kintilla

Privacy Policy

Version 1.3 · dated July 29, 2026 · effective when Kintilla activates this version · this policy covers the product as it ships and will be updated as it grows.

The short version

Kintilla is a shared weekly planner for households, operated by Kintilla LLC. We collect the minimum we need to run it, we don't sell your data, we don't show ads, and the people in your household control what's on your board. Questions, requests, or deletions: hi@kintilla.com.

What we collect

Optional product analytics

“Anonymous usage” is an optional, device-local setting and starts OFF. Until you turn it on, Kintilla does not load Google Tag Manager, create its analytics data layer, set Google Analytics cookies, or send product-analytics requests to Google. You can change the setting at any time in Legal & privacy; turning it off stops future collection from that device and clears Kintilla's analytics state and cookies there.

If you turn it on, Google Analytics receives pseudonymous product events: which broad surface or feature was used, a normalized route category, low-cardinality choices and outcomes, coarse device/browser information, timestamps, a one-way household reference derived from a service-issued identifier, and Google Analytics' device/browser identifier. Google also receives ordinary network metadata such as the IP address and may use it to derive coarse geography. “Pseudonymous” means the events can be associated with the same device or household over time even though the analytics payload does not carry a person's name or email. Kintilla never sends names, household or board words, task/event/jot text, Spark prompts, photos, raw account or home IDs, full URLs, or other free text to product analytics. Advertising storage, ad-user data, ad personalization, and cross-site tracking stay off.

Household profiles and kids

Household members can create profiles for people who never sign up — including children. An adult supplies the profile's name and avatar, marks whether it is a child profile, and may add an optional Kindled Day with a private year and tether or relationship information. These profiles have no login, no email, and no account. Kintilla does not knowingly collect information directly from children; adults provide and control child-profile data inside their household team.

How we use information

Who we share it with

No selling, no ad networks, no data brokers. Your information is shared only with the service providers that run Kintilla, under their own contractual privacy obligations:

Cloudflare and Supabase process the diagnostic and security-log fields described above. Google receives the bounded error-boundary and reliability events only when optional product analytics is on; error names, messages, stacks, household words, and free text do not enter those analytics events. Browser notifications may also pass through the push service operated by your browser or operating-system vendor.

Voice input. If you choose the microphone, the speech-recognition service supplied by your operating system or browser processes your live voice audio to create text. Depending on your device, browser, and system settings, it may send that audio to Apple, Google, or another system- or browser-selected provider for processing during the transcription under that provider's own privacy terms. Kintilla retains only the resulting text and does not retain an audio recording.

Paper photos. When you explicitly choose a photo (a flyer, schedule, or note) and tap read, that photo is resized on your device and sent once to Anthropic's Claude, which returns suggested dates and tasks for your review. Kintilla never stores the photo or the raw suggestions; Anthropic deletes API inputs and outputs within 30 days under its commercial retention policy and does not use them to train AI models. Nothing leaves your device until you approve each photo.

We may also disclose information if required by law, or as part of a business transfer (in which case this policy continues to apply).

Retention and deletion

Household history is kept so your team's board, streaks, and history search work. Free teams keep 90 days of searchable history; paid teams keep it while the home remains active. You can delete individual board items and accountless household profiles in-app. Any current member can also make one family-archive ZIP per home containing the shared household data they are allowed to see; a prepared archive expires after seven days and each download link expires after five minutes.

You can delete your account in Kintilla's Account & data screen, or use the always-available public deletion and support path if you cannot sign in. We complete verified support requests within 30 days. Account deletion removes the sign-in identity, email and provider identifier, every claimed person row linked to it, devices, sessions, and direct or targeted personal content from active product systems. Kintilla also removes the text, notes, board items, actions, profiles, drawings, files, and other user-generated content attributable to that account from shared homes, together with derived and cached copies. Content genuinely contributed by remaining members may stay with its home; unknown legacy authorship is purged conservatively rather than relabelled or assigned to a replacement profile.

An owner must hand off each shared home or choose whole-home deletion; a solo home is deleted with its owner account. Independent shared-home deletion may be immediate or use a seven-day grace period while its owner remains. Whole-home deletion removes the household and its boards, story, wall access, and home-owned files. We may retain limited security, fraud-prevention, billing, tax, provider-cleanup, closure-receipt, or legal records where necessary. For Sign in with Apple, Kintilla keeps a private, content-free marker after it observes the identity and stores any Apple revocation grant encrypted. At deletion, held grants are used to request revocation; a missing or unresolved grant goes to protected operator attention instead of being treated as proof that Apple has no record. This observation begins with the feature's rollout, so an Apple identity unlinked beforehand may be unknowable to Kintilla. Encrypted grants remain only while revocation or operator-verified absence is outstanding, then are removed. Content-free closure receipts expire within 30 days; protected backups and transactional-email or other technical processor copies age out under their configured retention; provider-managed sign-in or subscription records may remain with Google or Apple.

Your rights

Depending on where you live (including under GDPR and CCPA), you may have rights to access, correct, export, or delete your personal information, and to object to certain processing. Email hi@kintilla.com and we'll help — we don't discriminate against you for exercising these rights.

Security

Data is encrypted in transit, access is scoped per-household at the database layer (row-level security), and production credentials are held in managed secret stores with least-privilege access. No system is perfectly secure, but small-surface-area design is part of ours.

Changes

If this policy changes in a way that matters, we'll say so plainly on this page (and in-app once Kintilla has shipped) before the change takes effect.

← back to kintilla.com