Privacy policy
Last updated: August 2026
Kin is built on the principle that your family's data belongs to your family. This policy explains what we collect, why, and your rights.
What we collect
We collect the minimum necessary to run the service: account credentials (name, email, hashed password), circle membership data (roles, permissions, tasks, routines, calendar events, shopping lists), and device tokens for push notifications. We do not collect advertising identifiers, browsing history, or any data unrelated to the service.
Error monitoring
When something breaks, Kin sends a crash report to Sentry (hosted in the EU) so we can fix it. The report is scrubbed before it leaves the device or the server on a deny-by-default basis: fields are removed unless they have been explicitly allowed, so the contents of your tasks, events and lists are not in it. What remains is the shape of the failure — the code path, the error type, the app version.
Usage analytics
We keep a pseudonymized, append-only record of product events (an `analytics_events` table) to see which features are actually used and where people get stuck. Events are tied to a circle and a pseudonymous member reference, never to your name or email, and they never contain the content of a task, an event or a list. This is our own table on our own servers — there is no third-party analytics SDK in Kin, on the web or in the app.
How we use it
Your data is used solely to provide the Kin service: routing tasks, sending notifications, generating routines, and enforcing permissions. We do not sell, share, or license your data to third parties for advertising or any other commercial purpose.
Connected calendars (Google & Microsoft)
Connecting an outside calendar is optional and is done per member, from Settings → Connected services. Until a member completes that consent flow, Kin reads nothing from any outside account.
Access is read-only, always. Kin requests only the permissions needed to read calendars and their events, plus your account’s email address so we can label which account was linked. Kin never requests write access and cannot create, edit or delete anything in a connected calendar.
What we read and store: the list of calendars on the account, so the member can choose which ones to sync; for the selected calendars only, the events inside a bounded window — currently one month back and twelve months forward; and the account’s email address as the connection label.
Why: so those events appear beside your family’s own events in the Kin calendar. Nothing else. This data goes into your family’s own circle and is visible according to the member’s own visibility choice. It is not sold, not shared with third parties, not used for advertising, and not used to train any model.
Tokens: the OAuth access and refresh tokens are encrypted at rest and are never sent to the mobile app.
Disconnecting: any time, from Settings → Connected services. The events Kin synced are removed from your family’s calendar immediately, and Kin asks the provider to revoke the token. Google supports that; Microsoft does not publish a per-token revoke endpoint, so for a Microsoft account remove Kin from your account’s app permissions as well. You can always revoke Kin’s access to Google independently at https://myaccount.google.com/permissions.
Kin’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Data retention & deletion
Ask us and we’ll export or delete your family’s data — email [email protected] and we’ll action it within 30 days. A self-serve screen in the app is on the way; the right doesn’t wait for the button. When a member is removed from a circle, their personal identifiers are replaced with "Deleted Member" in historical records to preserve audit trails without retaining personal data.
AI-assisted features
Some Kin features can use an AI model — describing your week in words to draft a routine, turning "dentist thursday half four" into an event, and suggesting adjustments from your family’s own activity. They are off until the circle owner turns them on, and a family shares one budget of AI actions per month across all of them. What we send is pseudonymized and limited to what the request needs: the model sees "Child A", not your child’s name. Nothing an AI drafts is created until someone reviews and accepts it. Your family’s information is never shared with another family, and we do not use it to train models. Which provider serves a request is a configuration choice — Anthropic, OpenAI and Google models are supported.
Connected speakers (Alexa)
If a member links an Amazon Alexa device, Kin can add a single item to a shopping list by name when asked out loud. What leaves your household is that spoken item name, forwarded by Amazon to Kin — nothing else: Kin cannot read your lists back, change quantities, or remove items by voice. Amazon’s own terms and privacy policy govern what the speaker itself records. A link can be disabled at any time from Settings, which stops it immediately without unlinking, or removed entirely, which revokes its access token for good.
Minors
Kin supports family circles that include children. Children's accounts are managed by the circle owner (a parent or guardian). We do not knowingly collect personal data from children outside of the family circle context, and we do not use children's data for any commercial purpose.
Your GDPR rights
If you are in the European Economic Area, you have the right to access, correct, export, or delete your personal data. You also have the right to object to processing and to lodge a complaint with your local supervisory authority. To exercise these rights, email us at [email protected].
The waitlist
If you give us your email address for the Kin waitlist, we use it for exactly one thing: to tell you when Kin opens up. We confirm the address first — you are only on the list once you click the link in that confirmation email — and every email we send carries a one-click unsubscribe that needs no account and no explanation. We do not store your IP address or your browser’s user agent with a signup, we do not profile you, and we never pass the address to anyone else.
Cookies
This website uses only strictly necessary session cookies (no tracking or advertising cookies), and loads no third-party scripts or fonts. The mobile app does not use cookies.
Changes to this policy
We will notify you of material changes via in-app notification at least 30 days before they take effect.