Legal
Kin App Privacy Policy
JouleWorx Private Limited · Last updated: August 7, 2026
This policy covers the Kin mobile app only.
For how this website (not the app) handles your data, read the website Privacy Policy →
TL;DR: The short version: your check-in content and any location you share are end-to-end encrypted, so we can't read them even if we wanted to. Your phone number lives only with our sign-in provider, never in our own database. Your contact list stays on your device. The only exception: when you add a connection, we briefly check whether that one phone number is registered on Kin. We don't store it, log it, or keep your contact list anywhere on our servers. We don't sell your data. You can delete your account and data at any time.
Who are we?
JouleWorx Private Limited is a product studio registered in India (CIN: U62012DL2026PTC463416). Kin is a personal safety check-in app built on a simple rule: staying connected with people you trust shouldn't require handing over your privacy.
Questions? Write to us: hello@jouleworx.com
What information do we collect?
What you give us
- Phone number: used to sign you in via one-time passcode. It is verified and stored by our authentication provider (Firebase Authentication), never written into Kin's own database.
- Display name: the name your Trust Circle sees. Stored on our servers.
- Feedback you send us: if you use the in-app feedback form, we store the message text against your account.
What the app reads from your device
- Contacts: read locally on your device to help you find and add connections, and to flag likely spam numbers. Your contact list is never uploaded to or stored on our servers.
- Location: only captured at the moment you choose to attach it to a check-in response. Kin does not track your location in the background or at any other time. Before it ever reaches our servers, that location is end-to-end encrypted on your device (see below), so we only ever receive scrambled, unreadable data (called ciphertext), never your actual location.
What gets generated automatically
- Check-in requests and responses: the content is end-to-end encrypted on your device before it is sent. Our servers only ever store that scrambled, unreadable data, plus bookkeeping details: who a check-in was between, its status, and timestamps.
- Push notification token: a device identifier used to deliver check-in notifications, stored against your account.
- Encryption keys: your device generates a public/private key pair for end-to-end encryption. The private key lives in your device's secure hardware storage (iOS Keychain or Android Keystore) and is never sent to us in plain form. Only your public key is stored on our servers, which is how end-to-end encryption is supposed to work. If you turn on encrypted backup, an encrypted copy of your private key (locked with a password only you know) is stored so you can recover it on a new device; we cannot read it.
- Crash and error reports: if the app crashes, we automatically receive device model, OS version, app version, and a stack trace via Firebase Crashlytics. We do not attach your name, phone number, or any check-in content to these reports.
How is my check-in content protected?
TL;DR: Real end-to-end encryption: your device encrypts check-in content and any shared location before sending. Our servers only ever hold scrambled, unreadable data, not a promise, an architectural fact.
When you respond to a check-in, your device encrypts the response, including any location you choose to attach, using your recipient's public key before it ever leaves your phone. Our servers store and relay that encrypted data (technically called ciphertext); they have no way to decrypt it, because the private key needed to do so never leaves your device.
This means that even in the event of a server breach, an attacker would only find unreadable encrypted data, not your check-in content or location.
Do we track my location?
TL;DR: No background tracking, ever. Location is only captured the moment you choose to share it in a check-in response, and it's encrypted before it leaves your device.
Kin has no background location activity. It cannot tell where you are or when you arrive somewhere unless you are actively responding to a check-in and choose to attach your location. That is a deliberate design choice, not a missing feature.
Who do we share data with?
TL;DR: No selling, no advertising. A small set of infrastructure providers process data on our behalf, strictly to run the app.
We don't sell your data, run ads, or share it with data brokers. We use these service providers to operate Kin, each of which only receives what it needs to do its job:
- Firebase Authentication (Google) – phone number verification and sign-in.
- Firebase Cloud Messaging (Google) – delivering push notifications.
- Firebase Crashlytics (Google) – crash and error reporting.
- Supabase – our database and backend, storing the encrypted, unreadable check-in data and account metadata described above.
If a court or government authority legally compels us to disclose something, we will comply, but there is no plaintext check-in content or location for us to hand over even if compelled.
What gives us the right to use your data?
We operate under India's Digital Personal Data Protection Act, 2023 (DPDPA) and the Information Technology Act, 2000. We rely on your consent, given when you sign up, to process your phone number and profile data to provide the check-in service, and on legitimate interest to keep the app secure and working reliably.
How long do we keep your data?
- Encrypted check-in data: automatically purged within 30 days of being sent, whether or not your account is still active.
- Crash reports: retained per Firebase Crashlytics' standard retention.
- Account data: kept for as long as your account is active. See our account deletion page for exactly what happens, and when, if you delete your account.
What are your rights?
Under the DPDPA and applicable law, you can ask to see, correct, or delete your personal data, and withdraw consent at any time. The fastest way to delete your account and data is in the app: Settings → Delete account. Full details, including what gets deleted and when, are on our account deletion page.
For anything else, email hello@jouleworx.com. We will respond within 30 days.
How do we protect your data?
- End-to-end encryption: check-in content and shared location are encrypted on your device before they ever reach our servers.
- Secure key storage: your private encryption key lives in your device's Keychain (iOS) or Keystore (Android), backed by hardware security where available.
- Encryption in transit: all traffic between the app and our servers uses TLS.
- Minimal collection: we don't ask for your contact list, and we don't track your location in the background, because we don't need to.
No system is 100% secure. If we ever discover a breach that affects your data, we will notify you as required by law.
What about younger users?
Kin is not directed at children. If you are under 18 and want to use Kin, we ask that you do so with a parent or guardian's knowledge. We are mindful of our obligations under Section 9 of the DPDPA; if you believe a minor has signed up without appropriate guidance, write to us at hello@jouleworx.com and we will take care of it promptly.
Will this policy change?
We will update this page if anything changes, and mark the new date at the top. For anything significant, we will try to give you more visible notice in the app.
How do you contact us?
JouleWorx Private Limited
Email: hello@jouleworx.com
We aim to acknowledge your message within 72 hours and resolve it within 30 days.
This policy is governed by the laws of India. Disputes fall under the exclusive jurisdiction of the courts of New Delhi.
