Kinosaic

Loading your family workspace

KinosaicFamily history

Privacy

Privacy Policy

This policy explains what we collect, who can see it, what we will never do with it, and how to get it back or have it removed.

Version 1.4An 18-minute read
Counsel review pending

Version 1.4 is written and published in good faith. Independent legal review has not happened yet, and this notice stays until it has. As at 20 August 2026 there is no member-facing product and no family’s data is in any Kinosaic system. What follows describes commitments the product is being built to meet, and they bind us from the day the first family joins.

1. Who is responsible

Kinosaic is operated by its founder, Nathan Phillips, sole proprietor. For data-protection purposes that operator is the controller of the information this policy describes: the person responsible for what is collected, for how it is protected, and for answering you about it.

You can reach the controller at founder@kinosaic.com. Section 11 lists what you can ask for, and section 13 says how quickly you hear back.

2. Status of this policy

This policy covers kinosaic.com and the Kinosaic application. Every version is dated, and the previous versions stay available.

This section is new in version 1.1 and has not yet had counsel review.

The version number at the top of this page says which text you are reading.

When the words change in any way that matters, the number changes with them, and section 15 explains how you find out. Earlier versions are kept, and you can ask for any of them at founder@kinosaic.com.

3. What we never do

These are commitments, not current practice that could quietly change.

Your network address is not kept. Network addresses are reduced to a keyed digest for abuse prevention rather than stored directly, and the digest is removed after 30 days.

Your contact details are yours to share. An email address or phone number is not shown to other members unless you choose to share it. Contact details are shared only through a request you approve, and nobody, including us, passes them along on your behalf.

Messages are encrypted, not end-to-end. Kinosaic messaging is encrypted in transit and at rest.

What a keyed digest is, in plain wordsAbuse prevention without an address book

A digest is a scrambled, one-way form of a network address, made with a secret key held separately from the database. It lets the service notice that the same connection keeps failing sign-in or hammering a door, without keeping a list of who was where. After 30 days each digest is removed from its audit record entirely.

What the encryption coversIn transit and at rest

Encrypted in transit means nobody reading the network between you and Kinosaic can read what passes. Encrypted at rest means the stored copy is encrypted too. Section 6 covers who may read a conversation at all.

4. What we collect

Four kinds of thing. Your account details, the family content you add, technical records that keep the service running, and anything you write to us.

All four, with what each one covers
Account details
A name, an email address, a password hash, the country you tell us you are in, and a date of birth.
Family content
The people, relationships, dates, stories and photographs a member chooses to add. A grandmother's maiden name, the story behind a wedding photograph, the year the house was built: whatever your family decides is worth keeping.
Technical records
Security and audit records, a workspace activity log, and error reports. These describe events, such as a sign-in or a page that failed to load, and they are written so that names, messages and other family content stay out of them.
Support messages
What you write to us, kept with the answer we gave, so the next answer does not contradict the last one.

Precision has limits on purpose. Location in Kinosaic is a country and a region picked from a list, plus an optional place name, and the product is built not to accept anything more precise. Photographs are cleaned of embedded technical data, such as the place a camera recorded, when they are uploaded.

5. How we use it

  • To run the service and keep a workspace working.
  • To keep people safe: abuse prevention, moderation and audit.
  • To answer support requests.
  • Error monitoring is used for reliability and not for analysing family content.
What those uses look like in practiceConcrete examples of all four

Running the service means storing what your family adds, showing it only to the members allowed to see it, sending the emails that sign you in and tell you what changed, and keeping backups so that one mistake cannot destroy years of work.

Keeping people safe means noticing when a connection keeps failing sign-in, acting on what a member reports, and keeping the records that show what was done and by whom.

Answering support means a person reads your message and replies. Error monitoring means that when a page breaks, a technical report of the failure is recorded so it can be fixed; those reports are written to keep family content out of them.

Legal bases, for readers in the EU and UKPerformance of a contract, legitimate interests, consent

Running the service and keeping your workspace available is performance of a contract. Security, abuse prevention and audit rest on legitimate interests, balanced against the interests of the people in the workspace. A child’s account rests on guardian consent, which can be withdrawn at any time.

None of these bases reduces the rights in section 11. Whatever the basis, the same requests are open to you and the same clocks in section 13 apply.

6. Who can see what

The workspace is the boundary. Nothing crosses between two workspaces, and this is enforced in the database rather than by policy alone: a record that linked two workspaces cannot be written.

Nobody browses private conversations that have not been reported. Not an administrator, not an owner, and not us.

An unauthenticated visitor reaches nothing. An invitation is unreadable outside the workspace it belongs to.

What an administrator can and cannot doAuthority with edges

An administrator sits above members for membership and moderation, and still cannot reach a private conversation. The ordering is real for some actions and does not exist for others.

Concretely: an administrator can invite and remove members and act on reports, in this workspace only. An administrator cannot open a private conversation that has not been reported, cannot see contact details a member has not chosen to share, and gains nothing extra anywhere else.

One person in two family workspacesMemberships never merge

The same person can belong to a grandmother’s workspace and a grandfather’s, and those two memberships never merge. Nothing added in one appears in the other, members of one cannot see into the other, and the service will not even confirm to an outsider that a workspace exists.

If Kinosaic itself ever opens a workspaceSupport access leaves a visible trail

Support access into a workspace requires a recorded reason, a stated scope and a short expiry, and it writes an entry into that workspace’s own activity log. The family whose workspace was entered can see that it happened; it is their record before it is ours.

7. Children and families with minors

Anyone under 16 needs a parent or guardian’s consent before they can have a Kinosaic account, in every country. That is stricter than United States law requires and meets the highest age European law sets.

Full policy textGuardian rights, the three age bands, exports, deletion

Only an adult guardian who is already signed in can create the account. There is no path by which a child creates one alone, even briefly.

One threshold everywhere is deliberate. A family can span three countries, and which country’s rules protect a child should never be a puzzle for a parent, so Kinosaic applies its strictest reading to everyone.

Under 13: no private messages, and that cannot be changed. No route by which their contact details can be disclosed. Exports are run by a linked guardian.

13 to 15: Protected or Independent, chosen once at setup, reversible in either direction, recorded, and shown to your child and any other guardians. Moving back to Protected turns off new private messages. It does not erase ones already received.

16 and over: your child manages their own account, and protections persist until they confirm they have read what you agreed to on their behalf.

At every age: a child’s account can never hold an administrator or owner role, and blocking, muting and reporting always work in full. A linked guardian can always view the account, export it, restrict it, withdraw consent, or have it deleted.

The For parents page walks through all of this in plainer terms, age band by age band.

8. Service providers

Four providers touch the service. A database and file-storage platform, hosting and content delivery, transactional email, and error monitoring. None of them are given family content for their own purposes, and each is named here.

All four, with what each one covers
Database, authentication and file storage (Supabase)
Holds account data and family content, and signs you in. Processes both only on Kinosaic’s instructions and for no purpose of its own.
Hosting and content delivery (Cloudflare)
Runs the service, and every request to kinosaic.com passes through it. No access to family content beyond what operating the platform requires.
Transactional email (Resend)
Delivers sign-in and notification email. Holds delivery logs on its own schedule, which is why section 12 names provider logs as one of the things deletion cannot reach.
Error monitoring (Sentry)
Receives error reports. Used for reliability and not for analysing family content.

Each provider does one job with the minimum access that job needs. If a provider is ever added or replaced, this list is updated before the change takes effect.

9. Where your data is stored

Data is held in the United States and served through a global content network.

Exception, to be drafted. Standard contractual clauses for transfers out of the UK and EU still need to be drafted and executed. Until they are, this section states an exception rather than a control. This closes before the service opens wider.

If your family is not in the United StatesSame policy, wherever you are

The exception above is about the paperwork for moving data across borders, not about weaker handling once it arrives. Wherever you live, the same policy applies: the same rights in section 11, the same clocks in section 13, and the same deletion promise in section 12. Kinosaic holds itself to the stricter of the standards that could apply to a family, so which law covers you is never something you have to argue about.

10. How long we keep information

We keep your account and family content for as long as your account and workspace exist. When you ask us to delete something, section 12 governs. Beyond that, these are the fixed periods this policy binds us to.

The five fixed periods, in full400 days, 30 days, 90 days
Platform security and audit records
400 days
A workspace’s own activity log
400 days
Keyed network digests inside an audit record
30 days, and the rest of that record keeps its 400
Sign-in attempts to Kinosaic’s own admin access
30 days
An unconfirmed proposed family connection
90 days, then it lapses on its own
Why these periods, and what a backup restore doesEvidence records and the backup cycle

An audit record is a note that something happened: a sign-in, an invitation, a change of role. It is written to keep names, messages and other family content out, and it exists so that a question asked months later can still be answered. 400 days is deliberate: long enough to cover any question about the past year, short enough that the log never becomes a permanent store of anyone’s activity.

A workspace’s own activity log is the same kind of record for one family’s workspace, and its readers are that workspace’s own administrators. It carries no network information of any kind, so one relative can never use it to trace another’s comings and goings.

Records that exist as evidence, meaning a guardian’s consent for a child’s account, acceptance of these terms, and moderation evidence, are kept longer, because their whole purpose is to be available afterwards. Section 12 lists these and explains why each one is retained.

Backups run on a short rolling cycle and expire on their own schedule. A restore never brings back data that has been erased: any deletion carried out since a backup was taken is re-applied to it before the service comes back.

11. Your rights

Five requests, and you never have to name a law to make one.

All five, in full
  • Get a copy of what we hold about you.
  • Correct something that is wrong.
  • Delete your account, which is not the same as leaving a workspace.
  • Restrict or object to a particular use.
  • Withdraw consent, including a guardian withdrawing consent for a child.

To make any of them, write to founder@kinosaic.com in your own words. We confirm who is asking before anything is shown, changed or deleted, and until that confirmation we do not even say what exists, so that asking about a person can never become a way of finding things out about them.

You do not need an account to have rights here. A living person who appears in a family’s tree and never signed up can ask for their information to be corrected or removed, the same way a member can. And a linked guardian can make every one of these requests for their child.

12. What deletion actually does

Erasing you removes everything Kinosaic holds that describes you. It does not delete or falsify other people’s records of their own lives. “Sam has a father” is Sam’s record about Sam, and it survives you leaving.

Erased outrightWhat is genuinely deleted, not hidden
  • Your profile, your account details and your sign-in credentials.
  • Content you authored that no other member depends on.
  • Your contact details everywhere they appear.
Reduced to a markerWhen your spot in the tree has to stay
  • Your position in another person’s family tree, with your name removed.
  • Authorship of content another member relies on, shown as a removed member.
Kept, with a reasonA short list that survives, each bounded and stated why
  • A guardian’s consent record.
  • Acceptance of these terms.
  • Moderation evidence, bounded by section 10.
What deletion cannot reachExported copies, provider logs, other people’s records
  • Copies another member exported before you asked.
  • A provider’s own delivery logs.
  • Records other people keep about their own relatives.
Leaving, deleting an account, deleting one thingThree different requests, never confused

Leaving a workspace is a departure, not an erasure: your access ends, your relationships are marked as ended rather than rewritten, and you can come back. Deleting your account is the erasure this section describes. And you can ask for one thing to be erased, a photograph, a field, a story, without closing anything. The screen where you choose always says which of the three you are doing.

If the person who owns a workspace asks for erasure and no other member takes over as owner, the workspace winds down: every member is told, everyone has 30 days to export, and then the workspace and its contents are deleted.

13. How quickly we respond

10 days to acknowledge, 30 days to answer. A person reads it, and we tell you if a complex request needs longer.

All four, in full
  • We acknowledge a request within 10 days of receiving it, by a person.
  • We complete it within 30 days of the request being verified.
  • Where a request is genuinely complex we can take up to 60 further days, and we tell you inside the first 30, with reasons.
  • We can refuse a request that would expose another member’s data, and we say which part we refused and why.

Verification comes first, as section 11 explains: we confirm who is asking before acting, and the 30 days run from that confirmation. A refusal is never bare: it names its ground, says what is available instead, and states how to appeal.

14. Security

Encryption in transit and at rest, least-privilege access, audit logging of administrative actions, and a small attack surface because there is very little product.

What each of those meansThe controls, in plain words

Least privilege means every request is checked against what that member may do in that workspace at the moment they ask, rather than trusting an earlier answer. Someone whose role changed a minute ago is treated by their role now, not by a stale pass.

Administrative actions are written to an audit log that cannot be quietly edited: records there can be added, and expire on the schedule in section 10, but not rewritten.

A small attack surface: less software means fewer doors to guard.

If you believe you have found a security problem, tell us at founder@kinosaic.com.

15. Changes to this policy

Material changes are announced in the product and by email before they take effect. Every version stays dated and available.

A material change touches what is collected, who can see it, how long it is kept, or what you can ask us to do.

You hear about those before they happen, not after. Clearer wording that changes no commitment is still versioned, so the record stays complete.

16. Contact

Write to founder@kinosaic.com about anything in this policy: a question, a request under section 11, or something you think we have got wrong. Section 13’s clocks apply to all of it.

Version 1.4Last updated 20 August 2026founder@kinosaic.com