Kinster Privacy Policy

Last updated / Version 2026-06-18. (Matches POLICY_VERSION in the app; we bump it on material changes, which re-prompts your consent.)

The short version

  • You enter your family’s information once; Kinster reuses it to fill forms for you.
  • Your family’s data is encrypted at rest and in transit and isolated to your account. It is not end-to-end encrypted. Our systems can technically access it to provide the service.
  • We never sell your data, and we use no advertising or tracking.
  • You can export or delete everything at any time.
  • This is a parent-run service for adults; you enter and control your family’s information.

Who we are

Kinster (“we”, “us”) is a parent-owned tool that lets a parent or guardian store their family’s information and autofill the forms that schools, camps, sports, and childcare repeatedly ask for. This policy covers the Kinster web app and browser extension.

What we collect

Information you enter to build your family record:

  • Parents/guardians: names, relationship, phone, email, address, employer.
  • Children: legal name, date of birth, sex, gender, school, grade, preferred name/pronouns.
  • Emergency contacts & authorized pickups: names, phones, relationship.
  • Health information (sensitive): allergies, medical conditions, medications, physician, blood type, dietary/special needs, insurance carrier/member ID.
  • Consents & a saved signature you choose to store.
  • Documents you upload (e.g., an insurance card image).

We do not collect Social Security numbers. We do not sync your health data from any outside source. Everything in your record is entered by you.

Information from using the service: your sign-in email, and basic technical/security logs.

How we use it

Only to provide the service: to store your family record, fill it into the forms you choose, produce a printable one-page summary, and keep your account secure. That’s it. We don’t use it for advertising, and we don’t build profiles.

How it's stored and protected (in plain terms)

  • Your data is stored in a US-based database and file store (our infrastructure provider, Supabase).
  • It is encrypted at rest (AES-256) and in transit (TLS), and isolated to your account by row-level security, so other users can’t reach it.
  • It is not end-to-end encrypted. That means our systems can technically access your data to run the service, and we limit that access and don’t use it beyond providing Kinster. (A future “extra-private” mode may add end-to-end encryption; we’ll say so clearly if and when it exists.)

The AI that helps fill forms

To map unusual or unlabeled form fields, Kinster sends the form’s field labels (e.g., the words “Date of Birth” or “Caregiver”) to our AI provider (Anthropic, “Claude”) to suggest where they go. We send only the form’s structure and labels, never your family’s actual information (your child’s name, allergies, etc., are filled in locally on your device and never sent to the AI). We use the AI under terms that do not allow training on your data.

Who we share with

We do not sell your information and run no third-party advertising or tracking. We share data only with the service providers that run Kinster (“sub-processors”):

Sub-processorWhat forWhat they receive
Supabase (US)Database, file storage, sign-inYour family record + documents (encrypted at rest)
Anthropic (Claude)AI form-field mappingForm field labels only, never your family’s data

We may disclose information if required by law, or to protect safety, and we’ll resist overbroad requests.

Your rights and choices

  • Access & export: download your full family record (and your documents) any time from Settings → Your data.
  • Delete: Settings → Danger zone erases your family record and all uploaded documents immediately. To also delete your account/email record, contact us (full self-serve account deletion is coming).
  • Withdraw consent / correct: edit or remove any field at any time; stop using the service whenever you like.
  • Washington residents (My Health My Data Act): you have rights to access, delete, and withdraw consent for your “consumer health data” (e.g., allergies, conditions, medications). Contact us to exercise them.

Children

Kinster is for parents and guardians (adults). It is not directed to children and we don’t market to them or let children create accounts. A parent enters and controls all information about their family, including their children’s, consistent with keeping the service outside COPPA.

How long we keep it

We keep your data until you delete it or close your account. When you delete, your family record and documents are removed promptly.

Changes to this policy

If we make a material change, we’ll update this policy and its version, and ask you to agree again before you keep using the service.

Contact

Questions or requests: hello@kinster.app.