1. Scope and who operates Kinlo
Kinlo is operated by Vasudhamma Modem (“Kinlo,” “we,” “us,” or “our”). This Privacy Policy applies to the Kinlo mobile apps, private browser-sharing experience, getkinlo.app website, beta program, historical waitlist, and related services (together, the “Service”).
Contact us about privacy at vmodem.dev@gmail.com.
2. Adults and child-related information
Kinlo is intended for adults, including parents, guardians, and adult relatives. It is not directed to children, and children may not create or operate Kinlo accounts. An account holder must have reached the age of legal majority where they live.
Adults may choose to add information about children to a private family space, such as a nickname, birth month and year, photos, videos, audio, stories, or milestones. If you provide information about a child or another person, you are responsible for having the authority and permissions required to do so.
3. Information we collect
Account and profile information
We collect information used to create and secure your account, such as your email address, display name, profile photo, authentication provider, Kinlo user ID, and sign-in records. If you use Apple or Google sign-in, they provide the account details you authorize them to share.
Family and people information
We collect family names, memberships, roles, invitations, and people connected to a family. You may optionally provide a child’s nickname and birth month and year, and names or other details for people who appear in family content.
Memories, Milestones, media, and interactions
We collect content you create or upload, including titles, stories, dates, locations you type or speak, participants, photos, videos, uploaded audio, thumbnails, comments, reactions, and related metadata. We store information needed to organize, search, display, synchronize, and share that content with authorized people.
Voice capture and AI processing
If you use voice capture, we process the recording, transcript, relevant request context, and generated draft. Configured Google services, including Gemini, transcribe and structure the recording into an editable Memory or Milestone preview. You can review and change the preview before saving it. The source voice recording is not automatically saved as an audio attachment.
Private sharing and guest access
When you share eligible content, we collect the recipient, share token, guest or browser-session identifiers, access status, expiration or revocation information, viewed-entry activity, and security events needed to deliver and protect the share.
Subscriptions and storage
If you purchase Kinlo Plus, Apple or Google processes payment. We receive purchase and entitlement information, including the store, product, status, renewal or expiration state, and identifiers needed to associate the entitlement with your family. RevenueCat helps manage subscription entitlements. We do not receive your full payment-card number from the app stores.
Notifications
If you enable notifications, we collect a push token, time zone, preferences, and notification delivery or open information so we can send family activity and On This Day notifications.
Usage, device, and diagnostics
We collect limited app version, operating-system and device context, feature events, coarse usage buckets, errors, crashes, stack traces, performance information, and security events. Authenticated usage events may be associated with a Kinlo user ID. Kinlo’s telemetry rules prohibit family story text, media, transcripts, child-profile details, and raw family or content identifiers in analytics event properties.
Website, beta links, and historical waitlist
Google Firebase Hosting hosts getkinlo.app and may process ordinary request information, such as IP address, browser, requested page, and security or operational logs. If you allow website analytics, Google Analytics helps us measure visits and beta-link selections. The analytics page URL is limited to the requested path and sanitized standard UTM campaign values; raw Google and Meta advertising click IDs are removed before that page URL is sent. We may also send the referring hostname and which beta button was selected. We do not send family stories, photos, email addresses, or phone numbers in website analytics events.
Separately, Kinlo keeps sanitized standard UTM campaign values in same-tab session storage for first- and last-touch measurement. Campaign values are limited in length, and raw Google or Meta advertising click IDs are not retained in this attribution record. Your analytics choice is kept in local browser storage so the site can remember it; you can change that choice from the website footer.
When you choose an Apple or Google beta link, the outbound URL may include the sanitized UTM campaign values so the referral context remains attached to that click. If you previously joined the Kinlo waitlist, Kit processes your email address and available campaign, landing-page, and referring-page information to manage confirmation and launch emails. You can unsubscribe from those emails at any time.
Support
If you contact us, we collect your contact details, message, attachments you choose to send, and our response. Please do not send passwords, authentication codes, or private family media unless it is necessary to resolve the request.
Information on your device
Kinlo stores preferences, authentication state, cached decrypted media, and pending upload files on your device to operate the app and improve reliability. Logout, cache eviction, uninstall, and operating-system behavior affect when local information is removed.
4. How we use information
We use information to:
- create, authenticate, secure, and administer accounts and families;
- store, organize, search, display, and synchronize family content;
- prepare editable voice-capture drafts at your request;
- deliver invitations, private sharing, and revocation controls;
- send notifications and respect notification settings;
- measure storage use and provide Free or Kinlo Plus entitlements;
- provide support and service, security, transaction, and legal notices;
- diagnose crashes, maintain reliability, and understand feature performance;
- prevent fraud, abuse, and unauthorized access; and
- comply with law and protect users, Kinlo, and others.
Kinlo does not sell personal information, use it for cross-context behavioral advertising, or display third-party advertising in the first-release Service.
5. How information is disclosed
Your family and people you authorize
Family content is available to members according to their role and the Service’s access controls. When you invite someone or create a private share, we make the selected content and context available to that recipient. Revoking access prevents future access through Kinlo, but it cannot erase a copy or screenshot the recipient already made.
Service providers
Our current provider categories include:
- Google Firebase and Google Cloud for authentication, databases, server functions, configuration, push delivery, crash reporting, key management, and website hosting;
- Google Analytics for consented website campaign and beta-link analytics;
- Google Gemini for voice transcription and editable capture processing;
- Cloudflare, including R2 for encrypted-media transport, storage, and private web-sharing infrastructure;
- PostHog for privacy-filtered product analytics;
- Apple and Google for sign-in and app-store billing;
- RevenueCat for subscription and entitlement management;
- Kit for historical waitlist and launch-email management.
We may also preserve or disclose information when reasonably necessary to comply with law or valid legal process, enforce our agreements, investigate fraud or security incidents, or protect rights and safety. Information may transfer as part of a merger, acquisition, reorganization, financing, or sale of assets, subject to this policy and applicable law.
6. International processing
Kinlo and its providers may process information in the United States, India, and other countries where they operate. Those countries may have different privacy laws. Where required, we use contractual, technical, and organizational safeguards for international transfers.
7. Retention
We keep information only as long as reasonably needed to provide and secure the Service, fulfill the purposes in this policy, comply with law, resolve disputes, and enforce agreements. Retention depends on the information and why we hold it:
- account and profile information is retained while the account is active and through the time needed to complete a verified deletion request;
- family content and media is retained until an authorized person deletes it, the contributing account is deleted, or the family is deleted;
- voice-capture requests are retained only as needed to return the editable draft, secure the feature, and satisfy the configured provider’s operational requirements;
- private-share sessions and audit events are retained through expiration or revocation and for a limited security period;
- same-tab website campaign attribution is retained for the browser session, your analytics choice remains until you change it or clear browser storage, and Google Analytics identifiers are configured to expire after up to 90 days while analytics events follow the configured provider retention;
- analytics, crash, and operational data follows the configured provider retention needed for product and security operations;
- waitlist information remains until you unsubscribe or ask us to delete it; and
- transaction records may be retained to meet entitlement, tax, accounting, fraud-prevention, and legal obligations.
Deleted information may remain temporarily in restricted backups or security logs until those systems are overwritten under their normal retention cycle. We do not restore deleted information to ordinary use.
8. Security and encryption
We use administrative, technical, and organizational safeguards, including access controls, encrypted network connections, app-integrity checks, and monitoring. Media bytes are encrypted on your device before upload, and Cloudflare R2 stores the encrypted object. Per-object media keys are handled through Kinlo’s key-management design.
Account information, family membership, some timeline metadata, comments, reactions, sharing data, billing state, analytics, diagnostics, and voice-capture requests may be readable by Kinlo systems or providers when needed to operate the Service. No online system is completely secure.
9. Account and family deletion
You can initiate account deletion in Kinlo settings. We may require a recent sign-in or another verification step. A family owner must first transfer ownership to another adult or choose the whole-family deletion flow.
Personal-account deletion removes the person’s authentication, profile, membership, person record, push tokens, account-only preferences, and user-generated content associated with the account, including Memories, Milestones, media, comments, and reactions shared with the family. Kinlo explains the effect on the family archive before final confirmation. Whole-family deletion removes the family, its content and media, memberships, and guest access, subject to limited legal, fraud-prevention, security-log, and backup-expiry exceptions.
A public deletion-request option is available at getkinlo.app/delete-account.
10. Your choices and privacy rights
Depending on where you live, you may have rights to request access, correction, deletion, or a portable copy of personal information; to object to or restrict some processing; to withdraw consent where processing depends on consent; or to appeal our response.
Kinlo settings let you update eligible profile and family information, edit or delete content, revoke shares, manage notifications, and initiate account deletion. To make another privacy request, email vmodem.dev@gmail.com. We may verify your identity and authority to protect family information. We will not discriminate against you for exercising an applicable right.
11. Children’s privacy
Kinlo does not knowingly allow a child to create or operate an account. Adults may submit child-related information to a family archive and are responsible for having the parental responsibility, guardianship, permission, or other lawful authority required for that submission and sharing. If you believe a child created an account or information was submitted without appropriate authority, contact us so we can review it.
12. Changes to this policy
We may update this policy when the Service, law, or our practices change. We will post the revised policy with a new effective date. If a change materially affects your rights or how we use information, we will provide additional notice when required, such as in the app or by email.
13. Contact
Vasudhamma Modem
Email:
vmodem.dev@gmail.com