Skip to content
KinShield

Privacy policy

Draft — not legal advice. A solicitor must review this before it is published as a live privacy policy.

Last updated: 18 September 2026.

The legal entity, registered office, and a dedicated privacy email are not named here yet. Until they are, this page describes the product as built. Do not treat it as a finished GDPR notice.

Privacy questions and requests: privacy@kinshield.app.

What KinShield is

KinShield is a second channel for a phone call. Families pair in person, then ask for the words on the screen. Organisations that actually use KinShield can show a branded card on a customer’s phone.

KinShield is not a deepfake detector, not a call recorder, not a bank, and not a payment rail. It does not listen to your calls. It does not scan audio for clones. A green tick means a real check ran — never a guess, a timer, or an error treated as success.

Who this covers

This draft covers:

  • KinShield (circles, pairing, words, safe word, Learn, optional organisation cards).
  • The organisation console used by staff we invite.

We do not sell personal data. We do not sell lists of families to organisations.

What we collect

Account. Email and identifiers your sign-in provider (Clerk) sends us, plus the name, optional phone number, and optional profile photo you provide, so we can create a KinShield profile.

Circle data you type. Circle name, member display names, invite codes, optional invitee phone numbers, challenge questions a circle chooses to set. A safe word is stored as a hash and salt, not as the words you agreed. Emergency codes and recovery phrases are stored the same way: a hash on the server, the secret on your device.

Device and pairing. Device public keys and a fingerprint of each pair secret. After pairing, the rotating words are derived on your phones. The server does not need the pair secret to show you as verified to someone else, and it must not.

Verification history. That a check was started, which method was used (words, push, safe word, and similar), whether it succeeded, and when. Not call audio. Not a recording. History on Free is kept for seven days in the product; Pro is described as longer. Deleting the account removes the rows we hold.

Push tokens. If you allow notifications, we store an Expo push token so someone in your circle can ask this device to check. You can refuse the permission.

Organisation data staff type. Brand kit, case references, agent names, webhook URLs. Webhook payloads must not include customer profile ids or emails. An organisation can only prompt a customer who has already linked them from the Providers screen.

Optional crash reports. If a Sentry DSN is configured on a build, we may receive a stack trace after a crash. Pair secrets, safe words, codes, invite codes, fingerprints and recovery phrases are stripped before send. We do not use session replay or screenshots.

Subscriptions. If you buy KinShield Pro, Apple or Google processes the payment. We store whether the yearly plan is active, not your card number. KinShield does not send money to family members. In-app transfers are not available.

What we do not collect

  • Call audio, microphone recordings, or voicemail.
  • Precise or approximate location.
  • Your address book as a list. Contacts permission is optional and on-device: you pick one person to invite; we store the name and number you chose, not the rest of the book.
  • Camera frames, except while you scan a pairing code. Those frames are not kept as a photo album. A profile photo is separate and optional.
  • Advertising identifiers for ads. We do not run ads.
  • Payment card numbers.

Permissions

  • Camera — scan a family member’s pairing code, or take an optional profile photo.
  • Contacts — optional, to fill an invite form.
  • Notifications — optional, so a family member can ask you to check.
  • Photo library — optional profile photo.

None of these listen to a phone call.

Why we hold it

App functionality: so you can sign in, belong to a circle, pair, see the same words, keep a short history, and (if you link an organisation) approve or decline that organisation’s card.

We do not use this data to train a deepfake detector. There is no detector.

Processors

  • Clerk — sign-in (Apple, Google, or email).
  • Supabase — database and edge functions, with row-level security.
  • Apple or Google — KinShield Pro, when that product exists in their store.
  • Expo — optional push delivery.
  • Sentry — optional crash reports, only when a DSN is set.
  • Cloudflare — hosting for this website.

Stripe appears in the codebase as scaffolding. Sending money is switched off because a transfer would not reach the other person. We do not collect financial information through that path in the shipping product.

Sharing inside the product

People you add to a circle can see what that circle needs: names, the current words, verification history for that circle, a profile photo if you set one.

A linked organisation sees the outcome of its own check (approved, denied, expired) and the case reference it already had. It does not receive a directory of KinShield families.

Demo names such as Northbank or Orbit Mobile are fictional. They are not partners and they do not receive your data.

Retention and deletion

You can delete your account in Settings. That removes the profile we hold and the circle data that deletion is built to cascade. Clerk sign-in is removed on the device as part of the same flow.

UK GDPR rights (access, correction, erasure, objection) apply once a legal entity is named. Until then, use in-app deletion or write to privacy@kinshield.app.

Children

KinShield is built for families, including older relatives. It is not aimed at children under 13. Do not create a profile for a child under 13.

International transfers

Processors may store data in the UK, EEA, or the United States. A solicitor must complete this section (transfer tool, DPA, SCCs) before publication.

Changes

If this policy changes in a way that affects what we collect, we will update the date above. A live policy must not claim a check, a payment, or a partnership that the product does not perform.

Same draft as the in-repo file used for store submission.