on storage: High-resolution photos, videos, and documents are securely synced via peer-to-peer (P2P) connections between parent devices. The high-resolution files never transit kinnly's backend servers. In cases where fallback storage is required (e.g., for low-resolution thumbnails or vault files), files are uploaded to kinnly's Supabase Storage only after being fully encrypted on your device.
D. Chat & Communication
- Messages: Text messages exchanged in the family or parents-private channels are encrypted on your device before being stored (see Section 4). We cannot read the content of your messages, including in the push notifications we send about them (see Section 1.F).
- Delivery and read receipts: For each person in a chat, we record when a message reached their kinnly app and when they had it open on screen. Everyone in that chat can see these times on the messages they can read. The times are set by our server, can't be changed, and can't be turned off, so both parents can rely on them.
- Edits and deletions: You can edit a message for 10 minutes after sending it. The first version is kept, and anyone in the chat can see it. Deleting a message hides it from the chat but keeps its text, encrypted, in the family's record. Only the person who wrote a message can edit or delete it.
E. Payment Handles (Venmo / PayPal / Zelle)
- What we collect: If you enter Venmo, PayPal, or Zelle handles during onboarding or from Settings, we store them so your co-parent can build a pre-filled payment link when settling expenses.
- How they're stored: Handles are encrypted on your device using your family key before being written to our database, and are shared only with your linked co-parent. They are not visible to kinnly, not shared with third parties, and not used for marketing.
- How they're used: When your co-parent settles an expense on their device, we decrypt your handles locally and build a Venmo or PayPal link that opens the payment app on their phone. No payment ever transits kinnly's servers.
F. Device & Notification Information
- Device Push Tokens: An identifier for your device that lets us route notifications to it (e.g., handoff reminders, swap requests, partner-joined alerts). See Section 3 for the providers involved.
- Push Notification Content: A push notification travels through our servers, Expo, and then Apple (APNs) or Google (FCM) before reaching your device. None of those parties can read what the notification is about. The visible text that leaves your device is a generic placeholder — "New message", "Schedule update", "Expense update" — and the real content is encrypted with your family key and carried alongside it. Your own device decrypts it and replaces the placeholder before you see it. If your device cannot decrypt it (for example, before you have signed in), the placeholder is what you see; the real content is never sent in its place.
- Notification Preferences: Which events you want to be told about, and on which channels (push, in-app, email). Stored on our servers so we can decide what to send when the app is not running, and cached on your device.
- Local Device Storage: Some settings and caches are kept only on your device, in the app's local storage and your device's secure keychain or keystore. This includes app settings and preferences, cached copies of your family data, calendar sync state, and — critically — your family's plaintext encryption key. The plaintext key never leaves your device.
G. Encryption Keys
- Family Key: Generated on a parent's device to encrypt sensitive content (see Section 4) before it leaves that device. It is never stored on our servers in a form we can open.
- Device Keys: Each phone you use kinnly on has its own key. We store the public part of it, when it was added, and whether you've turned it off. A copy of the family key reaches each of your family's phones encrypted so that only that phone can open it; we store these encrypted copies but cannot open them.
- Recovery Key: During setup you are shown a recovery key, once. We do not store it or anything that could reveal it. We store its public part and a copy of the family key that only the recovery key can open. When you use it, or make a new one in Settings, the old one stops working. If you lose every phone and your recovery key, and the other parent cannot let you back in, we cannot restore your access.
- Invite Codes: An invite code works for 24 hours. We store only part of it — enough to find the invite, not enough to join with — along with when it was made, when it expires, and whether it was used.
- Letting a New Phone In: When a phone asks to be let into your family, we store the request, when it was made, and who approved or cancelled it. If you ask the other parent to let you back in, we first email your account's address about the request (see Resend in Section 3), and the other parent can approve it only 24 hours after that email is sent.
H. Billing Information (Stripe / Apple App Store / Google Play)
- Subscription Details: Billing records and subscription plans managed securely through Stripe (for web/backend flows) or through Apple App Store / Google Play for in-app purchases. We do not store credit card details directly on our servers.
I. Diagnostics
- Crash and Error Reports: When the app crashes or hits an error, we send diagnostic information to Sentry (see Section 3). To help us reproduce issues, we include your Account ID and email address alongside the error context. Sentry retention is configured to 30 days.
- App Updates: kinnly delivers some updates over the air rather than through the app store. To check whether an update applies to you, your device asks Expo's update service for the current version, sending your app version, runtime version, platform and a device identifier assigned by Expo. No family data is involved, and this check happens whether or not an update is waiting.
J. Personal Cloud Storage
kinnly does not currently let you connect a personal cloud account (such as Google Drive, Dropbox or Microsoft OneDrive), and does not send your files to one. If we add this, we will update this policy before it becomes available.
K. Optional Local Integrations
- Device Calendar Sync: If you enable calendar sync, kinnly writes custody events to your device's native calendar (Apple Calendar on iOS, Google Calendar on Android). Once written, those events follow whatever sync settings you have configured with Apple or Google — kinnly does not transmit them to any third party ourselves. We request calendar permission only for this feature.
- Calendar Link: If you create a calendar link to add your schedule to Google Calendar, Apple Calendar, Outlook or another calendar service, anyone with the link — including that service — can see your custody days, your household names, and the dates, times and responsible household of your events. Event names and locations are not included; they stay encrypted. The link is a random code that only works for this calendar, and we store only a one-way fingerprint of it. You can reset it or turn it off in the app at any time, which stops it working; a calendar service may keep showing what it had already downloaded.
- Biometric Unlock: If you enable Face ID / Touch ID unlock, authentication happens entirely on your device, using its built-in Face ID, Touch ID or fingerprint system. We never see your biometric data.
L. Our Website (kinnlyapp.com)
This section covers the kinnly website. The kinnly mobile app sets no cookies and contains no advertising or analytics SDKs.
- Analytics: kinnlyapp.com uses Plausible Analytics, which we run on our own server rather than using a third-party analytics company. It sets no cookies and creates no persistent or cross-site identifier, so there is nothing for you to consent to and nothing that can follow you to other websites. For each page view we record the page, the site that referred you, and your browser, operating system, device type and country. Your country is derived from your IP address, which is also combined with your browser details and a salt we rotate daily to form a one-way hash that counts repeat visits within a single day; your IP address itself is not stored. The analytics script is served from
stats.theasylum.cloud, a domain we own. These figures are only ever used in aggregate, are never joined to your kinnly account, and are not used for advertising. - Waitlist form: stores your email address, and nothing else.
- Beta form: stores your first and last name, your email address, your phone number, which phone platforms you use, how many children you have, anything you write in the notes field, and your co-parent's first name only. We ask for nothing else about them — not their surname, not their email address, not whether they know you are signing up. We previously collected all three; they have been deleted, and the columns that held them no longer exist. We do not contact your co-parent, and a first name alone is what lets us recognise your two households if they both sign up.
- What the forms do not collect: we do not record the IP address a submission came from, or your browser or device. Those were collected once, were never used, and the columns have been removed.
- Checking you are a person: both forms run Cloudflare Turnstile, which decides whether a submission looks automated. Most visitors never see anything. Cloudflare receives the information your browser sends when it loads that check, including your IP address. We deliberately do not pass your IP address to it ourselves. Turnstile sets no tracking cookie and is not used to profile you or to advertise.
- How long we keep signups: twelve months from the day you submit the form, after which the record is deleted automatically by a scheduled job — not by someone remembering. If you want out before then, email support@kinnlyapp.com from the address you signed up with and we will delete it; you do not need a kinnly account to ask, and we will not ask you why.
- Legal pages: the privacy and terms pages carry the same analytics as the rest of the site.
kinnlyapp.com sets no cookies at all, so there is nothing to block or delete. Its fonts and its analytics script are served from domains we control rather than from a third-party network.
2. How We Use Your Information
We use the collected information to:
- Provide, maintain, and secure the kinnly application.
- Synchronize custody calendars, journal entries, expenses, vault documents, and messages between linked family members.
- Send push notifications and reminders.
- Send invitation emails to co-parents or Family Circle members you nominate.
- Process subscription payments through Stripe, Apple App Store, or Google Play.
- Improve application functionality and debug issues (via Sentry telemetry).
- Protect the service and other people from abuse, such as limiting how often password reset emails can be requested.
We do not use your data for advertising, marketing profiling, or resale.
3. How Your Information is Shared
Your data is shared with the following parties, only to the extent necessary to run the app.
A. Your Linked Co-Parent (and Extended Family Circle)
The co-parent linked to your family has full access to the shared family data: custody calendar, children's profiles, shared journal entries, shared expenses, shared vault documents, messaging channels, medications, contacts, payment handles, and Family Circle members. Extended-family members (grandparents, sitters, etc.) that you and your co-parent approve receive only the per-feature access you grant them.
B. Third-Party Service Providers
| Provider | Purpose | What they receive |
|---|---|---|
| Authentication Provider (Google LLC, US) | User authentication | Email, password hash, Account ID |
| Supabase (Supabase Inc., US) | Database hosting, real-time sync, file storage, server-side functions | All application data (encrypted where indicated in Section 4); uploaded files |
| Stripe (Stripe Inc., US) | Payment and subscription processing | Email, subscription plan, payment method (Stripe stores card details; kinnly does not) |
| RevenueCat (RevenueCat Inc., US) | Subscription management | Account ID, purchase receipts, subscription status |
| Expo (Expo Inc., US) | Push notification delivery | Your device push token, a generic placeholder title and body, and an encrypted payload they cannot read |
| Apple Push Notification service (Apple Inc., US) | Delivering notifications to iOS devices | The same placeholder text and encrypted payload Expo relays; your device token |
| Firebase Cloud Messaging (Google LLC, US) | Delivering notifications to Android devices | The same placeholder text and encrypted payload Expo relays; your device token |
| Cloudflare (Cloudflare Inc., US) | Serving and protecting kinnlyapp.com, and the Turnstile check on both signup forms | The information your browser sends when requesting a page or the check, including your IP address, and the page requested. No tracking cookie; not used for advertising |
| Resend (Resend Inc., US) | Transactional and notification email delivery | Your email address. Mail sent by the app is designed to carry no family data. Mail from a website signup is different: your confirmation email carries your name, and the notification sent to us carries everything that form collected, including your co-parent's name and email address |
| Sentry (Functional Software Inc., US) | Crash and performance reporting | Account ID, email, error stacks, breadcrumbs, device info. Retention: 30 days |
| Google Identity Toolkit (Google LLC, US) | Server-side deletion of your authentication account when you delete your account | Your Account ID |
All of the providers above are US-based. kinnly's own data is stored in the United States.
Services you connect yourself. If you add a calendar link to a calendar service (Section 1.K), that service receives the calendar described there. It is listed separately from the table above on purpose: kinnly does not engage it and does not control what it does with your account. Your relationship with it is governed by your own agreement with that service.
We do not sell, rent, or trade your personal data to third parties for marketing or advertising purposes.
4. Security of Your Data
kinnly uses modern authenticated encryption on your device to protect sensitive content before it ever reaches our servers. The encryption key is a per-family key that lives only on your family's phones. It moves between them only in a form that the receiving phone alone can open, and neither invite codes nor anything we store can unlock it (see Section 1.G). We cannot decrypt your content.
Content that is encrypted on your device before we see it includes:
- Photos, Videos, Vault Documents, and Receipt Files (if fallback storage is used; otherwise these never touch our servers at all)
- Chat message bodies
- Journal captions and document names
- Vault document names, notes, and associated child names
- Expense titles and notes
- Contacts (names, phone numbers, emails, addresses, notes)
- Households' emergency-info block and payment handles
- Children's names, allergies, blood type, and photo URLs
- Swap request messages and titles
- Family Circle member names
- Shared list titles, items, and contribution names
- Medication names, dosages, frequencies, and administration history
- Information requests (titles and notes)
- Food preferences
- Event titles and notes
Content that is not encrypted (because the app needs to sort, route or calculate with it) includes: internal record, account and family IDs; dates and times; household display names; children's birthdays (used to show ages); status settings, such as whether a request has been approved; and expense amounts.
This applies to notifications as well as to storage. Push notifications about the content above do not carry it in readable form. What leaves your device is a generic placeholder plus an encrypted payload that only your family's devices can open — see Section 1.F. Emails are the exception and are described below.
Email is different, and cannot carry your content. Our email provider composes messages on a server, which has no access to your family key. So notification emails tell you only that something happened — for example, that members of your Family Circle are due for a review — and never who or what. To see details you open the app. This is a permanent consequence of the encryption design, not a temporary limitation.
In addition to client-side encryption:
- All network connections to our providers are secured via HTTPS/TLS.
- Database access controls: our database only returns a family's data to members of that family, and enforces this on every request.
- Verified email required: your email address must be verified before your account can read, change or receive updates to family data.
- Encryption at rest: our database provider (Supabase) encrypts data at rest at the infrastructure layer, independent of our client-side encryption above.
5. Your Rights & Data Deletion
You can update your profile, children's profiles, and family data directly within the app.
Data Access & Portability
You have the right to access and download the personal data we hold about your family. You can initiate a Data Export directly from the in-app settings screen. When you request an export, kinnly locally decrypts your database records and securely downloads all associated media (such as photos, videos, and vault documents) to your device, packaging them into a single ZIP archive for portability. This process ensures you retain full ownership and access to your memories outside of the app.
If you joined a website list and have no kinnly account
The rights above assume a kinnly account. If you only submitted the waitlist or beta form on kinnlyapp.com, none of the in-app screens apply to you, so: email support@kinnlyapp.com from the address you used and we will delete the record. You do not need an account, and we will not ask for a reason. Either way the record is deleted automatically twelve months after you submitted it.
Account Deletion
You can request permanent account deletion via the in-app settings screen (Delete my account). Because a single kinnly account may belong to more than one family, deletion behavior depends on your role in each family you're a member of:
For each family where you are the only parent (no co-parent has joined): we perform a full cascade deletion. Every family-scoped record — journal entries, expenses, messages, vault documents, events, medications, contacts, children's profiles, and the family record itself — is permanently deleted, along with every file you uploaded to storage.
For each family where a co-parent is linked: we unlink your account from that family so your co-parent still has access to their family record. Content you contributed to the shared family record — such as journal entries you posted, expenses you logged, and messages you sent — is retained as part of your co-parent's family history. If you would like specific content removed before deletion, please do so from within the app before initiating account deletion. Chat messages are the exception: deleting one hides it but keeps its text in the family's record (Section 1.D).
After we process every family you belong to, we delete your authentication account so it cannot sign in again. Your notification preferences, your device and recovery keys with every encrypted copy of a family key made for them, your pending invites, and any other account-level data are also deleted at that point.
Contact us at privacy@kinnlyapp.com if you have questions about deletion in any of these scenarios, or to request other data-rights actions.
6. Changes to This Privacy Policy
We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on our website and updating the "Effective Date" at the top.
7. Contact Us
If you have any questions about this Privacy Policy, please contact us at: privacy@kinnlyapp.com
8. Children's Data
kinnly is designed for use by parents (18 years or older). Children do not create kinnly accounts today, and there is no way for a child to sign in to the current app.
kinnly does collect information about your children — names, birthdays, optional photos, and optional health information — because that is essential to co-parenting coordination. You, as the parent, decide what to enter. That information is subject to the same encryption and access controls described elsewhere in this policy: it is shared only with your linked co-parent and, where applicable, with the Family Circle members you have granted access to.
A companion application ("kinnly kids") is planned for future release. When that companion app becomes available, we will update this policy to describe the additional safeguards, parental consent workflow, and data-handling practices that apply to child users under COPPA.