Theme

Privacy policy

Effective September 27, 2026. This page describes what KinCircle does with information, based on how the service works.

Who runs KinCircle

KinCircle is operated by Opal IT. For a question about this policy or your information, email [email protected].

What a family circle stores

A circle is your family's shared space. Members put in the care information they choose to keep, including:

  • The person in care and the care card
  • Appointments
  • Medications, including the name, dose, schedule, instructions, purpose, and dose logs
  • Notes, comments, and reactions
  • Documents such as insurance cards, policies, and IDs, plus words copied from a PDF so the circle can search them
  • Circle chat
  • Household bills, recorded payments, and household renewals
  • The family tree, contacts, and places
  • Member names, email addresses, optional phone numbers, and roles

Your account stores your name, email address, and a hash of your password. An optional phone number is a contact number. If you turn on more ways to sign in, KinCircle also stores what that method needs: an encrypted authenticator secret, hashed recovery codes, passkeys, or a Google link. Family-tree photos can be stored for a person. New family-tree photos in JPEG, PNG, and WebP, and new document images, have location data and camera make and model removed before they are saved. A GIF family photo is stored as uploaded. JPEG, PNG, and WebP document images already had that metadata removed. Family-tree photos and HEIC document images saved before September 27, 2026 may still contain location or camera data. Upload the file again to remove it. KinCircle does not rewrite a photo or document that is already stored.

Google sign-in

You can sign in with Google after that Google account is linked to an existing KinCircle account with the same verified email. KinCircle does not create an account or a circle from Google.

The sign-in request asks Google only for the openid and email scopes. From Google's ID token we keep the verified email address and Google's account id (the subject). We use those to sign you in and to remember the link on your account. You can turn Google sign-in off from Account.

KinCircle does not access Gmail, Google Contacts, Google Drive, Google Calendar, or any other Google product. Google user data is not sold, not shared for advertising, and not used to train AI models. KinCircle's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Cookies

KinCircle uses cookies only to sign you in and keep you signed in. The session cookie (kincircle_session) lasts about 14 days. It is httpOnly. In production it is sent only over HTTPS. The database stores a hash of the cookie, not the cookie itself.

Two short-lived httpOnly cookies finish sign-in when they are needed: one for the Google sign-in check (about 10 minutes, sent to /api/auth/google, which covers starting sign-in and the callback), and one for an authenticator-app check (about 5 minutes). Your theme choice is saved in this browser's local storage. It is not a cookie.

KinCircle does not use advertising cookies or analytics cookies. The app does not include an analytics or tracking script.

Where information is stored

KinCircle runs on a private server in the United States, operated by the owner. The public site is served through Cloudflare. The application and its PostgreSQL database run on that server. The database is not opened to the internet.

When a data encryption key is configured, sensitive care text is encrypted at rest with AES-256-GCM. That covers the care card, note and comment text, medication name, dose, schedule, instructions, and purpose, dose-log notes, and appointment title, location, notes, place, and the other person's name on a visit. A readable copy of those fields can remain in the database until the operator removes it. If that key is not set, those fields are stored without that extra encryption.

Document files are encrypted with a separate key and kept outside the public website. They are not public links. If the documents key is missing, document upload is unavailable. When the data encryption key is set, dual-write is the default: a new family photo is also stored as an encrypted file next to the photo. ENCRYPTION_DUAL_WRITE=false stores that photo without the encrypted file. ENCRYPTION_CIPHERTEXT_ONLY=true stores only the encrypted file, unless dual-write is also turned on explicitly. If a stored care field cannot be opened and no readable copy is left, KinCircle shows that it can't be decrypted instead of a blank. Passwords are stored as bcrypt hashes. Session secrets are stored as SHA-256 hashes.

The operator keeps encrypted backups for 30 days.

IP addresses

Sign-in, registration, invite accept, forgot-password, email sign-in links, and the Help form store the client IP address in a rate-limit key. A sign-in key that also names an account stores a hash of the email, not the email itself. The running app keeps these keys in the database. An operator can point that store at memory for one process; those keys are then gone when the process stops. Each key covers a 15-minute window. The next time a limit is recorded, keys older than that window are deleted. A key can remain longer if nothing else is recorded.

Forgot-password attempts and email sign-in-link attempts store the IP address and the email address in plaintext. The next attempt deletes rows older than 15 minutes. A row can remain if nobody tries again.

Assistant calls and calendar-feed checks keep the client IP in memory on that server process, for about one minute (assistant) or 15 minutes (calendar feed). Those keys are not written to the database.

Browser and push details

If you turn on device reminders, KinCircle stores that browser's push address, the keys the browser uses for the notification, and the browser's User-Agent. Turning reminders off removes that browser. Signing out removes it when the sign-out request includes that push address. Changing the password, or an Owner or operator resetting it, removes every device for that account. The row is also removed when the push service reports that the device is gone.

The Help form puts the browser's User-Agent, shortened to 180 characters, in the email sent to support. KinCircle does not keep a separate copy of that email in the database.

An email sign-in link stores a SHA-256 hash of the User-Agent from the browser that used the link, not the raw header. The link expires in about 15 minutes. That row is not deleted on the same timer.

Activity log

The circle activity log keeps some care text in the row, not only an id. That includes a medication name when one is deleted or stopped, a medication name and whether a dose was taken or skipped when a dose is logged, an appointment title when a visit is deleted or a volunteer ask changes, a bill payee when a bill or payment is added, changed, or deleted, a renewal label, a contact or place name, a family-tree person's name, and an invite email address. When an assistant reads the circle, the log stores the tool name and a count or a reason code, not the care text the tool returned. These rows are not erased on a timer.

Email

When a Resend API key is configured, KinCircle sends email through Resend. That includes invites, one-time sign-in links, password and sign-in notices, appointment and note mail, the weekly summary if you turn it on, and messages from the Help form. If Resend is not configured, those messages are not delivered. Email can include care details the feature is meant to send, such as an appointment title, a medication name in the weekly summary, or a short note preview, and it goes to the people that feature is for.

Push notifications

If you turn on device reminders, KinCircle can send a short notification through your browser's push service. The text stays small. Examples are "Appointment tomorrow at 3:00 PM", "New message in your circle", "A bill is due today", and "A renewal is due soon". The notification does not include chat text, note text, medication names, bill amounts, or renewal details. Bill and renewal reminders are these short notifications. They are not emails.

Who can see circle information

Other KinCircle users cannot open your circle. People in the circle see information according to their role. Owners and Caregivers can add and edit. A Viewer can look, with less detail: Viewers do not see caregivers-only notes or documents, circle chat, bill amounts, account details, or bill notes, or renewal costs, policy numbers, notes, or confirmation numbers.

The operator console shows circle administration. It does not show the care card, notes, medications, or document files. For each circle it shows the name, whether it is archived, the member count, and whether it has an Owner, plus the person in care's display name and preferred name. For each member it shows the name, email, phone, and role. When the circle has one Owner and two-factor sign-in is on, it shows a control to turn that off. It does not show the authenticator secret, and it does not list two-factor status for other members. It shows open Owner invites: the email, when the invite expires, and the invite link when that link can still be shown. It shows how much document space is used and the limit. It shows assistant tokens for that circle: the label, the person and role the token acts as, when it was created, last used, and whether it expires or is revoked. The token secret is shown once, when it is created. It shows operator audit rows: the action, the time, the actor's name, and a short subject when the row has a name, such as a circle name, a member name, or an email stored as that name. The response for that page carries the short subject and the two-factor flag for that one Owner. After an operator password reset, the temporary password is shown once on that screen. An Owner can also create a read-only token so an assistant can read what that person's role can already see. That token cannot change circle data through KinCircle. KinCircle does not sell circle information and does not share it for advertising.

Deletion

You can delete items your role is allowed to change. Most deleted items stay in Recently deleted, where an Owner can restore them. They are not erased on a timer.

Documents are different. A deleted document stays in the recycle bin for 30 days. After 30 days a daily job permanently removes the file, its preview, the database rows, and any words copied from it. An Owner or Caregiver can restore a document during those 30 days, or delete it forever sooner.

There is no button that deletes an account or permanently erases a whole circle. The operator can archive a circle, which closes it for members and keeps the care information. To ask for an account or a circle to be deleted, email [email protected]. Those requests are honored.

Children

KinCircle is for adult family caregivers. It is not for children under 13. Do not create an account if you are under 13. We do not knowingly collect account information from children under 13.

Changes

If this policy changes, the new version will be posted on this page and the effective date at the top will change.

Privacy policy