Privacy Policy
Version 1.3 · dated July 29, 2026 · effective when Kintilla activates this version · this policy covers the product as it ships and will be updated as it grows.
The short version
Kintilla is a shared weekly planner for households, operated by Kintilla LLC. We collect the minimum we need to run it, we don't sell your data, we don't show ads, and the people in your household control what's on your board. Questions, requests, or deletions: hi@kintilla.com.
What we collect
- Account basics — when you sign in with Google or Apple we receive your name, email address, and a sign-in identifier. We never see your password.
- Household content — what you and your household put on the board: tasks, events, claims, team names, profiles you create for household members, dates you choose to mark for them (including an optional private year), sigil choices, and short notes. This content is visible to your household team, by design; a private year is stored but never shown as an age.
- Notification and device data — if you turn on notifications, we store a browser push endpoint or native device token, the platform, and your notification choices so the service can reach that device. These selectors are retired when you turn notifications off, sign out, or delete your account.
- Subscription and billing records — your plan, billing provider, product and billing period, purchase or restore status, renewal or cancellation state, and provider-issued customer, subscription, or purchase references. Stripe, Google Play, or Apple handles the payment credentials; Kintilla does not receive your full card or bank details.
- Diagnostics and security logs — timestamps, IP address and user-agent or device/browser type, request and response status, bounded error category, and service identifiers used to keep Kintilla reliable, prevent abuse, and investigate failures. We do not intentionally put household content into technical logs.
Optional product analytics
“Anonymous usage” is an optional, device-local setting and starts OFF. Until you turn it on, Kintilla does not load Google Tag Manager, create its analytics data layer, set Google Analytics cookies, or send product-analytics requests to Google. You can change the setting at any time in Legal & privacy; turning it off stops future collection from that device and clears Kintilla's analytics state and cookies there.
If you turn it on, Google Analytics receives pseudonymous product events: which broad surface or feature was used, a normalized route category, low-cardinality choices and outcomes, coarse device/browser information, timestamps, a one-way household reference derived from a service-issued identifier, and Google Analytics' device/browser identifier. Google also receives ordinary network metadata such as the IP address and may use it to derive coarse geography. “Pseudonymous” means the events can be associated with the same device or household over time even though the analytics payload does not carry a person's name or email. Kintilla never sends names, household or board words, task/event/jot text, Spark prompts, photos, raw account or home IDs, full URLs, or other free text to product analytics. Advertising storage, ad-user data, ad personalization, and cross-site tracking stay off.
Household profiles and kids
Household members can create profiles for people who never sign up — including children. An adult supplies the profile's name and avatar, marks whether it is a child profile, and may add an optional Kindled Day with a private year and tether or relationship information. These profiles have no login, no email, and no account. Kintilla does not knowingly collect information directly from children; adults provide and control child-profile data inside their household team.
How we use information
- To run the product: showing your board, syncing devices in real time, sending the emails you'd expect (sign-in links, invitations, an optional daily household digest).
- To power AI features: Kintilla uses AI (Anthropic's Claude) to do things like suggest task schedules, name your team, summarize your week, and — only when you choose a photo and approve it — read a photo of a paper schedule or flyer to propose dates and tasks (Paper). Relevant household content is processed for these features. Kintilla does not use that content to train AI models or sell it.
- To improve and protect the service: debugging, abuse prevention, security, and—only when the device setting above is on—pseudonymous product analytics.
Who we share it with
No selling, no ad networks, no data brokers. Your information is shared only with the service providers that run Kintilla, under their own contractual privacy obligations:
- Supabase — database, authentication, and realtime infrastructure (hosted on AWS, US East)
- Anthropic — standard API AI processing for the features described above, including each Paper photo you explicitly approve; under its commercial retention policy, Anthropic may retain API inputs and outputs for up to 30 days and does not use them to train its models
- Postmark — transactional email delivery
- Cloudflare — website and app hosting
- Google — sign-in if you choose it; optional Google Analytics/Tag Manager; public-website font delivery; speech recognition when a Google, Android, or browser recognizer handles optional dictation; Firebase Cloud Messaging for native Android and iOS notifications; and Google Play billing on Android
- Apple — sign-in if you choose it; speech recognition when an Apple or iOS recognizer handles optional dictation; Apple Push Notification service for iOS delivery; and App Store billing
- Stripe — web checkout, receipts, and subscription management
- RevenueCat — native subscription purchase and entitlement processing, including provider-issued purchase history and status
Cloudflare and Supabase process the diagnostic and security-log fields described above. Google receives the bounded error-boundary and reliability events only when optional product analytics is on; error names, messages, stacks, household words, and free text do not enter those analytics events. Browser notifications may also pass through the push service operated by your browser or operating-system vendor.
Voice input. If you choose the microphone, the speech-recognition service supplied by your operating system or browser processes your live voice audio to create text. Depending on your device, browser, and system settings, it may send that audio to Apple, Google, or another system- or browser-selected provider for processing during the transcription under that provider's own privacy terms. Kintilla retains only the resulting text and does not retain an audio recording.
Paper photos. When you explicitly choose a photo (a flyer, schedule, or note) and tap read, that photo is resized on your device and sent once to Anthropic's Claude, which returns suggested dates and tasks for your review. Kintilla never stores the photo or the raw suggestions; Anthropic deletes API inputs and outputs within 30 days under its commercial retention policy and does not use them to train AI models. Nothing leaves your device until you approve each photo.
We may also disclose information if required by law, or as part of a business transfer (in which case this policy continues to apply).
Retention and deletion
Household history is kept so your team's board, streaks, and history search work. Free teams keep 90 days of searchable history; paid teams keep it while the home remains active. You can delete individual board items and accountless household profiles in-app. Any current member can also make one family-archive ZIP per home containing the shared household data they are allowed to see; a prepared archive expires after seven days and each download link expires after five minutes.
You can delete your account in Kintilla's Account & data screen, or use the always-available public deletion and support path if you cannot sign in. We complete verified support requests within 30 days. Account deletion removes the sign-in identity, email and provider identifier, every claimed person row linked to it, devices, sessions, and direct or targeted personal content from active product systems. Kintilla also removes the text, notes, board items, actions, profiles, drawings, files, and other user-generated content attributable to that account from shared homes, together with derived and cached copies. Content genuinely contributed by remaining members may stay with its home; unknown legacy authorship is purged conservatively rather than relabelled or assigned to a replacement profile.
An owner must hand off each shared home or choose whole-home deletion; a solo home is deleted with its owner account. Independent shared-home deletion may be immediate or use a seven-day grace period while its owner remains. Whole-home deletion removes the household and its boards, story, wall access, and home-owned files. We may retain limited security, fraud-prevention, billing, tax, provider-cleanup, closure-receipt, or legal records where necessary. For Sign in with Apple, Kintilla keeps a private, content-free marker after it observes the identity and stores any Apple revocation grant encrypted. At deletion, held grants are used to request revocation; a missing or unresolved grant goes to protected operator attention instead of being treated as proof that Apple has no record. This observation begins with the feature's rollout, so an Apple identity unlinked beforehand may be unknowable to Kintilla. Encrypted grants remain only while revocation or operator-verified absence is outstanding, then are removed. Content-free closure receipts expire within 30 days; protected backups and transactional-email or other technical processor copies age out under their configured retention; provider-managed sign-in or subscription records may remain with Google or Apple.
Your rights
Depending on where you live (including under GDPR and CCPA), you may have rights to access, correct, export, or delete your personal information, and to object to certain processing. Email hi@kintilla.com and we'll help — we don't discriminate against you for exercising these rights.
Security
Data is encrypted in transit, access is scoped per-household at the database layer (row-level security), and production credentials are held in managed secret stores with least-privilege access. No system is perfectly secure, but small-surface-area design is part of ours.
Changes
If this policy changes in a way that matters, we'll say so plainly on this page (and in-app once Kintilla has shipped) before the change takes effect.