Privacy policy
Effective date: [FOUNDER: effective date]
The short version
- The most personal things Kinwyn handles never leave your phone: your journal, your places, camera frames and audio, and the names of your apps.
- Our server holds an account, daily totals of minutes, and the records needed for circles, key holders, invites and subscriptions.
- Your circle and your key holder see minutes and streaks only.
- You can export your data and delete your account from inside the app.
Who is responsible
Kinwyn is provided by [FOUNDER: legal entity name], [FOUNDER: postal address]. For any privacy question or request, write to [FOUNDER: privacy contact email].
What stays on your phone and is never sent to us
- Journal text. It is stored on your device. Only the fact that you earned journal minutes that day is counted.
- Pin locations. Your stay-away pins and your location stay on your device. Only “avoided today: yes or no” is reflected, as minutes in your daily total.
- Camera frames and audio. Push-ups and squats are counted on the device. Frames are not stored and not uploaded.
- Names of apps. Which apps you block, open or mark as good is not sent. Where a record on the server has to refer to an app or a pin, it uses a random id that means nothing outside your phone.
- Raw sensor data. Step-sensor readings, screen events and similar signals are processed on the device. Only the resulting totals are sent.
What our server holds
| Data | Why |
|---|---|
| Email address | To sign you in. We email you a one-time code; there is no password. |
| Display name and home time zone | To show you to your circle and to decide when your day starts and ends. |
| Install hash, platform and an optional push token | The install hash is a random identifier the app creates when it is first installed and keeps in the phone’s secure storage. It is not derived from the device’s hardware or advertising identifiers. It lets us tell whether a device already had Kinwyn, so invite rewards cannot be farmed, and whether a phone carries a kid’s profile: for 30 days after a kid’s profile is deleted or taken out of its circle, a new account created on that phone starts as a kid’s profile until a parent decides. The push token lets us send you notifications if you allow them. |
| Sign-in codes | The one-time code we email you is stored only as a salted hash, works for 10 minutes and for at most 5 tries, and is deleted about a day after it expires. |
| Hashed session tokens | To keep you signed in. We store only a hash of each token. A session ends after 90 days without use, or when you sign out. |
| Daily totals | Minutes earned per goal source, minutes spent, your streak, your step count, and a short coded “last action” such as reps:30. These power the circle, the weekly ranking and the parent dashboard. Other people get your minutes and streak only; your step count is added into one total for the whole circle (the group goal). |
| Circle membership and invitations | Which circle you are in, your role in it (adult or kid), whether the owner made you a guardian of the circle’s kids, and the single-use invitations you created or accepted. |
| Key-holder links | Who holds the key for whom. For a key holder who uses the web link instead of the app, we hold the name you typed for them, their email address (so that we, not you, can send them their link; it is deleted when the link is removed, and only a salted hash of it stays), and a hash of their link’s secret token. |
| Rule-change records and current rule values | What kind of change was asked for, whether it makes your rules harder or easier, and when it takes effect; and the values currently in force (for example the minutes a goal earns, the night hours and price, and which blocked apps and pins exist), so that a change cannot be passed off as a tightening. Apps and pins appear only as random ids, never by name or place. |
| Requests and gifts | Emergency-unlock requests, gift requests, gifts of minutes, and how each was decided. |
| Promises | Who promised what to whom, the goal and target, the status, and the reward text exactly as the users typed it. Do not put anything sensitive in a reward text. |
| Nudges | That one circle member nudged another, and when. |
| Invite codes, redemptions and Virtue | Your invite code, who redeemed it, the install hash of the redeeming device, and your Virtue count. |
| Subscription status | Which plan is active, as reported by RevenueCat, and a log of the purchase events RevenueCat sent us (event id, type and time). We never receive your card details. |
| Product statistics (adults only) | For adult profiles the server records a few events to measure how Kinwyn is used: that an account was created, the size of a circle when an adult joins it, plan changes, and the minutes earned per goal source each day. They are stored with your account id in Cloudflare Workers Analytics Engine, which keeps them for three months. None are recorded for child profiles. |
| Abuse counters and request logs | To slow down guessing of sign-in codes and key-holder links and to limit how many emails can be requested, the server keeps counters keyed by your account id, or by a hash of the caller’s network address or of a key holder’s mailbox (they are deleted within about two days). Cloudflare also keeps technical logs of requests to the API (such as time, address requested and status) for a limited time; our code does not log request bodies, sign-in codes or tokens. |
Who can see what
- Your circle sees your display name, your minutes and your streak, and the circle’s combined step total. Never which apps, your journal, your places, your own step count or raw sensor data. In a circle of two, the other person can work out your steps from the combined total.
- Someone who has accepted an invitation to a circle sees nothing of it until the circle’s owner lets them in.
- Your key holder sees the same, plus the requests and rule changes that need their decision, and an alert if app locking was turned off on your phone. A rule change is described in general terms, for example “Unblock an app”, without naming the app.
- Parents (the circle’s owner, and adults the owner has made guardians) see their kids’ minutes and streaks and decide their requests. A kid’s journal is private, even from parents.
- A key holder who uses the web link sees your display name, the name you typed for them, and what needs their decision. We email them their link ourselves; you never receive it.
Children
- A parent creates a kid’s profile.
- A kid cannot delete their own account or leave the circle; a parent does that in the app.
- We record no analytics or product events for child profiles.
- Child profiles get no ads and no third-party tracking.
- A kid’s journal stays on the kid’s device and is not shown to parents.
Minimum ages and how parental consent is collected: [FOUNDER: minimum age and parental consent rules].
Companies that process data for us
| Company | What it does for Kinwyn |
|---|---|
| Cloudflare | Hosts this website, the Kinwyn API and its database, and runs Turnstile, the human check on the key-holder web page. |
| Resend | Delivers our sign-in and key-holder emails. It receives the recipient’s email address and the message. |
| Expo push service, with Google (FCM) and Apple (APNs) | Delivers push notifications to your phone. |
| RevenueCat, with Apple and Google | Handles purchases and tells us which plan is active. Payment itself is handled by Apple or Google. |
Where these companies process data, and the safeguards for transfers between countries: [FOUNDER: international transfer terms].
This website
- This site sets no cookies of its own, runs no analytics and loads no advertising.
- Fonts are served from this site, not from a font service.
- The key-holder page stores nothing in your browser. Your link’s secret token is sent only to the Kinwyn API. When you approve, deny or gift, Cloudflare Turnstile runs a check that you are a person; Turnstile is operated by Cloudflare under its own privacy terms and may use signals from your browser to do this.
- The invite page reads the code from its own address and shows it to you. It sends nothing to our server.
- Like any website, the hosting provider processes your IP address to deliver pages.
Why we use your data
We use the data above to run the service you asked for: signing you in, keeping your wallet rules honest, showing totals to your circle, letting your key holder decide, preventing invite abuse, delivering notifications and managing your plan. The legal bases we rely on: [FOUNDER: legal bases for processing].
Deleting your account and exporting your data
- Export. You can export your data from the app’s settings.
- Delete. You can delete your account from the app’s settings. This removes your account’s records from our server.
- What is kept. After deletion we keep the bare install hash of your device. If you had redeemed an invite, the inviter’s reward record also remains, with that install hash but no longer linked to you. This stops someone from deleting and reinstalling to collect invite rewards again. The log of purchase events is kept without your account id. Product statistics already recorded age out after three months.
- Data that only ever lived on your phone, such as your journal and pins, is removed from your phone when you uninstall the app.
How long we keep data
We keep your data while your account exists and remove it when you delete your account, except for what is described above. The server already removes some things on its own: expired sign-in codes after about a day; expired or signed-out sessions, expired key-holder links, used or expired invitations and expired kid invite codes after 30 days; requests nobody answered are closed after 24 hours. Other periods: [FOUNDER: retention periods].
Your rights
Depending on where you live, you may have rights to access, correct, delete, export or object to the use of your data. The export and delete tools in the app cover the most common requests. For anything else, write to [FOUNDER: privacy contact email]. The laws that apply and the authority you can complain to: [FOUNDER: country or region of establishment].
Changes to this policy
When this policy changes, we will update this page and its effective date.