Skip to content
Kinello
How it worksPrivacySupport
Get the app
How it worksPrivacySupport
Get the app

A private hub for one family.

Kinello Privacy Policy

On this page
  1. Age and family profiles
  2. Data Kinello handles
  3. Purposes and legal bases
  4. Health data notice and choices
  5. AI processing
  6. When data is disclosed
  7. Retention and deletion
  8. Security
  9. Rights and requests
  10. Changes

Effective and last updated: September 2, 2026

Policy revision: 2026-09-02-activation-events

Kinello is a private, invitation-only family app. This policy explains what Kinello collects, why it is used, who can receive it, how long it is kept, and the choices and rights available to account holders. Contact: support@kinello.net.

Age and family profiles

Kinello login accounts are for people age 13 or older. A parent or other adult may create an adult-managed family-tree profile for a younger child, elder, or deceased relative. Those profiles do not receive login access. If Kinello learns that a login account belongs to someone under 13, it will delete the account and associated personal data.

Data Kinello handles

  • Account and identity data: email address, authentication-provider identifiers, display name, optional birthday and profile photo, account eligibility attestation, and legal-notice versions accepted.
  • Private family content: family membership and role, invitations, events, celebrations, trips and flight details, shopping lists and audiences, polls, recipes, manually entered meal and produce records, pets, family-tree people and relationships, and the people, notes, dates, and photos members choose to add. Kinello does not analyze meal photos or generate calorie estimates from them with AI.
  • Memories and location: selected photos; photo capture date, time, timezone, and GPS metadata when available; a location taken from photo metadata, device location, search, or manual entry; place names and coordinates; and people tagged in a memory. When a member attaches photos, Kinello reads the earliest photo's capture date and time and turns its GPS metadata into a place name, fills those into the form before it is saved, and shows what it used with a one-tap undo beside it; nothing is saved until the member saves the memory, and the values can be changed or cleared first. Kinello re-encodes uploaded photos, but the date, time, place, and coordinates a member chooses to save with a memory remain in the memory record.
  • City and timezone: a chosen city, its center coordinates, timezone, and whether the member shares that city with family. Kinello does not request an address or continuously track location.
  • Health and fitness data: an aggregate daily step total, local date, timezone, source, and sync time only after the member enables step sharing. Raw step samples, routes, workouts, and other health categories remain in Apple Health or Health Connect and are not uploaded to Kinello. Family step sharing alone does not give an AI provider access. Named aggregate totals may reach an AI provider only when an owner or admin enables AI step insights for the family and that member separately allows AI analysis of their own totals.
  • Communications and AI: family-chat messages and Kinello answers. An ordinary family message stays in the family chat and is not sent to an AI provider. When a member explicitly includes `@Kinello`, that saved message and the family records needed to answer it go to an approved AI system; the answer is posted back into the shared family chat for every family member to read. Named step totals are included only under the separate two-key AI-step permission described below. See "AI processing" below for who receives the request and what is sent. Kinello changes data, such as adding a shopping item, only when the member explicitly requests that action.
  • Device and service data: push token, platform, notification preferences, app configuration, and security or service logs needed to operate and protect the service. Kinello does not include advertising or cross-app tracking SDKs. Kinello also stores first-party activation events (which screen was opened, and which of a fixed list of actions occurred) so the family owner can see whether the family is using the app. These events do not include message text, photo contents, names, or step totals, and they are not sent to any advertising or analytics company.
  • Referrals and invitations: a personal Kinello referral code and link, when that link is shared from Kinello, the account that later claims it, and whether the claim came from a Kinello share link or a family invitation. Kinello uses those verified claims to show the sharer an account-to-account referral tree and derived counts of families created and currently active Plus families. Kinello does not learn whom a member selected inside Messages, email, or a social app, and opening a share sheet alone does not create an attribution. A referral link never grants access to a private family. Names in the referral tree are shown only when the viewer and referred account are also members of the same family; otherwise the person appears as "Kinello member." An active Plus-family marker describes a family the referred account created and does not identify who paid.
  • Calendar and photo permissions: Kinello accesses a selected photo or camera only after a member chooses that action. Kinello reads or writes the device calendar only when a member asks to add a family event. Calendar contents are not uploaded as a contact list or background calendar copy.

Kinello receives data from the account holder, other members of the same family, the device and permissions the member enables, Apple or Google authentication if selected, Apple Health or Health Connect if step sharing is enabled, and service providers used to operate Kinello.

Purposes and legal bases

Kinello uses data to authenticate members; keep the family hub private; display and synchronize family content; provide requested health, calendar, photo, location, notification, weather, AI, invitation, and referral-tree features; measure verified referral conversions; prevent abuse; troubleshoot failures; meet legal obligations; and respond to privacy requests.

Where European or UK law applies, Kinello relies on performance of the service agreement, consent for optional permissions and health processing, legitimate interests in securing and improving the private service, and legal obligations. Health data is processed only after an explicit step-sharing choice and may be withdrawn at any time.

Health data notice and choices

Daily step totals may be consumer health data. Collection and family sharing are off unless the member affirmatively enables them. AI analysis is a separate two-key choice: an owner or admin enables AI step insights for the family, and each member separately decides whether their own aggregate totals may be analyzed. Neither key overrides the other, and a payer has no authority over a member's personal choice. A member may withdraw AI permission without stopping family sharing, or disable step sharing entirely. More detail is in the Kinello Consumer Health Data Privacy Policy.

AI processing

Two Kinello features send family information to an approved AI system: `@Kinello` in the family chat, when a member explicitly mentions it in a question, plus the recipe importer when a member asks it to read a recipe; and the weekly family newsletter, which is written automatically once a week for each family.

Which AI system processes it. Production Kinello keeps a short, ordered list of approved AI providers and sends each request to the first one on that list that is available:

  • Kinello's own self-hosted NVIDIA DGX Spark, operated by Kinello in the United States.
  • OpenAI, in the United States.
  • Anthropic, in the United States.

A request goes to one provider at a time, and Kinello may move to the next listed provider when a provider is unavailable or a request fails, so a single question can reach more than one of them in turn. The DGX Spark is operated by Kinello; OpenAI and Anthropic are outside processors. Adding a production provider that is not on this list requires an updated policy before family information is sent there. Kinello asks every provider handling a request not to keep a copy of it, and does not give family content to anyone to train an AI model.

What `@Kinello` sends. Only the saved family-chat message that explicitly contains `@Kinello`, plus the family records Kinello reads to answer it — only records the requesting member can already see in the app. Kinello does not send earlier, later, or unrelated messages from the family conversation. The generated answer is saved in that same shared conversation and is visible to every member of the family. For a step question, Kinello sends only the first name and aggregate total of members covered by both AI-step keys and current consent versions. A member who shares steps with family but does not allow AI analysis is excluded. Reading a recipe is the one case that sends a picture: when a member chooses a photo of a recipe to import, that photo is sent to the AI provider to be transcribed into a recipe. No other Kinello feature sends a photo to an AI provider.

What the weekly newsletter sends. The family's name, members' first names, how many new memories and completed shopping items there were, and—only when both AI-step keys apply—the combined aggregate steps of opted-in members, how many opted-in members had steps, and an AI-eligible step champion. A family that turns on richer newsletters in family settings also sends that week's memory titles and places, poll questions and results, trip names, destinations and dates, celebration names, and the first names of members who joined. The newsletter runs on a schedule; no member has to ask for it.

What neither feature sends. Memory and profile photos, ordinary family-message text that does not explicitly invoke `@Kinello` (the newsletter sends only how many messages there were), earlier or unrelated chat history, private memories, exact locations beyond a place name a member saved, contact details, login credentials, and anything belonging to another family.

Kinello stores a new `@Kinello` question and answer in the shared family chat. Older private Ask Kinello histories are not moved into the family chat and remain private to the account that created them until deletion. AI answers can be wrong and are not medical, legal, financial, or emergency advice.

When data is disclosed

  • Other members of the same invited family receive only records and fields allowed by the app's family, audience, and consent controls. A custom shopping list is limited to its selected audience. Private memories remain limited to their creator.
  • Supabase provides authentication, database, private file storage, and Edge Function hosting.
  • Vercel hosts Kinello's public invitation and referral landing pages and receives ordinary web-request data such as IP address, user agent, requested page, and time.
  • Expo's notification service and Apple or Google push services deliver notifications only when enabled.
  • Apple or Google provides authentication when selected and provides the on-device health store when step permission is enabled.
  • Open-Meteo receives city-search text or saved city-center coordinates needed to return a city, timezone, or weather result.
  • The approved production AI providers listed under "AI processing" above — Kinello's self-hosted DGX Spark, OpenAI, and Anthropic — process explicit `@Kinello` requests, recipe imports, and the weekly newsletter.
  • Authorities or another party may receive data when legally required or necessary to protect members, the service, or others.

Kinello does not sell personal data, does not share it for cross-context behavioral advertising, and does not make family content public. Service providers may process data only to provide their contracted service. Data may be processed in the United States and other locations where providers operate, subject to their contractual safeguards and applicable transfer requirements.

Retention and deletion

Account, family, family-chat, legacy assistant-history, referral-link, referral-share, and referral-attribution data is kept while needed to provide the active account, family, or referral-tree feature. Expired invitations, notifications, and operational logs may be retained for security, support, and legal needs. Members may remove individual content and sharing choices in the app.

Family photo storage has a family-wide allowance: 1 GB on Free and 20 GB on Plus. When Plus ends, existing media remains readable and downloadable, but new uploads pause if the family is above the Free allowance. Kinello gives a 90-day grace period and places notices in the family's Activity feed at the start of the grace period and again with approximately 30, 7, and 1 day remaining. A push notification is also attempted when that member has enabled push. After the deadline, Kinello removes only the oldest media needed to bring the family within the Free allowance, starting with content photos before profile, person, or pet photos. The family records themselves remain. Renewing Plus or reducing usage before cleanup cancels the scheduled removal. Transactional email is not currently part of this notice process.

Account deletion removes the login, account-owned private rows, push tokens, consents, step totals, assistant messages, referral links, referral share events, referral attributions involving that account, and uploads. Removing an attribution may also disconnect the deleted account's branch from an ancestor's referral-tree view. Shared family records are transferred to another family member so the family history is not unexpectedly destroyed; the deleting member's attribution is removed where it is not needed. If no family member remains, the family and its records are deleted. Provider backups may retain encrypted copies for a limited disaster-recovery period and are not used as active product data. Account holders can use Account settings in the app or the public Kinello account-deletion page.

Security

Kinello uses encrypted network connections, encrypted mobile credential storage, short-lived signed photo URLs, private storage, authenticated server functions, row-level and per-family authorization, least-privilege database grants, and tests for cross-family access and destructive account operations. No system is perfectly secure. Kinello will investigate suspected incidents and provide legally required notices.

Rights and requests

Depending on location, an account holder may request access, a portable copy, correction, deletion, restriction, withdrawal of consent, or an explanation or appeal of a privacy decision. California residents may also request to know, correct, or delete covered data and may exercise applicable opt-out rights; Kinello does not sell or use personal data for cross-context behavioral advertising. Washington and Nevada residents may exercise applicable consumer health data rights under the separate health policy.

Use in-app controls where available or email support@kinello.net from the account email. Use the subject "Kinello privacy request" and state the request. Kinello may verify identity before acting and will respond within the period required by applicable law. A member may also complain to their local data-protection authority.

Changes

Kinello will update the date and the relevant consent version when this policy materially changes. Base step sharing and personal AI-step consent have independent versions, so a change limited to AI recipients or AI use does not silently disable family step sharing.

Back to top

Kinello

Start your own private family. Invite the people in it.

Product

How it worksFamily step trackerPrivate family appGet the appiPhone updatesSupport

Legal

Privacy PolicyTerms of UseConsumer Health DataDelete your account

Contact

support@kinello.net

Kinello is a general wellness app for families. It is not a medical device, and it does not diagnose or treat anything. Login accounts are for ages 13 and up.