Privacy
Kin is a working prototype. This page describes what’s actually true about how it handles your information today. It is not a substitute for a formal, lawyer-drafted Privacy Policy, which we’ll publish before a wider launch.
What we collect
The information you or your family choose to enter: names and relationships, where documents and accounts are kept, care wishes, health details such as medications, conditions and insurance, and similar planning details. Files you upload. The email addresses of people you invite or send a shared link to. We don’t buy data about you from anyone else.
How it’s stored
In a hosted Postgres database, with uploaded files in private file storage, both run by Supabase. The website is hosted by Vercel.
Some of the most sensitive fields are also encrypted by the app before they’re written, so they can’t be read from the database without the app’s key:
- ballpark values and the last four digits of accounts
- where a login is kept, and how to get into a home or safe
- answers to the planning questions
- care wishes and funeral service wishes
- where the medication list is kept, what a medication is for, insurance member IDs, and notes on medications, conditions and insurance
- notes on how an item should pass on, and on designations
Everything else, including names, the list of what exists, medication and condition names, most other notes, and uploaded files, is not encrypted by the app. It relies on our hosting providers’ standard protections.
Who can see it
The people you invite into your workspace, and only the sections their access allows. Access is set person by person, section by section. Someone you add on People starts with no sections; someone named while you set up the workspace starts with every section until you change it.
Anyone you send a shared link to can see that one document, and nothing else. We don’t show your data to anyone else, and we don’t sell it, rent it, or use it for advertising.
Shared links and email
A shared link (to the Planning brief, the Summary, What’s changed, or a Runbook) is a private, unguessable web address. It expires after 30 days, and you can revoke it at any time.
Sign-in links and invitations are sent by Supabase, our sign-in provider. Notifications and shared-link emails are sent through Resend, a transactional email provider.
Cookies
We use only the cookies needed to keep you signed in, remember which workspace you’re in, and remember where you are in setting up. No advertising or tracking cookies.
Getting a copy, and deleting
There’s no full data export yet. The Planning brief, the Summary and the Runbooks can be printed or saved as PDF at any time.
You can delete individual items yourself, and leave a workspace if you belong to more than one. Deleting your whole account or workspace isn’t something the app does yet: write to preparewithkin@gmail.com and a person will handle it by hand and confirm back to you by email. The same address is for any question about your data, or a copy of it.
Last updated September 2026 · Kin is a working prototype.