Legal

Privacy Policy

Last updated: August 29, 2026

KinStone™ (“we,” “us,” or “our”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use the KinStone™ platform, website, and related services (collectively, the “Service”). By using the Service, you agree to the practices described in this policy. If you do not agree, please do not use the Service.

This policy is incorporated by reference into our Terms of Service.

1. Information We Collect

1.1 Account Information. When you register for KinStone™, we collect your name, email address, and a hashed password. We may also collect a display name and profile preferences you choose to provide.

1.2 Vault Content. You may upload sensitive personal information to your vault, including passwords, financial account details, legal documents, medical information, personal writings, voice recordings, and other materials (collectively, “Vault Content”). Vault Content is stored encrypted and is used only to provide the Service to you.

1.3 Biometric Data. KinStone™ offers an optional biometric verification feature that captures a facial image or live selfie for identity matching. Biometric data is processed locally and/or via our service infrastructure solely for identity verification. We do not sell biometric data and retain it only as long as necessary to operate the verification feature.

1.5 Code Holder Information. When you designate trusted individuals (“Code Holders”), we collect their name and email address in order to send them an invitation, deliver verification codes, and manage their access to your vault upon a qualifying trigger event.

1.6 Usage and Technical Data. We automatically collect certain technical information when you use the Service, including IP address, browser type, operating system, referring URLs, pages viewed, and timestamps. This information is used to maintain security, diagnose issues, and improve the Service.

1.7 Communications. If you contact us by email or through the Service, we retain records of that communication to respond to your inquiry and to improve support quality.

2. How We Use Your Information

We use the information we collect to:

  • Create and maintain your account and vault;
  • Deliver one-time passcodes and verification codes by email;
  • Authenticate your identity and verify the identity of Code Holders during the vault release process;
  • Process and enforce vault release conditions you have configured (death, disappearance, or incapacitation triggers);
  • Send transactional and service-related communications (e.g., invitation emails to Code Holders, security alerts, account notices);
  • Process subscription payments and manage your billing relationship;
  • Respond to your support requests and inquiries;
  • Monitor, analyze, and improve the security and performance of the Service;
  • Comply with applicable laws and enforce our Terms of Service.

We do not use your Vault Content to train machine-learning models or for any purpose other than operating the Service on your behalf.

3. Verification Codes

KinStone™ delivers one-time verification codes by email and supports authenticator apps for two-factor authentication. We do not send text messages (SMS) and we do not collect phone numbers for verification. Codes are sent only when you or a Code Holder starts a verification step, and they expire after 15 minutes. You can request a new code at any time.

4. How We Share Your Information

We do not sell, rent, or trade your personal information. We share your information only in the following circumstances:

4.1 Service Providers. We engage trusted third-party vendors to help operate the Service, including:

  • Supabase — cloud database and authentication infrastructure. Your account data and Vault Content are stored in Supabase's secure, encrypted data stores.
  • Stripe — payment processing for subscriptions. KinStone™ does not store full payment card details; Stripe handles all payment data under PCI-DSS compliance.
  • Google (Gemini API) — AI features such as vault assessment and heir plan generation. Prompts may include de-identified or user-provided content from your vault when you explicitly invoke an AI feature.

All service providers are contractually obligated to process your data only as instructed by KinStone™ and to maintain appropriate security measures.

4.2 Code Holders. When a vault release trigger is verified, designated Code Holders receive access to the Vault Content you have authorized them to view. This disclosure is a core function of the Service that you configure and control.

4.3 Legal Requirements. We may disclose your information if required to do so by law, regulation, legal process, or governmental request, or to protect the rights, property, or safety of KinStone™, our users, or the public.

4.4 Business Transfers. In the event of a merger, acquisition, or sale of all or substantially all of our assets, your information may be transferred to the acquiring entity. We will provide notice before your personal information is transferred and becomes subject to a different privacy policy.

4.5 With Your Consent. We may share your information for any other purpose with your explicit prior consent.

5. Data Storage and Security

5.1 Storage Location. Your data is stored on Supabase infrastructure hosted in the United States. If you access the Service from outside the United States, your data may be transferred to and processed in the United States.

5.2 Encryption. Vault Content is encrypted at rest using AES-256 encryption and in transit using TLS 1.2 or higher. Passwords and cryptographic credentials are never stored in plaintext.

5.3 Access Controls. Access to production systems and databases is restricted to authorized KinStone™ personnel on a need-to-know basis. All access is logged and audited.

5.4 Security Limitations. No method of electronic transmission or storage is 100% secure. While we implement industry-standard safeguards, we cannot guarantee absolute security. In the event of a data breach that affects your rights and freedoms, we will notify you as required by applicable law.

6. Data Retention

6.1 Active Accounts. We retain your account information and Vault Content for as long as your account is active or as needed to provide the Service.

6.2 Account Deletion. Upon account closure, we will delete or anonymize your personal information within 30 days, except as required by law or for legitimate business purposes such as fraud prevention, dispute resolution, or compliance with legal obligations.

6.3 Verification Data. Phone numbers and one-time passcode hashes used for identity verification are deleted after the verification session expires (typically 15 minutes) or upon successful verification.

6.4 Audit Logs. We retain security audit logs (login events, vault release actions, Code Holder submissions) for a minimum of 12 months to support security investigations and legal compliance.

7. Your Rights and Choices

Depending on your jurisdiction, you may have the following rights with respect to your personal information:

  • Access. You may request a copy of the personal information we hold about you.
  • Correction. You may request that we correct inaccurate or incomplete personal information.
  • Deletion. You may request deletion of your personal information, subject to our legal obligations and legitimate business purposes described in Section 6.
  • Portability. You may request a machine-readable copy of the personal information you have provided to us.
  • Restriction. You may request that we restrict processing of your personal information in certain circumstances.
  • Objection. You may object to processing of your personal information based on our legitimate interests.

To exercise any of these rights, please contact us at Support@KinStoneVault.com. We will respond to your request within 30 days. We may need to verify your identity before processing certain requests.

8. Cookies and Tracking Technologies

KinStone™ uses session cookies and local storage solely to maintain your authenticated session and remember your preferences. We do not use third-party advertising cookies or cross-site tracking technologies.

You can control cookies through your browser settings. Disabling cookies may prevent you from remaining logged in to the Service.

9. Children's Privacy

The Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from children under 18. If you believe we have inadvertently collected such information, please contact us immediately at Support@KinStoneVault.com and we will promptly delete it.

10. Third-Party Links and Services

The Service may contain links to third-party websites or services. This Privacy Policy does not apply to those third-party services, and we are not responsible for their privacy practices. We encourage you to review the privacy policies of any third-party services you access through links in our Service.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date at the top of this page and notify you via email or a prominent notice within the Service at least 14 days before the changes take effect. Your continued use of the Service after the effective date constitutes your acceptance of the revised Privacy Policy.

12. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact our privacy team: