Kinship Privacy Policy

Effective date: 2026-06-05
Last updated: 2026-08-24
Version: v2.5 — product scope
Replaces: Privacy Policy v1.1 (pre-launch invite phase), archived at /legal/privacy/invite-phase.


0. The short version

  • We are S4 Solutions, LLC. We run Kinship at kinshiprm.app and the app itself at my.kinshiprm.app.
  • Kinship is a personal relationship manager, so what you give us is your contacts and what you remember about them. That is sensitive data and we treat it that way.
  • We do not sell your data, show ads in the product, or train AI models on your data ourselves.
  • Our two AI vendors are different from each other, so §3.2 states each one separately instead of making one blanket promise. Anthropic is contractually barred from training on our inputs and outputs. Voyage AI's terms allow training by default; we have switched on the opt-out Voyage offers, but that opt-out only works going forward.
  • The free tier never reaches any third-party AI model. Paid AI features run only after you switch them on, and only on the note or query you point them at.
  • You can export your data and delete your account yourself from Settings. Export is free on every plan, including the free tier (§11.2). If you would rather ask us, use /contact?topic=privacy.
  • We offer Kinship in the United States only. We do not yet serve the EU, UK, Australia or anywhere else — see §12.

The rest of this policy is the detail.


1. Who we are and what this policy covers

S4 Solutions, LLC, a Georgia limited liability company, is the controller of your personal data. In this policy, "we" means that company. The policy covers the marketing site at kinshiprm.app, the application at my.kinshiprm.app, and any other sub-domain we run as part of the Service.

This policy replaces Privacy Policy v1.0 of 2026-05-14, the pre-launch invite-phase policy. We keep v1.0 archived at /legal/privacy/invite-phase so what we promised invite-form submitters stays on the record.


2. What personal data we process

2.1 Account data

Created when you sign up through Google or Microsoft. We do not offer email-and-password sign-up.

  • Your account email, profile name, and profile picture URL, from the sign-in provider.
  • Timestamps for account creation, last sign-in, MFA enrolment, and plan tier.
  • A separate display name you can set or change.

2.2 Contacts and the notes you keep on them

Created when you add a contact, write notes, log an activity, or record a life event.

  • Contacts: name, emails, phone numbers, organisation, role, tags, and any free text you fill in.
  • Activities: the raw notes you write, dates, the contact they relate to, and an AI summary if you have AI features on (§3).
  • Life events: title, description, date, and the contact they belong to.
  • Snapshot shares you create: a frozen copy of the contact as it was when you shared it, the recipient email, the expiry time, and any revocation.

This is the most sensitive data we hold, and we design around it that way — encryption, row-level security, and AI gating — whether or not U.S. law classifies it as sensitive.

2.3 Integration data

Created when you connect a Google or Microsoft account. Every scope we request is read-only.

  • The OAuth access and refresh tokens for that account, encrypted at rest in Supabase Auth's vault.
  • The least metadata the sync needs: your Google or Outlook contact entries, and for mail and calendar, subject, snippet, sender, recipients and date only — never message bodies.
  • A pointer back to the source, so we can deduplicate and you can disconnect.

We never send email, create calendar events, or write anything back to a connected system.

2.4 AI feature data (paid plans, opt-in)

Created only when you are on a paid plan, have switched AI features on in onboarding or /settings/privacy, and then use one.

  • The note, activity, or query you point the feature at — sent to the AI vendor for that request (§3).
  • The structured "contact document" we build for natural-language search: the contact's name, current role and organisation, tags, up to 20 activity summaries or notes, and life events.
  • Any AI output we store back against your account, such as summaries and suggestions.
  • An invocation log recording the feature name, plan tier, consent status, whether the request succeeded or was refused, and timestamps. We use it for auditing, debugging, and — in aggregate — for alerting when AI requests are being denied.

2.5 Billing data

Created when you start a paid subscription.

  • Your Stripe customer ID, your subscription state and price, and the email Stripe sends back to us.
  • Stripe processes your card directly. We never see or store card numbers.

2.6 Support and correspondence

  • Messages you send through /contact — topic, free text, your email, and anything you attach.
  • Email you exchange with us about privacy, support, or legal matters.
  • In-app feedback, including the page and version metadata we need to investigate it.

2.7 Telemetry and analytics

  • HTTP request metadata — IP, user-agent, path, referrer, timing — in Vercel's platform logs.
  • Sentry error reports, with email, name, and IP stripped before they are sent.
  • Aggregate Google Analytics 4 events: only if you accept the cookie banner, with ad signals hard-denied, IP anonymised, and no cross-site tracking.
  • Rate-limit and one-time-passcode counters, keyed on hashed identifiers rather than raw ones.
  • First-party product analytics, recorded on our own systems with no third-party analytics SDK. Before you sign up we record which pages you visit on kinshiprm.app and where you came from. After you sign up we record what you do in the product — adding a contact, running a search, generating an AI summary, sharing a note. Each event holds its name, a timestamp, an anonymous visitor id and a short-lived session id (the __kship_aid and kinship_sid cookies in §10), your account id once you have one, and the page, referrer and campaign parameters. We link your pre-signup and post-signup events using those ids, so we can see how people find Kinship, whether onboarding works, and which features get used. These events stay in our own database, only a few authorised S4 administrators can read them, no user session can query them, and they are never sold, shared for advertising, or sent to an ad network.

2.8 What we do not collect

We do not collect government identifiers, biometric data, precise location, or financial-account numbers beyond the Stripe data above. We do not collect the contents of your connected mailbox. We hold no "sensitive personal information" under Cal. Civ. Code § 1798.140(ae) except the "account log-in credentials" that are the integration OAuth tokens in §2.3.


3. AI features and AI vendors

This is what users ask about most. Read the whole section before you opt in.

3.1 The default is off

  • AI features are paid plans only. Free-tier content is never sent to any third-party language or embedding model. Our servers enforce that; it is not just a hidden button.
  • Even on a paid plan, AI features are off until you turn them on, in onboarding or /settings/privacy. You can turn them off at any time, and that stops new requests immediately.

3.2 Which vendor gets what

VendorUsed forWhat we sendWhat we don't send
Anthropic, PBC (claude-sonnet-4-6)Note summaries, follow-up prompts, search reranking, relationship-health digestsThe note, activity, or query you point the feature at, plus minimal scoping metadataYour full address book, OAuth tokens, payment details, other users' content
Voyage AI Innovations, Inc. (voyage-3)Embeddings behind natural-language searchThe structured contact document — name, current role and organisation, tags, up to 20 activity summaries or notes, life-event titles and descriptionsAnything for a contact you have marked do-not-summarise, anything from free-tier users, anything from users who have not switched AI features on

The two vendors have different training and retention postures, so we state them separately. A single promise would be wrong for one of them.

Anthropic — training. The Anthropic Commercial Terms in force say “Anthropic may not train models on Customer Content from Services.”

Anthropic — retention. Anthropic deletes inputs and outputs from its systems within 30 days. There is one exception you should know about: where Anthropic's automated trust-and-safety systems flag content as a Usage Policy violation, Anthropic may keep that request and response for up to 2 years and the resulting classification scores for up to 7 years. Anthropic says this applies even under a zero-retention arrangement. We have not signed a separate Zero Data Retention agreement with Anthropic; if we do, we will say so here.

Anthropic — where processing happens. Anthropic's data-residency contract pins storage to the United States, but it does not by itself pin inference: by default the Claude API can route a request to any available geography, which Anthropic describes as selected countries in the United States, Europe, Asia and Australia. So we do not rely on the default. Kinship marks every Claude request for U.S. inference, and every Kinship AI feature runs on a model that accepts that instruction. If a model cannot carry it, we refuse the request rather than send it — the feature fails visibly instead of quietly running outside the U.S. The result is that both inference and storage for Anthropic-processed Kinship data happen in the United States.

Voyage AI makes no equivalent commitment. Voyage's Terms of Service (§3, last updated 2026-05-27) give Voyage a licence to use Customer Content “to train, improve, and otherwise further develop the Service (such as by training the artificial intelligence models we use)” by default. Voyage offers a dashboard opt-out, but it is prospective only — Voyage says “any data provided prior to your opt out may continue to be subject” to that licence. Without the opt-out Voyage states no retention period; with it, Voyage says Customer Content “will be immediately deleted… after it is processed for you.”

Status as of 2026-08-09: we have the Voyage opt-out enabled. Our founder checked it directly in the Voyage dashboard on that date and reported it was already on before then. Voyage publishes no API or receipt for the setting, so we tell you the basis for our statement rather than overstate it. Because the opt-out only works going forward, and we cannot establish when it was first switched on, we do not claim that anything sent to Voyage before 2026-08-09 is outside Voyage's training licence. We believe that window is empty, because Voyage traffic is switched off in production — but we state the limit rather than rely on the belief. Earlier versions of this policy said Voyage does not train on your data and deletes inputs within 30 days; Voyage's published terms did not support that, and it is corrected here. If you do not want your data reaching either vendor, turn AI features off in settings.

3.3 Extra consent step for Voyage AI

If you switched AI features on under a disclosure earlier than v1.3.0, Voyage AI was not named at the time you consented. We have paused embedding requests for your account until you have seen an in-product notice naming Voyage, the data sent, the processing location, and Voyage's actual training and retention posture as set out above, and have acknowledged it. Anthropic-backed features keep working, because Anthropic was named in v1.2.0.

3.4 Your notes and AI output are kept apart

Deleting an AI summary does not delete your notes, and deleting your notes does not remove a summary we already saved. Withdrawing AI consent clears future AI summaries and leaves your raw notes untouched.

3.5 30 days' notice before we change AI vendor

This is the commitment in Terms §6, repeated here.


4. Integrations

The full detail is in the Subprocessor List. In summary:

  • Google (Contacts, Gmail, Calendar, Tasks): read-only scopes only. We do not store mail or calendar bodies — only subject, snippet, sender, recipients and date, so we can log the activity.
  • Microsoft Graph (Outlook Contacts, Mail, Calendar, Tasks): the same posture as Google.
  • LinkedIn: import from your own data export only. Your browser parses the files and we store the parsed rows. We call no LinkedIn API and use no scrapers or unofficial intermediaries. What we read from your export:
    • connections.csv — name, company, title; creates contacts.
    • messages.csv — sender, recipients, date, message body; stored as activities against matching contacts.
    • invitations.csv — invitations sent and received, and any attached note; stored as activities against matching contacts.
    • Contacts.csv — emails and phone numbers, added to contacts you already have. It never creates a new contact.
    • Recommendations_Given.csv and Recommendations_Received.csv — recommendation text; stored as activities against matching contacts.
    • Endorsement_Given_Info.csv and Endorsement_Received_Info.csv — endorsement events; stored as activities against matching contacts.

Disconnecting an integration in /settings/integrations revokes our OAuth grant and deletes the stored token. Anything already imported stays in your contacts for you to delete.


5. Our lawful bases for processing

U.S. law does not generally require us to publish this. We do it because we plan to operate in higher-protection jurisdictions later, and the discipline is good for us.

DataBasis (GDPR Art. 6 / CCPA business purpose)
Account (§2.1), billing (§2.5), correspondence (§2.6)Contract — needed to give you the Service you signed up for.
Contacts, notes, life events (§2.2) — about youContract — needed to give you the Service.
Contacts, notes, life events (§2.2) — about other people in your address bookLegitimate interest (Art. 6(1)(f)) — we run a personal CRM on behalf of the user, who controls the contact record. Subject to §11.6.
Integration data (§2.3)Consent — given at the OAuth grant, withdrawn by disconnecting.
AI feature data (§2.4)Consent — opt-in in onboarding or settings, withdrawable at any time.
Telemetry (§2.7) for security, fraud, and abuseLegitimate interest — the minimum needed, never for advertising, anonymised where we can.
First-party product analytics (§2.7), including linking pre-signup to post-signup activityLegitimate interest — measuring and improving the Service. Never for advertising, ad profiling, or any automated decision that affects you.
Google Analytics 4 (§2.7)Consent — the cookie banner, with no ad signals.
Legal claims and subpoenasLegal obligation.

6. How long we keep your data

DataHow long
Your account recordWhile the account exists; deleted within 30 days of account deletion.
Contacts, activities, life eventsWhile the account exists; deleted within 30 days of account deletion, apart from the backups below.
AI summaries and embeddingsAs long as the contact or activity they belong to, or until you withdraw AI consent, which clears the summaries.
Raw notesWhile the account exists; deleted independently of AI summaries.
OAuth refresh tokens (Google, Microsoft)Until you disconnect the integration.
Vercel runtime logs24 hours rolling on Vercel Pro.
Vercel build logsStored indefinitely per deployment, per Vercel's documentation.
Sentry error reports30 days.
Google Analytics 4 raw events2 months.
In-product engagement eventsWhile the account exists. Deleted with your profile when you delete your account — normally immediately, and always within 30 days.
First-party product-analytics events (§2.7)25 months from the date of the event. After that a monthly job permanently erases every identifying field on the row — your account id, the __kship_aid visitor id, the kinship_sid session id, the page URL, the referrer, and the campaign parameters. Only the event name, its timestamp, and non-identifying properties survive, in a form that can no longer be linked to you or your device. Separately, if you delete your account we remove your account id from these rows at the time of deletion, and always within 30 days.
The record linking a visitor id to an accountWhile the account exists. Deleted when you delete your account, and always within 30 days, so pre-signup and post-signup activity can no longer be re-linked.
Rate-limit and passcode countersExpire automatically on rolling windows; not stored long term.
Supabase daily backups7 days of daily backups on the Supabase Pro plan. We do not have point-in-time recovery enabled.
AI invocation logWhile the account exists, then 90 days after deletion, with your user id replaced by a hashed identifier. We do not keep the raw user id past account deletion.
Data-rights request log24 months, with identifiers hashed, to defend legal claims.
Email correspondence with usUp to 36 months, or sooner if you ask.
Snapshot-share records7 days from creation for the share itself, plus 24 months of revocation audit.

Deleting your account in the app is immediate and final, with no post-deletion export window. Encrypted backups age out on the schedule above.


7. How we secure your data

  • In transit: TLS on all traffic, between you and us and between us and our vendors.
  • At rest: Supabase-managed AES-256 on the database and file storage.
  • Row-level security: every table holding account data carries a policy keyed to your user id, enforced by the database itself.
  • Read-only OAuth: across every integration and every tier.
  • One AI chokepoint: a single place in our code checks plan tier, consent version, opt-out, and age gate before any third-party AI call.
  • MFA: available through Supabase Auth.
  • Audit logs: for AI invocations, share revocations, and data-rights requests.
  • Reporting a vulnerability: email security@kinshiprm.app. We acknowledge within 5 business days.

8. Our vendors and where they process data

Our full list — Anthropic, Voyage AI, Google, Microsoft, Supabase, Vercel, Stripe, Resend, Sentry, Upstash — is at /legal/subprocessors, with each one's legal entity, role, data received, processing location, and a link to its data-processing agreement.

Every current vendor except Voyage AI processes personal data in the United States. For Anthropic, storage is U.S. by contract and inference is U.S. because we pin it on every request rather than accept the API's multi-region default (§3.2). Voyage AI's published terms do not confirm a U.S.-only processing location for its embeddings API, and Voyage traffic is switched off in production. We do not offer the Service outside the United States, and signups from elsewhere go to a waitlist. If we start serving non-U.S. users we will update this section with the transfer mechanisms we rely on, such as the EU Standard Contractual Clauses and the UK Addendum.


9. Who we share your data with

We do not sell or rent personal data to anyone. We share it with:

  • The vendors in §8, only for the purposes named there and under a data-processing agreement.
  • People you send a snapshot to — only the frozen snapshot you chose, only at the link you generated, and only until you revoke it or the 7-day expiry passes. The representations in Terms §8 attach when you share.
  • Legal requests, where valid legal process requires it. We push back on overbroad requests where it makes sense.
  • A successor in a merger, acquisition, or asset sale, under the same or stronger privacy commitments. We will tell you by in-product banner and email at least 30 days before the transfer, unless the law forbids it.

We do not share with advertising networks, data brokers, employers, recruiters, outplacement firms, or anyone buying training data.


10. Cookies

The marketing site uses Google Analytics 4 cookies, and only if you accept the cookie banner. We also set two cookies of our own that no third party can read and that are never used for advertising: __kship_aid, an anonymous visitor id kept for 1 year, and kinship_sid, a session id kept for 30 minutes. We use them only to count visits and measure our own signup and onboarding funnel (§2.7), and we treat them as functional rather than advertising cookies. The app also sets the standard essential cookies needed to keep you signed in and to prevent cross-site request forgery. We use no advertising cookies, beacons, or pixels.

We do not respond to "Do Not Track" signals. We do no behavioural advertising and no cross-site tracking. If you decline analytics cookies, Google Analytics 4 does not load.


11. Your rights and how to use them

11.1 Rights everyone has here

  • Access — get a copy of your data. Do it yourself in /settings (§11.2), or ask us at /legal/data-request.
  • Correct — fix anything wrong. Contact and profile edits are self-service.
  • Delete — your account and everything tied to it, in /settings/delete-account. Deletion is immediate and final: no grace window and no export afterwards. Export first (§11.2 and Terms §13). Once you have deleted, we cannot rebuild your account from backups.
  • Withdraw consent — for AI features in /settings/privacy, for integrations in /settings/integrations, and for analytics cookies in the cookie banner.
  • Ask about someone else's data — use /legal/data-request, where we verify your identity by emailed passcode.

11.2 Exporting your data yourself

You can export at any time from the Data export section of /settings, also linked from /settings/privacy. You get one structured, machine-readable JSON bundle of everything tied to your account, free on every plan including the free tier.

Because an export is a copy of everything you have stored with us, three safeguards apply: your email must be verified, you must have signed in recently so we may ask you to sign in again, and you can run at most three exports in 24 hours. Exports never include your encrypted OAuth tokens.

If you would rather not use the tool, or cannot reach it, ask at /legal/data-request or /contact?topic=privacy and we will send you the same export within 30 days.

11.3 California (CCPA and CPRA)

  • Categories of personal information we collect: §2.
  • Where it comes from: you, Google or Microsoft when you connect them, CSV files you upload, and your own use of the Service.
  • Who receives it: the vendors in §8.
  • Why we collect and use it: to provide the Service, per §3, §4 and §6.
  • We do not sell or share personal information as the CCPA defines those terms, including for cross-context behavioural advertising. There is therefore no "Do Not Sell or Share My Personal Information" link to publish, but you can still make a formal request at /legal/data-request.
  • Right to limit use of sensitive personal information: the only qualifying category we hold is the OAuth credentials in §2.3, which we already use solely to run the integration. Revoke them any time in /settings/integrations.
  • We will not treat you differently for exercising your rights.

11.4 Virginia, Colorado, Connecticut, Utah, Texas, and similar state laws

You have rights of access, correction, deletion, and opt-out from sale, targeted advertising, and profiling that produces legal effects. Kinship does none of those three things. Use the same channels as §11.1 for the rest.

11.5 Children

Kinship is 18+ under Terms §2, and it is not directed at children under the age of digital consent where you live — 13 in the United States under COPPA, and 13 to 16 across EU member states. We do not knowingly collect children's data. Tell us if you think we have and we will delete it.

11.6 If you are someone else's contact

Kinship holds what our users record about other people — which may include you, if a Kinship user has added you as a contact. To exercise rights over that data, contact us at /legal/data-request or privacy@kinshiprm.app.

Because that data sits in another user's account, and that user controls the record, our default is to pass your request on to them. We will delete a contact record ourselves where there is credible evidence of harassment, doxxing, or other unlawful retention, or where a request comes with a court order or comparable legal process.


12. Data leaving the United States

We are a U.S. company. Every current vendor except Voyage AI processes data in the United States; Voyage's published terms do not confirm a U.S.-only location for its embeddings API, and Voyage traffic is switched off in production. If you reach the Service from outside the U.S., your data is transferred to the U.S. for processing.

We do not currently offer Kinship in the EU, UK, Australia, Canada, or anywhere else outside the United States. Signups from outside the supported jurisdictions go to a waitlist.

If we start serving non-U.S. users, we will update this section with the transfer mechanisms we rely on — such as the EU Standard Contractual Clauses and the UK Addendum — and any extra safeguards.


13. Australia

We do not offer Kinship in Australia today, and the signup geo-gate routes Australian visitors to a waitlist. If we start serving Australian residents, we will update this section to describe our position under the Australian Privacy Principles, including overseas disclosures under APP 8.


14. Children's privacy

Kinship is for adults aged 18 and over. We do not knowingly collect data from anyone under the age of digital consent where they live — 13 in the United States under COPPA, and 13 to 16 across EU member states. If we find we have, we delete it.


15. Changes to this policy

We post material changes here with a new effective date and a changelog entry at the bottom. If a change materially expands what we collect or who we share it with, we give paid-plan account holders at least 30 days' notice by in-product banner and email before it takes effect.

For changes to the Subprocessor List — including adding or replacing an AI vendor — the 30-day notice in Terms §6 governs.


16. Contact us about privacy


Changelog

  • 2026-08-24 — v2.5. Plain-language rewrite of the whole policy: shorter sentences, active voice, and the vendor and retention sections restructured so each fact stands on its own. We also removed links to our source code that pointed at a private repository and were therefore unreachable for readers; the claims those links were offered to support are unchanged and stated in full here. No change to what we collect, how we use it, how long we keep it, or who we share it with.
  • 2026-08-09 — v2.4. Correction: the Voyage AI opt-out is enabled. §0 and §3.2 previously said we had not confirmed executing the opt-out that Voyage's terms otherwise require. That understated our actual protections: our founder verified on 2026-08-09 in the Voyage dashboard that the opt-out is on, and reported it was already on before that date. Voyage publishes no receipt for the setting, so §3.2 now states the basis for the claim rather than a date we cannot establish. Because the opt-out only works going forward, §3.2 does not claim it covers anything sent before 2026-08-09. This corrected a disclosure in the user's favour; no vendor was added, removed, or replaced, and nothing changed about what we send or when, so the 30-day notice in Terms §6 was not triggered.
  • 2026-08-07 — v2.3. Correction: AI vendor training and retention were misstated. Versions up to v2.2 said both AI vendors were contractually barred from training on our inputs and outputs, with a single up-to-30-day retention window each. That was wrong for Voyage AI, whose terms permit training by default and publish no retention period without the opt-out, and incomplete for Anthropic, because the 30-day figure omitted the trust-and-safety exception under which flagged content may be kept for up to 2 years and classification scores for up to 7. §3.2 now states each vendor separately. No vendor was added, removed, or replaced, and nothing changed about what we send or when, so the 30-day notice in Terms §6 was not triggered.
  • 2026-08-02 — v2.2. Corrected the data-export description: self-service export had shipped and is free on every plan, but the policy still described it as unreleased and pointed at a route that did not exist. Also removed a reference to a 30-day post-termination export window, which never existed and contradicted Terms §13. No change to what we collect, how we use it, or who we share it with.
  • 2026-07-27 — v2.1. Disclosed our first-party product analytics and the linking of pre-signup to post-signup activity, added the matching lawful basis and retention rows, and named both first-party cookies with their purpose and lifetime.
  • 2026-06-05 — v2.0. First product-scope Privacy Policy, replacing the invite-phase Privacy Policy v1.1 archived at /legal/privacy/invite-phase.
Privacy Policy — Kinship