Privacy Policy
This policy is written in plain English on purpose. You should be able to understand how your data is handled without a law degree. It was last internally reviewed on July 7, 2026, and is re-reviewed periodically; the effective date above reflects the current version.
The short version: the things most sensitive to your family — where you are, what you say, and the SOS alerts you send — are end-to-end encrypted. Our servers relay those as ciphertext they cannot read. We do not sell your data, show ads, or use advertising trackers. We also keep a small amount of account information our servers can read (your email, the display names you choose, who is in your family) because we need it to run the service and deliver a notification when something happens. This policy tells you exactly what falls in each bucket — honestly, including the parts that are not encrypted.
This service is directed to users in the United States, and our infrastructure is hosted in the United States.
1. What our servers CAN read
To be straight with you, these items are stored on our servers in a form we can read. We keep them to the minimum needed to operate the service:
- Email address (adult account holders) — for passwordless sign-in and transactional notices.
- Display names you set for family members — stored in plaintext so they can appear in a push-notification title (for example, who triggered an SOS).
- Family name, member roles, and child/adult flags — the structure of your family group.
- Check-in timestamps — when a member last checked in (not where).
- Subscription status, plan, and founder status — billing state. We never see your card number (Stripe handles that).
- Push notification token (FCM) — a token your device gives us so Firebase can deliver pushes. It is associated with your member record. Most pushes — including place arrival and departure alerts, location check-ins, SOS, and low-battery alerts — carry only a sender's display name and a timestamp; the actual details are delivered to your device over an encrypted channel and shown inside the app. Account-recovery, new-device sign-in, and family-management notifications additionally include a short description of the account event (for example, "a new device is trying to sign in to your account," or "a member has left the family group") so you can recognize it and act quickly. No push notification ever contains your location, your coordinates, your messages, or the names of your saved places.
- Active session records — which devices are currently signed in to your account (a session token bound to the device), so we know which devices may access the account. Removed when you sign out, when a session expires, or when a member is removed.
- A device fingerprint at sign-up — your device model, OS name/version, screen size, time zone, and locale, hashed and stored to detect and prevent abuse. This is a separate thing from your encryption key.
- Network information — your IP address is visible to our edge provider and recorded in our security/audit log for abuse prevention and rate limiting.
- Issue and error reports — if you send us an issue report from the app, we receive the description you type and, only if you check the box to include them, basic diagnostics (app version, platform, device model, OS version). Entirely user-initiated; the app does not send error logs on its own.
- Beta/NDA acceptance records — if you accept a beta or non-disclosure agreement, that acceptance is recorded and kept as a permanent legal record (see Retention).
- Parent/guardian consent affirmations — when an adult adds a child to a family, we record that the parent/guardian affirmation was given and when (see Children and Families).
2. What our servers CANNOT read
These are end-to-end encrypted (Curve25519 key exchange + NaCl box / XSalsa20-Poly1305; Ed25519 device authentication). They are encrypted on your device before transmission and at rest on your device; our servers relay ciphertext only:
- Your location — GPS coordinates shared between family members.
- Your messages — secure family chat content.
- Your SOS details — the location and context attached to an SOS. The notification we relay carries only the sender's display name and a timestamp.
Key-substitution protection
Each family member's device encryption key is recorded with a cryptographic attestation in a key-change ledger, so a key substitution is detectable rather than silent. The app also displays a safety number for each family member's keys, which members can compare in person or over a trusted channel to verify each other's devices. Our servers route ciphertext and never hold the keys needed to read it.
Two honest nuances
- Geofences: the zones you define live on your device and are not synced to our servers. But when you cross one, the arrival/departure event is relayed through our server (with family/member metadata) so the right people are notified. Configurations stay on-device; events transit the server.
- Maps & place search (Mapbox): to draw the map, search for a place, or turn a GPS fix into a street address, your device sends location coordinates and search queries to Mapbox (our maps provider). This is a direct third-party data flow from your device — see Third-Party Services.
3. What we do NOT collect at all
No passwords (authentication is passwordless). No payment card numbers, CVVs, or billing addresses (Stripe). No advertising identifiers (IDFA/GAID). No contact list, photo library, browser history, or other apps' usage. No driving, speed, or commute behavior. No per-user behavioral analytics — we do not log screen views, taps, navigation, or time-on-screen. We keep only aggregate, anonymous session counts with no per-user attribution.
4. Third-Party Services (processors)
We use a small set of service providers. Each receives only what its function requires:
- Stripe — payment processing. Receives your payment details directly; we never see card numbers.
- Firebase Cloud Messaging (Google) — push notification delivery. Receives your FCM token. Most push payloads carry only a sender display name and a timestamp; account-recovery, new-device sign-in, and family-management pushes also include a short event description. No push payload ever contains your location, coordinates, messages, or place names.
- Mapbox — maps, place search, reverse-geocoding. Receives location coordinates and place-search queries sent from your device.
- Resend — transactional email (magic-link, invites). Receives the recipient email address and the email content.
- AbuseIPDB — sign-up abuse/reputation check. Receives the IP address used at sign-up.
- Cloudflare — edge network and DDoS protection. Receives IP and request metadata for all traffic (terminates TLS at the edge).
- Hetzner — infrastructure hosting in the United States. Hosts our servers, which store the readable account data above and the encrypted blobs we cannot read.
We do not share, sell, or rent your data to anyone else. We have no advertising or data-broker relationships.
5. How long we keep data (retention)
- Account, family, and member data — kept while your account is active. On deletion, a 30-day recovery window applies, after which it is permanently erased.
- Beta/NDA acceptance records — retained permanently as a legal record — including the email address tied to that acceptance, so the record identifies who agreed and when — even after account deletion.
- Magic-link sign-in tokens — short-lived (minutes), single-use.
- Relayed encrypted messages/SOS/location not yet delivered — held briefly in memory for delivery (up to about 48 hours) and then discarded; never written to a database.
- Security/audit log and device fingerprints — automatically deleted after 90 days (a daily cleanup job removes anything older).
- Active session records — removed at sign-out, session expiry, or member removal; expired sign-in artifacts are swept by the daily cleanup job.
- Issue and error reports — kept while we investigate and improve the app; they are not currently on an automatic deletion schedule. You can ask us to delete yours at any time.
- Parent/guardian consent affirmations — retained as a record that consent was given (see Children and Families).
- Aggregate session counts — anonymous; not tied to you.
6. Your choices and rights
- Access — you can view your family's data in the app at any time.
- Deletion — an account holder can delete the account from the app. Deletion starts a 30-day scheduled erasure: during that window the account can be reactivated; after it, the account, encryption keys, and family-membership records are permanently removed from our servers and any active subscription is canceled. Adult members can leave a family at any time from within the app; minor members cannot leave on their own and must be removed by the account holder (their parent or guardian). Exception: beta/NDA acceptance records are kept as a permanent legal record, including the email address tied to the acceptance.
- Withdraw consent — stop using the service at any time, no penalty.
- A copy of your data — we do not currently offer a self-serve export feature. Your family's end-to-end-encrypted content already lives on your devices, not readable on ours. If you want a copy of the readable account data listed in Section 1, email privacy@kinsightsecure.com and we will provide it.
- Parental controls — see Children and Families.
We are not currently a “covered business” under California's CCPA/CPRA or Tennessee's TIPA (we fall well below their thresholds), and this service is directed to US users, so we do not offer GDPR-specific mechanisms. That said, we honor the access, deletion, and consent-withdrawal rights above for everyone, regardless of where you live.
7. Children and Families
Kinsight Secure is a family-safety product, and families include children. We are explicit about how that works rather than pretending we do not serve them.
- Only an adult (18+) can create and hold an account. A child does not create an account.
- A parent or guardian adds a child to their family group. At the moment of adding a child, the adult must affirm that they are the child's parent or legal guardian — this affirmation is the documented consent step, and we record that it was given.
- We do not collect a child's email address. Children are added as members without an account and without an email — by design.
- What we hold about a child is minimized to what the safety features need: the child's display name, their child/member role, a push token (to deliver alerts), and check-in timestamps. The child's location and SOS details are end-to-end encrypted exactly like any other member's; we cannot read them. The relayed push carries only the child's display name and a timestamp.
- No advertising, no sale, and no behavioral profiling of children (or anyone).
- Parental rights: the adult who manages the family can review what is shared, remove the child from the family, and delete the associated data through account deletion. A child cannot remove themselves from the family — only the account holder can remove a minor member.
If you believe a child has been added without the proper parent/guardian relationship, contact us at privacy@kinsightsecure.com and we will help.
8. Security Breach Notification
No system is perfectly secure. If we discover a breach of security affecting personal information that we can read, we will notify affected users without unreasonable delay and consistent with applicable state law (including Tennessee Code § 47-18-2107). Because your location, messages, and SOS details are end-to-end encrypted, that category of data is not readable by us — and would not be readable by an attacker who obtained it from our servers.
9. How We Protect Your Data
- End-to-end encryption for location, messages, and SOS (Curve25519 + NaCl box; Ed25519 device authentication), with device-key attestations recorded against silent key substitution.
- Encrypted on your device before transmission, and at rest on your device.
- Passwordless authentication — biometric plus a device-bound cryptographic key; no passwords are ever created or stored.
- TLS in transit on top of end-to-end encryption.
- US-based hosting with access controls; abuse and rate-limiting protections at the edge.
If You Are Being Tracked Without Consent
Kinsight Secure is built for consensual family safety. If you believe this app is on your device or tracking you without your knowledge:
- You can review who has access to your location and remove yourself from any family group in the app's settings.
- If you are experiencing domestic abuse, the National Domestic Violence Hotline is available 24/7: 1-800-799-7233 (or text START to 88788), or visit thehotline.org.
- If you are in immediate danger, call 911.
We design the app to make non-consensual tracking difficult, but no technology fully prevents misuse. If you find the app on your device without your knowledge, uninstall it and contact a trusted person, support service, or law enforcement.
Changes to This Policy
We may update this policy. When we make a material change, we will update the effective date above and notify you through the app, by email, or by other reasonable means. Continued use after a change takes effect means you accept the updated policy.
Summary
| Can KS read my location, messages, or SOS details? | No. Those are end-to-end encrypted; our servers relay ciphertext. |
| What can KS read on its servers? | Your email, the display names you set, your family structure, check-in timestamps, subscription status, push token, a hashed device fingerprint, your IP, signed-in device sessions, and any issue reports you send us. That's it. |
| Does KS sell my data or show ads? | No. Never have, never will. No advertising trackers. |
| Who else receives my data? | A small set of processors (Stripe, Firebase, Mapbox, Resend, AbuseIPDB, Cloudflare, Hetzner) — each only what its function needs. See Third-Party Services. |
| Can I delete my data? | Yes — account deletion triggers a 30-day erasure. Beta/NDA acceptance records are kept as a legal record. |
| Who sees my location? | Your family group's devices (and Mapbox, to draw your map). Not our servers. |
Contact: privacy@kinsightsecure.com
Stillwater Rise Group LLC — State of Tennessee, United States.